Text Exploits

31,337 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-112343 EXPLOITDB text VERIFIED
Sonar - Multiple Cross-Site Scripting Vulnerabilities
by DevilTeam
EIP-2026-110356 EXPLOITDB text VERIFIED
osCommerce - Cross-Site Request Forgery
by Jakub Galczyk
EIP-2026-105509 EXPLOITDB text VERIFIED
BlackNova Traders - 'news.php' SQL Injection
by ITTIHACK
CVE-2013-10062 EXPLOITDB MEDIUM text VERIFIED
Linksys router <1.0.00-1.0.05 - Path Traversal
A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05), specifically in the /apply.cgi endpoint. Authenticated attackers can exploit the next_page POST parameter to access arbitrary files outside the intended web root by injecting traversal sequences. This allows exposure of sensitive system files and configuration data.
by m-1-k-3
CVE-2013-10059 EXPLOITDB HIGH text
D-Link DIR-615H1 <8.04 - Command Injection
An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowing attackers to inject arbitrary shell commands using backtick encapsulation. With default credentials, an attacker can exploit this blind injection vector to execute arbitrary commands.
by m-1-k-3
CVSS 7.2
CVE-2013-10058 EXPLOITDB HIGH text
Linksys router <v2.0.03 - Command Injection
An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operations. An attacker with valid credentials can inject arbitrary shell commands, enabling remote code execution.
by m-1-k-3
CVE-2013-0008 EXPLOITDB text
Microsoft Windows Vista - Access Control
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
by 0vercl0k
EIP-2026-107954 EXPLOITDB text
IRIS Citations Management Tool - (Authenticated) Remote Command Execution
by aeon
EIP-2026-107946 EXPLOITDB text VERIFIED
IP.Gallery 4.2.x/5.0.x - Persistent Cross-Site Scripting
by Mohamed Ramadan
EIP-2026-103483 EXPLOITDB text
Google Chrome - Silent HTTP Authentication
by T355
EIP-2026-102053 EXPLOITDB text
TP-Link - Admin Panel Multiple Cross-Site Request Forgery Vulnerabilities
by CYBSEC Labs
CVE-2013-2678 EXPLOITDB HIGH text
Cisco Linksys E4200 1.0.05 - Code Injection
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.
by m-1-k-3
CVSS 8.1
EIP-2026-101836 EXPLOITDB text
Linksys WAG200G - Multiple Vulnerabilities
by m-1-k-3
CVE-2013-2678 EXPLOITDB HIGH text VERIFIED
Cisco Linksys E4200 1.0.05 - Code Injection
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.
by m-1-k-3
CVSS 8.1
EIP-2026-101515 EXPLOITDB text
Air Disk Wireless 1.9 iPad iPhone - Multiple Vulnerabilities
by Vulnerability-Lab
EIP-2026-106697 EXPLOITDB text VERIFIED
Easy Live Shop System - SQL Injection
by Ramdan Yantu
EIP-2026-114345 EXPLOITDB text VERIFIED
WordPress Theme Pinboard - 'tab' Cross-Site Scripting
by Henrique Montenegro
EIP-2026-101482 EXPLOITDB text VERIFIED
TP-Link TL-WR2543ND Router - Admin Panel Multiple Cross-Site Request Forgery Vulnerabilities
by Juan Manuel Garcia
CVE-2013-10061 EXPLOITDB HIGH text
Netgear routers <1.1.00.45 - Command Injection
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in the setup.cgi endpoint. The vulnerability arises from improper input neutralization, enabling command injection through crafted POST requests. This flaw enables remote attackers to deploy payloads or manipulate system state post-authentication.
by m-1-k-3
CVSS 7.2
CVE-2012-4914 EXPLOITDB text VERIFIED
CoolPDF 3.0.2.256 - Buffer Overflow
Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a PDF document with a crafted stream.
by Chris Gabriel
CVE-2013-1465 EXPLOITDB CRITICAL text VERIFIED
Cubecart < 5.2.0 - Insecure Deserialization
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
by EgiX
CVSS 9.8
EIP-2026-102121 EXPLOITDB text
WirelessFiles 1.1 iPad iPhone - Multiple Vulnerabilities
by Vulnerability-Lab
CVE-2013-1408 EXPLOITDB text VERIFIED
Wysija Newsletters < 2.2 - SQL Injection
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.
by High-Tech Bridge
CVE-2013-1409 EXPLOITDB text VERIFIED
Commentluv < 2.92.3 - XSS
Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/admin-ajax.php.
by High-Tech Bridge
EIP-2026-107597 EXPLOITDB text VERIFIED
Hiverr 2.2 - Multiple Vulnerabilities
by xStarCode