Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-54339 EXPLOITDB CRITICAL text
webgrind < 1.1 - Unauthenticated Remote Command Execution via dataFile Parameter
Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%27' to execute commands on the target system.
by Rafael Pedrero
CVSS 9.8
CVE-2023-54338 EXPLOITDB HIGH text
Tftpd32 SE 4.60 - Unquoted Service Path Privilege Escalation
Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permissions.
by Ismael Nava
CVSS 8.4
CVE-2023-54337 EXPLOITDB CRITICAL text
Sysax Multi Server 6.95 - Denial of Service via Administrative Password Field Overflow
Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.
by Luis Martínez
CVSS 9.1
CVE-2023-54336 EXPLOITDB HIGH text
Mediconta 3.7.27 - Privilege Escalation
Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\medicont3\ to inject malicious code that would execute with LocalSystem permissions during service startup.
by Luis Martínez
CVSS 8.4
CVE-2023-54335 EXPLOITDB CRITICAL text
eXtplorer < 2.1.14 - Unauthenticated Authentication Bypass and Remote Code Execution
eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.
by ErPaciocco
CVSS 9.8
CVE-2023-54334 EXPLOITDB CRITICAL text
Explorer++ 1.3.5.531 - Buffer Overflow via Long File Name Argument
Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH chain and potentially execute malicious code.
by Rafael Pedrero
CVSS 9.8
EIP-2026-117853 EXPLOITDB text
Resource Hacker v3.6.0.92 - Buffer overflow
by Rafael Pedrero
EIP-2026-117237 EXPLOITDB text
Gestionale Open 12.00.00 - 'DB_GO_80' Unquoted Service Path
by Luis Martínez
EIP-2026-117205 EXPLOITDB text
Frhed (Free hex editor) v1.6.0 - Buffer overflow
by Rafael Pedrero
EIP-2026-116223 EXPLOITDB text
Scdbg 1.0 - Buffer overflow DoS
by Rafael Pedrero
EIP-2026-115389 EXPLOITDB text
Hex Workshop v6.7 - Buffer overflow DoS
by Rafael Pedrero
CVE-2019-13068 EXPLOITDB MEDIUM text VERIFIED
Grafana < 6.2.5 - Cross-Site Scripting via Panel Drilldown Link Title or URL Field
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
by SimranJeet Singh
CVSS 5.4
EIP-2026-114615 EXPLOITDB text
Zentao Project Management System 17.0 - Authenticated Remote Code Execution (RCE)
by mister0xf
EIP-2026-114384 EXPLOITDB text
WPN-XM Serverstack for Windows 0.8.6 - Multiple Vulnerabilities
by Rafael Pedrero
EIP-2026-113376 EXPLOITDB text
WebTareas 2.4 - Reflected XSS (Unauthorised)
by Hubert Wojciechowski
EIP-2026-107125 EXPLOITDB text
FlatCore CMS 2.1.1 - Stored Cross-Site Scripting (XSS)
by Sinem Şahin
EIP-2026-105874 EXPLOITDB text
Clansphere CMS 2011.4 - Stored Cross-Site Scripting (XSS)
by Sinem Şahin
EIP-2026-105707 EXPLOITDB text
Canteen-Management v1.0 - XSS-Reflected
by nu11secur1ty
EIP-2026-105706 EXPLOITDB text
Canteen-Management v1.0 - SQL Injection
by nu11secur1ty
EIP-2026-105004 EXPLOITDB text
Aero CMS v0.0.1 - SQL Injection (no auth)
by Hubert Wojciechowski
EIP-2026-102477 EXPLOITDB text
Desktop Central 9.1.0 - Multiple Vulnerabilities
by Rafael Pedrero
CVE-2023-31903 EXPLOITDB CRITICAL text
GuppY CMS 6.00.10 - Unrestricted File Upload and Remote Code Execution via PHP File Upload
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
by Chokri Hammedi
CVSS 9.8
CVE-2018-5701 EXPLOITDB CRITICAL text
iolo System Shield 5.0.0.136 - Arbitrary Write via amp.sys IOCtl 0x00226003
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerability due to not validating input values from IOCtl 0x00226003.
by Brandon Marshall
CVSS 9.8
CVE-2022-37109 EXPLOITDB CRITICAL text
camp_project camp < 2022-07-21 - Insufficiently Protected Credentials via StaticFileHandler
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the password.txt file is not properly restricted as it is in the root directory served by StaticFileHandler and the Tornado rule to throw a 403 error when password.txt is accessed can be bypassed. Furthermore, it is not necessary to crack the password hash to authenticate with the application because the password hash is also used as the cookie secret, so an attacker can generate his own authentication cookie.
by Elias Hohl
CVSS 9.8
CVE-2022-34668 EXPLOITDB CRITICAL text
NVFLARE < 2.1.4 - Remote Code Execution via Pickle Deserialization
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.
by Elias Hohl
CVSS 9.8