header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Vulnerability Type
No results found
Cross-Site Scripting (2389)
Cross-Site Scripting (XSS) (823)
HTML Injection (366)
Stored XSS (237)
SQL Injection (223)
Stored Cross-Site Scripting (XSS) (196)
Persistent Cross Site Scripting (176)
XSS (127)
Stored Cross Site Scripting (115)
Persistent XSS (95)
SQL Injection and Cross Site Scripting (93)
Cross Site Scripting and SQL Injection (57)
Information Disclosure (56)
Reflected XSS (56)
Reflected Cross Site Scripting (XSS) (50)
Cross-Site Request Forgery (46)
Cross-site Scripting and HTML Injection (38)
Directory Traversal (38)
Persistent Cross Site Scripting (XSS) (26)
Reflected Cross-Site Scripting (24)
Script Injection (24)
Arbitrary File Upload (23)
SQL Injection and XSS (23)
Authentication Bypass (22)
Local File Inclusion (20)
Remote Code Execution (19)
CSRF (18)
Input Validation (17)
Denial of Service (16)
HTML-injection and Cross-Site Scripting (16)
Local File Include (16)
Persistent Input Validation Web Vulnerability (16)
SQL Injection / Cross-Site Scripting (16)
Full Path Disclosure (15)
SQLi (15)
Cross site scripting [CWE-79] (14)
Cross-site Scripting (XSS) and Cross-site Request Forgery (CSRF) (13)
Multiple Cross-Site Scripting (13)
Multiple Vulnerabilities (13)
Persistent Input Validation (13)
Blind SQL Injection (12)
Remote File Inclusion (12)
SQL Injection & XSS (12)
Multiple XSS (11)
Security Bypass (11)
Stored Cross-site scripting(XSS) (11)
Cross Site Scripting - Persistent (10)
Cross-Site Request Forgery (CSRF) (10)
Persistant XSS (10)
Cross-Site Request Forgery [CWE-352] (9)
79
No results found
89 (8351)
79 (5937)
119 (4722)
78 (2037)
22 (1944)
98 (1882)
N/A (1389)
200 (1304)
400 (1281)
264 (1205)
287 (1099)
352 (1097)
120 (1032)
94 (1031)
20 (1026)
Unknown (897)
434 (850)
269 (267)
416 (254)
284 (219)
121 (196)
134 (187)
190 (149)
399 (138)
611 (120)
426 (115)
476 (110)
Buffer Overflow (110)
120 (Buffer Copy without Checking Size of Input) (104)
362 (95)
125 (92)
601 (87)
428 (86)
843 (86)
502 (85)
787 (84)
798 (79)
122 (77)
427 (73)
Not mentioned (70)
522 (65)
Not provided (59)
80 (55)
259 (54)
918 (44)
113 (40)
285 (40)
613 (39)
614 (37)
None (35)
CPE
No results found
N/A (1841)
Unknown (25)
Not mentioned (23)
a:microsoft:internet_explorer (17)
Not provided (16)
Not Specified (12)
a:wordpress:wordpress (11)
None (7)
a:joomla:joomla (6)
Not Available (6)
osticket (6)
a:alkacon:opencms (5)
a:cacti:cacti (5)
a:igniterealtime:openfire (5)
a:moodle:moodle (5)
a:mybb:mybb (5)
a:petrol_pump_management_software:petrol_pump_management_software:1.0 (5)
a:piwigo:piwigo (5)
2.0 (4)
2.7.17 (4)
a:adobe:coldfusion (4)
a:apache:tomcat (4)
a:apache:xampp (4)
a:freepbx:freepbx (4)
a:invision_power_services:invision_power_board (4)
a:otrs:otrs (4)
a:wondercms:wondercms:3.1.3 (4)
a:zoho:manageengine_servicedesk_plus:9.3 (4)
vbulletin:vbulletin (4)
2.1 (3)
4images (3)
a:apache:struts (3)
a:bitweaver:bitweaver (3)
a:centos-webpanel:centos_web_panel (3)
a:cisco:unified_operations_manager (3)
a:collabtive:collabtive (3)
a:cpanel:cpanel (3)
a:directadmin:directadmin (3)
a:domainmod:domainmod (3)
a:dotclear:dotclear (3)
a:fork_cms:fork_cms (3)
a:geeklog:geeklog (3)
a:limesurvey:limesurvey (3)
a:logitech:logitech_media_server (3)
a:osticket:osticket:1.14.1 (3)
a:php-fusion:php-fusion (3)
a:phpnuke:php-nuke (3)
a:rumble:rumble_mail_server:0.51.3135 (3)
a:seopanel:seo_panel:4.8.0 (3)
a:snipeit:snipeit:6.2.1 (3)
Vendor
No results found
N/A (607)
WordPress (195)
Sourcecodester (84)
Microsoft (50)
Unknown (49)
IBM (40)
Joomla! (37)
MyBB (37)
Apache (36)
PHPGurukul (34)
Oracle (29)
Codecanyon (22)
Cisco (21)
D-Link (19)
PHP-Nuke (16)
vBulletin (16)
SAP (15)
Adobe (13)
e107 (13)
phpBB (13)
TP-Link (13)
ManageEngine (12)
PostNuke (12)
Sun (12)
XOOPS (12)
Apple (11)
Inc (11)
Kayako (11)
osTicket (11)
Piwigo (11)
Barracuda Networks (10)
Horde (10)
HP (10)
Invision Power Services (10)
Atlassian (9)
Drupal (9)
Geeklog (9)
Google (9)
Moodle (9)
Mozilla (9)
Novell (9)
vtiger (9)
ATutor (8)
Bitweaver (8)
cPanel (8)
Dell (8)
Liferay (8)
Linksys (8)
McAfee (8)
Not mentioned (8)
Product Name
No results found
N/A (37)
Internet Explorer (23)
vBulletin (18)
MyBB (17)
WordPress (17)
CMS (16)
Guestbook (15)
Joomla (12)
Invision Power Board (10)
osTicket (10)
Piwigo (10)
Geeklog (9)
Moodle (9)
pfSense (9)
Phorum (9)
XAMPP (9)
DCP Portal (8)
OpenCMS (8)
Openfire (8)
PHP-Nuke (8)
phpMyAdmin (8)
PostNuke (8)
XOOPS (8)
Achievo (7)
ATutor (7)
Bitweaver (7)
CMS Made Simple (7)
efront (7)
GetSimple CMS (7)
osCommerce (7)
Petrol Pump Management Software (7)
PHP-Fusion (7)
phpBB (7)
Serendipity (7)
SmarterMail (7)
Tomcat (7)
Vtiger CRM (7)
WonderCMS (7)
CentOS Web Panel (6)
Claroline (6)
CubeCart (6)
CuteNews (6)
e107 (6)
Flatnux (6)
ManageEngine ServiceDesk Plus (6)
Opera (6)
PHP Address Book (6)
PHPMyChat (6)
phpMyFAQ (6)
Scoop (6)
Version
From
No results found
N/A (1066)
Unknown (207)
1 (152)
1.0 (120)
3.1 (83)
2 (54)
1.1 (46)
2.1 (40)
All versions (29)
1.5 (27)
3 (27)
1.2 (26)
2.0 (25)
1.3 (24)
4 (23)
2.2 (22)
1.0.1 (21)
2.3 (19)
0.1 (18)
1.0.0 (18)
1.6 (18)
1.4 (17)
5 (17)
2.5 (16)
6 (16)
All (16)
3.0.0 (15)
3.0 (14)
1.0.2 (13)
2.0.0 (13)
1.2.2001 (12)
v1.0 (12)
0.2 (11)
1.7 (11)
1.8 (11)
2.4 (11)
Version 1 (11)
< 3.2 (10)
1.0.3 (10)
1.0.4 (10)
1.2.2000 (10)
1.2.2002 (10)
2.0.1 (10)
4.2 (10)
2.0.2 (9)
2.1.1 (9)
2.1.2001 (9)
1.1.2000 (8)
1.2.2 (8)
2.6 (8)
To
No results found
N/A (1094)
Unknown (439)
1 (122)
1.0 (117)
3.5-RC7 (49)
2 (47)
1.1 (45)
Not mentioned (34)
Prior versions (30)
2.1 (29)
Other versions may also be affected. (27)
1.2 (26)
2.0 (26)
3 (25)
All versions (25)
1.5 (21)
2.2 (21)
4 (20)
1.6 (19)
1.3 (18)
5 (18)
1.4 (16)
6 (16)
All (16)
0.1 (15)
2.3 (15)
1.0.1 (14)
1.0.2 (14)
2.5 (14)
3.0 (13)
Not provided (13)
not specified (13)
1.7 (12)
3.1 (12)
v1.0 (12)
1.0.0 (11)
1.2.2001 (11)
4.2 (11)
Unknown (other versions may also be affected) (11)
1.8 (10)
2.4 (10)
2.0.1 (9)
3.0.0 (9)
Version 1 (9)
0.5 (8)
1.0.4 (8)
1.2.2 (8)
1.2.2002 (8)
1.5.1 (8)
2.1.1 (8)
Severity Type
No results found
HIGH (3846)
MEDIUM (1962)
CRITICAL (60)
N/A (38)
LOW (25)
Severity Number
No results found
7.5 (2152)
5 (750)
7 (691)
5.5 (632)
8.8 (455)
8 (417)
6.1 (256)
3.3 (248)
4.3 (236)
3 (209)
Exploit Author
No results found
SecurityFocus (2118)
Unknown (587)
Gjoko 'LiquidWorm' Krstic (56)
indoushka (42)
Vulnerability Laboratory Research Team (37)
Not mentioned (36)
0xB9 (32)
Mirabbas Agalarov (22)
Vulnerability-Lab (22)
High-Tech Bridge SA - Ethical Hacking & Penetration Testing (20)
loneferret (19)
Not Specified (19)
Not provided (18)
CraCkEr (17)
Vulnerability Laboratory (17)
TaurusOmar (16)
High-Tech Bridge Security Research Lab (14)
Anonymous (13)
Ismail Tasdelen (13)
Shai rod (13)
AmnPardaz Security Research Team (12)
LiquidWorm (12)
milw0rm.com (12)
Sid3^effects aKa haRi (12)
CWH Underground (11)
Ozer Goker (11)
Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (bkm@vulnerability-lab.com) (11)
N/A (10)
Valentin Hoebel (10)
Dolev Farhi (9)
Henry Hoggard (9)
Mesut Cetin (9)
Moudi (9)
nu11secur1ty (9)
Özkan Mustafa Akkuş (AkkuS) (9)
tmrswrr (9)
Cakes (8)
cp77fk4r (8)
HackXBack (8)
Halil Dalabasmaz (8)
John Page (hyp3rlinx) (8)
loneferret of Offensive Security (8)
Matthew Aberegg (8)
Piyush Patil (8)
Saif El-Sherei (8)
Borna nematzadeh (L0RD) (7)
Hemant Patidar (HemantSolo) (7)
hyp3rlinx (7)
John Page (aka hyp3rlinx) (7)
ManhNho (7)
Platforms Tested
No results found
N/A (2599)
Windows (317)
Linux (270)
None (254)
Unknown (189)
Windows 10 (127)
Mac (85)
WordPress (81)
Kali Linux (77)
Windows 7 (36)
PHP (33)
Not mentioned (32)
unix (27)
iOS (24)
Windows 10 Pro (19)
Not Specified (18)
Ubuntu 18.04 (18)
macOS (17)
Web (17)
Web Application (17)
Microsoft Windows (16)
Ubuntu (16)
All (14)
Not provided (14)
Windows 10 / Kali Linux (14)
Linux & Windows (13)
Parrot OS (12)
Windows 10 / XAMPP (12)
Xampp (12)
Chrome) (11)
Windows & XAMPP (11)
Windows 7 pro SP1 x86 (11)
Windows Server 2003 sp2 (11)
Windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu) (11)
Centos 7 (10)
FireFox (10)
Microsoft Windows XP Professional SP3 (EN) (10)
Ubuntu 20.04 (10)
Windows/Linux (10)
any (9)
Browser (9)
Web-based (8)
Webapps (8)
Windows 10 x64 (8)
Windows 11 (8)
Proprietary devices (7)
Windows 8.1 (7)
Apache (6)
Apache 2.2.14 (Win32) (6)
IE 8 (6)
Year
Year
No results found
2008 (521)
2012 (517)
Unknown (443)
2005 (436)
2020 (364)
2009 (359)
2002 (326)
2010 (296)
2006 (281)
2021 (265)
2013 (210)
2018 (199)
2019 (159)
2014 (143)
2023 (136)
2011 (133)
2016 (94)
2015 (88)
2007 (86)
2017 (84)
2022 (79)
2004 (66)
Not mentioned (26)
2024 (24)
2003 (17)
N/A (17)
Not provided (14)
Not Specified (13)
2001 (6)
2015-2016 (2)
0 day (1)
Discovered in 2009 (1)
NA (1)
Zero day (1)

Explore all Exploits:

Stored Cross-Site Scripting (XSS) in NoteMark

The vulnerability exists in NoteMark version 0.13.0 and below. By injecting a malicious payload into a note and rendering it using the 'Rendered' tab, an attacker can execute arbitrary JavaScript code in the context of the user's session.

Stored XSS Vulnerability via File Name

The vulnerability allows attackers to execute malicious scripts by embedding them in the filename of an image file uploaded as part of creating a new ticket in the HelpDeskZ software version 2.0.2. Successful exploitation can lead to compromise of the administration panel and execution of unauthorized scripts in the administrator's environment.

Stored XSS in Calibre-web

Calibre-web 0.6.21 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability. This allows an attacker to insert malicious scripts stored on the server and run in the context of another user's session. By exploiting this vulnerability, an attacker can execute arbitrary scripts in the victim's browser.

Sitefinity 15.0 – Cross-Site Scripting (XSS)

A Cross-Site Scripting (XSS) vulnerability was found in Sitefinity CMS versions prior to 15.0.0. The vulnerability exists in all features using SF-Editor in the backend of the CMS. An attacker with lower privileges can insert malicious XSS payloads in the content form, which will be executed when a user with higher privileges, the victim, views the affected page.

PyroCMS v3.0.1 Stored Cross-Site Scripting

An attacker can exploit the vulnerability in PyroCMS v3.0.1 by injecting a malicious payload into the 'Redirect From' field, triggering a stored cross-site scripting (XSS) attack. This could lead to unauthorized access, data theft, and other malicious activities. No CVE has been assigned yet.

Chyrp 2.5.2 – Stored Cross-Site Scripting (XSS)

Chyrp 2.5.2 is vulnerable to stored cross-site scripting (XSS) due to improper sanitization of user-supplied data. An attacker can inject malicious scripts into the 'Title' field, leading to the execution of arbitrary code in the context of the user's browser. This vulnerability has been assigned CVE-ID: N/A.

WordPress File Upload < 4.23.3 Stored XSS

A Stored Cross-Site Scripting (XSS) vulnerability exists in WordPress File Upload plugin version 4.23.3 and prior. By inserting a malicious shortcode in a post, an attacker can trigger an XSS attack when a file is uploaded, leading to potential script execution in the victim's browser. This vulnerability has been assigned CVE-2023-4811.

WordPress Plugin Alemha Watermarker 1.3.1 – Stored Cross-Site Scripting (XSS)

The Alemha Watermarker Wordpress Plugin version 1.3.1 is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient sanitization of user-supplied data in the 'watermark_title' field. An attacker can insert malicious scripts in the Watermark Text field, which will execute whenever a user attempts to edit the page.

Blood Bank v1.0 Stored Cross Site Scripting (XSS)

The 'rename', 'remail', 'rphone', and 'rcity' parameters in the 'updateprofile.php' file of Code-Projects Blood Bank V1.0 are vulnerable to Stored Cross-Site Scripting (XSS) due to lack of proper input validation. An attacker can inject malicious scripts into these parameters, and when stored on the server, these scripts may get executed when viewed by other users.

Recent Exploits:

cqrsecured