Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
CVE-2021-43462 EXPLOITDB MEDIUM text
Rumble Mail Server 0.51.3135 - Cross-Site Scripting via Username Parameter
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.
by Mohammed Alshehri
CVSS 5.4
CVE-2021-43461 EXPLOITDB MEDIUM text
Rumble Mail Server 0.51.3135 - Cross-Site Scripting via Servername Parameter
Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter.
by Mohammed Alshehri
CVSS 5.4
CVE-2021-43460 EXPLOITDB HIGH text
System Explorer 7.0.0 - Privilege Escalation
An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService service executable path.
by Mohammed Alshehri
CVSS 7.8
CVE-2021-43459 EXPLOITDB MEDIUM text
Rumble Mail Server <0.51.3135 - XSS
A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parameters.
by Mohammed Alshehri
CVSS 5.4
CVE-2020-36932 EXPLOITDB MEDIUM text
SeaCMS 11.1 - Stored Cross-Site Scripting via Checkuser Parameter
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
by j5s
CVSS 6.1
EIP-2026-111815 EXPLOITDB text
Rukovoditel 2.6.1 - Cross-Site Request Forgery (Change password)
by KeopssGroup0day_Inc
EIP-2026-104498 EXPLOITDB text
WordPress Plugin Total Upkeep 1.14.9 - Database and Files Backup Download
by Wadeek
EIP-2026-104424 EXPLOITDB text
Seacms 11.1 - 'ip and weburl' Remote Command Execution
by j5s
EIP-2026-104423 EXPLOITDB text
Seacms 11.1 - 'file' Local File Inclusion
by j5s
CVE-2020-2231 EXPLOITDB MEDIUM text
Jenkins < 2.251 and LTS < 2.235.3 - Stored Cross-Site Scripting via Remote Build Trigger
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
by gx1
CVSS 5.4
CVE-2020-35202 EXPLOITDB MEDIUM text
Ignite Realtime Openfire 4.6.0 - Stored Cross-Site Scripting in DB Access Plugin
Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.
by j5s
CVSS 5.4
CVE-2020-35201 EXPLOITDB MEDIUM text
Ignite Realtime Openfire 4.6.0 - XSS
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.
by j5s
CVSS 5.4
CVE-2020-35199 EXPLOITDB MEDIUM text
Ignite Realtime Openfire 4.6.0 - XSS
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.
by j5s
CVSS 5.4
CVE-2020-35329 EXPLOITDB MEDIUM text
Courier Management System 1.0 - SQL Injection via MULTIPART street Parameter
Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '.
by Zhaiyi
CVSS 6.5
CVE-2020-35328 EXPLOITDB MEDIUM text
Courier Management System 1.0 - Stored Cross-Site Scripting via First Name Field
Courier Management System 1.0 - 'First Name' Stored XSS
by Zhaiyi
CVSS 5.4
CVE-2020-35327 EXPLOITDB MEDIUM text
Courier Management System 1.0 - SQL Injection via ref_no Parameter
SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php
by Zhaiyi
CVSS 6.5
EIP-2026-112493 EXPLOITDB text
Supply Chain Management System - Auth Bypass SQL Injection
by Piyush Malviya
EIP-2026-109391 EXPLOITDB text
Medical Center Portal Management System 1.0 - Multiple Stored XSS
by Saeed Bala Ahmed
CVE-2020-2229 EXPLOITDB MEDIUM text
Jenkins < 2.235.3 and < 2.251 - Stored Cross-Site Scripting via Help Icon Tooltip
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
by gx1
CVSS 5.4
CVE-2020-2230 EXPLOITDB MEDIUM text
Jenkins < 2.235.3 and < 2.251 - Stored Cross-Site Scripting in Project Naming Strategy Description
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
by gx1
CVSS 5.4
CVE-2020-36957 EXPLOITDB HIGH text
PDF Complete <3.5.310.2002 - Code Injection
PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its pdfsvc.exe service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.
by Zaira Alquicira
CVSS 7.8
CVE-2020-36956 EXPLOITDB MEDIUM text
Openfire < 4.6.0 - Stored Cross-Site Scripting via NodeJS Plugin Path Parameter
Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration page.
by j5s
CVSS 6.4
CVE-2020-35396 EXPLOITDB MEDIUM text
EGavilan Barcodes generator 1.0 - Stored Cross-Site Scripting via index.php
EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.
by Nikhil Kumar
CVSS 6.1
CVE-2020-28838 EXPLOITDB LOW text
OpenCart 3.0.3.6 - Cross-Site Request Forgery in Cart Option
Cross Site Request Forgery (CSRF) in CART option in OpenCart Ltd. Opencart CMS 3.0.3.6 allows attacker to add cart items via Add to cart.
by Mahendra Purbia
CVSS 3.5
EIP-2026-113974 EXPLOITDB text
WordPress Plugin Popup Builder 3.69.6 - Multiple Stored Cross Site Scripting
by Ilca Lucian Florin