Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-103999 EXPLOITDB text VERIFIED
Nagios XI - 'users.php' SQL Injection
by Adam Baldwin
EIP-2026-109155 EXPLOITDB text
Link CMS - SQL Injection
EIP-2026-108611 EXPLOITDB text VERIFIED
Joomla! Component com_zoomportfolio - SQL Injection
by Chip d3 bi0s
EIP-2026-107351 EXPLOITDB text VERIFIED
Gazelle CMS - Multiple Vulnerabilities
by Sweet
CVE-2010-4882 EXPLOITDB text VERIFIED
Auto CMS 1.6 - Cross-Site Scripting via Sitetitle Parameter
Cross-site scripting (XSS) vulnerability in autocms.php in Auto CMS 1.6 allows remote attackers to inject arbitrary web script or HTML via the sitetitle parameter.
by High-Tech Bridge SA
EIP-2026-105180 EXPLOITDB text VERIFIED
AneCMS 1.0/1.3 - 'register/next' SQL Injection
by Sweet
EIP-2026-105177 EXPLOITDB text
AneCMS - '/registre/next' SQL Injection
by Sweet
EIP-2026-104845 EXPLOITDB text
4Images 1.7.8 - Remote File Inclusion
by LoSt.HaCkEr
EIP-2026-100456 EXPLOITDB text VERIFIED
netStartEnterprise 4.0 - SQL Injection
by L1nK
EIP-2026-108648 EXPLOITDB text VERIFIED
Joomla! Component Fabrik - SQL Injection
by Mkr0x
EIP-2026-108610 EXPLOITDB text VERIFIED
Joomla! Component com_zina - SQL Injection
by Th3 RDX
EIP-2026-108221 EXPLOITDB text
Joomla! Component Biblioteca 1.0 Beta - Multiple SQL Injections
by Salvatore Fresta
EIP-2026-100578 EXPLOITDB text VERIFIED
T-dreams Announcement Script - SQL Injection
by Br0wn Sug4r
EIP-2026-108343 EXPLOITDB text VERIFIED
Joomla! Component com_extcalendar - Blind SQL Injection
by Lagripe-Dz
CVE-2010-3683 EXPLOITDB text VERIFIED
Oracle MySQL 5.1 < 5.1.49 and 5.5 < 5.5.5 - Authenticated Denial of Service via LOAD DATA INFILE
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL errors, which allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a crafted request.
by Elena Stepanova
CVE-2010-3679 EXPLOITDB text VERIFIED
Oracle MySQL 5.1 - Authenticated Denial of Service via BINLOG Command
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via certain arguments to the BINLOG command, which triggers an access of uninitialized memory, as demonstrated by valgrind.
by Shane Bester
CVE-2010-3681 EXPLOITDB text VERIFIED
Oracle MySQL 5.1 < 5.1.49 and 5.5 < 5.5.5 - Authenticated Denial of Service via HANDLER Interface
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the HANDLER interface and performing "alternate reads from two indexes on a table," which triggers an assertion failure.
by Matthias Leich
CVE-2010-3682 EXPLOITDB text VERIFIED
MySQL < 5.1.49 and < 5.0.92 - Authenticated Denial of Service via EXPLAIN with Crafted SELECT UNION ORDER BY
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.
by Bjorn Munch
EIP-2026-116270 EXPLOITDB text
SonicWALL E-Class SSL-VPN - ActiveX Control Format String Overflow
by Nikolas Sotiriu
EIP-2026-112973 EXPLOITDB text
vbbuletin 4.0.4 - Multiple Vulnerabilities
by mc2_s3lector
EIP-2026-112534 EXPLOITDB text VERIFIED
Syntax Highlighter 3.0.83 - 'index.html' HTML Injection
by indoushka
CVE-2010-2544 EXPLOITDB text VERIFIED
Cacti < 0.8.7g - Cross-Site Scripting via Filter Parameter
Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
by Marc Schoenefeld
CVE-2010-3680 EXPLOITDB text VERIFIED
Oracle MySQL 5.1 - Authenticated Denial of Service via Temporary Table Creation with Nullable Columns
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by creating temporary tables with nullable columns while using InnoDB, which triggers an assertion failure.
by Boris Reisig
EIP-2026-103172 EXPLOITDB text VERIFIED
Nagios XI - 'login.php' Multiple Cross-Site Scripting Vulnerabilities
by Adam Baldwin
EIP-2026-118518 EXPLOITDB text VERIFIED
Enemy Territory: Quake Wars 1.5.12642.33243 - Remote Buffer Overflow
by Luigi Auriemma