Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-105897 EXPLOITDB text VERIFIED
Claus Muus Spitfire 1.0.336 - Multiple Cross-Site Scripting Vulnerabilities
by High-Tech Bridge SA
CVE-2010-2915 EXPLOITDB text VERIFIED
AJ Square AJ HYIP PRIME - SQL Injection
SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter.
by JosS
CVE-2010-2916 EXPLOITDB text VERIFIED
AJ Square AJ HYIP MERIDIAN - SQL Injection
SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter.
by JosS
EIP-2026-119411 EXPLOITDB text VERIFIED
Outlook Web Access 2003 - Cross-Site Request Forgery
by anonymous
EIP-2026-118673 EXPLOITDB text VERIFIED
id Software id Tech 4 Engine - 'idGameLocal::GetGameStateObject()' Remote Code Execution
by Luigi Auriemma
EIP-2026-111677 EXPLOITDB text VERIFIED
RapidLeech Scripts - Arbitrary File Upload
by H-SK33PY
EIP-2026-110330 EXPLOITDB text
OpenX - 'phpAdsNew' Remote File Inclusion
by ViRuS Qalaa
EIP-2026-103552 EXPLOITDB text VERIFIED
Monolith Lithtech Game Engine - Memory Corruption
by Luigi Auriemma
EIP-2026-116462 EXPLOITDB text VERIFIED
Unreal Tournament 3 2.1 - 'STEAMBLOB' Remote Denial of Service
by Luigi Auriemma
EIP-2026-115724 EXPLOITDB text
Microsoft Internet Explorer 7 - Microsoft Clip Organizer Multiple Insecure ActiveX Control Denial of Service Vulnerabilities
by Beenu Arora
EIP-2026-115559 EXPLOITDB text VERIFIED
Lithtech Engine - Memory Corruption
by Luigi Auriemma
EIP-2026-110662 EXPLOITDB text VERIFIED
PHP Chat for 123 Flash Chat - Remote File Inclusion
by HaCkEr arar
EIP-2026-108549 EXPLOITDB text VERIFIED
Joomla! Component com_spa - SQL Injection (1)
by ALTBTA
CVE-2010-1214 EXPLOITDB text VERIFIED
Mozilla Firefox <3.5.11 & SeaMonkey <2.0.6 - RCE
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.
by J23
EIP-2026-100420 EXPLOITDB text VERIFIED
Mayasan Portal 2.0 - 'makaledetay.asp' SQL Injection
by v0calist
EIP-2026-100419 EXPLOITDB text VERIFIED
Mayasan Portal 2.0 - 'haberdetay.asp' SQL Injection
by CoBRa_21
EIP-2026-100181 EXPLOITDB text VERIFIED
Caner Hikaye Script - SQL Injection
by v0calist
EIP-2026-112279 EXPLOITDB text VERIFIED
SnowFlake CMS 0.9.5 Beta - 'uid' SQL Injection
by Dinesh Arora
CVE-2010-0211 EXPLOITDB CRITICAL text VERIFIED
OpenLDAP 2.4.22 - Denial of Service via Invalid UTF-8 RDN String
The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.
by Ilkka Mattila
CVSS 9.8
CVE-2015-0096 EXPLOITDB text VERIFIED
Microsoft Windows Shell LNK Code Execution
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, leading to DLL loading during Windows Explorer access to the icon of a crafted shortcut, aka "DLL Planting Remote Code Execution Vulnerability."
by Ivanlef0u
EIP-2026-115638 EXPLOITDB text VERIFIED
Microsoft DirectX 8/9 DirectPlay - Multiple Denial of Service Vulnerabilities
by Luigi Auriemma
EIP-2026-114503 EXPLOITDB text VERIFIED
YACS CMS 10.5.27 - 'context[path_to_root]' Remote File Inclusion
by eidelweiss
EIP-2026-111676 EXPLOITDB text VERIFIED
rapidCMS 2.0 - Authentication Bypass
by Mahjong
EIP-2026-110802 EXPLOITDB text
PHP-Fusion - Remote Command Execution
by ViRuS Qalaa
CVE-2010-2912 EXPLOITDB text
Kayako eSupport 3.70.02 - SQL Injection
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action.
by ScOrPiOn