Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-107696 EXPLOITDB text VERIFIED
I-net Enquiry Management Script - SQL Injection
by D4rk357
EIP-2026-106437 EXPLOITDB text VERIFIED
Diem 5.1.2 - Multiple Cross-Site Scripting Vulnerabilities
by High-Tech Bridge SA
EIP-2026-106284 EXPLOITDB text
CustomCMS - Persistent Cross-Site Scripting
by Sid3^effects
CVE-2010-2917 EXPLOITDB text
AJ Square AJ Article 3.0 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company, (5) address1, (6) address2, (7) city, (8) state, (9) zipcode, (10) phone, and (11) fax parameters in an update action. NOTE: some of these details are obtained from third party information.
by Sid3^effects
CVE-2010-2375 EXPLOITDB text VERIFIED
Oracle Fusion Middleware - Confidentiality Integrity
Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
by Timothy D. Morgan
CVE-2010-2370 EXPLOITDB text VERIFIED
Oracle Fusion Middleware <10.3 - Info Disclosure
Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 MP5, and 10.3 MP2 allows remote attackers to affect integrity, related to BPM.
by Markot
EIP-2026-115096 EXPLOITDB text VERIFIED
Corel Presentations X5 15.0.0.357 - 'shw' Buffer Preoccupation (PoC)
by LiquidWorm
EIP-2026-108670 EXPLOITDB text VERIFIED
Joomla! Component healthstats - Persistent Cross-Site Scripting
by Sid3^effects
EIP-2026-108632 EXPLOITDB text VERIFIED
Joomla! Component EasyBlog - Persistent Cross-Site Scripting
by Sid3^effects
EIP-2026-103866 EXPLOITDB text VERIFIED
Asterisk Recording Interface 0.7.15/0.10 - Multiple Vulnerabilities
by TurboBorland
CVE-2010-2630 EXPLOITDB text VERIFIED
Libtiff - Improper Input Validation
The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.
by Tom Lane
EIP-2026-102366 EXPLOITDB text VERIFIED
dotDefender 4.02 - 'clave' Cross-Site Scripting
by David K
EIP-2026-111834 EXPLOITDB text VERIFIED
RunCMS 2.1 - 'magpie_debug.php' Cross-Site Scripting
by John Leitch
EIP-2026-106256 EXPLOITDB text VERIFIED
CSSTidy 1.3 - 'css_optimiser.php' Cross-Site Scripting
by John Leitch
EIP-2026-102398 EXPLOITDB text VERIFIED
Mac's CMS 1.1.4 - 'SearchString' Cross-Site Scripting
by 10n1z3d
CVE-2010-4984 EXPLOITDB text VERIFIED
My Kazaam Notes Management System - SQL Injection
SQL injection vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to execute arbitrary SQL commands via vectors involving the "Enter Reference Number Below" text box.
by L0rd CrusAd3r
CVE-2010-2699 EXPLOITDB text VERIFIED
Edge PHP Clickbank Affiliate Marketplace Script - SQL Injection
SQL injection vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to execute arbitrary SQL commands via the search parameter.
by L0rd CrusAd3r
EIP-2026-112043 EXPLOITDB text VERIFIED
Sillaj time tracking tool - Authentication Bypass
by L0rd CrusAd3r
CVE-2010-4985 EXPLOITDB text VERIFIED
My Kazaam Notes Management System - XSS
Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to inject arbitrary web script or HTML via vectors involving the "Enter Reference Number Below" text box.
by L0rd CrusAd3r
CVE-2010-4982 EXPLOITDB text
My Kazaam Address & Contact Organizer - SQL Injection
SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attackers to execute arbitrary SQL commands via the var1 parameter.
by v3n0m
CVE-2010-2694 EXPLOITDB text
Joomla! com_redshop 1.0 - SQL Injection
SQL injection vulnerability in the redSHOP Component (com_redshop) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter to index.php.
by v3n0m
EIP-2026-108840 EXPLOITDB text
Joomla! Component Rapid-Recipe - Persistent Cross-Site Scripting
by Sid3^effects
EIP-2026-108839 EXPLOITDB text VERIFIED
Joomla! Component Rapid-Recipe - HTML Injection
by Sid3^effects
EIP-2026-108808 EXPLOITDB text
Joomla! Component MySMS - Arbitrary File Upload
by Sid3^effects
EIP-2026-108806 EXPLOITDB text
Joomla! Component MyHome - Blind SQL Injection
by Sid3^effects