Text Exploits

31,364 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-8682 EXPLOITDB HIGH text VERIFIED
Microsoft Office 2007 - Improper Input Validation
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office 2007 Service Pack 3 , and Microsoft Office 2010 Service Pack 2 allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8683.
by Google Security Research
CVSS 8.8
CVE-2017-8683 EXPLOITDB MEDIUM text VERIFIED
Microsoft Windows 10 - Information Disclosure
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8682.
by Google Security Research
CVSS 5.5
CVE-2017-14244 EXPLOITDB CRITICAL text
iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 - Auth Bypass
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.
by Gem George
CVSS 9.8
CVE-2017-14507 EXPLOITDB CRITICAL text
Content Timeline plugin 4.4.2 - SQL Injection
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.
by Jeroen - IT Nerdbox
CVSS 9.8
EIP-2026-111572 EXPLOITDB text
PTCEvolution 5.50 - SQL Injection
by Ihsan Sencan
EIP-2026-107996 EXPLOITDB text
iTech Gigs Script 1.20 - 'cat' SQL Injection
by 8bitsec
EIP-2026-106138 EXPLOITDB text
Contact Manager 1.0 - 'femail' SQL Injection
by Ihsan Sencan
CVE-2017-14243 EXPLOITDB CRITICAL text
UTStar WA3002G4 ADSL Broadband Modem - Auth Bypass
An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administrative settings and obtain cleartext credentials from HTML source, as demonstrated by info.cgi, upload.cgi, backupsettings.cgi, pppoe.cgi, resetrouter.cgi, and password.cgi.
by Gem George
CVSS 9.8
EIP-2026-112645 EXPLOITDB text
Theater Management Script - SQL Injection
by Ihsan Sencan
EIP-2026-111569 EXPLOITDB text
PTC KSV1 Script 1.7 - 'type' SQL Injection
by Ihsan Sencan
EIP-2026-108944 EXPLOITDB text
Justdial Clone Script - 'fid' SQL Injection
by Ihsan Sencan
EIP-2026-106885 EXPLOITDB text
Enterprise Edition Payment Processor Script 3.7 - SQL Injection
by Ihsan Sencan
EIP-2026-104964 EXPLOITDB text
Adserver Script 5.6 - SQL Injection
by Ihsan Sencan
CVE-2017-8759 EXPLOITDB HIGH text
Microsoft .net Framework - Code Injection
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
by Voulnet
CVSS 7.8
EIP-2026-118755 EXPLOITDB text VERIFIED
Mako Web Server 2.5 - Multiple Vulnerabilities
by hyp3rlinx
EIP-2026-107749 EXPLOITDB text
ICTraveling 2.2 - Authentication Bypass
by Ihsan Sencan
EIP-2026-107748 EXPLOITDB text
ICSurvey 1.1 - SQL Injection
by Ihsan Sencan
EIP-2026-107747 EXPLOITDB text
ICStudents 1.2 - 'key' SQL Injection
by Ihsan Sencan
EIP-2026-107746 EXPLOITDB text
ICSiteBuilder 1.1 - SQL Injection
by Ihsan Sencan
EIP-2026-107745 EXPLOITDB text
ICRestaurant software 1.4 - 'key' SQL Injection
by Ihsan Sencan
EIP-2026-107744 EXPLOITDB text
ICProjectBidding 1.1 - SQL Injection
by Ihsan Sencan
EIP-2026-107743 EXPLOITDB text
ICProductConfigurator 1.1 - 'key' SQL Injection
by Ihsan Sencan
EIP-2026-107740 EXPLOITDB text
ICMLM 2.1 - 'key' SQL Injection
by Ihsan Sencan
EIP-2026-107739 EXPLOITDB text
ICLowBidAuction 3.3 - SQL Injection
by Ihsan Sencan
EIP-2026-107738 EXPLOITDB text
ICJewelry 1.1 - 'key' SQL Injection
by Ihsan Sencan