Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106099 EXPLOITDB text
Company's Recruitment Management System 1.0. - 'title' Stored Cross-Site Scripting (XSS)
by Aniket Deshmane
EIP-2026-106097 EXPLOITDB text
Company's Recruitment Management System 1.0 - 'Add New user' Cross-Site Request Forgery (CSRF)
by Aniket Deshmane
EIP-2026-106096 EXPLOITDB text
Company's Recruitment Management System 1.0 - 'description' Stored Cross-Site Scripting (XSS)
by Aniket Deshmane
CVE-2021-41382 EXPLOITDB HIGH text
Plastic SCM <10.0.16.5622 - Info Disclosure
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
by Basavaraj Banakar
CVSS 7.5
CVE-2018-16060 EXPLOITDB HIGH text
Mitsubishi Electric Europe B.V. SmartRTU - Info Disclosure
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.
by Hamit CİBO
CVSS 7.5
CVE-2018-16061 EXPLOITDB MEDIUM text
Mitsubishi Electric SmartRTU Firmware - Cross-Site Scripting via Login Username Parameter or PATH_INFO
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
by Hamit CİBO
CVSS 6.1
CVE-2021-41878 EXPLOITDB MEDIUM text
i-Panel Administration System 2.0 - Reflected Cross-Site Scripting
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable malicious button.
by Forster Chiu
CVSS 6.1
CVE-2021-47943 EXPLOITDB HIGH text
TextPattern CMS 4.8.7 Remote Code Execution via File Upload
TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functionality. Attackers can upload a PHP shell via the Files section in the content area and execute commands by accessing the uploaded file at /textpattern/files/ with GET parameters passed to the system function.
by Mert Daş
CVSS 8.8
EIP-2026-117925 EXPLOITDB text
SolarWinds Kiwi CatTools 3.11.8 - Unquoted Service Path
by Mert Daş
CVE-2021-42169 EXPLOITDB CRITICAL text
Simple Payroll System with Dynamic Tax Bracket - SQL Injection via Login Username Parameter
The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious payloads.
by Yash Mahajan
CVSS 9.8
CVE-2021-47745 EXPLOITDB HIGH text
Cypress Solutions CTM-200 2.7.1 - Command Injection
Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script that allows remote attackers to execute shell commands. Attackers can exploit the 'fw_url' parameter in the ctm-config-upgrade.sh script to inject and execute arbitrary commands with root privileges.
by LiquidWorm
CVSS 8.8
EIP-2026-112453 EXPLOITDB text
Student Quarterly Grading System 1.0 - 'grade' Stored Cross-Site Scripting (XSS)
by Hüseyin Serkan Balkanli
EIP-2026-112102 EXPLOITDB text
Simple Issue Tracker System 1.0 - SQLi Authentication Bypass
by Bekir Bugra TURKOGLU
EIP-2026-110135 EXPLOITDB text
Online Learning System 2.0 - 'Multiple' SQLi Authentication Bypass
by Blackhan
EIP-2026-106098 EXPLOITDB text
Company's Recruitment Management System 1.0 - 'Multiple' SQL Injection (Unauthenticated)
by Yash Mahajan
EIP-2026-104310 EXPLOITDB text
Logitech Media Server 8.2.0 - 'Title' Cross-Site Scripting (XSS)
by Mert Daş
CVE-2021-20031 EXPLOITDB MEDIUM text
SonicOS < 7.0.1-r1262 - Host Header Redirection
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
by Ramikan
CVSS 6.1
CVE-2025-34077 EXPLOITDB CRITICAL text
WordPress Pie Register <3.7.1.4 - Auth Bypass
An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the user_id_social_site parameter, an attacker can generate a valid WordPress session cookie for any user ID, including administrators. Once authenticated, the attacker may exploit plugin upload functionality to install a malicious plugin containing arbitrary PHP code, resulting in remote code execution on the underlying server.
by Lotfi13-DZ
CVE-2021-42224 EXPLOITDB CRITICAL text
IFSC Code Finder Project 1.0 - SQL Injection via searchifsccode Parameter
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
by Yash Mahajan
CVSS 9.8
CVE-2021-47781 EXPLOITDB CRITICAL text
Cmder Console Emulator 1.3.18 - DoS
Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of service condition through a maliciously crafted .cmd file. Attackers can create a specially constructed .cmd file with repeated characters to overwhelm the console emulator's buffer and crash the application.
by Aryan Chehreghani
CVSS 9.8
CVE-2021-42053 EXPLOITDB MEDIUM text
django-unicorn < 0.36.0 - Cross-Site Scripting via Component Name
The Unicorn framework through 0.35.3 for Django allows XSS via component.name.
by Raven Security Associates
CVSS 5.4
EIP-2026-112120 EXPLOITDB text
Simple Online College Entrance Exam System 1.0 - Unauthenticated Admin Creation
by Amine ismail
EIP-2026-112118 EXPLOITDB text
Simple Online College Entrance Exam System 1.0 - Account Takeover
by Amine ismail
EIP-2026-112117 EXPLOITDB text
Simple Online College Entrance Exam System 1.0 - 'Multiple' SQL injection
by Amine ismail
EIP-2026-110197 EXPLOITDB text
Online Traffic Offense Management System 1.0 - Privilage escalation (Unauthenticated)
by snup