Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-111233 EXPLOITDB text VERIFIED
phpvidz 0.9.5 - Administrative Credentials Disclosure
by Michael Brooks
EIP-2026-107391 EXPLOITDB text
Getsimple CMS 2.01 < 2.02 - Administrative Credentials Disclosure
by Michael Brooks
CVE-2010-4298 EXPLOITDB text
Dustincowell Free Simple Software - SQL Injection
SQL injection vulnerability in the download module in Free Simple Software 1.0 allows remote attackers to execute arbitrary SQL commands via the downloads_id parameter in a download_now action to index.php.
by Mark Stanislav
EIP-2026-101225 EXPLOITDB text VERIFIED
D-Link DIR-300 - WiFi Key Security Bypass
by Gaurav Saha
EIP-2026-100894 EXPLOITDB text VERIFIED
SimpLISTic SQL 2.0 - 'email.cgi' Cross-Site Scripting
by Aliaksandr Hartsuyeu
EIP-2026-111133 EXPLOITDB text
PHPmotion 1.62 - 'FCKeditor' Arbitrary File Upload
by trycyber
EIP-2026-104517 EXPLOITDB text VERIFIED
ZYXEL P-660R-T1 V2 - 'HomeCurrent_Date' Cross-Site Scripting
by Usman Saeed
EIP-2026-108932 EXPLOITDB text
jSchool Advanced - Blind SQL Injection
by Don Tukulesto
CVE-2010-4774 EXPLOITDB text
AuraCMS 1.62 - SQL Injection
SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-4804 and CVE-2007-4171.
by Don Tukulesto
CVE-2010-4172 EXPLOITDB text VERIFIED
Apache Tomcat < 7.0.5 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.
by Adam Muntner
EIP-2026-102486 EXPLOITDB text
JCMS 2010 - File Download
by Beach
CVE-2010-3830 EXPLOITDB text VERIFIED
Apple Iphone OS < 4.1 - Access Control
Networking in Apple iOS before 4.2 accesses an invalid pointer during the processing of packet filter rules, which allows local users to gain privileges via unspecified vectors.
by Apple
EIP-2026-100814 EXPLOITDB text VERIFIED
Hot Links SQL 3.2 - 'report.cgi' SQL Injection
by Aliaksandr Hartsuyeu
EIP-2026-100092 EXPLOITDB text
Acidcat CMS 3.3 - 'FCKeditor' Arbitrary File Upload
by Net.Edit0r
EIP-2026-111874 EXPLOITDB text
sahitya graphics CMS - Multiple Vulnerabilities
by Dr.0rYX & Cr3W-DZ
CVE-2010-4771 EXPLOITDB text
S-CMS 2.5 - SQL Injection
SQL injection vulnerability to viewforum.php in S-CMS 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by LordTittiS
EIP-2026-117668 EXPLOITDB text
Native Instruments Service Center 2.2.5 - Local Privilege Escalation
by LiquidWorm
EIP-2026-115897 EXPLOITDB text VERIFIED
Native Instruments Reaktor 5 Player 5.5.1 - Heap Memory Corruption
by LiquidWorm
EIP-2026-113001 EXPLOITDB text VERIFIED
vBulletin 4.0.8 PL1 - Cross-Site Scripting Filter Bypass within Profile Customization
by MaXe
CVE-2010-4772 EXPLOITDB text
S-CMS 2.5 - XSS
Cross-site scripting (XSS) vulnerability in blocks/lang.php in S-CMS 2.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter to viewforum.php.
by LordTittiS
CVE-2010-4769 EXPLOITDB text VERIFIED
Joomla! com_jimtawl 1.0.2 - Path Traversal
Directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the task parameter to index.php.
by Mask_magicianz
EIP-2026-113062 EXPLOITDB text
ViArt Shop 4.0.5 - Multiple Vulnerabilities
by Ariko-Security
CVE-2010-4770 EXPLOITDB text
CommodityRentals DVD Rentals Script - SQL Injection
SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.
by JaMbA
EIP-2026-105218 EXPLOITDB text
Arabian YouTube Script - Blind SQL Injection
by R3d-D3V!L
EIP-2026-113343 EXPLOITDB text
WebRCSdiff 0.9 - 'viewver.php' Remote File Inclusion
by FL0RiX