Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2026-03-03   WordPress Backup Migration 1.3.7 - Remote Command Execution 2 WEB dangwenjing
2026-03-03   mailcow 2025-01a - Host Header Password Reset Poisoning 2 WEB alvarez
2026-03-03   Easy File Sharing Web Server v7.2 - Buffer Overflow 2 WEB diogo
2026-03-03   WeGIA 3.5.0 - SQL Injection 1 WEB onurdemir
2026-03-03   Boss Mini v1.4.0 - Local File Inclusion (LFI) 2 WEB andersoncezar048
2026-02-11   motionEye 0.43.1b4 - RCE 25 WEB prabhat
2026-02-04   OctoPrint 1.11.2 - File Upload 51 WEB prabhat
2026-02-04   aiohttp 3.9.1 - directory traversal PoC 28 WEB Beatriz Fresno Naumova
2026-02-04   FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution 22 WEB Milad Karimi (Ex3ptionaL)
2026-02-02   Piranha CMS 12.0 - Stored XSS in Text Block 25 WEB terminalvenoms
2026-02-02   RPi-Jukebox-RFID 2.8.0 - Stored Cross-Site Scripting (XSS) 16 WEB Beatriz Fresno Naumova
2026-02-02   D-Link DIR-825 Rev.B 2.10 - Stack Buffer Overflow (DoS) 25 WEB Beatriz Fresno Naumova
2026-01-17   RPi-Jukebox-RFID 2.8.0 - Remote Command Execution 50 WEB Beatriz Fresno Naumova
2026-01-17   Siklu EtherHaul Series EH-8010 - Arbitrary File Upload 40 WEB semaja2
2026-01-17   Siklu EtherHaul Series EH-8010 - Remote Command Execution 30 WEB semaja2
2025-12-25   WordPress Quiz Maker 6.7.0.56 - SQL Injection 93 WEB Rahul Sreenivasan
2025-12-25   Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie 28 WEB 0xsabre
2025-12-25   FreeBSD rtsold 15.x - Remote Code Execution via DNSSL 47 WEB Lukas Johannes Möller
2025-12-16   Summar Employee Portal 3.98.0 - Authenticated SQL Injection 53 WEB Peter Gabaldon
2025-12-16   esm-dev 136 - Path Traversal 34 WEB Byte Reaper
2025-12-08   Pluck 4.7.7-dev2 - PHP Code Execution 60 WEB CodeSecLab
2025-12-03   phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF) 51 WEB CodeSecLab
2025-12-03   phpMyFAQ 2.9.8 - Cross-Site Request Forgery (CSRF) 35 WEB CodeSecLab
2025-12-03   MaNGOSWebV4 4.0.6 - Reflected XSS 36 WEB CodeSecLab
2025-12-03   Django 5.1.13 - SQL Injection 68 WEB Wafcontrol Security Team
2025-12-03   phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF) 34 WEB CodeSecLab
2025-12-03   MobileDetect 2.8.31 - Cross-Site Scripting (XSS) 22 WEB CodeSecLab
2025-12-03   phpIPAM 1.4 - SQL-Injection 29 WEB CodeSecLab
2025-12-03   OpenRepeater 2.1 - OS Command Injection 27 WEB CodeSecLab
2025-12-03   phpMyAdmin 5.0.0 - SQL Injection 37 WEB CodeSecLab
2025-12-03   RosarioSIS 6.7.2 - Cross Site Scripting (XSS) 24 WEB CodeSecLab
2025-12-03   RosarioSIS 6.7.2 - Cross-Site Scripting (XSS) 24 WEB CodeSecLab
2025-12-03   PluckCMS 4.7.10 - Unrestricted File Upload 36 WEB CodeSecLab
2025-12-03   openSIS Community Edition 8.0 - SQL Injection 18 WEB CodeSecLab
2025-12-02   YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF) 15 WEB CodeSecLab
2025-12-02   phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS) 30 WEB CodeSecLab
2025-12-02   phpIPAM 1.5.1 - SQL Injection 26 WEB CodeSecLab
2025-12-02   Piwigo 13.6.0 - SQL Injection 26 WEB CodeSecLab
2025-12-02   phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS) 21 WEB CodeSecLab
2025-12-02   phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS) 23 WEB CodeSecLab
2025-10-31   Flowise 3.0.4 - Remote Code Execution (RCE) 102 WEB nltt0
2025-10-29   Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF) 52 WEB Van Lam Nguyen
2025-09-16   Tourism Management System 2.0 - Arbitrary Shell Upload 147 WEB Debug Security
2025-09-16   Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF) 74 WEB Van Lam Nguyen
2025-09-16   dotCMS 25.07.02-1 - Authenticated Blind SQL Injection 76 WEB Matan Sandori (OSCP_ OSEP_ OSWE)
2025-09-16   ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection 70 WEB Byte Reaper
2025-09-16   XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE) 70 WEB Maksim Rogov
2025-09-16   Concrete CMS 9.4.3 - Stored XSS 65 WEB Chokri Hammedi
2025-08-26   StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload 127 WEB xpl0dec
2025-08-26   Lingdang CRM 8.6.4.7 - SQL Injection 102 WEB Beatriz Fresno Naumova
2025-08-26   Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure 61 WEB Byte Reaper
2025-08-18   Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE) 67 WEB Byte Reaper
2025-08-18   Soosyze CMS 2.0 - Brute Force Login 78 WEB Beatriz Fresno Naumova
2025-08-18   RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS) 58 WEB Gurjot Singh
2025-08-18   BigAnt Office Messenger 5.6.06 - SQL Injection 39 WEB Nicat Abbasov
2025-08-11   JetBrains TeamCity 2023.11.4 - Authentication Bypass 54 WEB İbrahimsql
2025-08-11   ServiceNow Multiple Versions - Input Validation & Template Injection 38 WEB İbrahimsql
2025-08-11   Ghost CMS 5.59.1 - Arbitrary File Read 49 WEB İbrahimsql
2025-08-11   Ghost CMS 5.42.1 - Path Traversal 42 WEB İbrahimsql
2025-08-11   VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS) 72 WEB Imraan Khan (Lich-Sec)
2025-08-11   Microsoft Edge Renderer Process (Mojo IPC) 134.0.6998.177 - Sandbox Escape 29 WEB nu11secur1ty
2025-08-11   Grav CMS 1.7.48 - Remote Code Execution (RCE) 35 WEB /bin/neko
2025-08-11   atjiu pybbs 6.0.0 - Cross Site Scripting (XSS) 51 WEB Byte Reaper
2025-08-11   projectworlds Online Admission System 1.0 - SQL Injection 46 WEB Byte Reaper
2025-08-03   Ultimate Member WordPress Plugin 2.6.6 - Privilege Escalation 85 WEB Gurjot Singh
2025-08-03   LPAR2RRD 8.04 - Remote Code Execution (RCE) 38 WEB Byte Reaper
2025-08-03   Copyparty 1.18.6 - Reflected Cross-Site Scripting (XSS) 24 WEB Byte Reaper
2025-08-03   Gandia Integra Total 4.4.2236.1 - SQL Injection 23 WEB Byte Reaper
2025-07-28   Adobe ColdFusion 2023.6 - Remote File Read 35 WEB İbrahimsql
2025-07-28   Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS) 57 WEB Kevin Dicks
2025-07-28   XWiki 14 - SQL Injection via getdeleteddocuments.vm 25 WEB Byte Reaper
2025-07-28   Invision Community 4.7.20 - (calendar/view.php) SQL Injection 41 WEB Egidio Romano
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field 52 WEB Manojkumar J
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function 23 WEB Manojkumar J
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages 19 WEB Manojkumar J
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field 20 WEB Manojkumar J
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surname 18 WEB Manojkumar J
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username 24 WEB Manojkumar J
2025-07-22   Discourse 3.1.1 - Unauthenticated Chat Message Access 25 WEB İbrahimsql
2025-07-22   Joomla JS Jobs plugin 1.4.2 - SQL injection 20 WEB Adam Wallwork
2025-07-22   Simple File List WordPress Plugin 4.2.2 - File Upload to RCE 34 WEB Md Amanat Ullah (xSwads)
2025-07-22   Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE 22 WEB Md Amanat Ullah (xSwads)
2025-07-16   WP Publications WordPress Plugin 1.2 - Stored XSS 58 WEB Zeynalxan Quliyev
2025-07-16   White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI) 62 WEB Imraan Khan (Lich-Sec)
2025-07-16   SugarCRM 14.0.0 - SSRF/Code Injection 48 WEB Egidio Romano
2025-07-16   Langflow 1.2.x - Remote Code Execution (RCE) 51 WEB Raghad Abdallah Al-syouf
2025-07-16   TOTOLINK N300RB 8.54 - Command Execution 62 WEB Skander BELABED - Magellan Sécurité
2025-07-16   PivotX 3.0.0 RC3 - Remote Code Execution (RCE) 95 WEB HayToN
2025-07-08   Discourse 3.2.x - Anonymous Cache Poisoning 62 WEB İbrahimsql
2025-07-08   Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover 67 WEB stealthcopter
2025-07-02   Moodle 4.4.0 - Authenticated Remote Code Execution 67 WEB Likhith Appalaneni
2025-06-26   Social Warfare WordPress Plugin 3.5.2 - Remote Code Execution (RCE) 93 WEB Huseyin Mardinli
2025-06-26   Sitecore 10.4 - Remote Code Execution (RCE) 53 WEB Yesith Alvarez
2025-06-26   Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE) 52 WEB Zen-kun04
2025-06-15   Skyvern 0.1.85 - Remote Code Execution (RCE) via SSTI 56 WEB Cristian Branet
2025-06-15   PHP CGI Module 8.3.4 - Remote Code Execution (RCE) 71 WEB İbrahimsql
2025-06-15   Litespeed Cache WordPress Plugin 6.3.0.1 - Privilege Escalation 42 WEB Milad karimi
2025-06-15   Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS) 39 WEB /bin/neko
2025-06-13   Roundcube 1.6.10 - Remote Code Execution (RCE) 73 WEB Maksim Rogov
2025-06-09   Laravel Pulse 1.3.1 - Arbitrary Code Injection 76 WEB Mohammed Idrees Banyamer
2025-06-05   CloudClassroom PHP Project 1.0 - SQL Injection 34 WEB Sanjay Singh
2025-05-29   Campcodes Online Hospital Management System 1.0 - SQL Injection 50 WEB Carine Constantino
2025-05-29   WordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP Bruteforcing 43 WEB Saleh Tarawneh
2025-05-25   Java-springboot-codebase 1.1 - Arbitrary File Read 51 WEB d3sca
2025-05-25   WordPress User Registration & Membership Plugin 4.1.2 - Authentication Bypass 39 WEB Mohammed Idrees Banyamer
2025-05-13   WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation 39 WEB Md Shoriful Islam
2025-05-13   Kentico Xperience 13.0.178 - Cross Site Scripting (XSS) 29 WEB Alex Messham
2025-05-09   SureTriggers OttoKit Plugin 1.0.82 - Privilege Escalation 36 WEB Abdualhadi khalifa
2025-05-09   WordPress Depicter Plugin 3.6.1 - SQL Injection 31 WEB Andrew Long
2025-05-06   ERPNext 14.82.1 - Account Takeover via Cross-Site Request Forgery (CSRF) 37 WEB Ahmed Thaiban
2025-05-06   Grokability Snipe-IT 8.0.4 - Insecure Direct Object Reference (IDOR) 37 WEB Sn1p3r-H4ck3r
2025-05-06   Casdoor 1.901.0 - Cross-Site Request Forgery (CSRF) 43 WEB Van Lam Nguyen
2025-04-22   WordPress Core 6.2 - Directory Traversal 27 WEB Milad karimi
2025-04-19   FoxCMS 1.2.5 - Remote Code Execution (RCE) 43 WEB VeryLazyTech
2025-04-19   Drupal 11.x-dev - Full Path Disclosure 27 WEB Milad karimi
2025-04-18   KiviCare Clinic & Patient Management System (EHR) 3.6.4 - Unauthenticated SQL Injection 30 WEB samogod
2025-04-18   UJCMS 9.6.3 - User Enumeration via IDOR 35 WEB Cyd Tseng
2025-04-18   Inventio Lite 4 - SQL Injection 28 WEB pointedsec
2025-04-18   Apache Commons Text 1.10.0 - Remote Code Execution 30 WEB Arjun Chaudhary
2025-04-18   Tatsu 3.3.11 - Unauthenticated RCE 29 WEB Milad karimi
2025-04-18   Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation 32 WEB Jun Takemura
2025-04-17   compop.ca 3.5.3 - Arbitrary code Execution 25 WEB dmlino
2025-04-17   Blood Bank & Donor Management System 2.4 - CSRF Improper Input Validation 32 WEB Kwangyun Keum
2025-04-17   Usermin 2.100 - Username Enumeration 30 WEB Kjesper
2025-04-17   Angular-Base64-Upload Library 0.1.21 - Unauthenticated Remote Code Execution (RCE) 29 WEB Ravindu Wickramasinghe