Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-104000 EXPLOITDB text VERIFIED
Nagios XI - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
by anonymous
EIP-2026-113758 EXPLOITDB text VERIFIED
WordPress Plugin flash-album-gallery - 'flagshow.php' Cross-Site Scripting
by Am!r
CVE-2011-4684 EXPLOITDB text VERIFIED
Opera < 11.60 - Certificate Revocation Handling Issue
Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."
by anonymous
EIP-2026-113800 EXPLOITDB text VERIFIED
WordPress Plugin GRAND FlAGallery 1.57 - 'flagshow.php' Cross-Site Scripting
by Am!r
EIP-2026-114464 EXPLOITDB text
Xoops 2.5.4 - Blind SQL Injection
by blkhtc0rp
EIP-2026-114153 EXPLOITDB text VERIFIED
WordPress Plugin UPM Polls 1.0.4 - Blind SQL Injection
by Saif
EIP-2026-111306 EXPLOITDB text VERIFIED
Pixie 1.04 - Blog Post Cross-Site Request Forgery
by hackme
EIP-2026-107065 EXPLOITDB text VERIFIED
FCMS CMS 2.7.2 - Multiple Cross-Site Request Forgery Vulnerabilities
by Ahmed Elhady Mohamed
CVE-2012-0699 EXPLOITDB HIGH text VERIFIED
Family Connections CMS < 2.9.0 - Cross-Site Request Forgery via News or Prayer Add Action
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an add action to familynews.php or (2) add a prayer via an add action to prayers.php.
by Ahmed Elhady Mohamed
CVSS 8.8
EIP-2026-111996 EXPLOITDB text
SePortal 2.5 - SQL Injection (1)
by Don
EIP-2026-110554 EXPLOITDB text VERIFIED
Pet Listing - 'preview.php' Cross-Site Scripting
by Mr.PaPaRoSSe
EIP-2026-111890 EXPLOITDB text VERIFIED
SantriaCMS - SQL Injection
by Troy
EIP-2026-108501 EXPLOITDB text
Joomla! Component com_qcontacts 1.0.6 - SQL Injection
by Don
CVE-2011-4836 EXPLOITDB text VERIFIED
HomeSeer HS2 2.5.0.20 - Cross-Site Scripting via Crafted URI
Cross-site scripting (XSS) vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to inject arbitrary web script or HTML via a request for a crafted URI.
by Silent Dream
EIP-2026-116087 EXPLOITDB text VERIFIED
PowerDVD 11.0.0.2114 - Remote Denial of Service
by Luigi Auriemma
EIP-2026-112355 EXPLOITDB text
SourceBans 1.4.8 - SQL Injection / Local File Inclusion Injection
by Havok
EIP-2026-110979 EXPLOITDB text
phpBB MyPage Plugin - SQL Injection
by CrazyMouse
EIP-2026-110664 EXPLOITDB text VERIFIED
PHP City Portal Script Software - SQL Injection
by Don
CVE-2011-5057 EXPLOITDB text VERIFIED
Apache Struts 2.0.0-2.3.1.2 and 2.3.19-2.3.23 - Session Tampering via Unrestricted Interface Access
Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
by Hisato Killing
CVE-2011-5261 EXPLOITDB text VERIFIED
Axis M10 Series Network Cameras Firmware < 5.21 - Cross-Site Scripting via pageTitle Parameter
Cross-site scripting (XSS) vulnerability in serverreport.cgi in Axis M10 Series Network Cameras M1054 firmware 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the pageTitle parameter to admin/showReport.shtml.
by Matt Metzger
CVE-2011-4595 EXPLOITDB MEDIUM text VERIFIED
Caseproof Prettylinks - XSS
Pretty-Link WordPress plugin 1.5.2 has XSS
by Am!r
CVSS 6.1
EIP-2026-112111 EXPLOITDB text VERIFIED
Simple Machines Forum (SMF) 1.1.15 - 'fckeditor' Arbitrary File Upload
by HELLBOY
EIP-2026-105130 EXPLOITDB text
Alstrasoft EPay Enterprise 4.0 - Blind SQL Injection
by Don
CVE-2011-2189 EXPLOITDB HIGH text VERIFIED
Linux Kernel < 2.6.32 - Denial of Service via Network Namespace Creation
net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as demonstrated by vsftpd.
by Serge Hallyn
CVSS 7.5
CVE-2011-5044 EXPLOITDB text
SopCast 3.4.7.45585 - Unauthenticated Arbitrary Code Execution via Weak Diagnose.exe Permissions
SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing Diagnose.exe with a Trojan horse program.
by LiquidWorm