Exploitdb Exploits

31,346 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-100353 EXPLOITDB text
htmlArea 2.03 - Database Disclosure
by indoushka
EIP-2026-100335 EXPLOITDB text VERIFIED
Futility Forum 1.0 Revamp - Database Disclosure
by indoushka
EIP-2026-100332 EXPLOITDB text VERIFIED
Fully Functional ASP Forum 1.0 - Database Disclosure
by indoushka
EIP-2026-100157 EXPLOITDB text VERIFIED
BaalASP 2.0 - Database Disclosure
by indoushka
EIP-2026-100128 EXPLOITDB text VERIFIED
AspBB - Active Server Page Bulletin Board Database Disclosure
by indoushka
EIP-2026-100116 EXPLOITDB text VERIFIED
ASP Battle Blog - Database Disclosure
by indoushka
EIP-2026-112481 EXPLOITDB text VERIFIED
Sunbyte e-Flower - SQL Injection
by Don Tukulesto
EIP-2026-108754 EXPLOITDB text VERIFIED
Joomla! Component Joomulus 2.0 - 'tagcloud.swf' Cross-Site Scripting
by MustLive
EIP-2026-108295 EXPLOITDB text VERIFIED
Joomla! Component com_calendario - Blind SQL Injection
by Mr.tro0oqy
CVE-2009-4458 EXPLOITDB text VERIFIED
FreePBX 2.5.2 and 2.6.0rc2 - Cross-Site Scripting via Tech Parameter and Description Parameter
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) tech parameter to admin/admin/config.php during a trunks display action, the (2) description parameter during an Add Zap Channel action, and (3) unspecified vectors during an Add Recordings action.
by Global-Evolution
CVE-2009-4458 EXPLOITDB text VERIFIED
FreePBX 2.5.2 and 2.6.0rc2 - Cross-Site Scripting via Tech Parameter and Description Parameter
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow remote attackers to inject arbitrary web script or HTML via the (1) tech parameter to admin/admin/config.php during a trunks display action, the (2) description parameter during an Add Zap Channel action, and (3) unspecified vectors during an Add Recordings action.
by Global-Evolution
EIP-2026-106577 EXPLOITDB text
Dren's PHP Uploader - Arbitrary File Upload
by Cyb3r IntRue
EIP-2026-105690 EXPLOITDB text VERIFIED
Calendar Express 2.0 - SQL Injection
by BAYBORA
EIP-2026-104512 EXPLOITDB text
Yonja - Arbitrary File Upload
by indoushka
CVE-2009-4679 EXPLOITDB text VERIFIED
Joomla! com_if_nexus 1.5 - Path Traversal
Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
by FL0RiX
EIP-2026-104171 EXPLOITDB text VERIFIED
ASP Simple Blog 3.0 - Arbitrary File Upload
by indoushka
EIP-2026-103310 EXPLOITDB text VERIFIED
PHP Forum ohne My SQL - Arbitrary File Upload
by wlhaan hacker
EIP-2026-103300 EXPLOITDB text VERIFIED
MySimpleFileUploader 1.6 - Arbitrary File Upload
by FormatXformat
EIP-2026-103275 EXPLOITDB text VERIFIED
egegen turkish script - SQL Injection
by FormatXformat
EIP-2026-112232 EXPLOITDB text VERIFIED
Smart PHP Uploader 1.0 - Arbitrary File Upload
by Phenom
EIP-2026-110778 EXPLOITDB text VERIFIED
PHP upload - 'unijimpe' Arbitrary File Upload
by wlhaan hacker
EIP-2026-109982 EXPLOITDB text VERIFIED
Nuke - SQL Injection
by FormatXformat
EIP-2026-109292 EXPLOITDB text
Mambo Component Material Suche 1.0 - SQL Injection
by Gamoscu
EIP-2026-109151 EXPLOITDB text VERIFIED
lineaCMS - Cross-Site Scripting
by Phenom
EIP-2026-108785 EXPLOITDB text
Joomla! Component memorybook 1.2 - Multiple Vulnerabilities
by jdc