Exploitdb Exploits
31,339 exploits tracked across all sources.
XnView - '.ECW' Image Processing Heap Overflow
by Francis Provencher
Webify (Multiple Products) - Multiple HTML Injection / Local File Inclusions
by snup
Simple Document Management System 1.1.5 - Multiple SQL Injections
by JosS
News Script PHP 1.2 - Multiple Vulnerabilities
by Vulnerability-Lab
iScripts EasyCreate 2.0 - Multiple Vulnerabilities
by Vulnerability-Lab
WordPress Plugin ORGanizer - Multiple Vulnerabilities
by MustLive
Joomla! Component JCal Pro Calendar - SQL Injection
by Taurus Omar
ADICO - 'index.php' Script SQL Injection
by Ibrahim El-Sayed
Esri Arcmap < 10.0.2.3200 - Code Injection
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.
by Boston Cyber Defense
Swoopo Gold Shop CMS 8.4.56 - Multiple Web Vulnerabilities
by Vulnerability-Lab
Squirrelcart Cart Shop 3.3.4 - Multiple Web Vulnerabilities
by Vulnerability-Lab
Simple Forum PHP - Multiple SQL Injections
by Vulnerability Research Laboratory
NetArt Media Jobs Portal - SQL Injection
by Ibrahim El-Sayed
Myrephp Myre Real Estate Software - SQL Injection
Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrary SQL commands via the (1) link_idd parameter to 1_mobile/listings.php or (2) userid parameter to 1_mobile/agentprofile.php.
by Vulnerability-Lab
Cells Blog CMS 1.1 - Multiple Web Vulnerabilities
by Vulnerability-Lab
Squiz CMS - Multiple Cross-Site Scripting / XML External Entity Injection Vulnerabilities
by Nadeem Salim
Juniper Networks MSS <7.6.3-7.7.1-7.5.3-7.4-7.3 - XSS
Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter name.
by Craig Lambert
XAMPP for Windows 1.7.7 - Multiple Cross-Site Scripting / SQL Injections
by Sangteamtham
Microsoft Windows OpenType Font - File Format Denial of Service
by Cr4sh
Devfarm WP Gpx Maps - Unrestricted File Upload
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
by Adrien Thierry
CVSS 9.8
By Source