Text Exploits

31,341 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-113707 EXPLOITDB text
WordPress Plugin Easy Contact Form 1.1.7 - 'Name' Stored Cross-Site Scripting (XSS)
by Rahul Ramakant Singh
EIP-2026-110119 EXPLOITDB text
Online Hotel Reservation System 1.0 - Cross-site request forgery (CSRF)
by Mesut Cetin
EIP-2026-110117 EXPLOITDB text
Online Hotel Reservation System 1.0 - 'person' time-based SQL Injection
by Mesut Cetin
EIP-2026-110115 EXPLOITDB text
Online Hotel Reservation System 1.0 - 'id' Time-based SQL Injection
by Mesut Cetin
EIP-2026-110114 EXPLOITDB text
Online Hotel Reservation System 1.0 - 'description' Stored Cross-site Scripting
by Mesut Cetin
EIP-2026-105140 EXPLOITDB text
Alumni Management System 1.0 - _Last Name field in Registration page_ Stored XSS
by Siva Rajendran
EIP-2026-110176 EXPLOITDB text VERIFIED
Online Shopping Cart System 1.0 - 'id' SQL Injection
by Aydın Baran Ertemir
EIP-2026-110148 EXPLOITDB text
Online Movie Streaming 1.0 - Admin Authentication Bypass
by Richard Jones
EIP-2026-110118 EXPLOITDB text
Online Hotel Reservation System 1.0 - Admin Authentication Bypass
by Richard Jones
EIP-2026-105773 EXPLOITDB text
Cemetry Mapping and Information System 1.0 - Multiple SQL Injections
by Mesut Cetin
CVE-2021-3124 EXPLOITDB MEDIUM text VERIFIED
Newtarget Custom Global Variables - XSS
Stored cross-site scripting (XSS) in form field in robust.systems product Custom Global Variables v 1.0.5 allows a remote attacker to inject arbitrary code via the vars[0][name] field.
by Swapnil Subhash Bodekar
CVSS 5.4
CVE-2021-3110 EXPLOITDB CRITICAL text
Prestashop - SQL Injection
The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade id_products[] parameter.
by Jaimin Gondaliya
CVSS 9.8
EIP-2026-110274 EXPLOITDB text
OpenCart 3.0.36 - ATO via Cross Site Request Forgery
by Mahendra Purbia
EIP-2026-105774 EXPLOITDB text
Cemetry Mapping and Information System 1.0 - Multiple Stored Cross-Site Scripting
by Mesut Cetin
EIP-2026-104247 EXPLOITDB text
EyesOfNetwork 5.3 - RCE & PrivEsc
by Audencia Business SCHOOL Red Team
EIP-2026-104246 EXPLOITDB text
EyesOfNetwork 5.3 - LFI
by Audencia Business SCHOOL Red Team
EIP-2026-104157 EXPLOITDB text
Anchor CMS 0.12.7 - 'markdown' Stored Cross-Site Scripting
by Ramazan Mert GÖKTEN
CVE-2021-25791 EXPLOITDB MEDIUM text
Online Doctor Appointment System Php Full Source Code - XSS
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
by Mohamed habib Smidi
CVSS 5.4
EIP-2026-109123 EXPLOITDB text
Life Insurance Management System 1.0 - Multiple Stored XSS
by Arnav Tripathy
EIP-2026-104205 EXPLOITDB text
Cockpit Version 234 - Server-Side Request Forgery (Unauthenticated)
by Metin Yunus Kandemir
CVE-2021-3118 EXPLOITDB CRITICAL text
Medicalexpo Ecs Imaging < 6.21.5 - SQL Injection
EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The database component runs as root.) NOTE: This vulnerability only affects products that are no longer supported by the maintainer
by shoxxdj
CVSS 9.8
CVE-2020-35131 EXPLOITDB CRITICAL text
Cockpit <0.6.1 - RCE
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
by Rafael Resende
CVSS 9.8
EIP-2026-106864 EXPLOITDB text
Employee Record System 1.0 - Unrestricted File Upload to Remote Code Execution
by Saeed Bala Ahmed
EIP-2026-106765 EXPLOITDB text
ECSIMAGING PACS 6.21.5 - Remote code execution
by shoxxdj
EIP-2026-106279 EXPLOITDB text
Curfew e-Pass Management System 1.0 - Stored XSS
by Arnav Tripathy