Text Exploits

31,386 exploits tracked across all sources.

Sort: Activity Stars
CVE-2020-25449 EXPLOITDB MEDIUM text
Arachnys Cabot 0.11.12 - Cross-Site Scripting via Address Column
Cross Site Scripting (XSS) vulnerability in Arachnys Cabot 0.11.12 can be exploited via the Address column.
by Abhiram V
CVSS 4.8
CVE-2020-15253 EXPLOITDB HIGH text
grocy < 2.7.1 - Authenticated Stored Cross-Site Scripting via Shopping List Deletion
Versions of Grocy <= 2.7.1 are vulnerable to Cross-Site Scripting via the Create Shopping List module, that is rendered upon deleting that Shopping List. The issue was also found in users, batteries, chores, equipment, locations, quantity units, shopping locations, tasks, taskcategories, product groups, recipes and products. Authentication is required to exploit these issues and Grocy should not be publicly exposed. The linked reference details a proof-of-concept.
by Mufaddal Masalawala
CVSS 7.3
CVE-2020-36992 EXPLOITDB HIGH text
Nord VPN 6.31.13.0 - Code Injection
Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path during system startup or reboot to potentially run malicious code with LocalSystem permissions.
by chipo
CVSS 7.8
CVE-2020-23834 EXPLOITDB HIGH text
Real Time Logic BarracudaDrive <6.5 - Privilege Escalation
Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem.
by boku
CVSS 8.8
CVE-2020-24193 EXPLOITDB CRITICAL text
Sourcecodetester Daily Tracker System 1.0 - SQL Injection
A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.
by Adeeb Shah
CVSS 9.8
CVE-2020-29282 EXPLOITDB CRITICAL text
BloodX 1.0 - SQL Injection
SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.
by BKpatron
CVSS 9.8
EIP-2026-112190 EXPLOITDB text
SiteMagic CMS 4.4.2 - Arbitrary File Upload (Authenticated)
by V1n1v131r4
CVE-2020-24609 EXPLOITDB MEDIUM text
Savsoft Quiz < 5.5 - Stored Cross-Site Scripting in User Registration
TechKshetra Info Solutions Pvt. Ltd Savsoft Quiz 5.5 and earlier has XSS which can result in an attacker injecting the XSS payload in the User Registration section and each time the admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie via crafted payload.
by Hemant Patidar
CVSS 6.1
CVE-2020-23830 EXPLOITDB HIGH text
SourceCodester Stock Management System <v1.0 - CSRF
A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when they visit a third-party site.
by boku
CVSS 7.1
CVE-2020-25042 EXPLOITDB HIGH text
MaraCMS 7.5 - Authenticated Arbitrary File Upload via codebase/dir.php
An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session and make a codebase/dir.php?type=filenew request to upload PHP code to codebase/handler.php.
by 0blio_
CVSS 7.2
EIP-2026-109598 EXPLOITDB text
moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)
by Abdulkadir Kaya
CVE-2021-34249 EXPLOITDB HIGH text
Online Book Store 1.0 - SQL Injection via ID Parameter
SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.
by Moaaz Taha
CVSS 7.5
CVE-2020-24791 EXPLOITDB CRITICAL text
FUEL CMS 1.4.8 - SQL Injection via fuel_replace_id Parameter
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
by c0mpu7er
CVSS 9.8
CVE-2020-24223 EXPLOITDB MEDIUM text
Mara CMS 7.5 - Cross-Site Scripting via contact.php theme or pagetheme Parameters
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
by George Tsimpidas
CVSS 6.1
CVE-2020-25362 EXPLOITDB HIGH text
Online Shopping Alphaware 1.0 - SQL Injection via id Parameter in details.php
The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.
by Moaaz Taha
CVSS 7.5
CVE-2020-25343 EXPLOITDB MEDIUM text
Symphony CMS 3.0.0 - Stored Cross-Site Scripting via Event Publish Article Body Field
Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['body'] param via events\event.publish_article.php
by SunCSR
CVSS 5.4
EIP-2026-104347 EXPLOITDB text
Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting
by Jinson Varghese Behanan
EIP-2026-113577 EXPLOITDB text
Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
by SunCSR Team
CVE-2020-36893 EXPLOITDB HIGH text
Eibiz i-Media Server Digital Signage 3.8.0 - Path Traversal
Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini.
by LiquidWorm
CVSS 7.5
EIP-2026-104241 EXPLOITDB text
Ericom Access Server x64 9.2.0 - Server-Side Request Forgery
by hyp3rlinx
CVE-2020-36993 EXPLOITDB MEDIUM text
LimeSurvey < 4.3.10 - Stored Cross-Site Scripting in Survey Menu via Surveymenu Parameters
LimeSurvey 4.3.10 contains a stored cross-site scripting vulnerability in the Survey Menu functionality of the administration panel. Attackers can inject malicious SVG scripts through the Surveymenu[title] and Surveymenu[parent_id] parameters to execute arbitrary JavaScript in administrative contexts.
by Matthew Aberegg
CVSS 5.4
CVE-2020-36895 EXPLOITDB HIGH text
EIBIZ i-Media Server Digital Signage 3.8.0 - Info Disclosure
EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the SiteConfig.properties file through an HTTP GET request, exposing administrative credentials, database connection details, and system configuration information.
by LiquidWorm
CVSS 7.5
CVE-2020-36894 EXPLOITDB HIGH text
Eibiz i-Media Server Digital Signage 3.8.0 - Auth Bypass
Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through AMF-encoded object manipulation. Attackers can send crafted serialized objects to the /messagebroker/amf endpoint to create administrative users without authentication, bypassing security controls.
by LiquidWorm
CVSS 7.5
CVE-2020-24932 EXPLOITDB CRITICAL text
Sourcecodester Complaint Management System 1.0 - SQL Injection via cid Parameter
An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.
by Mohamed Elobeid
CVSS 9.8
EIP-2026-101989 EXPLOITDB text
Seowon SlC 130 Router - Remote Code Execution
by maj0rmil4d