Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-110508 EXPLOITDB text VERIFIED
pbboard 2.1.1 - Multiple Vulnerabilities
by JIKO
EIP-2026-109864 EXPLOITDB text VERIFIED
NetArt Media Car Portal 2.0 - 'car' SQL Injection
by RoAd_KiLlEr
EIP-2026-109788 EXPLOITDB text VERIFIED
MySITE - SQL Injection / Cross-Site Scripting
by MustLive
CVE-2010-3695 EXPLOITDB text VERIFIED
Horde IMP < 4.3.8 & Groupware Webmail < 1.2.7 - XSS via Fetchmail fm_id Parameter
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via the fm_id parameter in a fetchmail_prefs_save action, related to the Fetchmail configuration.
by Moritz Naumann
CVE-2010-4935 EXPLOITDB text VERIFIED
Entrans < 0.3.2 - SQL Injection via Poll SID Parameter
SQL injection vulnerability in poll.php in Entrans 0.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sid parameter.
by keracker
EIP-2026-105713 EXPLOITDB text VERIFIED
Car Portal 2.0 - Blind SQL Injection
by **RoAd_KiLlEr**
EIP-2026-100453 EXPLOITDB text VERIFIED
ndCMS - SQL Injection
by Abysssec
EIP-2026-110539 EXPLOITDB text VERIFIED
PEEL Premium 5.71 - SQL Injection
by KnocKout
CVE-2010-3468 EXPLOITDB text VERIFIED
Mura CMS <5.1.498-5.2.2809 & Sava CMS 5-5.2 - Path Traversal
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote attackers to read arbitrary files via a .. (dot dot) in the FILEID parameter to the default URI under tasks/render/file/.
by mr_me
EIP-2026-100341 EXPLOITDB text VERIFIED
gokhun asp stok 1.0 - Multiple Vulnerabilities
by KnocKout
EIP-2026-100605 EXPLOITDB text VERIFIED
VisualSite CMS 1.3 - Multiple Vulnerabilities
by Abysssec
EIP-2026-119570 EXPLOITDB text VERIFIED
Traidnt UP - Cross-Site Request Forgery (Add Admin)
by John Johnz
CVE-2010-4944 EXPLOITDB text
Mambo/Joomla! - com_elite_experts - SQL Injection
SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showExpertProfileDetailed action to index.php.
by **RoAd_KiLlEr**
CVE-2010-3490 EXPLOITDB text VERIFIED
FreePBX < 2.8.0 - Authenticated Path Traversal and Arbitrary File Write via System Recordings Component
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earlier allows remote authenticated administrators to create arbitrary files via a .. (dot dot) in the usersnum parameter to admin/config.php, as demonstrated by creating a .php file under the web root.
by Trustwave's SpiderLabs
EIP-2026-106056 EXPLOITDB text
Collaborative Passwords Manager 1.07 - Multiple Local File Inclusions
by sh00t0ut
EIP-2026-115651 EXPLOITDB text VERIFIED
Microsoft Excel 2002 - Memory Corruption
by Abysssec
EIP-2026-115650 EXPLOITDB text VERIFIED
Microsoft Excel - HFPicture Record Parsing Memory Corruption
by Abysssec
CVE-2010-4940 EXPLOITDB text VERIFIED
WAnewsletter 2.1.2 - SQL Injection via id Parameter
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
by BrOx-Dz
EIP-2026-110414 EXPLOITDB text VERIFIED
OvBB 0.16a - Multiple Local File Inclusions
by cOndemned
EIP-2026-110328 EXPLOITDB text VERIFIED
OpenText LiveLink 9.7.1 - Multiple Cross-Site Scripting Vulnerabilities
by Alejandro Ramos
CVE-2010-4933 EXPLOITDB text
Geeklog 1.3.8 - SQL Injection via lid Parameter
SQL injection vulnerability in filemgmt/singlefile.php in Geeklog 1.3.8 allows remote attackers to execute arbitrary SQL commands via the lid parameter.
by Gamoscu
EIP-2026-112205 EXPLOITDB text VERIFIED
Skybluecanvas 1.1-r248 - Cross-Site Request Forgery
by Sweet
CVE-2010-4926 EXPLOITDB text VERIFIED
com_timetrack 1.2.4 - SQL Injection via ct_id Parameter
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the ct_id parameter in a timetrack action to index.php.
by Salvatore Fresta
CVE-2010-4929 EXPLOITDB text VERIFIED
Joostina (com_ezautos) - SQL Injection
SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the firstCode parameter in a helpers action to index.php.
by Gamoscu
EIP-2026-105633 EXPLOITDB text
BSI Hotel Booking System Admin 1.4/2.0 - Authentication Bypass
by K-159