Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-104538 EXPLOITDB text VERIFIED
Novell eDirectory 8.8 SP5 - 'dconserv.dlm' Cross-Site Scripting
by Francis Provencher
EIP-2026-115030 EXPLOITDB text VERIFIED
Cerberus FTP server 3.0.6 - Denial of Service
by Francis Provencher
CVE-2009-3489 EXPLOITDB HIGH text VERIFIED
Adobe Photoshop Elements 8.0 - Incorrect Permission Assignment for Critical Resource in Active File Monitor Service
Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) stop the service via the stop command, (2) execute arbitrary commands as SYSTEM by using the config command to modify the binPath variable, or (3) restart the service via the start command.
by pyrokinesis
CVSS 7.8
CVE-2009-4192 EXPLOITDB text VERIFIED
Interspire Knowledge Manager 5 - Path Traversal
Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Infected Web
EIP-2026-107139 EXPLOITDB text VERIFIED
Flatpress 0.804 < 0.812.1 - Local File Inclusion
by Giuseppe Fuggiano
EIP-2026-118519 EXPLOITDB text VERIFIED
EnjoySAP 6.4/7.1 - File Overwrite
by sh2kerr
EIP-2026-108677 EXPLOITDB text VERIFIED
Joomla! Component IRCm Basic - SQL Injection
by kaMtiEz
EIP-2026-106659 EXPLOITDB text VERIFIED
e107 0.7.x - CAPTCHA Security Bypass / Cross-Site Scripting
by MustLive
CVE-2009-3642 EXPLOITDB text VERIFIED
FrontRange HEAT 8.01 - SQL Injection via Call Logging Username and Password Parameters
Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
by 0 0
EIP-2026-104756 EXPLOITDB text VERIFIED
PHP 5.3 - 'preg_match()' Full Path Disclosure
by David Vieira-Kurz
EIP-2026-118775 EXPLOITDB text VERIFIED
Mereo Web Server 1.8 - Source Code Disclosure
by Dr_IDE
EIP-2026-109023 EXPLOITDB text VERIFIED
Klonet E-Commerce - 'products.php' SQL Injection
by S3T4N
EIP-2026-104240 EXPLOITDB text VERIFIED
Engeman 6.x - SQL Injection
by crashbrz
CVE-2009-3525 EXPLOITDB text VERIFIED
Xen 3.0.3, 3.3.0, 3.3.1 - Unauthenticated Boot Parameter Modification via pyGrub
The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.
by Jan Lieskovsky
CVE-2009-3457 EXPLOITDB text VERIFIED
Cisco ACE Web Application Firewall and ACE XML Gateway < 6.1 - Information Disclosure via Unhandled HTTP Request
Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.
by nitr0us
EIP-2026-100096 EXPLOITDB text VERIFIED
Activedition - '/activedition/aelogin.asp' Multiple Cross-Site Scripting Vulnerabilities
by Richard Brain
EIP-2026-112514 EXPLOITDB text VERIFIED
Swiss Mango CMS - SQL Injection
by kaMtiEz
EIP-2026-111735 EXPLOITDB text VERIFIED
Regental Medien - Blind SQL Injection
by NoGe
EIP-2026-109474 EXPLOITDB text VERIFIED
MindSculpt CMS - SQL Injection
by kaMitEz
CVE-2009-3443 EXPLOITDB text VERIFIED
Fastball (com_fastball) 1.1.0-1.2 - SQL Injection via League Parameter
SQL injection vulnerability in the Fastball (com_fastball) component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.
by kaMtiEz
EIP-2026-107292 EXPLOITDB text VERIFIED
FSphp 0.2.1 - Remote File Inclusion
by NoGe
CVE-2009-3444 EXPLOITDB text VERIFIED
e107 < 0.7.16 - Cross-Site Scripting via HTTP Referer Header
Cross-site scripting (XSS) vulnerability in email.php in e107 0.7.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header in a news.1 (aka news to email) action.
by MustLive
EIP-2026-116856 EXPLOITDB text VERIFIED
Avast! AntiVirus 4.8.1351.0 - Denial of Service / Privilege Escalation
by Evilcry
EIP-2026-112969 EXPLOITDB text VERIFIED
Vastal I-Tech Agent Zone - 'view_listing.php' SQL Injection
by OoN_Boy
CVE-2009-3440 EXPLOITDB text VERIFIED
OSSIM < 2.1.2 - Cross-Site Scripting via Option Parameter
Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu).
by Alexey Sintsov