Text Exploits

31,383 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106263 EXPLOITDB text
CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
by Daniel González
CVE-2023-4407 EXPLOITDB MEDIUM text
Credit Lite 1.5.4 - SQL Injection via POST Request Handler
A vulnerability classified as critical was found in Codecanyon Credit Lite 1.5.4. Affected by this vulnerability is an unknown functionality of the file /portal/reports/account_statement of the component POST Request Handler. The manipulation of the argument date1/date2 leads to sql injection. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-237511.
by CraCkEr
CVSS 6.3
EIP-2026-105536 EXPLOITDB text VERIFIED
Blood Donor Management System v1.0 - Stored XSS
by Ehlullah Albayrak
CVE-2022-23513 EXPLOITDB MEDIUM text
Pi-hole AdminLTE < 5.17 - Unauthenticated Improper Access Control in queryads Endpoint
Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of application, this vulnerability exists because of a lack of validation in code on a root server path: `/admin/scripts/pi-hole/phpqueryads.php.` Potential threat actor(s) are able to perform an unauthorized query search in blocked domain lists. This could lead to the disclosure for any victims' personal blacklists.
by kv1to
CVSS 5.3
CVE-2023-40852 EXPLOITDB CRITICAL text VERIFIED
User Registration & Login and User Management System With Admin Panel 3.0 - SQL Injection via Admin Username Field
SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.
by Ashutosh Singh Umath
CVSS 9.8
CVE-2023-40851 EXPLOITDB MEDIUM text VERIFIED
User Registration & Login System 3.0 - Stored XSS via Registration Form
Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page.
by Ashutosh Singh Umath
CVSS 5.4
EIP-2026-112939 EXPLOITDB text
Uvdesk 1.1.4 - Stored XSS (Authenticated)
by Hubert Wojciechowski
CVE-2023-31067 EXPLOITDB CRITICAL text
TSplus Remote Access <16.0.2.14 - Info Disclosure
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.
by shinnai
CVSS 9.8
CVE-2023-31068 EXPLOITDB CRITICAL text
TSplus Remote Access <16.0.2.14 - Info Disclosure
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.
by shinnai
CVSS 9.8
CVE-2023-31069 EXPLOITDB CRITICAL text
TSplus Remote Access <16.0.2.14 - Info Disclosure
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.
by shinnai
CVSS 9.8
CVE-2023-31468 EXPLOITDB HIGH text
Inosoft VisiWin <2022-2.1 - Privilege Escalation
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\INOSOFT GmbH" folder has weak permissions for Everyone, allowing an attacker to insert a Trojan horse file that runs as SYSTEM. 2024-1 is a fixed version.
by shinnai
CVSS 7.8
EIP-2026-112563 EXPLOITDB text
Taskhub CRM Tool 2.8.6 - SQL Injection
by Ahmet Ümit BAYRAM
EIP-2026-111086 EXPLOITDB text
PHPJabbers Business Directory Script v3.2 - Multiple Vulnerabilities
by Kerimcan Ozturk
EIP-2026-110427 EXPLOITDB text
OVOO Movie Portal CMS v3.3.3 - SQL Injection
by Ahmet Ümit BAYRAM
EIP-2026-107425 EXPLOITDB text
Global - Multi School Management System Express v1.0- SQL Injection
by Ahmet Ümit BAYRAM
EIP-2026-106527 EXPLOITDB text
Dolibarr Version 17.0.1 - Stored XSS
by Furkan Karaarslan
CVE-2023-37759 EXPLOITDB CRITICAL text
Crypto Currency Tracker < 9.5 - Unauthenticated Admin Registration via User Registration Page
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.
by 0xBr
CVSS 9.8
EIP-2026-106065 EXPLOITDB text VERIFIED
Color Prediction Game v1.0 - SQL Injection
by Ahmet Ümit BAYRAM
EIP-2026-101267 EXPLOITDB text
EuroTel ETL3100 - Transmitter Unauthenticated Config/Log Download
by LiquidWorm
EIP-2026-101266 EXPLOITDB text
EuroTel ETL3100 - Transmitter Default Credentials
by LiquidWorm
EIP-2026-101265 EXPLOITDB text
EuroTel ETL3100 - Transmitter Authorization Bypass (IDOR)
by LiquidWorm
CVE-2022-47636 EXPLOITDB HIGH text
OutSystems Service Studio 11 11.53.30 - Uncontrolled Search Path Element via .oml File Handling
A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Modeling Language), the application will load the following DLLs from the same directory av_libGLESv2.dll, libcef.DLL, user32.dll, and d3d10warp.dll. Using a crafted DLL, it is possible to execute arbitrary code in the context of the current logged in user.
by shinnai
CVSS 7.8
CVE-2023-53880 EXPLOITDB MEDIUM text
Lucee 5.4.2.17 - Authenticated Reflected Cross-Site Scripting via Admin Interface Parameters
Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through administrative interface parameters. Attackers can craft specific payloads targeting admin pages like server.cfm and web.cfm to execute arbitrary JavaScript in victim's browser sessions.
by Yehia Elghaly
CVE-2023-29689 EXPLOITDB CRITICAL text
PyroCMS 3.9 - Remote Code Execution via Server-Side Template Injection
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
by Daniel Barros
CVSS 9.8
CVE-2023-4174 EXPLOITDB LOW text VERIFIED
mooSocial mooStore 3.1.6 - Cross-Site Scripting
A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The identifier VDB-236209 was assigned to this vulnerability.
by CraCkEr
CVSS 3.5