Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-111446 EXPLOITDB text VERIFIED
Powder Blue Design - SQL Injection
by cyberlog
EIP-2026-109970 EXPLOITDB text VERIFIED
NPDS REvolution 10.02 - 'admin.php' Cross-Site Request Forgery
by High-Tech Bridge SA
EIP-2026-109167 EXPLOITDB text VERIFIED
Lisk CMS 4.4 - 'id' Multiple Cross-Site Scripting / SQL Injections
by High-Tech Bridge SA
EIP-2026-106377 EXPLOITDB text VERIFIED
DB[CMS] - 'article.php' SQL Injection
by blackraptor
EIP-2026-101487 EXPLOITDB text VERIFIED
U.S.Robotics USR5463 0.06 Firmware - 'setup_ddns.exe' HTML Injection
by SH4V
EIP-2026-100572 EXPLOITDB text VERIFIED
Spaw Editor 1.0/2.0 - Arbitrary File Upload
by Ma3sTr0-Dz
EIP-2026-100525 EXPLOITDB text VERIFIED
Renista CMS - SQL Injection
by Amir Afghanian
EIP-2026-118762 EXPLOITDB text VERIFIED
McAfee Email Gateway 6.7.1 - 'systemWebAdminConfig.do' Remote Security Bypass
by Nahuel Grisolia
CVE-2010-1663 EXPLOITDB text VERIFIED
Google Chrome < 4.1.249.1063 - Access Control
The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
by Jordi Chancel
EIP-2026-112328 EXPLOITDB text VERIFIED
SoftDirec 1.05 - 'delete_confirm.php' Cross-Site Scripting
by indoushka
CVE-2010-2040 EXPLOITDB text VERIFIED
V-eva Shopzilla Affiliate Script Php - XSS
Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter.
by Andrea Bocchetti
CVE-2010-2033 EXPLOITDB text VERIFIED
Com Perchacategoriestree - Path Traversal
Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
by AntiSecurity
CVE-2010-2034 EXPLOITDB text VERIFIED
Com Perchaimageattach - Path Traversal
Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
by AntiSecurity
CVE-2010-2035 EXPLOITDB text VERIFIED
Com Perchagallery - Path Traversal
Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
by AntiSecurity
CVE-2010-2036 EXPLOITDB text VERIFIED
Com Perchafieldsattach - Path Traversal
Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
by AntiSecurity
CVE-2010-2037 EXPLOITDB text VERIFIED
Com Perchadownloadsattach - Path Traversal
Directory traversal vulnerability in the Percha Downloads Attach (com_perchadownloadsattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
by AntiSecurity
EIP-2026-108368 EXPLOITDB text VERIFIED
Joomla! Component com_horses - 'id' SQL Injection
by Kernel Security Group
EIP-2026-106378 EXPLOITDB text VERIFIED
DB[CMS] - 'section.php' SQL Injection
by CoBRa_21
CVE-2010-2051 EXPLOITDB text
Debliteck Dbcart - SQL Injection
SQL injection vulnerability in article.php in Debliteck DBCart allows remote attackers to execute arbitrary SQL commands via the id parameter.
by v3n0m
CVE-2010-2032 EXPLOITDB text VERIFIED
Caucho Resin - Cross-Site Scripting via digest_realm or digest_username Parameters
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm or (2) digest_username parameters. NOTE: some of these details are obtained from third party information.
by xuanmumu
EIP-2026-105672 EXPLOITDB text VERIFIED
C99Shell 1.0 Pre-Release build 16 (Web Shell) - 'ch99.php' Cross-Site Scripting
by indoushka
EIP-2026-105415 EXPLOITDB text VERIFIED
Battle Scrypt - Arbitrary File Upload
by DigitALL
CVE-2010-0475 EXPLOITDB text VERIFIED
Palo Alto Networks Firewall < 3.0.8 - XSS
Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.
by Jeromie Jackson
EIP-2026-100970 EXPLOITDB text VERIFIED
McAfee Email Gateway - Web Administration Broken Access Control
by Nahuel Grisolia
EIP-2026-116126 EXPLOITDB text
QtWeb Browser 3.3 - Denial of Service
by PoisonCode