Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-110439 EXPLOITDB text
Pacer Edition CMS 2.1 - 'l' Local File Inclusion
by LiquidWorm
EIP-2026-105183 EXPLOITDB text
Angora Guestbook 1.5 - Local File Inclusion
by AutoSec Tools
EIP-2026-101925 EXPLOITDB text
Polycom IP Phone - Web Interface Data Disclosure
by Yakir Wizman
EIP-2026-101511 EXPLOITDB text VERIFIED
Aastra IP Phone 9480i - Web Interface Data Disclosure
by Yakir Wizman
EIP-2026-100309 EXPLOITDB text VERIFIED
EquiPCS - SQL Injection
by Sideswipe
CVE-2011-2194 EXPLOITDB text VERIFIED
VLC media player <1.1.9 - DoS/Buffer Overflow
Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 through 1.1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow.
by TecR0c
EIP-2026-113780 EXPLOITDB text VERIFIED
WordPress Plugin GD Star Rating - 'votes' SQL Injection
by anonymous
EIP-2026-114409 EXPLOITDB text VERIFIED
Xataface 1.x - 'action' Local File Inclusion
by ITSecTeam
EIP-2026-105525 EXPLOITDB text VERIFIED
Blog:CMS 4.2 - Multiple Cross-Site Scripting Vulnerabilities
by Stefan Schurtz
EIP-2026-113026 EXPLOITDB text VERIFIED
vBulletin vBExperience 3 - 'sortorder' Cross-Site Scripting
by Mr.ThieF
EIP-2026-112415 EXPLOITDB text VERIFIED
Squiz Matrix 4 - 'colour_picker.php' Cross-Site Scripting
by Patrick Webster
EIP-2026-111408 EXPLOITDB text VERIFIED
PopScript - 'index.php' Multiple Input Validation Vulnerabilities
by NassRawI
EIP-2026-109832 EXPLOITDB text VERIFIED
Nakid CMS 1.0.2 - 'CKEditorFuncNum' Cross-Site Scripting
by AutoSec Tools
EIP-2026-109641 EXPLOITDB text VERIFIED
Multiple WordPress WooThemes Themes - 'test.php' Cross-Site Scripting
by MustLive
EIP-2026-108233 EXPLOITDB text VERIFIED
Joomla! Component CCBoard - SQL Injection / Arbitrary File Upload
by KedAns-Dz
EIP-2026-119452 EXPLOITDB text VERIFIED
WebSVN 2.3.2 - Unproper Metacharacters Escaping 'exec()' Remote Command Injection
by rgod
EIP-2026-112937 EXPLOITDB text VERIFIED
Ushahidi 2.0.1 - 'range' SQL Injection
by Gjoko Krstic
EIP-2026-101367 EXPLOITDB text VERIFIED
MODACOM URoad-5000 1450 - Remote Command Execution / Backdoor Access
by Alex Stanev
EIP-2026-112585 EXPLOITDB text VERIFIED
TEDE Simplificado 1.01/S2.04 - Multiple SQL Injections
by KnocKout
EIP-2026-105234 EXPLOITDB text VERIFIED
ARSC Really Simple Chat 3.3-rc2 - Cross-Site Scripting / Multiple SQL Injections
by High-Tech Bridge SA
CVE-2011-2179 EXPLOITDB text VERIFIED
Nagios 3.2.3-Icinga <1.4.1 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.
by Stefan Schurtz
EIP-2026-101381 EXPLOITDB text VERIFIED
Netgear WNDAP350 Wireless Access Point - Multiple Information Disclosure Vulnerabilities
by Juerd Waalboer
EIP-2026-111863 EXPLOITDB text VERIFIED
S9Y Serendipity Freetag-plugin 3.21 - 'index.php' Cross-Site Scripting
by Stefan Schurtz
CVE-2011-1944 EXPLOITDB text VERIFIED
libxml2 <2.6.32 & 2.7.8 - DoS/Code Injection
Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XML file that triggers a heap-based buffer overflow when adding a new namespace node, related to handling of XPath expressions.
by Chris Evans
EIP-2026-100386 EXPLOITDB text VERIFIED
Kentico CMS 5.5R2.23 - 'userContextMenu_Parameter' Cross-Site Scripting
by LiquidWorm