Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-110187 EXPLOITDB text
Online Student's Management System 1.0 - Remote Code Execution (Authenticated)
by Akıner Kısa
EIP-2026-110129 EXPLOITDB text
Online Job Portal 1.0 - Cross Site Scripting (Stored)
by Akıner Kısa
EIP-2026-109828 EXPLOITDB text
Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection
by Matthew Aberegg
EIP-2026-109827 EXPLOITDB text
Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection
by Matthew Aberegg
EIP-2026-109826 EXPLOITDB text
Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting
by Matthew Aberegg
CVE-2020-25270 EXPLOITDB MEDIUM text
PHPGurukul hostel-management-system 2.1 - Stored XSS via Guardian Name/Relation/Contact/Address/City
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
by Kokn3t
CVSS 5.4
CVE-2019-1003030 EXPLOITDB CRITICAL text
Jenkins Pipeline: Groovy Plugin <2.63 - RCE
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.
by Daniel Morris
CVSS 9.9
CVE-2020-29215 EXPLOITDB MEDIUM text
SourceCodester Employee Management System 1.0 - XSS
A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.
by Ankita Pal
CVSS 5.4
CVE-2020-29214 EXPLOITDB CRITICAL text
SourceCodester Alumni Management System 1.0 - SQL Injection
SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.
by Ankita Pal
CVSS 9.8
EIP-2026-114675 EXPLOITDB text
aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated)
by Ünsal Furkan Harani
CVE-2020-25762 EXPLOITDB CRITICAL text
Seat Reservation System 1.0 - SQL Injection via admin_class.php Login Parameters
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input validation on the username and password parameters. An attacker can send malicious input in the post request to /admin/ajax.php?action=login and bypass authentication, extract sensitive information etc.
by Rahul Ramkumar
CVSS 9.1
EIP-2026-111757 EXPLOITDB text
Restaurant Reservation System 1.0 - 'date' SQL Injection (Authenticated)
by b1nary
EIP-2026-106856 EXPLOITDB text
Employee Management System 1.0 - Authentication Bypass
by Ankita Pal
EIP-2026-106249 EXPLOITDB text
CS-Cart 1.3.3 - authenticated RCE
by 0xmmnbassel
EIP-2026-106248 EXPLOITDB text
CS-Cart 1.3.3 - 'classes_dir' LFI
by 0xmmnbassel
EIP-2026-106095 EXPLOITDB text
Company Visitor Management System (CVMS) 1.0 - Authentication Bypass
by Oğuz Türkgenç
CVE-2020-28133 EXPLOITDB CRITICAL text
Simple Grocery Store Sales and Inventory System - Authentication Bypass and SQL Injection via Login
An issue was discovered in SourceCodester Simple Grocery Store Sales And Inventory System 1.0. There was authentication bypass in web login functionality allows an attacker to gain client privileges via SQL injection in sales_inventory/login.php.
by Saurav Shukla
CVSS 9.8
EIP-2026-114645 EXPLOITDB text
Zoo Management System 1.0 - Authentication Bypass
by Jyotsna Adhana
EIP-2026-113044 EXPLOITDB text
Vehicle Parking Management System 1.0 - Authentication Bypass
by BKpatron
EIP-2026-117261 EXPLOITDB text
Guild Wars 2 - Insecure Folder Permissions
by George Tsimpidas
EIP-2026-104359 EXPLOITDB text
NodeBB Forum 1.12.2-1.14.2 - Account Takeover
by Muhammed Eren Uygun
CVE-2020-37006 EXPLOITDB HIGH text
berliCRM 1.0.24 - SQL Injection via src_record Parameter
berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database information.
by Ahmet Ümit BAYRAM
CVSS 8.2
EIP-2026-116883 EXPLOITDB text
Battle.Net 1.27.1.12428 - Insecure File Permissions
by George Tsimpidas
CVE-2020-37007 EXPLOITDB MEDIUM text
Liman 0.7 - Cross-Site Request Forgery
Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests.
by George Tsimpidas
CVSS 5.3
EIP-2026-112220 EXPLOITDB text
Small CRM 2.0 - 'email' SQL Injection
by Ahmet Ümit BAYRAM