Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-108418 EXPLOITDB text
Joomla! Component com_jstore - SQL Injection
by Sid3^effects
EIP-2026-108403 EXPLOITDB text
Joomla! Component com_jnewsletter - SQL Injection
by Sid3^effects
EIP-2026-108400 EXPLOITDB text
Joomla! Component com_jmarket - SQL Injection
by Sid3^effects
EIP-2026-108388 EXPLOITDB text
Joomla! Component com_jcommunity - SQL Injection
by Sid3^effects
EIP-2026-108239 EXPLOITDB text
Joomla! Component cinema - SQL Injection
by Sudden_death
CVE-2010-2312 EXPLOITDB text VERIFIED
Hauntmax Haunted House Directory Listing Cms - SQL Injection
SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to execute arbitrary SQL commands via the state parameter in a listings action.
by Sid3^effects
EIP-2026-107497 EXPLOITDB text VERIFIED
GREEZLE - Global Real Estate Agent Site Auth SQL Injection
by L0rd CrusAd3r
CVE-2010-2356 EXPLOITDB text VERIFIED
Pilotgroup Elms Pro - XSS
Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the course_id parameter.
by Sid3^effects
EIP-2026-104296 EXPLOITDB text
Joomla! Component Jreservation 1.5 - SQL Injection / Cross-Site Scripting
by Sid3^effects
EIP-2026-104144 EXPLOITDB text VERIFIED
(GREEZLE) Global Real Estate Agent Login - Multiple SQL Injections
by L0rd CrusAd3r
CVE-2010-1297 EXPLOITDB HIGH text VERIFIED
Adobe Flash Player
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
by anonymous
CVSS 7.8
EIP-2026-101336 EXPLOITDB text VERIFIED
Juniper Networks SA2000 SSL VPN Appliance - 'welcome.cgi' Cross-Site Scripting
by Richard Brain
EIP-2026-100624 EXPLOITDB text VERIFIED
Web Wiz Forums 9.68 - SQL Injection
by Sid3^effects
CVE-2010-5013 EXPLOITDB text VERIFIED
Mckenzie Creations VRM <3.5 - SQL Injection
SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter.
by Sid3^effects
CVE-2010-2342 EXPLOITDB text VERIFIED
Dmxready Online Notebook Manager - SQL Injection
SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
by L0rd CrusAd3r
EIP-2026-100367 EXPLOITDB text VERIFIED
iClone - SQL Injection
by Sid3^effects
EIP-2026-111683 EXPLOITDB text
Rayzz Photoz - Arbitrary File Upload
by Sid3^effects
EIP-2026-111480 EXPLOITDB text VERIFIED
Pre Web Host - SQL Injection
by Mr.Benladen
EIP-2026-111262 EXPLOITDB text VERIFIED
Phreebooks 2.0 - Multiple Persistent Cross-Site Scripting Vulnerabilities
by Gustavo Sorondo
EIP-2026-111261 EXPLOITDB text VERIFIED
Phreebooks 2.0 - Local File Inclusion
by Gustavo Sorondo
EIP-2026-111260 EXPLOITDB text VERIFIED
Phreebooks 2.0 - Directory Traversal
by Gustavo Sorondo
EIP-2026-111117 EXPLOITDB text VERIFIED
phpList 2.8.11 - SQL Injection
by d3v1l
EIP-2026-107793 EXPLOITDB text
Image Store - Arbitrary File Upload
by Mr.FireStormm
EIP-2026-107643 EXPLOITDB text VERIFIED
Hotel / Resort Site Script with OnLine Reservation System - SQL Injection
by L0rd CrusAd3r
CVE-2010-5000 EXPLOITDB text VERIFIED
MCLogin System <1.3 - SQL Injection
SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the myusername parameter (aka Username field) in a do_login action. NOTE: some of these details are obtained from third party information.
by L0rd CrusAd3r