Exploitdb Exploits

31,364 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-117478 EXPLOITDB text
Microsoft Baseline Security Analyzer 2.3 - XML External Entity Injection
by hyp3rlinx
EIP-2026-112333 EXPLOITDB text
Softneta MedDream PACS Server Premium 6.7.1.1 - Directory Traversal
by Carlos Avila
EIP-2026-109382 EXPLOITDB text
MedDream PACS Server Premium 6.7.1.1 - 'email' SQL Injection
by Carlos Avila
EIP-2026-103231 EXPLOITDB text
Tenable WAS-Scanner 7.4.1708 - Remote Command Execution
by Sameer Goyal
CVE-2018-0715 EXPLOITDB MEDIUM text
Qnap Photo Station < 5.7.0 - XSS
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
by Mitsuaki Shiraishi
CVSS 6.1
CVE-2018-25142 EXPLOITDB CRITICAL text
NovaRad NovaPACS Diagnostics Viewer <8.5.19.75 - XXE Injection
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.
by LiquidWorm
CVSS 9.8
CVE-2018-15917 EXPLOITDB MEDIUM text
Jorani - XSS
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.
by Javier Olmedo
CVSS 5.4
CVE-2018-15918 EXPLOITDB MEDIUM text VERIFIED
Jorani - SQL Injection
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.
by Javier Olmedo
CVSS 5.4
CVE-2018-16059 EXPLOITDB MEDIUM text
Endress Wirelesshart Fieldgate Swg70 Firmware - Path Traversal
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
by Hamit CİBO
CVSS 5.3
EIP-2026-101626 EXPLOITDB text
D-Link Dir-600M N150 - Cross-Site Scripting
by PUNIT DARJI
EIP-2026-119594 EXPLOITDB text
Microsoft People 10.1807.2131.0 - Denial of service (PoC)
by L0RD
CVE-2018-14497 EXPLOITDB MEDIUM text
Tenda D152 - XSS
Tenda D152 ADSL routers allow XSS via a crafted SSID.
by Sandip Dey
CVSS 5.4
CVE-2018-19457 EXPLOITDB HIGH text
Logicspice FAQ Script <2.9.7 - Command Injection
Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faqimages with a .php file.
by AkkuS
CVSS 7.2
CVE-2018-17110 EXPLOITDB CRITICAL text
Simple POS 4.0.24 - SQL Injection
Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.
by Renos Nikolaou
CVSS 9.8
EIP-2026-110696 EXPLOITDB text
PHP File Browser Script 1 - Directory Traversal
by AkkuS
EIP-2026-109589 EXPLOITDB text
mooSocial Store Plugin 2.6 - SQL Injection
by Andrea Bocchetti
CVE-2018-25207 EXPLOITDB HIGH text
Online Quiz Maker 1.0 SQL Injection via catid Parameter
Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POST requests to quiz-system.php or add-category.php with crafted SQL payloads in POST parameters to extract sensitive database information or bypass authentication.
by AkkuS
CVSS 7.1
CVE-2018-16252 EXPLOITDB LOW text
Fspro Event Log Explorer - XXE
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
by hyp3rlinx
CVSS 3.3
EIP-2026-104955 EXPLOITDB text
Admidio 3.3.5 - Cross-Site Request Forgery (Change Permissions)
by Nawaf Alkeraithe
CVE-2018-15839 EXPLOITDB CRITICAL text
Dlink Dir-615 Firmware - Memory Corruption
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
by Aniket Dinda
CVSS 9.8
CVE-2018-15844 EXPLOITDB HIGH text
Damicms - CSRF
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.
by Autism_JH
CVSS 8.8
EIP-2026-102108 EXPLOITDB text VERIFIED
Vox TG790 ADSL Router - Cross-Site Scripting
by cakes
CVE-2018-17140 EXPLOITDB MEDIUM text
WordPress Quizlord <2.0 - XSS
The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php.
by Renos Nikolaou
CVSS 5.4
CVE-2018-17138 EXPLOITDB MEDIUM text
Jibu Pro <1.7 - XSS
The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php name (aka Quiz Name) field.
by Renos Nikolaou
CVSS 5.4
CVE-2018-16133 EXPLOITDB MEDIUM text VERIFIED
Cybrotech Cybrohttpserver - Path Traversal
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
by Emre ÖVÜNÇ
CVSS 5.3