Text Exploits

31,329 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-7456 EXPLOITDB HIGH text
Moxa MXView 2.8 - DoS
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.
by hyp3rlinx
CVSS 7.5
EIP-2026-108119 EXPLOITDB text
Jobscript4Web 4.5 - Authentication Bypass
by TurkCyberArmy
CVE-2017-7461 EXPLOITDB MEDIUM text
Intellinet NFC-30ir IP Camera <LM.1.6.16.05 - Path Traversal
Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows remote attackers to read arbitrary files via a request to a vendor-supplied CGI script that is used to read HTML text file, but that does not do any URI/path sanitization.
by Dimitri Fousekis
CVSS 4.9
CVE-2017-6360 EXPLOITDB CRITICAL text VERIFIED
Qnap Qts < 4.2.4 - OS Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
by Harry Sintonen
CVSS 9.8
CVE-2017-6359 EXPLOITDB CRITICAL text VERIFIED
Qnap Qts < 4.2.4 - OS Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
by Harry Sintonen
CVSS 9.8
EIP-2026-114189 EXPLOITDB text
WordPress Plugin WHIZZ < 1.1.1 - Cross-Site Request Forgery
by Zhiyang Zeng
EIP-2026-112502 EXPLOITDB text
Survey Template 1.1 - 'masterkey1' SQL Injection
by Ihsan Sencan
EIP-2026-112029 EXPLOITDB text
Shopping Cart Template - 'item' SQL Injection
by Ihsan Sencan
EIP-2026-111653 EXPLOITDB text
Quiz Template 1.0 - 'testid' SQL Injection
by Ihsan Sencan
EIP-2026-109665 EXPLOITDB text
My Gaming Ladder Combo System 7.5 - SQL Injection
by Ihsan Sencan
EIP-2026-109060 EXPLOITDB text
Ladder System 6.0 - 'faqid' SQL Injection
by Ihsan Sencan
EIP-2026-107942 EXPLOITDB text
Invoice Template - 'hash' SQL Injection
by Ihsan Sencan
EIP-2026-107200 EXPLOITDB text
Forum Template 1.0 - SQL Injection
by Ihsan Sencan
EIP-2026-106496 EXPLOITDB text
Document Management Template - 'hash' SQL Injection
by Ihsan Sencan
EIP-2026-105692 EXPLOITDB text
Calendar Template 2.0 - 'editid1' SQL Injection
by Ihsan Sencan
CVE-2017-7462 EXPLOITDB CRITICAL text
Intellinet NFC-30ir IP Camera - RCE
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.
by Dimitri Fousekis
CVSS 9.8
CVE-2017-6190 EXPLOITDB HIGH text
Dlink Dwr-116 Firmware - Path Traversal
Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.
by Patryk Bogdan
CVSS 7.5
CVE-2017-6361 EXPLOITDB CRITICAL text VERIFIED
Qnap Qts < 4.2.4 - OS Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
by Harry Sintonen
CVSS 9.8
CVE-2017-7185 EXPLOITDB HIGH text
Cesanta Mongoose <6.7 - DoS
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.
by Compass Security
CVSS 7.5
CVE-2017-7446 EXPLOITDB HIGH text
HelpDEZk 1.1.1 - CSRF
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
by rungga_reksya
CVSS 8.8
CVE-2017-7237 EXPLOITDB CRITICAL text
Spiceworks Inventory <7.5 - Path Traversal
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69, as demonstrated by a WRQ (aka Write request) operation for a configuration file or an executable file.
by hyp3rlinx
CVSS 9.8
EIP-2026-112504 EXPLOITDB text
Sweepstakes Pro Software - SQL Injection
by Ihsan Sencan
EIP-2026-111488 EXPLOITDB text
Premium Penny Auction Script - SQL Injection
by Ihsan Sencan
EIP-2026-107795 EXPLOITDB text
ImagePro Lazygirls Clone Script - SQL Injection
by Ihsan Sencan
CVE-2017-7447 EXPLOITDB HIGH text
HelpDEZk 1.1.1 - CSRF
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
by rungga_reksya
CVSS 8.8