Text Exploits

31,337 exploits tracked across all sources.

Sort: Activity Stars
CVE-2013-1662 EXPLOITDB text VERIFIED
Vmware Workstation - Access Control
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.
by Tavis Ormandy
CVE-2013-4124 EXPLOITDB text
Samba - Numeric Error
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
by x90c
CVE-2013-0632 EXPLOITDB CRITICAL text
Adobe ColdFusion <10 - Auth Bypass
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
by Scott Buckel
CVSS 9.8
EIP-2026-119011 EXPLOITDB text
Oracle Java - 'BytePackedRaster.verify()' Signed Integer Overflow
by Packet Storm
CVE-2013-4888 EXPLOITDB text VERIFIED
Digital Signage Xibo 1.4.2 - XSS
Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the layout parameter in the layout page.
by Jacob Holcomb
EIP-2026-114115 EXPLOITDB text
WordPress Plugin ThinkIT 0.1 - Multiple Vulnerabilities
by Yashar shahinzadeh
CVE-2013-4900 EXPLOITDB text VERIFIED
DeWeS web server <0.4.2 - Path Traversal
Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read arbitrary files via a ..%5c (dot dot encoded backslash) in a GET request.
by High-Tech Bridge
EIP-2026-102006 EXPLOITDB text
Sitecom N300/N600 Devices - Multiple Vulnerabilities
by Roberto Paleari
CVE-2013-3586 EXPLOITDB text
Samsung Smart Viewer - Authentication Bypass
Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.
by Andrea Fabrizi
EIP-2026-105571 EXPLOITDB text VERIFIED
Bo-Blog 2.1.1 - Cross-Site Scripting / SQL Injection
by Ashiyane Digital Security Team
CVE-2013-0526 EXPLOITDB text
IBM Avocent 1754 KVM - Command Injection
ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.
by Alejandro Alvarez Bravo
EIP-2026-111625 EXPLOITDB text VERIFIED
Quack Chat 1.0 - Multiple Vulnerabilities
by Dylan Irzi
EIP-2026-102275 EXPLOITDB text
Photo Transfer Upload 1.0 iOS - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-102222 EXPLOITDB text
Copy to WebDAV 1.1 iOS - Multiple Vulnerabilities
by Vulnerability-Lab
CVE-2013-5092 EXPLOITDB text VERIFIED
AlgoSec Firewall Analyzer 6.1-b86 - XSS
Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
by Asheesh kumar Mani Tripathi
EIP-2026-119012 EXPLOITDB text
Oracle Java - 'IntegerInterleavedRaster.verify()' Signed Integer Overflow
by Packet Storm
EIP-2026-113168 EXPLOITDB text
w-CMS 2.0.1 - Remote Code Execution
by ICheer_No0M
EIP-2026-112395 EXPLOITDB text
Spitfire CMS 1.1.4 - Cross-Site Request Forgery
by Yashar shahinzadeh
EIP-2026-111337 EXPLOITDB text VERIFIED
Pligg CMS 2.0.0rc2 - Cross-Site Request Forgery (File Creation)
by DaOne
EIP-2026-109233 EXPLOITDB text
Mac's CMS 1.1.4 - Multiple Vulnerabilities
by Yashar shahinzadeh
CVE-2014-1222 EXPLOITDB text
Vtiger Crm < 6.0.0 - Path Traversal
Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter in a download action. NOTE: it is likely that this issue is actually in the KCFinder third-party component, and it affects additional products besides Vtiger CRM.
by DaOne
CVE-2013-5117 EXPLOITDB text VERIFIED
DotNetNuke <10.1 - SQL Injection
SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.
by Sajjad Pourali
EIP-2026-105087 EXPLOITDB text
Alibaba Clone Tritanium Version - 'news_desc.html' SQL Injection
by IRAQ_JAGUAR
EIP-2026-104901 EXPLOITDB text VERIFIED
ACal 2.2.6 - 'view' Local File Inclusion
by ICheer_No0M
EIP-2026-105687 EXPLOITDB text VERIFIED
CakePHP 2.2.8/2.3.7 - AssetDispatcher Class Local File Inclusion
by Takeshi Terada