Exploitdb Exploits

31,344 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-101687 EXPLOITDB text
Edimax AR-7084GA Router - Cross-Site Request Forgery / Persistent Cross-Site Scripting
by l3D
EIP-2026-100529 EXPLOITDB text
SafeSHOP 1.5.6 - Cross-Site Scripting / Multiple Cross-Site Request Forgery Vulnerabilities
by cp77fk4r
CVE-2011-5165 EXPLOITDB text VERIFIED
Cleanersoft Free Mp3 CD Ripper < 2.6 - Memory Corruption
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wav file.
by Richard leahy
EIP-2026-115352 EXPLOITDB text VERIFIED
Google Chrome 4.1 - Out-of-Bounds Array Indexing
by Tobias Klein
EIP-2026-113052 EXPLOITDB text
Velhost Uploader Script 1.2 - Local File Inclusion
by cr4wl3r
EIP-2026-108463 EXPLOITDB text VERIFIED
Joomla! Component com_ops - SQL Injection
by DevilZ TM
EIP-2026-108444 EXPLOITDB text VERIFIED
Joomla! Component com_menu - SQL Injection
by DevilZ TM
EIP-2026-108350 EXPLOITDB text VERIFIED
Joomla! Component com_football - SQL Injection
by DevilZ TM
CVE-2010-1299 EXPLOITDB text
dynpg < 4.1.0 - Remote Code Execution via PHP File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) DefineRootToTool parameter to counter.php, (2) PathToRoot parameter to plugins/DPGguestbook/guestbookaction.php and (3) get_popUpResource parameter to backendpopup/popup.php. NOTE: some of these details are obtained from third party information.
by eidelweiss
EIP-2026-104863 EXPLOITDB text
68KB Knowledge Base 1.0.0rc3 - Cross-Site Request Forgery (Edit Main Settings)
by Jelmer de Hen
EIP-2026-104862 EXPLOITDB text
68kb 68KB Base 1.0.0rc3 - Cross-Site Request Forgery (Admin)
by Jelmer de Hen
EIP-2026-114561 EXPLOITDB text VERIFIED
Zabbix 1.8.1 - SQL Injection
by Dawid Golunski
EIP-2026-112166 EXPLOITDB text VERIFIED
SimpNews 2.16.2 - Multiple SQL Injections
by NoGe
EIP-2026-112164 EXPLOITDB text VERIFIED
Simply Sites RGV - Local File Inclusion
by DevilZ TM
EIP-2026-112067 EXPLOITDB text
Simple Calculator by Peter Rekdal Sunde - Arbitrary File Upload
by indoushka
EIP-2026-111521 EXPLOITDB text VERIFIED
Profi Einzelgebots Auktions System - Blind SQL Injection
by Easy Laster
EIP-2026-110712 EXPLOITDB text
PHP Jokesite 2.0 - exec Command
by indoushka
EIP-2026-110050 EXPLOITDB text VERIFIED
onepound Shop / CMS - Cross-Site Scripting / SQL Injection
by Valentin
EIP-2026-109652 EXPLOITDB text VERIFIED
MusicBox 3.3 - Arbitrary File Upload
by indoushka
CVE-2010-1315 EXPLOITDB text
com_weberpcustomer 1.2.1 and 1.x before 1.06.02 - Path Traversal via Controller Parameter
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1.x before 1.06.02 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.
by Chip d3 bi0s
CVE-2010-1304 EXPLOITDB text
Joomla! com_userstatus <1.21.16 - Path Traversal
Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
by Chip d3 bi0s
CVE-2010-1873 EXPLOITDB text
com_jvehicles 1.0, 2.0, and 2.1111 - SQL Injection via aid Parameter
SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third party information.
by Chip d3 bi0s
EIP-2026-108634 EXPLOITDB text VERIFIED
Joomla! Component EContent - Local File Inclusion
by Chip d3 bi0s
EIP-2026-108570 EXPLOITDB text VERIFIED
Joomla! Component com_trading - Blind SQL Injection
by DevilZ TM
EIP-2026-108568 EXPLOITDB text VERIFIED
Joomla! Component com_tour - SQL Injection
by DevilZ TM