Exploitdb Exploits

50,076 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-107034 EXPLOITDB text VERIFIED
Faculty Evaluation System v1.0 - SQL Injection
by Andrey Stoykov
CVE-2023-33131 EXPLOITDB HIGH text
Microsoft Outlook - Remote Code Execution
Microsoft Outlook Remote Code Execution Vulnerability
by nu11secur1ty
CVSS 8.8
EIP-2026-111298 EXPLOITDB text
Piwigo v13.7.0 - Stored Cross-Site Scripting (XSS) (Authenticated)
by Okan Kurtulus
CVE-2023-33592 EXPLOITDB CRITICAL python
Lost and Found Information System v1.0 - SQL Injection
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
by Amirhossein Bahramizadeh
CVSS 9.8
EIP-2026-107411 EXPLOITDB python
Gila CMS 1.10.9 - Remote Code Execution (RCE) (Authenticated)
by Omer Shaik
CVE-2023-33145 EXPLOITDB MEDIUM text
Microsoft Edge Chromium < 114.0.1823.51 - Information Disclosure
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
by nu11secur1ty
CVSS 6.5
EIP-2026-105720 EXPLOITDB text
Car Rental Script 1.8 - Stored Cross-site scripting (XSS)
by CraCkEr
EIP-2026-105435 EXPLOITDB text
Beauty Salon Management System v1.0 - SQLi
by Fatih Nacar
CVE-2023-37602 EXPLOITDB MEDIUM text
Alkacon OpenCMS 15.0 - Arbitrary File Upload and Remote Code Execution via PNG File
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
by tmrswrr
CVSS 6.1
CVE-2023-53903 EXPLOITDB MEDIUM text VERIFIED
WebsiteBaker 2.13.3 - Authenticated Stored Cross-Site Scripting via SVG File Upload
WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks.
by Mirabbas Ağalarov
CVSS 5.4
CVE-2023-53902 EXPLOITDB MEDIUM text VERIFIED
WebsiteBaker 2.13.3 - Path Traversal
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.
by Mirabbas Ağalarov
CVSS 6.5
CVE-2023-53901 EXPLOITDB MEDIUM text
WBCE CMS 1.6.1 - Stored Cross-Site Scripting via CSS Keylogging
WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attackers can upload a crafted HTML file with CSS-based keylogging techniques to intercept password characters through background image requests.
by Mirabbas Ağalarov
CVSS 5.4
CVE-2023-53900 EXPLOITDB HIGH text
Spip 4.1.10 - Stored Cross-Site Scripting via Malicious SVG Upload
Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.
by nu11secur1ty
CVSS 8.8
CVE-2023-53899 EXPLOITDB CRITICAL text
PodcastGenerator 3.2.9 - Server-Side Request Forgery via Episode Upload Shortdesc Parameter
PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.
by Mirabbas Ağalarov
CVSS 9.8
CVE-2023-53898 EXPLOITDB MEDIUM text
Rukovoditel 3.4.1 - Authenticated Stored Cross-Site Scripting via Application Copyright Text
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.
by Mirabbas Ağalarov
CVSS 5.4
CVE-2023-53897 EXPLOITDB MEDIUM text
Rukovoditel 3.4.1 - Authenticated Stored Cross-Site Scripting via Project Task Comments
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.
by Mirabbas Ağalarov
CVSS 5.4
CVE-2023-53896 EXPLOITDB HIGH text
D-Link DAP-1325 1.01 - Info Disclosure
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.
by ieduardogoncalves
CVSS 7.5
CVE-2022-4297 EXPLOITDB CRITICAL text
WP AutoComplete Search < 1.0.4 - Unauthenticated SQL Injection via AJAX Parameter
The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection
by matitanium
CVSS 9.8
EIP-2026-112943 EXPLOITDB text
Vacation Rental 1.8 - Stored Cross-Site Scripting (XSS)
by CraCkEr
EIP-2026-112690 EXPLOITDB text
Time Slot Booking Calendar 1.8 - Stored Cross-Site Scripting (XSS)
by CraCkEr
CVE-2023-36346 EXPLOITDB MEDIUM python
POS Codekop v2.0 - Reflected Cross-Site Scripting via nm_member Parameter
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.
by Amirhossein Bahramizadeh
CVSS 6.1
EIP-2026-111500 EXPLOITDB text
Prestashop 8.0.4 - Cross-Site Scripting (XSS)
by Mirabbas Ağalarov
CVE-2023-36348 EXPLOITDB HIGH text
POS Codekop v2.0 - Authenticated RCE
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
by yuyudhn
CVSS 8.8
EIP-2026-107543 EXPLOITDB text
GZ Forum Script 1.8 - Stored Cross-Site Scripting (XSS)
by CraCkEr
CVE-2023-24078 EXPLOITDB HIGH python
FuguHub < 8.1 - Remote Code Execution via CMS Docs Component
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.
by redfire359
CVSS 8.8