Text Exploits

31,368 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-25195 EXPLOITDB HIGH text
Wecodex Hotel CMS 1.0 SQL Injection via Admin Login
Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.
by AkkuS
CVSS 8.2
CVE-2018-25185 EXPLOITDB HIGH text
Wecodex Restaurant CMS 1.0 SQL Injection via Login
Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the username parameter. Attackers can send POST requests to the login endpoint with malicious SQL payloads using boolean-based blind or time-based blind techniques to extract sensitive database information.
by AkkuS
CVSS 8.2
CVE-2018-25183 EXPLOITDB HIGH text
Shipping System CMS 1.0 SQL Injection via admin login
Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious SQL payloads using boolean-based blind techniques in POST requests to the admin login endpoint to authenticate without valid credentials.
by AkkuS
CVSS 8.2
EIP-2026-119470 EXPLOITDB text
FTPShell Server 6.80 - Denial of Service
by Hashim Jawad
EIP-2026-113950 EXPLOITDB text
WordPress Plugin Peugeot Music - Arbitrary File Upload
by Mr.7z
EIP-2026-113389 EXPLOITDB text
Wecodex Store Paypal 1.0 - SQL Injection
by AkkuS
EIP-2026-110677 EXPLOITDB text
PHP Dashboards 4.5 - SQL Injection
by AkkuS
EIP-2026-110676 EXPLOITDB text
PHP Dashboards 4.5 - 'email' SQL Injection
by AkkuS
EIP-2026-109800 EXPLOITDB text
MySQL Smart Reports 1.0 - 'id' SQL Injection / Cross-Site Scripting
by AkkuS
EIP-2026-109797 EXPLOITDB text
MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection / Cross-Site Scripting
by AkkuS
EIP-2026-109796 EXPLOITDB text
MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection
by AkkuS
EIP-2026-109795 EXPLOITDB text
MySQL Blob Uploader 1.7 - 'home-file-edit.php' SQL Injection / Cross-Site Scripting
by AkkuS
EIP-2026-109794 EXPLOITDB text
MySQL Blob Uploader 1.7 - 'download.php' SQL Injection / Cross-Site Scripting
by AkkuS
EIP-2026-109524 EXPLOITDB text
Mobile Card Selling Platform 1 - Cross-Site Request Forgery
by L0RD
EIP-2026-109375 EXPLOITDB text
Mcard Mobile Card Selling Platform 1 - SQL Injection
by L0RD
EIP-2026-107467 EXPLOITDB text
GPSTracker 1.0 - 'id' SQL Injection
by AkkuS
EIP-2026-107409 EXPLOITDB text
Gigs 2.0 - 'username' SQL Injection
by AkkuS
EIP-2026-106947 EXPLOITDB text
eWallet Online Payment Gateway 2 - Cross-Site Request Forgery
by L0RD
EIP-2026-106737 EXPLOITDB text
EasyService Billing 1.0 - SQL Injection / Cross-Site Scripting
by AkkuS
EIP-2026-106736 EXPLOITDB text
EasyService Billing 1.0 - 'p1' SQL Injection
by AkkuS
EIP-2026-103280 EXPLOITDB text
Honeywell Scada System - Information Disclosure
by t4rkd3vilz
EIP-2026-102007 EXPLOITDB text
SKT LTE Wi-Fi SDT-CW3B1 - Unauthorized Admin Credential Change
by Safak Aslan
CVE-2018-10751 EXPLOITDB MEDIUM text VERIFIED
Samsung Mobile - Integer Overflow
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.
by Google Security Research
CVSS 5.3
CVE-2018-8897 EXPLOITDB HIGH text VERIFIED
Intel 64 and IA-32 Architectures - Privilege Escalation
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a Linux kernel crash. The MOV to SS and POP SS instructions inhibit interrupts (including NMIs), data breakpoints, and single step trap exceptions until the instruction boundary following the next instruction (SDM Vol. 3A; section 6.8.3). (The inhibited data breakpoints are those on memory accessed by the MOV to SS or POP to SS instruction itself.) Note that debug exceptions are not inhibited by the interrupt enable (EFLAGS.IF) system flag (SDM Vol. 3A; section 2.3). If the instruction following the MOV to SS or POP to SS instruction is an instruction like SYSCALL, SYSENTER, INT 3, etc. that transfers control to the operating system at CPL < 3, the debug exception is delivered after the transfer to CPL < 3 is complete. OS kernels may not expect this order of events and may therefore experience unexpected behavior when it occurs.
by Can Bölük
CVSS 7.8
EIP-2026-114580 EXPLOITDB text
Zechat 1.5 - SQL Injection / Cross-Site Request Forgery
by L0RD