|
2020-03-11
|
|
Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
|
32 |
WEB
|
Andrea Cardaci
|
|
2020-03-11
|
|
Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
|
33 |
WEB
|
Andrea Cardaci
|
|
2020-03-12
|
|
rConfig 3.9 - 'searchColumn' SQL Injection
|
35 |
WEB
|
vikingfr
|
|
2020-03-12
|
|
rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
|
32 |
WEB
|
Engin Demirbilek
|
|
2020-03-12
|
|
HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
|
34 |
WEB
|
Ismail Akıcı
|
|
2020-03-12
|
|
WordPress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
|
36 |
WEB
|
Daniel Monzón
|
|
2020-03-12
|
|
WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
|
33 |
WEB
|
RedTeam Pentesting GmbH
|
|
2020-03-12
|
|
Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
|
34 |
WEB
|
Milad karimi
|
|
2020-03-11
|
|
TeamCity Agent XML-RPC 10.0 - Remote Code Execution
|
32 |
WEB
|
1F98D
|
|
2020-03-11
|
|
Wing FTP Server - Authenticated CSRF (Delete Admin)
|
30 |
WEB
|
Dhiraj Mishra
|
|
2020-03-11
|
|
PlaySMS 1.4.3 - Template Injection / Remote Code Execution
|
31 |
WEB
|
Touhid M.Shaikh
|
|
2020-03-11
|
|
Joomla! 3.9.0 < 3.9.7 - CSV Injection
|
27 |
WEB
|
i4bdullah
|
|
2020-03-11
|
|
WordPress Plugin Search Meter 2.13.2 - CSV injection
|
37 |
WEB
|
Daniel Monzón
|
|
2020-03-10
|
|
Persian VIP Download Script 1.0 - 'active' SQL Injection
|
32 |
WEB
|
Amir Hossein Vafifar
|
|
2020-03-10
|
|
YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
|
32 |
WEB
|
En_dust
|
|
2020-03-10
|
|
Sysaid 20.1.11 b26 - Remote Command Execution
|
33 |
WEB
|
Ahmed Sherif
|
|
2020-03-09
|
|
Sentrifugo HRMS 3.2 - 'id' SQL Injection
|
34 |
WEB
|
minhnb
|
|
2020-03-09
|
|
60CycleCMS - 'news.php' SQL Injection
|
32 |
WEB
|
Unkn0wn
|
|
2019-12-12
|
|
ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization / Unauthenticated Remote
|
34 |
WEB
|
mr_me
|
|
2020-03-04
|
|
UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read
|
38 |
WEB
|
NgoAnhDuc
|
|
2020-03-03
|
|
RICOH Aficio SP 5210SF Printer - 'entryNameIn' HTML Injection
|
34 |
WEB
|
Olga Villagran
|
|
2020-03-03
|
|
GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
|
32 |
WEB
|
emaragkos
|
|
2020-03-03
|
|
Alfresco 5.2.4 - Persistent Cross-Site Scripting
|
36 |
WEB
|
Alexandre ZANNI
|
|
2020-03-03
|
|
RICOH Aficio SP 5200S Printer - 'entryNameIn' HTML Injection
|
35 |
WEB
|
Paulina Girón
|
|
2020-03-02
|
|
Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
|
31 |
WEB
|
Lucas Amorim
|
|
2020-03-02
|
|
Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
|
36 |
WEB
|
Elber Tavares
|
|
2020-03-02
|
|
TP LINK TL-WR849N - Remote Code Execution
|
34 |
WEB
|
Elber Tavares
|
|
2020-03-02
|
|
Wing FTP Server 6.2.5 - Privilege Escalation
|
36 |
WEB
|
Cary Hooper
|
|
2020-03-02
|
|
TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
|
36 |
WEB
|
Elber Tavares
|
|
2020-03-02
|
|
WordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
|
38 |
WEB
|
Jinson Varghese Behanan
|
|
2020-03-02
|
|
Netis WF2419 2.2.36123 - Remote Code Execution
|
36 |
WEB
|
Elias Issa
|
|
2020-03-02
|
|
Joplin Desktop 1.0.184 - Cross-Site Scripting
|
32 |
WEB
|
Javier Olmedo
|
|
2020-02-28
|
|
qdPM < 9.1 - Remote Code Execution
|
37 |
WEB
|
Tobin Shields
|
|
2020-02-03
|
|
Cacti 1.2.8 - Unauthenticated Remote Code Execution
|
31 |
WEB
|
Askar
|
|
2020-02-03
|
|
Cacti 1.2.8 - Authenticated Remote Code Execution
|
29 |
WEB
|
Askar
|
|
2020-02-20
|
|
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
|
30 |
WEB
|
YDHCUI
|
|
2020-02-27
|
|
Comtrend VR-3033 - Command Injection
|
32 |
WEB
|
Raki Ben Hamouda
|
|
2020-02-27
|
|
Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)
|
38 |
WEB
|
Meisam Monsef
|
|
2020-02-26
|
|
PhpIX 2012 Professional - 'id' SQL Injection
|
40 |
WEB
|
indoushka
|
|
2020-02-25
|
|
Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass
|
35 |
WEB
|
GeekHack
|
|
2020-02-25
|
|
WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass
|
37 |
WEB
|
GeekHack
|
|
2020-02-24
|
|
Cacti 1.2.8 - Remote Code Execution
|
33 |
WEB
|
Askar
|
|
2020-02-24
|
|
Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure
|
40 |
WEB
|
Todor Donev
|
|
2020-02-24
|
|
DotNetNuke 9.5 - File Upload Restrictions Bypass
|
42 |
WEB
|
Sajjad Pourali
|
|
2020-02-24
|
|
DotNetNuke 9.5 - Persistent Cross-Site Scripting
|
38 |
WEB
|
Sajjad Pourali
|
|
2020-02-24
|
|
eLection 2.0 - 'id' SQL Injection
|
35 |
WEB
|
J3rryBl4nks
|
|
2020-02-24
|
|
ManageEngine EventLog Analyzer 10.0 - Information Disclosure
|
39 |
WEB
|
Scott Goodwin
|
|
2020-02-24
|
|
I6032B-P POE 2.0MP Outdoor Camera - Remote Configuration Disclosure
|
36 |
WEB
|
Todor Donev
|
|
2020-02-24
|
|
ATutor 2.2.4 - 'id' SQL Injection
|
36 |
WEB
|
Andrey Stoykov
|
|
2020-02-24
|
|
SecuSTATION SC-831 HD Camera - Remote Configuration Disclosure
|
37 |
WEB
|
Todor Donev
|
|
2020-02-24
|
|
AMSS++ 4.7 - Backdoor Admin Account
|
38 |
WEB
|
indoushka
|
|
2020-02-24
|
|
CandidATS 2.1.0 - Cross-Site Request Forgery (Add Admin)
|
37 |
WEB
|
J3rryBl4nks
|
|
2020-02-24
|
|
SecuSTATION IPCAM-130 HD Camera - Remote Configuration Disclosure
|
36 |
WEB
|
Todor Donev
|
|
2020-02-24
|
|
AMSS++ v 4.31 - 'id' SQL Injection
|
38 |
WEB
|
indoushka
|
|
2020-02-24
|
|
Real Web Pentesting Tutorial Step by Step - [Persian]
|
36 |
WEB
|
Meisam Monsef
|
|
2020-02-24
|
|
ESCAM QD-900 WIFI HD Camera - Remote Configuration Disclosure
|
39 |
WEB
|
Todor Donev
|
|
2020-02-24
|
|
GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
|
32 |
WEB
|
emaragkos
|
|
2020-02-24
|
|
Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
|
37 |
WEB
|
Scott Goodwin
|
|
2020-02-20
|
|
Easy2Pilot 7 - Cross-Site Request Forgery (Add User)
|
35 |
WEB
|
indoushka
|
|
2020-02-19
|
|
Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak
|
33 |
WEB
|
byteGoblin
|
|
2020-02-19
|
|
DBPower C300 HD Camera - Remote Configuration Disclosure
|
31 |
WEB
|
Todor Donev
|
|
2020-02-19
|
|
Virtual Freer 1.58 - Remote Command Execution
|
29 |
WEB
|
SajjadBnd
|
|
2020-02-18
|
|
WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
|
34 |
WEB
|
Ultra Security Team
|
|
2020-02-17
|
|
LabVantage 8.3 - Information Disclosure
|
32 |
WEB
|
Joel Aviad Ossi
|
|
2020-02-17
|
|
SOPlanning 1.45 - 'users' SQL Injection
|
32 |
WEB
|
J3rryBl4nks
|
|
2020-02-17
|
|
WordPress Plugin WOOF Products Filter for WooCommerce 1.2.3 - Persistent Cross-Site Scripting
|
35 |
WEB
|
Shahab.ra.9
|
|
2020-02-17
|
|
SOPlanning 1.45 - Cross-Site Request Forgery (Add User)
|
34 |
WEB
|
J3rryBl4nks
|
|
2020-02-17
|
|
WordPress Theme Fruitful 3.8 - Persistent Cross-Site Scripting
|
30 |
WEB
|
Ultra Security Team
|
|
2020-02-17
|
|
Ice HRM 26.2.0 - Cross-Site Request Forgery (Add User)
|
29 |
WEB
|
J3rryBl4nks
|
|
2020-02-17
|
|
Avaya Aura Communication Manager 5.2 - Remote Code Execution
|
36 |
WEB
|
Sarang Tumne
|
|
2020-02-17
|
|
WordPress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scripting
|
31 |
WEB
|
Jinson Varghese Behanan
|
|
2020-02-17
|
|
SOPlanning 1.45 - 'by' SQL Injection
|
31 |
WEB
|
J3rryBl4nks
|
|
2020-02-14
|
|
phpMyChat Plus 1.98 - 'pmc_username' SQL Injection
|
34 |
WEB
|
J3rryBl4nks
|
|
2020-02-13
|
|
WordPress Plugin ultimate-member 2.1.3 - Local File Inclusion
|
38 |
WEB
|
Mehran Feizi
|
|
2020-02-13
|
|
PANDORAFMS 7.0 - Authenticated Remote Code Execution
|
35 |
WEB
|
Engin Demirbilek
|
|
2020-02-13
|
|
WordPress Plugin contact-form-7 5.1.6 - Remote File Upload
|
44 |
WEB
|
Mehran Feizi
|
|
2020-02-13
|
|
WordPress Plugin Wordfence.7.4.5 - Local File Disclosure
|
35 |
WEB
|
Mehran Feizi
|
|
2020-02-13
|
|
WordPress Plugin tutor.1.5.3 - Persistent Cross-Site Scripting
|
34 |
WEB
|
Mehran Feizi
|
|
2020-02-13
|
|
WordPress Plugin Tutor.1.5.3 - Local File Inclusion
|
32 |
WEB
|
Mehran Feizi
|
|
2020-02-11
|
|
WordPress Plugin InfiniteWP - Client Authentication Bypass (Metasploit)
|
32 |
WEB
|
Metasploit
|
|
2020-02-11
|
|
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
|
33 |
WEB
|
Sayak Naskar
|
|
2020-02-11
|
|
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
|
37 |
WEB
|
Luca.Chiou
|
|
2020-02-10
|
|
WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scripting
|
36 |
WEB
|
Jinson Varghese Behanan
|
|
2020-02-10
|
|
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
|
35 |
WEB
|
Prasenjit Kanti Paul
|
|
2020-02-07
|
|
Google Invisible RECAPTCHA 3 - Spoof Bypass
|
38 |
WEB
|
Matamorphosis
|
|
2020-02-07
|
|
ExpertGPS 6.38 - XML External Entity Injection
|
33 |
WEB
|
Trent Gordon
|
|
2020-02-07
|
|
EyesOfNetwork 5.3 - Remote Code Execution
|
32 |
WEB
|
Clément Billac
|
|
2020-02-07
|
|
PackWeb Formap E-learning 1.0 - 'NumCours' SQL Injection
|
33 |
WEB
|
Amel BOUZIANE-LEBLOND
|
|
2020-02-07
|
|
VehicleWorkshop 1.0 - 'bookingid' SQL Injection
|
33 |
WEB
|
Mehran Feizi
|
|
2020-02-07
|
|
QuickDate 1.3.2 - SQL Injection
|
37 |
WEB
|
Ihsan Sencan
|
|
2020-02-06
|
|
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
|
33 |
WEB
|
mr_me
|
|
2020-02-06
|
|
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
|
31 |
WEB
|
mr_me
|
|
2020-02-06
|
|
Cisco Data Center Network Manager 11.2 - Remote Code Execution
|
29 |
WEB
|
mr_me
|
|
2020-02-06
|
|
Ecommerce Systempay 1.0 - Production KEY Brute Force
|
33 |
WEB
|
live3
|
|
2020-02-06
|
|
Online Job Portal 1.0 - Cross Site Request Forgery (Add User)
|
38 |
WEB
|
Ihsan Sencan
|
|
2020-02-06
|
|
Online Job Portal 1.0 - Remote Code Execution
|
36 |
WEB
|
Ihsan Sencan
|
|
2020-02-06
|
|
Online Job Portal 1.0 - 'user_email' SQL Injection
|
37 |
WEB
|
Ihsan Sencan
|
|
2020-02-05
|
|
AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
|
33 |
WEB
|
Ihsan Sencan
|
|
2020-02-05
|
|
Verodin Director Web Console 3.5.4.0 - Remote Authenticated Password Disclosure (PoC)
|
32 |
WEB
|
nxkennedy
|
|
2020-02-05
|
|
Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
|
36 |
WEB
|
nxkennedy
|
|
2020-02-05
|
|
Wago PFC200 - Authenticated Remote Code Execution (Metasploit)
|
28 |
WEB
|
0x483d
|
|
2020-02-05
|
|
AVideo Platform 8.1 - Information Disclosure (User Enumeration)
|
32 |
WEB
|
Ihsan Sencan
|
|
2020-02-04
|
|
F-Secure Internet Gatekeeper 5.40 - Heap Overflow (PoC)
|
37 |
WEB
|
Kevin Joensen
|
|
2020-02-04
|
|
Centreon 19.10.5 - 'Pollers' Remote Command Execution (Metasploit)
|
37 |
WEB
|
mekhalleh
|
|
2020-02-03
|
|
School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
|
33 |
WEB
|
J3rryBl4nks
|
|
2020-02-03
|
|
Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
|
32 |
WEB
|
Cosmin Craciun
|
|
2020-02-03
|
|
Jira 8.3.4 - Information Disclosure (Username Enumeration)
|
29 |
WEB
|
Mufeed VH
|
|
2020-02-03
|
|
phpList 3.5.0 - Authentication Bypass
|
41 |
WEB
|
Suvadip Kar
|
|
2020-02-03
|
|
IceWarp WebMail 11.4.4.1 - Reflective Cross-Site Scripting
|
33 |
WEB
|
Lutfu Mert Ceylan
|
|
2020-01-31
|
|
FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)
|
34 |
WEB
|
Ismail Tasdelen
|
|
2020-01-31
|
|
Lotus Core CMS 1.0.1 - Local File Inclusion
|
38 |
WEB
|
Daniel Monzón
|
|
2020-01-30
|
|
rConfig 3.9.3 - Authenticated Remote Code Execution
|
33 |
WEB
|
vikingfr
|
|
2020-01-29
|
|
Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
|
32 |
WEB
|
LiquidWorm
|
|
2020-01-29
|
|
Centreon 19.10.5 - 'centreontrapd' Remote Command Execution
|
35 |
WEB
|
Fabien AUNAY
|
|
2020-01-29
|
|
Centreon 19.10.5 - 'Pollers' Remote Command Execution
|
42 |
WEB
|
Omri Baso
|
|
2020-01-29
|
|
Satellian 1.12 - Remote Code Execution
|
39 |
WEB
|
Xh4H
|
|
2020-01-29
|
|
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
|
37 |
WEB
|
J3rryBl4nks
|
|
2020-01-29
|
|
Liferay CE Portal 6.0.2 - Remote Command Execution
|
39 |
WEB
|
Berk Dusunur
|
|
2020-01-29
|
|
Kibana 6.6.1 - CSV Injection
|
36 |
WEB
|
Aamir Rehman
|
|
2020-01-28
|
|
Centreon 19.10.5 - Remote Command Execution
|
44 |
WEB
|
Fabien AUNAY
|
|
2020-01-28
|
|
Centreon 19.10.5 - Database Credentials Disclosure
|
39 |
WEB
|
Fabien AUNAY
|
|
2020-01-28
|
|
Octeth Oempro 4.8 - 'CampaignID' SQL Injection
|
38 |
WEB
|
Bruno de Barros Bulle
|
|
2020-01-28
|
|
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
|
39 |
WEB
|
Sarthak Saini
|
|
2020-01-24
|
|
Genexis Platinum-4410 2.1 - Authentication Bypass
|
38 |
WEB
|
Husinul Sanub
|
|
2020-01-24
|
|
OLK Web Store 2020 - Cross-Site Request Forgery
|
37 |
WEB
|
Joel Aviad Ossi
|