Exploitdb Exploits

31,364 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-1188 EXPLOITDB MEDIUM text VERIFIED
Dell EMC Isilon - XSS
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and versions 7.2.1.x is affected by a cross-site scripting vulnerability in the Authorization Providers page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
by Core Security
CVSS 4.8
CVE-2018-1187 EXPLOITDB MEDIUM text VERIFIED
Dell EMC Isilon - XSS
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6 is affected by a cross-site scripting vulnerability in the Network Configuration page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
by Core Security
CVSS 4.8
CVE-2018-1186 EXPLOITDB MEDIUM text VERIFIED
Dell EMC Isilon - XSS
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
by Core Security
CVSS 4.8
CVE-2018-6940 EXPLOITDB MEDIUM text
Nat32 - CSRF
A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with CSRF.
by hyp3rlinx
CVSS 6.1
CVE-2018-6941 EXPLOITDB HIGH text
Nat32 - CSRF
A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with XSS.
by hyp3rlinx
CVSS 8.8
EIP-2026-112934 EXPLOITDB text
userSpice 4.3 - Cross-Site Scripting
by Dolev Farhi
EIP-2026-112296 EXPLOITDB text
Social Oauth Login PHP - Authentication Bypass
by L0RD
EIP-2026-112280 EXPLOITDB text
SOA School Management - 'access_login' SQL Injection
by L0RD
CVE-2018-1213 EXPLOITDB HIGH text VERIFIED
Dell Emc Isilon Onefs < 7.2.1.6 - CSRF
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2 is affected by a cross-site request forgery vulnerability. A malicious user may potentially exploit this vulnerability to send unauthorized requests to the server on behalf of authenticated users of the application.
by Core Security
CVSS 8.8
CVE-2018-6928 EXPLOITDB CRITICAL text
News Website Script - SQL Injection
PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.
by Varun Bagaria
CVSS 9.8
CVE-2015-5112 EXPLOITDB text
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2015. Notes: none
by smgorelik
CVE-2018-6889 EXPLOITDB HIGH text
Typesetter - Code Injection
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.
by Navina Asrani
CVSS 8.8
CVE-2019-25258 EXPLOITDB HIGH text
LogicalDOC Enterprise 7.7.4 - Info Disclosure
LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files through unverified 'suffix' and 'fileVersion' parameters. Attackers can exploit directory traversal techniques in /thumbnail and /convertpdf endpoints to access sensitive system files like win.ini and /etc/passwd by manipulating path traversal sequences.
by LiquidWorm
CVSS 7.5
CVE-2019-25257 EXPLOITDB MEDIUM text
LogicalDOC Enterprise 7.7.4 - Command Injection
LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.
by LiquidWorm
CVSS 6.5
EIP-2026-102396 EXPLOITDB text
LogicalDOC Enterprise 7.7.4 - User Enumeration
by LiquidWorm
EIP-2026-111700 EXPLOITDB text
Readymade Video Sharing Script 3.2 - 'search' SQL Injection
by Varun Bagaria
EIP-2026-110503 EXPLOITDB text
Paypal Clone Script 1.0.9 - 'id' / 'acctype' SQL Injection
by L0RD
EIP-2026-109838 EXPLOITDB text
Naukri Clone Script 3.0.3 - 'indus' SQL Injection
by L0RD
CVE-2018-6845 EXPLOITDB MEDIUM text
Olx Clone Script - XSS
PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field.
by Varun Bagaria
CVSS 6.1
EIP-2026-110189 EXPLOITDB text VERIFIED
Online Test Script 2.0.7 - 'cid' SQL Injection
by L0RD
EIP-2026-106890 EXPLOITDB text VERIFIED
Entrepreneur Dating Script 2.0.2 - Authentication Bypass
by L0RD
CVE-2017-13236 EXPLOITDB HIGH text VERIFIED
Google Android - Incorrect Permission Assignment
In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217699.
by Google Security Research
CVSS 7.8
CVE-2017-14521 EXPLOITDB HIGH text VERIFIED
WonderCMS 2.3.1 - Code Injection
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
by Samrat Das
CVSS 8.8
CVE-2017-14523 EXPLOITDB HIGH text
WonderCMS 2.3.1 - SSRF
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack
by Samrat Das
CVSS 7.5
EIP-2026-112452 EXPLOITDB text
Student Profile Management System Script 2.0.6 - Authentication Bypass
by L0RD