Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-106836 EXPLOITDB text VERIFIED
eliteCMS 1.01 - Multiple Cross-Site Scripting Vulnerabilities
by 10n1z3d
CVE-2010-2700 EXPLOITDB text VERIFIED
Edge PHP Clickbank Affiliate Marketplace Script - XSS
Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.
by L0rd CrusAd3r
EIP-2026-114510 EXPLOITDB text VERIFIED
Yappa 3.1.2 - 'yappa.php' Multiple Remote Command Execution Vulnerabilities
by Sn!pEr.S!Te Hacker
EIP-2026-113752 EXPLOITDB text VERIFIED
WordPress Plugin Firestats 1.6.5 - Multiple Cross-Site Scripting Vulnerabilities
by Jelmer de Hen
EIP-2026-113749 EXPLOITDB text VERIFIED
WordPress Plugin Firestats - Remote Configuration File Download
by Jelmer de Hen
EIP-2026-112379 EXPLOITDB text VERIFIED
sphider 1.3.5 - Remote File Inclusion
by Li0n-PaL
CVE-2010-2858 EXPLOITDB text VERIFIED
SimpNews <2.47.03 - XSS
Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and (2) sortorder parameters.
by MustLive
EIP-2026-111705 EXPLOITDB text VERIFIED
Real Estate Manager 1.0.1 - 'index.php' Cross-Site Scripting
by bi0
CVE-2010-2845 EXPLOITDB text
Joomla! com_quickfaq 1.0.3 - SQL Injection
SQL injection vulnerability in the QuickFAQ (com_quickfaq) component 1.0.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a category action to index.php.
by RoAd_KiLlEr
EIP-2026-108787 EXPLOITDB text
Joomla! Component Minify4Joomla! - Arbitrary File Upload / Persistent Cross-Site Scripting
by Sid3^effects
EIP-2026-108679 EXPLOITDB text VERIFIED
Joomla! Component IXXO Cart - SQL Injection
by Sid3^effects
EIP-2026-107604 EXPLOITDB text
HoloCMS 9.0.47 - 'news.php' SQL Injection
by GlaDiaT0R
EIP-2026-105964 EXPLOITDB text VERIFIED
CMS Contentia - 'news.php' SQL Injection
by GlaDiaT0R
EIP-2026-103894 EXPLOITDB text VERIFIED
dotDefender - Cross-Site Scripting Security Bypass
by SH4V
CVE-2010-3676 EXPLOITDB text VERIFIED
Oracle Mysql - Denial of Service
storage/innobase/dict/dict0crea.c in mysqld in Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (assertion failure) by modifying the (1) innodb_file_format or (2) innodb_file_per_table configuration parameters for the InnoDB storage engine, then executing a DDL statement.
by Elena Stepanova
CVE-2010-3213 EXPLOITDB text VERIFIED
Microsoft Outlook Web Access <SP2 - CSRF
Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.
by Rosario Valotta
EIP-2026-119080 EXPLOITDB text VERIFIED
Real Player 12.0.0.879 - Code Execution
by webDEViL
CVE-2010-2627 EXPLOITDB text VERIFIED
EA Battlefield 2 < 2.1.50 - Path Traversal
Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via "..\" (dot dot backslash) sequences in URLs for the (1) sponsor or (2) community logos, and other URLs related to (3) DemoDownloadURL, (4) DemoIndexURL and (5) CustomMapsURL.
by Luigi Auriemma
EIP-2026-115777 EXPLOITDB text VERIFIED
Microsoft Windows - 'cmd.exe' Unicode Buffer Overflow (SEH)
by bitform
EIP-2026-115327 EXPLOITDB text VERIFIED
Ghost Recon Advanced Warfighter - Integer Overflow / Array Indexing Overflow
by Luigi Auriemma
EIP-2026-114658 EXPLOITDB text VERIFIED
Zylone IT - Multiple Blind SQL Injections
by Callo
EIP-2026-111284 EXPLOITDB text
Pithcms - 'theme' Local/Remote File Inclusion
by eidelweiss
EIP-2026-110571 EXPLOITDB text
PG Social Networking - Arbitrary File Upload
by SONIC
CVE-2010-2856 EXPLOITDB text VERIFIED
osCSS <1.2.2 - XSS
Cross-site scripting (XSS) vulnerability in admin/currencies.php in osCSS 1.2.2, and probably earlier versions, allows remote attackers to inject arbitrary web script or HTML via the page parameter.
by High-Tech Bridge SA
CVE-2010-2857 EXPLOITDB text VERIFIED
Joomla! - Path Traversal
Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the cid parameter to album.html.
by Sid3^effects