Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
CVE-2011-3597 EXPLOITDB text VERIFIED
Perl <1.17 - Command Injection
Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.
by anonymous
EIP-2026-107009 EXPLOITDB text
ezCourses - 'admin.asp' Security Bypass
by J.O
CVE-2011-3863 EXPLOITDB text VERIFIED
WordPress RedLine <1.66 - XSS
Cross-site scripting (XSS) vulnerability in the RedLine theme before 1.66 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by SiteWatch
CVE-2011-3862 EXPLOITDB text VERIFIED
Morning Coffee <3.6 - XSS
Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
by SiteWatch
CVE-2011-3865 EXPLOITDB text VERIFIED
WordPress <1.6 - XSS
Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.
by SiteWatch
EIP-2026-114208 EXPLOITDB text VERIFIED
WordPress Plugin WP Bannerize 2.8.7 - 'ajax_sorter.php' SQL Injection
by Miroslav Stampar
EIP-2026-113588 EXPLOITDB text VERIFIED
WordPress Plugin Bannerize 2.8.7 - SQL Injection
by Miroslav Stampar
EIP-2026-111534 EXPLOITDB text VERIFIED
ProjectForum 7.0.1 3038 - 'more' Object HTML Injection
by Paul Davis
EIP-2026-109326 EXPLOITDB text
Marinet CMS - 'room.php' Blind SQL Injection
by BHG Security Center
EIP-2026-115908 EXPLOITDB text VERIFIED
NCSS 07.1.21 - Array Overflow with Write2
by Luigi Auriemma
CVE-2011-3858 EXPLOITDB text VERIFIED
Pixiv Custom <2.1.6 - XSS
Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by SiteWatch
CVE-2011-3852 EXPLOITDB text VERIFIED
WordPress EvoLve <1.2.6 - XSS
Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by SiteWatch
CVE-2011-3856 EXPLOITDB text VERIFIED
WordPress Elegant Grunge <1.0.4 - XSS
Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme before 1.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by SiteWatch
CVE-2011-3850 EXPLOITDB text VERIFIED
Atahualpa <3.6.8 - XSS
Cross-site scripting (XSS) vulnerability in the Atahualpa theme before 3.6.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by SiteWatch
EIP-2026-112831 EXPLOITDB text VERIFIED
Typo3 - File Disclosure
by Number 7
EIP-2026-108188 EXPLOITDB text VERIFIED
Joomla! < 1.7.0 - Multiple Cross-Site Scripting Vulnerabilities
by Aung Khant
EIP-2026-105495 EXPLOITDB text VERIFIED
Bitweaver 2.8.1 - Multiple Cross-Site Scripting Vulnerabilities
by Stefan Schurtz
EIP-2026-112783 EXPLOITDB text VERIFIED
Traq 2.2 - Multiple SQL Injections / Cross-Site Scripting
by High-Tech Bridge SA
EIP-2026-104878 EXPLOITDB text VERIFIED
A2CMS - 'index.php' Local File Disclosure
by St493r
EIP-2026-100591 EXPLOITDB text
timelive time and expense tracking 4.1.1 - Multiple Vulnerabilities
by Nathaniel Carew
EIP-2026-119127 EXPLOITDB text VERIFIED
ServersCheck Monitoring Software 8.8.x - Multiple Vulnerabilities
by Vulnerability-Lab
CVE-2011-4045 EXPLOITDB text VERIFIED
ARC Informatique PcVue <10.0 - Buffer Overflow
Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document.
by Luigi Auriemma
EIP-2026-113894 EXPLOITDB text VERIFIED
WordPress Plugin Mingle Forum 1.0.31 - SQL Injection
by Miroslav Stampar
EIP-2026-112966 EXPLOITDB text VERIFIED
Vanira CMS - 'vtpidshow' SQL Injection
by kurdish hackers team
EIP-2026-111733 EXPLOITDB text
redmind Online-Shop / E-Commerce-System - SQL Injection
by Indonesian BlackCoder