Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-102856 EXPLOITDB text
GNU Barcode 0.99 - Memory Leak
by LiquidWorm
CVE-2018-11523 EXPLOITDB CRITICAL text
NUUO NVRmini 2 Firmware < 3.6.5 - Arbitrary File Upload via upload.php
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
by M3@Pandas
CVSS 9.8
EIP-2026-100375 EXPLOITDB text
IssueTrak 7.0 - SQL Injection
by Chris Anastasio
CVE-2018-11714 EXPLOITDB CRITICAL text
TP-Link TL-WR840N/TL-WR841N <5 - Info Disclosure
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
by BlackFog Team
CVSS 9.8
EIP-2026-113729 EXPLOITDB text
WordPress Plugin Events Calendar - SQL Injection
by AkkuS
CVE-2018-11512 EXPLOITDB MEDIUM text
wityCMS 0.6.1 - Authenticated Stored Cross-Site Scripting via Website Name Field
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.
by Nathu Nandwani
CVSS 4.8
EIP-2026-108657 EXPLOITDB text
Joomla! Component Full Social 1.1.0 - 'search_query' SQL Injection
by L0RD
CVE-2018-11404 EXPLOITDB MEDIUM text
DomainMod 4.09.03 - Cross-Site Scripting via SSL Provider Account Parameter
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
by longer
CVSS 6.1
CVE-2018-11403 EXPLOITDB MEDIUM text
DomainMod 4.09.03 - Cross-Site Scripting via Account Owner OID Parameter
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
by longer
CVSS 5.4
EIP-2026-113596 EXPLOITDB text
WordPress Plugin Booking Calendar 3.0.0 - SQL Injection / Cross-Site Scripting
by AkkuS
EIP-2026-109664 EXPLOITDB text
My Directory 2.0 - SQL Injection / Cross-Site Scripting
by AkkuS
EIP-2026-109231 EXPLOITDB text
Lyrist - 'id' SQL Injection
by Meisam Monsef
EIP-2026-109170 EXPLOITDB text
Listing Hub CMS 1.0 - SQL Injection
by AkkuS
EIP-2026-107843 EXPLOITDB text
Ingenious School Management System - 'id' SQL Injection
by Meisam Monsef
CVE-2018-11332 EXPLOITDB MEDIUM text
ClipperCMS 1.3.3 - Stored Cross-Site Scripting via Site Name Field
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file.
by Nathu Nandwani
CVSS 4.8
EIP-2026-105590 EXPLOITDB text
BookingWizz Booking System 5.5 - 'id' SQL Injection
by AkkuS
EIP-2026-105369 EXPLOITDB text
Baby Names Search Engine 1.0 - 'a' SQL Injection
by AkkuS
CVE-2018-11220 EXPLOITDB HIGH text
Bitmain Antminer D3, L3+, and S9 Firmware - Remote Command Execution via System Restore Function
Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.
by CorryL
CVSS 8.8
CVE-2018-11505 EXPLOITDB HIGH text
Werewolf Online 0.8.8 - Exposure of Firebase Token via Logcat Output
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
by ManhNho
CVSS 7.5
EIP-2026-109807 EXPLOITDB text
mySurvey 1.0 - 'id' SQL Injection
by AkkuS
EIP-2026-106865 EXPLOITDB text
Employee Work Schedule 5.9 - 'cal_id' SQL Injection
by AkkuS
CVE-2018-11443 EXPLOITDB MEDIUM text
EasyService Billing 1.0 - Cross-Site Scripting via jobcard-ongoing.php q Parameter
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
by Divya Jain
CVSS 6.1
CVE-2018-11444 EXPLOITDB CRITICAL text
EasyService Billing 1.0 - SQL Injection via jobcard-ongoing.php q Parameter
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
by Divya Jain
CVSS 9.8
EIP-2026-106720 EXPLOITDB text
easyLetters 1.0 - 'id' SQL Injection
by AkkuS
EIP-2026-105055 EXPLOITDB text
Ajax Full Featured Calendar 2.0 - 'search' SQL Injection
by AkkuS