Text Exploits

31,368 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-6410 EXPLOITDB CRITICAL text VERIFIED
Machform - SQL Injection
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
by Amine Taouirsa
CVSS 9.8
CVE-2018-6409 EXPLOITDB MEDIUM text VERIFIED
Machform - Path Traversal
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.
by Amine Taouirsa
CVSS 5.3
CVE-2018-6411 EXPLOITDB CRITICAL text VERIFIED
Machform - Unrestricted File Upload
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
by Amine Taouirsa
CVSS 9.8
CVE-2018-10094 EXPLOITDB CRITICAL text VERIFIED
Dolibarr <7.0.2 - SQL Injection
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.
by Sysdream
CVSS 9.8
CVE-2018-11522 EXPLOITDB MEDIUM text
Yosoro - XSS
Yosoro 1.0.4 has stored XSS.
by Carlo Pelliccioni
CVSS 6.1
CVE-2018-1124 EXPLOITDB HIGH text
procps-ng <3.3.15 - Privilege Escalation
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
by Qualys Corporation
CVSS 7.8
CVE-2018-11538 EXPLOITDB HIGH text
Searchblox - CSRF
servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.
by Ahmet Gurel
CVSS 8.8
CVE-2018-25154 EXPLOITDB CRITICAL text
GNU Barcode 0.99 - Buffer Overflow
GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.
by LiquidWorm
CVSS 9.8
CVE-2018-11535 EXPLOITDB CRITICAL text
Sitemakin Slac - SQL Injection
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection.
by Divya Jain
CVSS 9.8
CVE-2018-11532 EXPLOITDB MEDIUM text
Changuondyu Advanced Statistics - XSS
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.
by 0xB9
CVSS 6.1
EIP-2026-107027 EXPLOITDB text
Facebook Clone Script 1.0.5 - Cross-Site Request Forgery
by L0RD
EIP-2026-107026 EXPLOITDB text
Facebook Clone Script 1.0.5 - 'search' SQL Injection
by L0RD
EIP-2026-102856 EXPLOITDB text
GNU Barcode 0.99 - Memory Leak
by LiquidWorm
CVE-2018-11523 EXPLOITDB CRITICAL text
Nuuo Nvrmini 2 Firmware < 3.6.5 - Unrestricted File Upload
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
by M3@Pandas
CVSS 9.8
EIP-2026-100375 EXPLOITDB text
IssueTrak 7.0 - SQL Injection
by Chris Anastasio
CVE-2018-11714 EXPLOITDB CRITICAL text
TP-Link TL-WR840N/TL-WR841N <5 - Info Disclosure
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
by BlackFog Team
CVSS 9.8
EIP-2026-113729 EXPLOITDB text
WordPress Plugin Events Calendar - SQL Injection
by AkkuS
CVE-2018-11512 EXPLOITDB MEDIUM text
Creatiwity Witycms - XSS
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.
by Nathu Nandwani
CVSS 4.8
EIP-2026-108657 EXPLOITDB text
Joomla! Component Full Social 1.1.0 - 'search_query' SQL Injection
by L0RD
CVE-2018-11404 EXPLOITDB MEDIUM text
Domainmod - XSS
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
by longer
CVSS 6.1
CVE-2018-11403 EXPLOITDB MEDIUM text
Domainmod - XSS
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
by longer
CVSS 5.4
EIP-2026-113596 EXPLOITDB text
WordPress Plugin Booking Calendar 3.0.0 - SQL Injection / Cross-Site Scripting
by AkkuS
EIP-2026-109664 EXPLOITDB text
My Directory 2.0 - SQL Injection / Cross-Site Scripting
by AkkuS
EIP-2026-109231 EXPLOITDB text
Lyrist - 'id' SQL Injection
by Meisam Monsef
EIP-2026-109170 EXPLOITDB text
Listing Hub CMS 1.0 - SQL Injection
by AkkuS