Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-17590 EXPLOITDB MEDIUM text
AirTies Air 5442 Firmware 1.0.0.18 - Cross-Site Scripting via top.html productboardtype Parameter
AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
by Ismail Tasdelen
CVSS 6.1
CVE-2018-17588 EXPLOITDB MEDIUM text
AirTies Air 5021 1.0.0.18 - Cross-Site Scripting via top.html productboardtype Parameter
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
by Ismail Tasdelen
CVSS 6.1
CVE-2018-17587 EXPLOITDB MEDIUM text
AirTies Air 5750 1.0.0.18 - Cross-Site Scripting via top.html productboardtype Parameter
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
by Ismail Tasdelen
CVSS 6.1
CVE-2018-17399 EXPLOITDB CRITICAL text
jimtawl 2.2.7 - SQL Injection via id Parameter
SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17313 EXPLOITDB MEDIUM text
RICOH MP C307 Firmware - Stored Cross-Site Scripting via entryNameIn Parameter
On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
by Ismail Tasdelen
CVSS 6.1
CVE-2018-17310 EXPLOITDB MEDIUM text
RICOH MP C1803 JPN Firmware - Stored Cross-Site Scripting via entryNameIn Parameter
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
by Ismail Tasdelen
CVSS 6.1
CVE-2018-17593 EXPLOITDB MEDIUM text
AirTies Air 5453 1.0.0.18 - Cross-Site Scripting via top.html productboardtype Parameter
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
by Ismail Tasdelen
CVSS 6.1
EIP-2026-110217 EXPLOITDB text
OPAC EasyWeb Five 5.7 - 'nome' SQL Injection
by Ihsan Sencan
CVE-2018-17428 EXPLOITDB CRITICAL text
OPAC EasyWeb Five <5.7 - SQL Injection
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.
by Dino Barlattani
CVSS 9.8
EIP-2026-106041 EXPLOITDB text
Coaster CMS 5.5.0 - Cross-Site Scripting
by Ismail Tasdelen
CVE-2018-17843 EXPLOITDB CRITICAL text
ADD Clicking MLM Software <1.0 - SQL Injection
SQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0, Autopool MLM Software 1.0, Investment MLM Software 1.0, Bidding MLM Software 1.0, Moneyorder MLM Software 1.0, Repurchase MLM Software 1.0, and Gift MLM Software 1.0 via the member/readmsg.php msg_id parameter, the member/tree.php pid parameter, or the member/downline.php m_id parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17842 EXPLOITDB CRITICAL text
Scriptzee Hotel Booking Engine 1.0 - SQL Injection
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17840 EXPLOITDB CRITICAL text
Scriptzee Education Website 1.0 - SQL Injection
SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2018-17832 EXPLOITDB MEDIUM text
WUZHI CMS 2.0 - Cross-Site Scripting via index.php v or f Parameter
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
by Renzi
CVSS 6.1
EIP-2026-107187 EXPLOITDB text
Fork CMS 5.4.0 - Cross-Site Scripting
by Ismail Tasdelen
EIP-2026-107151 EXPLOITDB text
Flippa Marketplace Clone 1.0 - 'date_started' SQL Injection
by Ihsan Sencan
EIP-2026-105482 EXPLOITDB text
Binary MLM Software 1.0 - 'pid' SQL Injection
by Ihsan Sencan
EIP-2026-102402 EXPLOITDB text
ManageEngine AssetExplorer 6.2.0 - Cross-Site Scripting
by Ismail Tasdelen
EIP-2026-101566 EXPLOITDB text VERIFIED
Billion ADSL Router 400G 20151105641 - Cross-Site Scripting
by cakes
CVE-2018-17776 EXPLOITDB HIGH text VERIFIED
PCProtect Anti-Virus <4.8.35 - Privilege Escalation
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges by replacing an executable file with a Trojan horse.
by Hashim Jawad
CVSS 7.8
CVE-2018-8463 EXPLOITDB HIGH text VERIFIED
Microsoft Edge - Privilege Escalation
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8469.
by Google Security Research
CVSS 7.4
CVE-2018-8468 EXPLOITDB MEDIUM text VERIFIED
Windows - Elevation of Privilege via Sandbox Escape
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
by Google Security Research
CVSS 4.7
CVE-2018-16659 EXPLOITDB CRITICAL text
Rausoft ID.prove <2.95 - SQL Injection
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.
by Ilya Timchenko
CVSS 9.8
EIP-2026-119383 EXPLOITDB text
iWay Data Quality Suite Web Console 10.6.1.ga - XML External Entity Injection
by Sureshbabu Narvaneni
CVE-2018-8469 EXPLOITDB HIGH text VERIFIED
Microsoft Edge - Privilege Escalation
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8463.
by Google Security Research
CVSS 7.4