Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2017-09-19   Digirez 3.4 - Cross-Site Request Forgery (Update Admin) 122 WEB Ihsan Sencan
2017-09-18   D-Link DIR8xx Routers - Local Firmware Upload 220 WEB embedi
2017-09-18   D-Link DIR8xx Routers - Root Remote Code Execution 144 WEB embedi
2017-09-18   D-Link DIR8xx Routers - Leak Credentials 124 WEB embedi
2017-09-11   Nimble Professional 1.0 - Cross-Site Request Forgery (Update Admin) 136 WEB Ihsan Sencan
2017-09-11   Topsites Script 1.0 - Cross-Site Request Forgery / PHP Code Injection 115 WEB Ihsan Sencan
2017-08-31   Invoice Manager 3.1 - Cross-Site Request Forgery (Add Admin) 238 WEB Ali BawazeEer
2017-08-24   Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution 130 WEB LiquidWorm
2017-08-11   DALIM SOFTWARE ES Core 5.0 Build 7184.1 User Enumeration 145 WEB LiquidWorm
2017-08-09   Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution 111 WEB Kacper Szurek
2017-08-02   Advantech SUSIAccess <= 3.0 - 'RecoveryMgmt' File Upload 124 WEB James Fitts
2017-08-02   Advantech SUSIAccess <= 3.0 - Directory Traversal / Information Disclosure (Metasploit) 107 WEB James Fitts
2017-07-31   GitHub Enterprise < 2.8.7 - Remote Code Execution 118 WEB orange
2017-07-27   WebKit JSC - 'JSObject::putInlineSlow and JSValue::putToPrimitive' Universal Cross-Site Scripting 90 WEB Google Security Research
2017-07-25   ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit) 196 WEB Kacper Szurek
2017-07-21   Netscaler SD-WAN 9.1.2.26.561201 - Command Injection (Metasploit) 137 WEB xort
2017-07-21   Sonicwall < 8.1.0.2-14sv - 'sitecustomization.cgi' Command Injection (Metasploit) 116 WEB xort
2017-07-21   Sonicwall < 8.1.0.6-21sv - 'gencsr.cgi' Command Injection (Metasploit) 108 WEB xort
2017-07-19   Easy File Sharing Web Server 7.2 Buffer Overflow 141 WEB N_A
2017-07-18   Barracuda Load Balancer Firmware <= 6.0.1.006 - Remote Command Injection (Metasploit) 142 WEB xort
2017-07-18   Sophos Web Appliance 4.3.0.2 - 'trafficType' Remote Command Injection (Metasploit) 116 WEB xort
2017-07-17   WDTV Live SMP 2.03.20 - Remote Password Reset 183 WEB Sw1tCh
2017-07-17   Apache Struts 2.3.x Showcase - Remote Code Execution (PoC) 285 WEB Vex Woo
2017-07-13   RaidenHTTPD 2.0.44 User-Agent Cross Site Scripting 99 WEB sultan albalawi
2017-07-12   NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection 160 WEB Paul Taylor