Exploitdb Exploits

31,329 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-17616 EXPLOITDB CRITICAL text
Event Calendar Category Script - SQL Injection
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17596 EXPLOITDB CRITICAL text
Entrepreneur Job Portal Script - SQL Injection
Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17648 EXPLOITDB CRITICAL text
Entrepreneur Dating Script - SQL Injection
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17610 EXPLOITDB CRITICAL text
E-commerce Mlm Software - SQL Injection
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17594 EXPLOITDB CRITICAL text VERIFIED
Domainsale Php Script - SQL Injection
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17611 EXPLOITDB CRITICAL text
Doctor Search Script - SQL Injection
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17605 EXPLOITDB CRITICAL text
Consumer Complaints Clone Script - SQL Injection
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17606 EXPLOITDB CRITICAL text
Co-work Space Search Script - SQL Injection
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17607 EXPLOITDB CRITICAL text
Cms Auditor Website - SQL Injection
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17608 EXPLOITDB CRITICAL text
Kindergarten - Elementary School Listing Script - SQL Injection
Child Care Script 1.0 has SQL Injection via the /list city parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17609 EXPLOITDB CRITICAL text
Chartered Accountant Booking Script - SQL Injection
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17601 EXPLOITDB CRITICAL text
Cab Booking Script - SQL Injection
Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.
by Ihsan Sencan
CVSS 9.8
EIP-2026-110292 EXPLOITDB text
OpenEMR 5.0.0 - OS Command Injection / Cross-Site Scripting
by SEC Consult
EIP-2026-110291 EXPLOITDB text
OpenEMR 5.0.0 - OS Command Injection / Cross-Site Scripting
by SEC Consult
EIP-2026-107281 EXPLOITDB text VERIFIED
FS IMDB Clone - 'id' SQL Injection
by Dan°
EIP-2026-107277 EXPLOITDB text VERIFIED
FS Facebook Clone - 'token' SQL Injection
by Dan°
CVE-2017-17085 EXPLOITDB HIGH text VERIFIED
Wireshark <2.4.3 & <2.2.11 - DoS
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.
by Wireshark
CVSS 7.5
EIP-2026-107288 EXPLOITDB text VERIFIED
FS Shaadi Clone - 'token' SQL Injection
by Dan°
EIP-2026-107284 EXPLOITDB text VERIFIED
FS Makemytrip Clone - 'id' SQL Injection
by Dan°
CVE-2017-11319 EXPLOITDB HIGH text VERIFIED
Resolver Perspective - Improper Privilege Management
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges by leveraging insufficient validation methods and missing cross server side checking mechanisms.
by Konstantinos Alexiou
CVSS 8.8
CVE-2017-17110 EXPLOITDB CRITICAL text VERIFIED
Techno Portfolio Management Panel 1.0 - SQL Injection
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
by Ihsan Sencan
CVSS 9.8
CVE-2017-17111 EXPLOITDB CRITICAL text VERIFIED
Posty Readymade Classifieds Script 1.0 - SQL Injection
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.
by Ihsan Sencan
CVSS 9.8
EIP-2026-114837 EXPLOITDB text VERIFIED
Abyss Web Server < 2.11.6 - Heap Memory Corruption
by hyp3rlinx
CVE-2017-17055 EXPLOITDB CRITICAL text
Artica Web Proxy <3.06.112911 - XSS
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.
by hyp3rlinx
CVSS 9.0
CVE-2017-16884 EXPLOITDB MEDIUM text VERIFIED
MistServer <2.13 - XSS
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to failed authentication requests alerts.
by hyp3rlinx
CVSS 6.1