Text Exploits

31,346 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-4367 EXPLOITDB CRITICAL text VERIFIED
Apple Iphone OS < 12.1 - Memory Corruption
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
by Google Security Research
CVSS 9.8
CVE-2018-18957 EXPLOITDB CRITICAL text
Mz-automation Libiec61850 - Out-of-Bounds Write
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c.
by Dhiraj Mishra
CVSS 9.8
CVE-2018-4384 EXPLOITDB HIGH text VERIFIED
Apple Iphone OS < 12.1 - Memory Corruption
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1, watchOS 5.1.
by Google Security Research
CVSS 7.8
EIP-2026-117498 EXPLOITDB text
Microsoft Internet Explorer 11 - Null Pointer Dereference
by LiquidWorm
EIP-2026-113384 EXPLOITDB text
WebVet 0.1a - 'id' SQL Injection
by Ihsan Sencan
EIP-2026-113142 EXPLOITDB text
Voovi Social Networking Script 1.0 - 'user' SQL Injection
by Ihsan Sencan
EIP-2026-112039 EXPLOITDB text
SiAdmin 1.1 - 'id' SQL Injection
by Ihsan Sencan
EIP-2026-111407 EXPLOITDB text
Poppy Web Interface Generator 0.8 - Arbitrary File Upload
by Ihsan Sencan
EIP-2026-109555 EXPLOITDB text
Mongo Web Admin 6.0 - Information Disclosure
by Ihsan Sencan
CVE-2018-25208 EXPLOITDB HIGH text
qdPM 9.1 SQL Injection via filter_by Parameters
qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through filter_by parameters. Attackers can submit malicious POST requests to the timeReport endpoint with crafted filter_by[CommentCreatedFrom] and filter_by[CommentCreatedTo] parameters to execute arbitrary SQL queries and retrieve sensitive data.
by AkkuS
CVSS 8.2
CVE-2018-25135 EXPLOITDB CRITICAL text
Anviz AIM CrossChex Standard 4.3.6.0 - Code Injection
Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.
by LiquidWorm
CVSS 9.8
EIP-2026-114537 EXPLOITDB text
Yot CMS 3.3.1 - 'aid' SQL Injection
by Ihsan Sencan
EIP-2026-108076 EXPLOITDB text
Jelastic 5.4 - 'host' SQL Injection
by Procode701
EIP-2026-107349 EXPLOITDB text
Gate Pass Management System 2.1 - 'login' SQL Injection
by Ihsan Sencan
EIP-2026-107045 EXPLOITDB text
Fantastic Blog CMS 1.0 - 'id' SQL Injection
by Ihsan Sencan
CVE-2018-18776 EXPLOITDB MEDIUM text
Microstrategy Web - XSS
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product.
by Rafael Pedrero
CVSS 6.1
CVE-2018-18775 EXPLOITDB MEDIUM text
Microstrategy Web - XSS
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product.
by Rafael Pedrero
CVSS 6.1
EIP-2026-113317 EXPLOITDB text
Webiness Inventory 2.9 - Arbitrary File Upload
by Boumediene KADDOUR
EIP-2026-112904 EXPLOITDB text
University Application System 1.0 - SQL Injection / Cross-Site Request Forgery (Add Admin)
by Ihsan Sencan
EIP-2026-112903 EXPLOITDB text
University Application System 1.0 - SQL Injection / Cross-Site Request Forgery (Add Admin)
by Ihsan Sencan
EIP-2026-112359 EXPLOITDB text
South Gate Inn Online Reservation System 1.0 - 'q' SQL Injection
by Ihsan Sencan
EIP-2026-111224 EXPLOITDB text
phptpoint Pharmacy Management System 1.0 - 'username' SQL Injection
by Boumediene KADDOUR
EIP-2026-109958 EXPLOITDB text
Notes Manager 1.0 - Arbitrary File Upload
by Ihsan Sencan
EIP-2026-109711 EXPLOITDB text
MyBB Downloads 2.0.3 - SQL Injection
by Lucian Ioan Nitescu
EIP-2026-107873 EXPLOITDB text
Instagram Clone 1.0 - Arbitrary File Upload
by Ihsan Sencan