Text Exploits

31,329 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108009 EXPLOITDB text
Itech News Portal Script 6.28 - 'sc' SQL Injection
by Ihsan Sencan
EIP-2026-108003 EXPLOITDB text
Itech Movie Portal Script 7.37 - SQL Injection
by Ihsan Sencan
EIP-2026-107998 EXPLOITDB text
Itech Inventory Management Software 3.77 - SQL Injection
by Ihsan Sencan
EIP-2026-107981 EXPLOITDB text
Itech Auction Script 6.49 - 'pid' SQL Injection
by Ihsan Sencan
EIP-2026-100027 EXPLOITDB text VERIFIED
Google Android - 'rkp_set_init_page_ro' RKP Memory Corruption
by Google Security Research
EIP-2026-109205 EXPLOITDB text
LogoStore - 'query' SQL Injection
by Kaan KAMIS
EIP-2026-101068 EXPLOITDB text
QNAP NVR/NAS Devices - Buffer Overflow (PoC)
by bashis
EIP-2026-100056 EXPLOITDB text VERIFIED
Google Android - RKP EL1 Code Loading Bypass
by Google Security Research
EIP-2026-100031 EXPLOITDB text VERIFIED
Google Android - Unprotected MSRs in EL1 RKP Privilege Escalation
by Google Security Research
EIP-2026-100030 EXPLOITDB text VERIFIED
Google Android - RKP Information Disclosure via s2-remapping Physical Ranges
by Google Security Research
EIP-2026-100023 EXPLOITDB text VERIFIED
Google Android - 'cfp_ropp_new_key_reenc' / 'cfp_ropp_new_key' RKP Memory Corruption
by Google Security Research
EIP-2026-118068 EXPLOITDB text
Viscosity 1.6.7 - Local Privilege Escalation
by Kacper Szurek
EIP-2026-101893 EXPLOITDB text
Netman 204 - Backdoor Account / Password Reset
by Simon Gurney
EIP-2026-101565 EXPLOITDB text
Billion / TrueOnline / ZyXEL Routers - Multiple Vulnerabilities
by Pedro Ribeiro
CVE-2017-20137 EXPLOITDB MEDIUM text
Itech B2B Script 4.28 - SQL Injection
A vulnerability was found in Itech B2B Script 4.28. It has been rated as critical. This issue affects some unknown processing of the file /catcompany.php. The manipulation of the argument token with the input 704667c6a1e7ce56d3d6fa748ab6d9af3fd7' AND 6539=6539 AND 'Fakj'='Fakj leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
by Kaan KAMIS
CVSS 6.3
CVE-2017-20136 EXPLOITDB MEDIUM text
Itech Classifieds Script 7.27 - SQL Injection
A vulnerability classified as critical has been found in Itech Classifieds Script 7.27. Affected is an unknown function of the file /subpage.php. The manipulation of the argument scat with the input =51' AND 4941=4941 AND 'hoCP'='hoCP leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
by Kaan KAMIS
CVSS 6.3
CVE-2017-20135 EXPLOITDB MEDIUM text
Itech Dating Script 3.26 - SQL Injection
A vulnerability classified as critical was found in Itech Dating Script 3.26. Affected by this vulnerability is an unknown functionality of the file /see_more_details.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
by Kaan KAMIS
CVSS 6.3
CVE-2017-20134 EXPLOITDB MEDIUM text
Itech Freelancer Script 5.13 - SQL Injection
A vulnerability, which was classified as critical, has been found in Itech Freelancer Script 5.13. Affected by this issue is some unknown functionality of the file /category.php. The manipulation of the argument sk leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
by Kaan KAMIS
CVSS 6.3
CVE-2017-20132 EXPLOITDB MEDIUM text
Itech Multi Vendor Script 6.49 - SQL Injection
A vulnerability was found in Itech Multi Vendor Script 6.49 and classified as critical. This issue affects some unknown processing of the file /multi-vendor-shopping-script/product-list.php. The manipulation of the argument pl leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
by Kaan KAMIS
CVSS 6.3
CVE-2017-20131 EXPLOITDB MEDIUM text
Itech News Portal 6.28 - SQL Injection
A vulnerability was found in Itech News Portal 6.28. It has been classified as critical. Affected is an unknown function of the file /news-portal-script/information.php. The manipulation of the argument inf leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
by Kaan KAMIS
CVSS 6.3
CVE-2017-20130 EXPLOITDB MEDIUM text
Itech Real Estate Script 3.12 - SQL Injection
A vulnerability was found in Itech Real Estate Script 3.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /real-estate-script/search_property.php. The manipulation of the argument property_for leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
by Kaan KAMIS
CVSS 6.3
EIP-2026-110744 EXPLOITDB text
PHP Product Designer Script - Arbitrary File Upload
by Ihsan Sencan
CVE-2017-5630 EXPLOITDB HIGH text
PHP Pear - Injection
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.
by hyp3rlinx
CVSS 7.5
EIP-2026-110720 EXPLOITDB text
PHP Logo Designer Script - Arbitrary File Upload
by Ihsan Sencan
EIP-2026-108018 EXPLOITDB text
Itech Video Sharing Script 4.94 - SQL Injection
by Ihsan Sencan