Exploitdb Exploits
31,339 exploits tracked across all sources.
Apple Quicktime < 7.7.2 - Memory Corruption
Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Targa image.
by Senator of Pirates
WordPress Theme Madebymilk - 'id' SQL Injection
by Ashiyane Digital Security Team
WordPress Plugin Facebook Survey 1.0 - SQL Injection
by Vulnerability Research Laboratory
openSIS 5.1 - 'ajax.php' Local File Inclusion
by Julian Horoszkiewicz
SonicWALL CDP 5040 6.x - Multiple Vulnerabilities
by Vulnerability-Lab
Omni-Secure - 'dir' Multiple File Disclosure Vulnerabilities
by HaCkeR_EgY
WordPress Theme Dailyedition-mouss - 'id' SQL Injection
by Ashiyane Digital Security Team
WordPress Plugin Tagged Albums - 'id' SQL Injection
by Ashiyane Digital Security Team
friendsinwar FAQ Manager - 'view_faq.php?question' SQL Injection
by unsuprise
Friends in War The FAQ Manager - 'question' SQL Injection
by unsuprise
ATutor 2.1 - 'tool_file' Local File Inclusion
by Julian Horoszkiewicz
Novell NetIQ Privileged User Manager 2.3.1 - 'ldapagnt.dll' ldapagnt_eval() Perl Code Evaluation Remote Code Execution
by rgod
Microfocus Privileged User Manager - Path Traversal
Directory traversal vulnerability in the set_log_config function in regclnt.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 allows remote authenticated users to create or overwrite arbitrary files via directory traversal sequences in a log pathname.
by rgod
iDev Rentals 1.0 - Multiple Vulnerabilities
by Vulnerability-Lab
Friends in War Make or Break 1.3 - Authentication Bypass
by d3b4g
Baby Gekko <1.2.2f - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/index.php or the (2) username or (3) password parameter in blocks/loginbox/loginbox.template.php to index.php. NOTE: some of these details are obtained from third party information.
by High-Tech Bridge SA
Myrephp Myre Business Directory - SQL Injection
SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter.
by d3b4g
Myrephp Myre Vacation Rental - SQL Injection
Multiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL commands via the (1) garage1 or (2) bathrooms1 parameter to vacation/1_mobile/search.php, or (3) unspecified input to vacation/widgate/request_more_information.php.
by d3b4g
Myrephp Myre Realty Manager - SQL Injection
Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands via the bathrooms1 parameter to (1) demo2/search.php or (2) search.php.
by d3b4g
By Source