Exploitdb Exploits

31,341 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-53893 EXPLOITDB MEDIUM text
Ateme TITAN File 3.9.12.4 - SSRF
Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations.
by LiquidWorm
CVSS 6.5
CVE-2023-38904 EXPLOITDB MEDIUM text VERIFIED
Netlify CMS <2.10.192 - XSS
A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code via a crafted payload to the body parameter of the new post function.
by tmrswrr
CVSS 5.4
CVE-2023-36165 EXPLOITDB text
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
by Idan Malihi
CVE-2023-36164 EXPLOITDB text
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
by Idan Malihi
CVE-2023-36166 EXPLOITDB text
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
by Idan Malihi
CVE-2023-36167 EXPLOITDB text
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
by Idan Malihi
EIP-2026-114679 EXPLOITDB text
Frappe Framework (ERPNext) 13.4.0 - Remote Code Execution (Authenticated)
by Sander Ferdinand
CVE-2023-36163 EXPLOITDB MEDIUM text
IP-DOT BuildaGate <v.BuildaGate5 - XSS
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.
by Idan Malihi
CVSS 6.1
CVE-2022-21907 EXPLOITDB CRITICAL text
HTTP Protocol Stack - RCE
HTTP Protocol Stack Remote Code Execution Vulnerability
by nu11secur1ty
CVSS 9.8
EIP-2026-107034 EXPLOITDB text VERIFIED
Faculty Evaluation System v1.0 - SQL Injection
by Andrey Stoykov
CVE-2023-33131 EXPLOITDB HIGH text
Microsoft Outlook - RCE
Microsoft Outlook Remote Code Execution Vulnerability
by nu11secur1ty
CVSS 8.8
EIP-2026-111298 EXPLOITDB text
Piwigo v13.7.0 - Stored Cross-Site Scripting (XSS) (Authenticated)
by Okan Kurtulus
CVE-2023-33145 EXPLOITDB MEDIUM text
Microsoft Edge < - Info Disclosure
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
by nu11secur1ty
CVSS 6.5
EIP-2026-105720 EXPLOITDB text
Car Rental Script 1.8 - Stored Cross-site scripting (XSS)
by CraCkEr
EIP-2026-105435 EXPLOITDB text
Beauty Salon Management System v1.0 - SQLi
by Fatih Nacar
CVE-2023-37602 EXPLOITDB MEDIUM text
Alkacon Opencms - XSS
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
by tmrswrr
CVSS 6.1
CVE-2023-53903 EXPLOITDB MEDIUM text VERIFIED
WebsiteBaker 2.13.3 - XSS
WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks.
by Mirabbas Ağalarov
CVSS 5.4
CVE-2023-53902 EXPLOITDB MEDIUM text VERIFIED
WebsiteBaker 2.13.3 - Path Traversal
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.
by Mirabbas Ağalarov
CVSS 6.5
CVE-2023-53901 EXPLOITDB MEDIUM text
WBCE CMS 1.6.1 - XSS
WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attackers can upload a crafted HTML file with CSS-based keylogging techniques to intercept password characters through background image requests.
by Mirabbas Ağalarov
CVSS 5.4
CVE-2023-53900 EXPLOITDB HIGH text
Spip 4.1.10 - XSS
Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.
by nu11secur1ty
CVSS 8.8
CVE-2023-53899 EXPLOITDB CRITICAL text
PodcastGenerator 3.2.9 - SSRF
PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.
by Mirabbas Ağalarov
CVSS 9.8
CVE-2023-53898 EXPLOITDB MEDIUM text
Rukovoditel 3.4.1 - XSS
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.
by Mirabbas Ağalarov
CVSS 5.4
CVE-2023-53897 EXPLOITDB MEDIUM text
Rukovoditel 3.4.1 - XSS
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.
by Mirabbas Ağalarov
CVSS 5.4
CVE-2023-53896 EXPLOITDB HIGH text
D-Link DAP-1325 1.01 - Info Disclosure
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.
by ieduardogoncalves
CVSS 7.5
CVE-2022-4297 EXPLOITDB CRITICAL text
Netflixtech WP Autocomplete Search < 1.0.4 - SQL Injection
The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection
by matitanium
CVSS 9.8