Exploitdb Exploits

31,341 exploits tracked across all sources.

Sort: Activity Stars
CVE-2022-40319 EXPLOITDB HIGH text
Lsoft Listserv - IDOR
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauthorized modification of a victim's LISTSERV account.
by Shaunt Der-Grigorian
CVSS 7.5
CVE-2023-53974 EXPLOITDB HIGH text
D-Link DSL-124 ME_1.00 - Info Disclosure
D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.
by Aryan Chehreghani
CVSS 7.5
CVE-2023-54331 EXPLOITDB HIGH text
Outline 1.6.0 - Privilege Escalation
Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the OutlineService executable to inject malicious code that will be executed with LocalSystem permissions.
by Milad karimi
CVSS 7.8
EIP-2026-118693 EXPLOITDB text
Internet Download Manager v6.41 Build 3 - Remote Code Execution (RCE)
by M. Akil Gündoğan
EIP-2026-107676 EXPLOITDB text
Human Resource Management System 1.0 - SQL Injection (unauthenticated)
by Matthijs van der Vaart (eMVee)
EIP-2026-107574 EXPLOITDB text
Helmet Store Showroom v1.0 - SQL Injection
by Ameer Hamza
EIP-2026-105586 EXPLOITDB text
Book Store Management System 1.0.0 - Stored Cross-Site Scripting (XSS)
by Rajeshwar Singh
EIP-2026-102093 EXPLOITDB text
Uniview NVR301-04S2-P4 - Reflected Cross-Site Scripting (XSS)
by Bleron Rrustemi
CVE-2023-54333 EXPLOITDB HIGH text
Social-Share-Buttons 2.2.3 - SQL Injection
Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted POST requests with malicious SQL payloads to retrieve and potentially steal entire database contents.
by nu11secur1ty
CVSS 8.2
CVE-2023-54332 EXPLOITDB MEDIUM text
Automattic Jetpack - XSS
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.
by Behrouz Mansoori
CVSS 6.1
CVE-2021-47750 EXPLOITDB MEDIUM text
Youphptube < 7.8 - XSS
YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.
by Rafael Pedrero
CVSS 6.1
CVE-2021-47749 EXPLOITDB MEDIUM text
Youphptube < 7.8 - Path Traversal
YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php to include and view PHP files outside the intended directory by using directory traversal sequences.
by Rafael Pedrero
CVSS 5.5
EIP-2026-117974 EXPLOITDB text
SugarSync 4.1.3 - 'SugarSync Service' Unquoted Service Path
by Jorge Manuel Lozano Gómez
EIP-2026-117266 EXPLOITDB text
HDD Health 4.2.0.112 - 'HDDHealth' Unquoted Service Path
by Jorge Manuel Lozano Gómez
EIP-2026-116508 EXPLOITDB text
VMware Workstation 15 Pro - Denial of Service
by Milad karimi
EIP-2026-116348 EXPLOITDB text
SuperMailer v11.20 - Buffer overflow DoS
by Rafael Pedrero
CVE-2022-36551 EXPLOITDB MEDIUM text
Heartex - Label Studio Community Edition <1.5.0 - SSRF
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF.
by Ryan Smith
CVSS 6.5
EIP-2026-112468 EXPLOITDB text
Subrion CMS 4.2.1 - Stored Cross-Site Scripting (XSS)
by Sinem Şahin
EIP-2026-111977 EXPLOITDB text
Senayan Library Management System v9.5.0 - SQL Injection
by nu11secur1ty
EIP-2026-111816 EXPLOITDB text
rukovoditel 3.2.1 - Cross-Site Scripting (XSS)
by nu11secur1ty
EIP-2026-110182 EXPLOITDB text VERIFIED
Online shopping system advanced 1.0 - Multiple Vulnerabilities
by Rafael Pedrero
EIP-2026-109587 EXPLOITDB text
Moodle LMS 4.0 - Cross-Site Scripting (XSS)
by Saud Alenazi
EIP-2026-107708 EXPLOITDB text
iBooking v1.0.8 - Arbitrary File Upload
by d1z1n370/oPty
CVE-2022-3552 EXPLOITDB HIGH text VERIFIED
Boxbilling < 0.0.1 - Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.
by zetc0de
CVSS 7.2
EIP-2026-105436 EXPLOITDB text
Beauty-salon v1.0 - Remote Code Execution (RCE)
by nu11secur1ty