Text Exploits

31,337 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-113756 EXPLOITDB text VERIFIED
WordPress Plugin FlagEm - 'cID' Cross-Site Scripting
by IeDb ir
EIP-2026-109509 EXPLOITDB text
MLM (Multi Level Marketing) Script - Multiple Vulnerabilities
by 3spi0n
EIP-2026-106057 EXPLOITDB text VERIFIED
Collabtive - Multiple Vulnerabilities
by Enrico Cinquini
EIP-2026-102536 EXPLOITDB text
Sybase EAServer 6.3.1 - Multiple Vulnerabilities
by SEC Consult
EIP-2026-101550 EXPLOITDB text
Barracuda LB / SVF / WAF / WEF - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-101547 EXPLOITDB text
Barracuda CudaTel 2.6.02.040 - SQL Injection
by Vulnerability-Lab
EIP-2026-119359 EXPLOITDB text
Dell PacketTrap PSA 7.1 - Multiple Cross-Site Scripting Vulnerabilities
by Vulnerability-Lab
EIP-2026-119358 EXPLOITDB text
Dell PacketTrap MSP RMM 6.6.x - Multiple Cross-Site Scripting Vulnerabilities
by Vulnerability-Lab
CVE-2013-5979 EXPLOITDB text
Xibo - Path Traversal
Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php.
by Mahendra
CVE-2013-5099 EXPLOITDB text VERIFIED
Anchor CMS 0.9.1 - XSS
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some sources have reported that comments.php is vulnerable, but certain functions from comments.php are used by article.php.
by DURAKIBOX
EIP-2026-102315 EXPLOITDB text
WiFly 1.0 Pro iOS - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-102236 EXPLOITDB text
Flux Player 3.1.0 iOS - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-102228 EXPLOITDB text
ePhoto Transfer 1.2.1 iOS - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-101172 EXPLOITDB text VERIFIED
Barracuda CudaTel - Multiple Cross-Site Scripting Vulnerabilities
by Benjamin Kunz Mejri
EIP-2026-111902 EXPLOITDB text
Saurus CMS 4.7.1 - Multiple Vulnerabilities
by waraxe
EIP-2026-109377 EXPLOITDB text VERIFIED
MCImageManager - Multiple Vulnerabilities
by MustLive
EIP-2026-106402 EXPLOITDB text
Dell Kace 1000 SMA 5.4.70402 - Persistent Cross-Site Scripting
by Vulnerability-Lab
CVE-2013-2248 EXPLOITDB text VERIFIED
Apache Struts < 2.3.15.1 - Improper Input Validation
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
by Takeshi Terada
EIP-2026-102264 EXPLOITDB text
Olive File Manager 1.0.1 iOS - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-102242 EXPLOITDB text
FTP Sprite 1.2.1 iOS - Persistent Cross-Site Scripting
by Vulnerability-Lab
CVE-2013-4945 EXPLOITDB text
BMC Service Desk Express 10.2.1.95 - SQL Injection
Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLE_WIDGET_1, (3) TABLE_WIDGET_2, (4) browserDateTimeInfo, or (5) browserNumberInfo cookie parameter to DashBoardGUI.aspx; or the (6) UID parameter to login.aspx.
by Nuri Fattah
CVE-2013-4883 EXPLOITDB text
McAfee ePolicy Orchestrator <4.6.6 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary web script or HTML via the (1) instanceId parameter core/loadDisplayType.do; (2) instanceId or (3) monitorUrl parameter to console/createDashboardContainer.do; uid parameter to (4) ComputerMgmt/sysDetPanelBoolPie.do or (5) ComputerMgmt/sysDetPanelSummary.do; (6) uid, (7) orion.user.security.token, or (8) ajaxMode parameter to ComputerMgmt/sysDetPanelQry.do; or (9) uid, (10) orion.user.security.token, or (11) ajaxMode parameter to ComputerMgmt/sysDetPanelSummary.do.
by Nuri Fattah
EIP-2026-114080 EXPLOITDB text VERIFIED
WordPress Plugin Spicy Blogroll - Local File Inclusion
by Ahlspiess
CVE-2013-4946 EXPLOITDB text
BMC Service Desk Express 10.2.1.95 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.aspx, the (2) CallBack parameter to QV_grid.aspx, or the (3) HelpPage parameter to commonhelp.aspx.
by Nuri Fattah
CVE-2013-4954 EXPLOITDB text VERIFIED
Genetech Solutions Pie-Register <1.31 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in a register action. NOTE: some of these details are obtained from third party information.
by gravitylover