Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-01-29   Cups Easy 1.0 - Cross Site Request Forgery (Password Reset) 11 WEB J3rryBl4nks
2020-01-29   Liferay CE Portal 6.0.2 - Remote Command Execution 11 WEB Berk Dusunur
2020-01-29   Kibana 6.6.1 - CSV Injection 12 WEB Aamir Rehman
2020-01-28   Centreon 19.10.5 - Remote Command Execution 12 WEB Fabien AUNAY
2020-01-28   Centreon 19.10.5 - Database Credentials Disclosure 11 WEB Fabien AUNAY
2020-01-28   Octeth Oempro 4.8 - 'CampaignID' SQL Injection 10 WEB Bruno de Barros Bulle
2020-01-28   Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password) 13 WEB Sarthak Saini
2020-01-24   Genexis Platinum-4410 2.1 - Authentication Bypass 12 WEB Husinul Sanub
2020-01-24   OLK Web Store 2020 - Cross-Site Request Forgery 12 WEB Joel Aviad Ossi
2020-01-24   Webtareas 2.0 - 'id' SQL Injection 7 WEB Greg.Priest
2020-01-24   TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot 9 WEB PCEumel
2020-01-23   qdPM 9.1 - Remote Code Execution 8 WEB Rishal Dwivedi
2020-01-22   Citrix XenMobile Server 10.8 - XML External Entity Injection 12 WEB Jonas Lejon
2020-01-21   ManageEngine Network Configuration Manager 12.2 - 'apiKey' SQL Injection 11 WEB Ertebat Gostar Co
2020-01-20   Centreon 19.04 - Authenticated Remote Code Execution (Metasploit) 11 WEB TheCyberGeek
2020-01-20   Adive Framework 2.0.8 - Persistent Cross-Site Scripting 13 WEB Sarthak Saini
2020-01-17   WordPress Plugin Time Capsule 1.21.16 - Authentication Bypass 15 WEB B. Canavate
2020-01-17   WordPress Plugin InfiniteWP Client 1.9.4.5 - Authentication Bypass 11 WEB Raphael Karger
2020-01-16   Rukovoditel Project Management CRM 2.5.2 - 'filters' SQL Injection 11 WEB Fatih Çelik
2020-01-16   Rukovoditel Project Management CRM 2.5.2 - 'entities_id' SQL Injection 14 WEB Fatih Çelik
2020-01-16   Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal 10 WEB Dhiraj Mishra
2020-01-16   Online Book Store 1.0 - Arbitrary File Upload 15 WEB Or4nG.M4N
2020-01-16   Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting 10 WEB Ai Ho
2020-01-16   Rukovoditel Project Management CRM 2.5.2 - 'reports_id' SQL Injection 10 WEB Fatih Çelik
2020-01-16   WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting 11 WEB V1n1v131r4
2020-01-15   Huawei HG255 - Directory Traversal (Metasploit) 11 WEB Ismail Tasdelen
2020-01-15   Online Book Store 1.0 - 'bookisbn' SQL Injection 9 WEB Ertebat Gostar Co
2020-01-14   IBM RICOH 6400 Printer - HTML Injection 11 WEB Ismail Tasdelen
2020-01-14   IBM RICOH InfoPrint 6500 Printer - HTML Injection 13 WEB Ismail Tasdelen
2020-01-13   Digi AnywhereUSB 14 - Reflective Cross-Site Scripting 14 WEB Raspina Net Pars Group
2020-01-13   Citrix Application Delivery Controller and Gateway 10.5 - Remote Code Execution (Metasploit) 13 WEB mekhalleh
2020-01-13   Chevereto 3.13.4 Core - Remote Code Execution 12 WEB Jinny Ramsmark
2020-01-11   Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution 12 WEB TrustedSec
2020-01-11   Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution (PoC) 11 WEB Project Zero India
2020-01-10   ASTPP 4.0.1 VoIP Billing - Database Backup Download 9 WEB Fabien AUNAY
2020-01-10   PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution 11 WEB .:UND3R:.
2020-01-10   Pandora 7.0NG - Remote Code Execution 9 WEB Askar
2020-01-09   Oracle Weblogic 10.3.6.0.0 - Remote Command Execution 12 WEB james
2019-12-31   Sony Playstation 4 (PS4) < 6.72 - WebKit Code Execution (PoC) 14 WEB TJ Corley
2020-01-08   Tomcat proprietaryEvaluate 9.0.0.M1 - Sandbox Escape 14 WEB hantwister
2020-01-08   Online Book Store 1.0 - Unauthenticated Remote Code Execution 17 WEB Tib3rius
2020-01-08   Codoforum 4.8.3 - 'input_txt' Persistent Cross-Site Scripting 13 WEB Vyshnav nk
2020-01-07   Complaint Management System 4.0 - Remote Code Execution 13 WEB Metin Yunus Kandemir
2020-01-07   piSignage 2.6.4 - Directory Traversal 14 WEB JunYeong Ko
2020-01-07   Job Portal 1.0 - Remote Code Execution 15 WEB Tib3rius
2019-12-24   Django < 3.0 < 2.2 < 1.11 - Account Hijack 13 WEB Ryuji Tsutsui
2020-01-06   Codoforum 4.8.3 - Persistent Cross-Site Scripting 13 WEB Prasanth
2020-01-06   Voyager 1.3.0 - Directory Traversal 13 WEB NgoAnhDuc
2020-01-06   Small CRM 2.0 - Authentication Bypass 15 WEB FULLSHADE
2020-01-06   elaniin CMS 1.0 - Authentication Bypass 15 WEB riamloo
2020-01-06   Hostel Management System 2.0 - 'id' SQL Injection 12 WEB FULLSHADE
2020-01-06   Subrion CMS 4.0.5 - Cross-Site Request Forgery (Add Admin) 13 WEB Ismail Tasdelen
2020-01-06   IBM RICOH Infoprint 1532 Printer - Persistent Cross-Site Scripting 12 WEB Ismail Tasdelen
2020-01-06   Complaint Management System 4.0 - 'cid' SQL injection 15 WEB FULLSHADE
2020-01-06   Dairy Farm Shop Management System 1.0 - 'username' SQL Injection 14 WEB Chris Inzinga
2020-01-03   Karakuzu ERP Management Web 5.7.0 - 'k_adi_duz' SQL Injection 13 WEB Hakan TAŞKÖPRÜ
2020-01-03   Online Course Registration 2.0 - Remote Code Execution 14 WEB Metin Yunus Kandemir
2020-01-02   BloodX 1.0 - Authentication Bypass 12 WEB riamloo
2020-01-02   Hospital Management System 4.0 - Persistent Cross-Site Scripting 13 WEB FULLSHADE
2020-01-02   Hospital Management System 4.0 - 'searchdata' SQL Injection 12 WEB FULLSHADE
2020-01-01   Hospital Management System 4.0 - Authentication Bypass 12 WEB Metin Yunus Kandemir
2020-01-01   IBM InfoPrint 4247-Z03 Impact Matrix Printer - Directory Traversal 13 WEB Raif Berkay Dincel
2020-01-01   Shopping Portal ProVersion 3.0 - Authentication Bypass 12 WEB Metin Yunus Kandemir
2019-12-31   WordPress Plugin Ultimate Addons for Beaver Builder 1.2.4.1 - Authentication Bypass 14 WEB Raphael Karger
2019-12-30   Heatmiser Netmonitor 3.03 - HTML Injection 11 WEB Ismail Tasdelen
2019-12-30   RICOH Web Image Monitor 1.09 - HTML Injection 11 WEB Ismail Tasdelen
2019-12-30   RICOH SP 4510SF Printer - HTML Injection 12 WEB Ismail Tasdelen
2019-12-30   MyDomoAtHome REST API Domoticz ISS Gateway 0.2.40 - Information Disclosure 11 WEB LiquidWorm
2019-12-30   Heatmiser Netmonitor 3.03 - Hardcoded Credentials 8 WEB Ismail Tasdelen
2019-12-30   AVE DOMINAplus 1.10.x - Authentication Bypass 9 WEB LiquidWorm
2019-12-30   AVE DOMINAplus 1.10.x - Cross-Site Request Forgery (enable/disable alarm) 9 WEB LiquidWorm
2019-12-30   AVE DOMINAplus 1.10.x - Unauthenticated Remote Reboot 8 WEB LiquidWorm
2019-12-30   AVE DOMINAplus 1.10.x - Credential Disclosure 12 WEB LiquidWorm
2019-12-30   WEMS BEMS 21.3.1 - Undocumented Backdoor Account 12 WEB LiquidWorm
2019-12-30   XEROX WorkCentre 7830 Printer - Cross-Site Request Forgery (Add Admin) 9 WEB Ismail Tasdelen
2019-12-30   XEROX WorkCentre 7855 Printer - Cross-Site Request Forgery (Add Admin) 9 WEB Ismail Tasdelen
2019-12-30   Thrive Smart Home 1.1 - Authentication Bypass 11 WEB LiquidWorm
2019-12-30   XEROX WorkCentre 6655 Printer - Cross-Site Request Forgery (Add Admin) 11 WEB Ismail Tasdelen
2019-12-30   elearning-script 1.0 - Authentication Bypass 12 WEB riamloo
2019-12-30   HomeAutomation 3.3.2 - Remote Code Execution 12 WEB LiquidWorm
2019-12-30   HomeAutomation 3.3.2 - Cross-Site Request Forgery (Add Admin) 11 WEB LiquidWorm
2019-12-30   HomeAutomation 3.3.2 - Authentication Bypass 11 WEB LiquidWorm
2019-12-30   HomeAutomation 3.3.2 - Persistent Cross-Site Scripting 10 WEB LiquidWorm
2019-12-20   phpMyChat-Plus 1.98 - 'pmc_username' Reflected Cross-Site Scripting 10 WEB Chris Inzinga
2019-12-19   Deutsche Bahn Ticket Vending Machine Local Kiosk - Privilege Escalation 10 WEB Vulnerability-Lab
2019-12-18   Telerik UI - Remote Code Execution via Insecure Deserialization 11 WEB Bishop Fox
2019-12-18   Rumpus FTP Web File Manager 8.2.9.1 - Reflected Cross-Site Scripting 11 WEB Harshit Shukla
2019-12-18   Xerox AltaLink C8035 Printer - Cross-Site Request Forgery (Add Admin) 13 WEB Ismail Tasdelen
2019-12-18   Tautulli 2.1.9 - Cross-Site Request Forgery (ShutDown) 14 WEB Ismail Tasdelen
2019-12-17   NopCommerce 4.2.0 - Privilege Escalation 16 WEB Alessandro Magnosi
2019-12-17   Netgear R6400 - Remote Code Execution 13 WEB Kevin Randall
2019-12-17   Zendesk App SweetHawk Survey 1.6 - Persistent Cross-Site Scripting 11 WEB MTK
2019-12-16   D-Link DIR-615 - Privilege Escalation 11 WEB Sanyam Chawla
2019-12-16   Roxy Fileman 1.4.5 - Directory Traversal 10 WEB Patrik Lantz
2019-12-16   D-Link DIR-615 Wireless Router  -  Persistent Cross-Site Scripting 10 WEB Sanyam Chawla
2019-12-13   NVMS 1000 - Directory Traversal 12 WEB numan türle
2019-12-12   Bullwark Momentum Series JAWS 1.0 - Directory Traversal 12 WEB numan türle
2019-12-12   OpenNetAdmin 18.1.1 - Command Injection Exploit (Metasploit) 12 WEB Onur ER
2019-12-11   Apache Olingo OData 4.0 - XML External Entity Injection 8 WEB Compass Security
2019-12-10   Inim Electronics Smartliving SmartLAN 6.x - Remote Command Execution 11 WEB LiquidWorm
2019-12-10   Inim Electronics Smartliving SmartLAN 6.x - Unauthenticated Server-Side Request Forgery 9 WEB LiquidWorm
2019-12-09   Oracle Siebel Sales 8.1 - Persistent Cross-Site Scripting 7 WEB omurugur
2019-12-09   Alcatel-Lucent Omnivista 8770 - Remote Code Execution 8 WEB 0x1911
2019-12-09   Yachtcontrol Webapplication 1.0 - Unauthenticated Remote Code Execution 7 WEB Hodorsec
2019-12-09   PRO-7070 Hazır Profesyonel Web Sitesi 1.0 - Authentication Bypass 8 WEB Ahmet Ümit BAYRAM
2019-12-09   Snipe-IT Open Source Asset Management 4.7.5 - Persistent Cross-Site Scripting 10 WEB Metin Yunus Kandemir
2019-12-06   Verot 2.0.3 - Remote Code Execution 11 WEB Jinny Ramsmark
2019-12-05   Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution 11 WEB Peter Lapp
2019-12-04   OwnCloud 8.1.8 - Username Disclosure 11 WEB Daniel Moreno
2019-12-04   Online Clinic Management System 2.2 - HTML Injection 12 WEB Cemal Cihad ÇİFTÇİ
2019-12-03   Revive Adserver 4.2 - Remote Code Execution 9 WEB crlf
2019-12-03   Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery 11 WEB Prof. Joas Antonio
2019-12-03   Online Invoicing System 2.6 - 'description' Persistent Cross-Site Scripting 11 WEB Cemal Cihad ÇİFTÇİ
2019-12-02   Dokuwiki 2018-04-22b - Username Enumeration 10 WEB Talha ŞEN
2019-12-02   SmartHouse Webapp 6.5.33 - Cross-Site Request Forgery 8 WEB LiquidWorm
2019-11-29   Online Inventory Manager 3.2 - Persistent Cross-Site Scripting 13 WEB Cemal Cihad ÇİFTÇİ
2019-11-28   Mersive Solstice 2.8.0 - Remote Code Execution 10 WEB Alexandre Teyar
2019-11-28   WordPress Core 5.3 - User Disclosure 10 WEB SajjadBnd
2019-11-21   Network Management Card 6.2.0 - Host Header Injection 9 WEB Amal E Thamban
2019-11-21   TestLink 1.9.19 - Persistent Cross-Site Scripting 9 WEB Milad Khoshdel
2019-11-20   OpenNetAdmin 18.1.1 - Remote Code Execution 11 WEB mattpascoe
2019-10-14   WordPress Core < 5.2.3 - Viewing Unauthenticated/Password/Private Posts 11 WEB Sebastian Neef
2019-10-14   Apache Httpd mod_rewrite - Open Redirects 10 WEB Sebastian Neef
2019-10-14   Apache Httpd mod_proxy - Error Page Cross-Site Scripting 12 WEB Sebastian Neef
2019-11-18   TemaTres 3.0 - 'value' Persistent Cross-site Scripting 12 WEB Pablo Santiago