Exploitdb Exploits
31,344 exploits tracked across all sources.
Aastra IP Phone 9480i - Web Interface Data Disclosure
by Yakir Wizman
VLC media player <1.1.9 - DoS/Buffer Overflow
Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 through 1.1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow.
by TecR0c
WordPress Plugin GD Star Rating - 'votes' SQL Injection
by anonymous
Blog:CMS 4.2 - Multiple Cross-Site Scripting Vulnerabilities
by Stefan Schurtz
vBulletin vBExperience 3 - 'sortorder' Cross-Site Scripting
by Mr.ThieF
Squiz Matrix 4 - 'colour_picker.php' Cross-Site Scripting
by Patrick Webster
PopScript - 'index.php' Multiple Input Validation Vulnerabilities
by NassRawI
Nakid CMS 1.0.2 - 'CKEditorFuncNum' Cross-Site Scripting
by AutoSec Tools
Multiple WordPress WooThemes Themes - 'test.php' Cross-Site Scripting
by MustLive
Joomla! Component CCBoard - SQL Injection / Arbitrary File Upload
by KedAns-Dz
WebSVN 2.3.2 - Unproper Metacharacters Escaping 'exec()' Remote Command Injection
by rgod
MODACOM URoad-5000 1450 - Remote Command Execution / Backdoor Access
by Alex Stanev
TEDE Simplificado 1.01/S2.04 - Multiple SQL Injections
by KnocKout
ARSC Really Simple Chat 3.3-rc2 - Cross-Site Scripting / Multiple SQL Injections
by High-Tech Bridge SA
Nagios 3.2.3-Icinga <1.4.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.
by Stefan Schurtz
Netgear WNDAP350 Wireless Access Point - Multiple Information Disclosure Vulnerabilities
by Juerd Waalboer
S9Y Serendipity Freetag-plugin 3.21 - 'index.php' Cross-Site Scripting
by Stefan Schurtz
libxml2 <2.6.32 & 2.7.8 - DoS/Code Injection
Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.
by Chris Evans
Kentico CMS 5.5R2.23 - 'userContextMenu_Parameter' Cross-Site Scripting
by LiquidWorm
By Source