Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-113849 EXPLOITDB text VERIFIED
WordPress Plugin jRSS Widget 1.1.1 - 'url' Information Disclosure
by John Leitch
EIP-2026-113742 EXPLOITDB text VERIFIED
WordPress Plugin FeedList 2.61.01 - 'handler_image.php' Cross-Site Scripting
by John Leitch
EIP-2026-111988 EXPLOITDB text VERIFIED
Seo Panel 2.1.0 - Critical File Disclosure
by MaXe
CVE-2008-6222 EXPLOITDB text VERIFIED
Joomlashowroom Pro Desk Support Center - Path Traversal
Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter to index.php.
by d3v1l
CVE-2010-1345 EXPLOITDB text VERIFIED
Cookex Agency CKForms <1.3.3 - Path Traversal
Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
by ALTBTA
EIP-2026-108306 EXPLOITDB text VERIFIED
Joomla! Component com_clanlist - SQL Injection
by CoBRa_21
EIP-2026-108305 EXPLOITDB text VERIFIED
Joomla! Component com_clan - SQL Injection
by AtT4CKxT3rR0r1ST
CVE-2010-4412 EXPLOITDB text VERIFIED
Bsdperimeter Pfsense - XSS
Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in an olsrd.xml action to pkg_edit.php, (2) the xml parameter to pkg.php, or the if parameter to (3) status_graph.php or (4) interfaces.php, a different vulnerability than CVE-2008-1182 and CVE-2010-4246.
by dave b
CVE-2010-4412 EXPLOITDB text VERIFIED
Bsdperimeter Pfsense - XSS
Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in an olsrd.xml action to pkg_edit.php, (2) the xml parameter to pkg.php, or the if parameter to (3) status_graph.php or (4) interfaces.php, a different vulnerability than CVE-2008-1182 and CVE-2010-4246.
by dave b
CVE-2010-4412 EXPLOITDB text VERIFIED
Bsdperimeter Pfsense - XSS
Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in an olsrd.xml action to pkg_edit.php, (2) the xml parameter to pkg.php, or the if parameter to (3) status_graph.php or (4) interfaces.php, a different vulnerability than CVE-2008-1182 and CVE-2010-4246.
by dave b
CVE-2010-4412 EXPLOITDB text VERIFIED
Bsdperimeter Pfsense - XSS
Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in an olsrd.xml action to pkg_edit.php, (2) the xml parameter to pkg.php, or the if parameter to (3) status_graph.php or (4) interfaces.php, a different vulnerability than CVE-2008-1182 and CVE-2010-4246.
by dave b
CVE-2010-4631 EXPLOITDB text VERIFIED
Pilotcart Pilot Cart - XSS
Multiple cross-site scripting (XSS) vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) countrycode parameter to contact.asp, USERNAME parameter to (2) gateway.asp and (3) cart.asp, and the specific parameter to (4) quote.asp and (5) buyitnow.
by Ariko-Security
EIP-2026-118544 EXPLOITDB text VERIFIED
filecopa ftp server 6.01 - Directory Traversal
by Pawel Wylecial
EIP-2026-111582 EXPLOITDB text
Punbb 1.3.4 - Multiple Full Path Disclosures
by SYSTEM_OVERIDE
CVE-2010-4632 EXPLOITDB text VERIFIED
Pilotcart Pilot Cart - SQL Injection
Multiple SQL injection vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to execute arbitrary SQL commands via the (1) article parameter to kb.asp, (2) specific parameter to cart.asp, (3) countrycode parameter to contact.asp, and the (4) srch parameter to search.asp. NOTE: the article parameter to pilot.asp is already covered by CVE-2008-2688.
by Ariko-Security
CVE-2010-10011 EXPLOITDB MEDIUM text VERIFIED
Acritum Femitter Server 1.04 - Path Traversal
A vulnerability, which was classified as problematic, was found in Acritum Femitter Server 1.04. Affected is an unknown function. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250446 is the identifier assigned to this vulnerability.
by chr1x
CVSS 4.3
EIP-2026-118285 EXPLOITDB text VERIFIED
AT-TFTP Server 1.8 - Directory Traversal
by Yakir Wizman
EIP-2026-115320 EXPLOITDB text
G Data TotalCare 2011 - 'NtOpenKey' Race Condition
by Nikita Tarakanov
EIP-2026-114587 EXPLOITDB text
Zeeways Adserver - Multiple Vulnerabilities
by Valentin
EIP-2026-111026 EXPLOITDB text
phpCow 2.1 - File Inclusion
by ViRuS_HiMa
EIP-2026-109335 EXPLOITDB text
MassMirror Uploader - Remote File Inclusion
by ViciOuS
EIP-2026-108351 EXPLOITDB text VERIFIED
Joomla! Component com_forme 1.0.5 - Multiple Vulnerabilities
by jdc
EIP-2026-108326 EXPLOITDB text VERIFIED
Joomla! Component com_dcnews - Local File Inclusion
by Th3 RDX
EIP-2026-108316 EXPLOITDB text VERIFIED
Joomla! Component com_connect - Local File Inclusion
by Th3 RDX
EIP-2026-119289 EXPLOITDB text VERIFIED
WinTFTP Server Pro 3.1 - Directory Traversal
by Yakir Wizman