|
2022-02-09
|
|
Exam Reviewer Management System 1.0 - Remote Code Execution (RCE) (Authenticated)
|
8 |
WEB
|
Juli Agarwal
|
|
2022-02-09
|
|
Exam Reviewer Management System 1.0 - ‘id’ SQL Injection
|
11 |
WEB
|
Juli Agarwal
|
|
2022-02-08
|
|
WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS)
|
11 |
WEB
|
Shweta Mahajan
|
|
2022-02-08
|
|
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
|
14 |
WEB
|
Shweta Mahajan
|
|
2022-02-08
|
|
Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion
|
12 |
WEB
|
Ven3xy
|
|
2022-02-08
|
|
WordPress Plugin International Sms For Contact Form 7 Integration V1.2 - Cross Site Scripting (XSS)
|
15 |
WEB
|
Milad karimi
|
|
2022-02-08
|
|
Hospital Management System 4.0 - 'multiple' SQL Injection
|
10 |
WEB
|
nu11secur1ty
|
|
2022-02-08
|
|
FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)
|
13 |
WEB
|
FEBIN MON SAJI
|
|
2022-02-08
|
|
Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit)
|
13 |
WEB
|
WackyH4cker
|
|
2022-02-08
|
|
Hotel Reservation System 1.0 - SQLi (Unauthenticated)
|
14 |
WEB
|
Nefrit ID
|
|
2022-02-04
|
|
Servisnet Tessa - Add sysAdmin User (Unauthenticated) (Metasploit)
|
14 |
WEB
|
AkkuS
|
|
2022-02-04
|
|
Servisnet Tessa - MQTT Credentials Dump (Unauthenticated) (Metasploit)
|
14 |
WEB
|
AkkuS
|
|
2022-02-04
|
|
Servisnet Tessa - Privilege Escalation (Metasploit)
|
13 |
WEB
|
AkkuS
|
|
2022-02-04
|
|
WordPress Plugin IP2Location Country Blocker 2.26.7 - Stored Cross Site Scripting (XSS) (Authenticat
|
17 |
WEB
|
Ahmet Serkan Ari
|
|
2022-02-04
|
|
WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)
|
13 |
WEB
|
Antonio Cuomo
|
|
2022-02-02
|
|
WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming
|
15 |
WEB
|
Ceylan BOZOĞULLARINDAN
|
|
2022-02-02
|
|
WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS)
|
12 |
WEB
|
0xB9
|
|
2022-02-02
|
|
WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
|
9 |
WEB
|
0xB9
|
|
2022-02-02
|
|
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
|
9 |
WEB
|
0xB9
|
|
2022-02-02
|
|
PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated)
|
10 |
WEB
|
souzo
|
|
2022-02-02
|
|
Huawei DG8045 Router 1.0 - Credential Disclosure
|
9 |
WEB
|
Abdalrahman Gamal
|
|
2022-02-02
|
|
Moodle 3.11.4 - SQL Injection
|
9 |
WEB
|
lavclash75
|
|
2022-02-02
|
|
PHP Restaurants 1.0 - SQLi (Unauthenticated)
|
11 |
WEB
|
Nefrit ID
|
|
2022-02-02
|
|
Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated)
|
13 |
WEB
|
Ron Jost
|
|
2022-02-02
|
|
WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
|
13 |
WEB
|
Ceylan BOZOĞULLARINDAN
|
|
2022-02-02
|
|
Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
|
12 |
WEB
|
Ron Jost
|
|
2022-02-02
|
|
Chamilo LMS 1.11.14 - Account Takeover
|
14 |
WEB
|
sirpedrotavares
|
|
2022-02-02
|
|
uBidAuction v2.0.1 - 'Multiple' Cross Site Scripting (XSS)
|
12 |
WEB
|
Vulnerability-Lab
|
|
2022-02-02
|
|
Ametys CMS v4.4.1 - Cross Site Scripting (XSS)
|
11 |
WEB
|
Vulnerability-Lab
|
|
2022-01-27
|
|
WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated)
|
13 |
WEB
|
Ron Jost
|
|
2022-01-27
|
|
WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated)
|
10 |
WEB
|
Ron Jost
|
|
2022-01-27
|
|
WordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
11 |
WEB
|
Ceylan BOZOĞULLARINDAN
|
|
2022-01-25
|
|
PHPIPAM 1.4.4 - SQLi (Authenticated)
|
12 |
WEB
|
Rodolfo Tavares
|
|
2022-01-25
|
|
Online Project Time Management System 1.0 - Multiple Stored Cross Site Scripting (XSS) (Authenticate
|
10 |
WEB
|
Felipe Alcantara
|
|
2022-01-25
|
|
Online Project Time Management System 1.0 - SQLi (Authenticated)
|
11 |
WEB
|
Felipe Alcantara
|
|
2022-01-24
|
|
Landa Driving School Management System 2.0.1 - Arbitrary File Upload
|
13 |
WEB
|
Sohel Yousef
|
|
2022-01-19
|
|
Affiliate Pro 1.7 - 'Multiple' Cross Site Scripting (XSS)
|
10 |
WEB
|
Vulnerability-Lab
|
|
2022-01-19
|
|
Rocket LMS 1.1 - Persistent Cross Site Scripting (XSS)
|
10 |
WEB
|
Vulnerability-Lab
|
|
2022-01-19
|
|
uDoctorAppointment v2.1.1 - 'Multiple' Cross Site Scripting (XSS)
|
11 |
WEB
|
Vulnerability-Lab
|
|
2022-01-18
|
|
Creston Web Interface 1.0.0.2159 - Credential Disclosure
|
11 |
WEB
|
RedTeam Pentesting GmbH
|
|
2022-01-18
|
|
Nyron 1.0 - SQLi (Unauthenticated)
|
10 |
WEB
|
Miguel Santareno
|
|
2022-01-18
|
|
Simple Chatbot Application 1.0 - 'message' Blind SQLi
|
12 |
WEB
|
Saud Alenazi
|
|
2022-01-18
|
|
Simple Chatbot Application 1.0 - Remote Code Execution (RCE)
|
11 |
WEB
|
Saud Alenazi
|
|
2022-01-18
|
|
OpenBMCS 2.4 - Information Disclosure
|
12 |
WEB
|
LiquidWorm
|
|
2022-01-18
|
|
OpenBMCS 2.4 - Server Side Request Forgery (SSRF) (Unauthenticated)
|
14 |
WEB
|
LiquidWorm
|
|
2022-01-18
|
|
OpenBMCS 2.4 - Create Admin / Remote Privilege Escalation
|
11 |
WEB
|
LiquidWorm
|
|
2022-01-18
|
|
OpenBMCS 2.4 - SQLi (Authenticated)
|
13 |
WEB
|
LiquidWorm
|
|
2022-01-18
|
|
OpenBMCS 2.4 - Cross Site Request Forgery (CSRF)
|
14 |
WEB
|
LiquidWorm
|
|
2022-01-18
|
|
Online Resort Management System 1.0 - SQLi (Authenticated)
|
12 |
WEB
|
Gaurav Grover
|
|
2022-01-13
|
|
WordPress Core 5.8.2 - 'WP_Query' SQL Injection
|
17 |
WEB
|
Aryan Chehreghani
|
|
2022-01-13
|
|
Online Diagnostic Lab Management System 1.0 - SQL Injection (Unauthenticated)
|
14 |
WEB
|
Himash
|
|
2022-01-13
|
|
Online Diagnostic Lab Management System 1.0 - Stored Cross Site Scripting (XSS)
|
13 |
WEB
|
Himash
|
|
2022-01-13
|
|
Online Diagnostic Lab Management System 1.0 - Account Takeover (Unauthenticated)
|
13 |
WEB
|
Himash
|
|
2022-01-13
|
|
SalonERP 3.0.1 - 'sql' SQL Injection (Authenticated)
|
13 |
WEB
|
Betul Denizler
|
|
2022-01-13
|
|
Hospitals Patient Records Management System 1.0 - 'doctors' Stored Cross Site Scripting (XSS)
|
13 |
WEB
|
Sant268
|
|
2022-01-13
|
|
Hospitals Patient Records Management System 1.0 - 'room_list' Stored Cross Site Scripting (XSS)
|
13 |
WEB
|
Sant268
|
|
2022-01-13
|
|
Hospitals Patient Records Management System 1.0 - 'room_types' Stored Cross Site Scripting (XSS)
|
11 |
WEB
|
Sant268
|
|
2022-01-12
|
|
WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated)
|
9 |
WEB
|
Veshraj Ghimire
|
|
2022-01-10
|
|
Open-AudIT Community 4.2.0 - Cross-Site Scripting (XSS) (Authenticated)
|
13 |
WEB
|
Dominic Clark
|
|
2022-01-10
|
|
Online Railway Reservation System 1.0 - 'Multiple' Stored Cross Site Scripting (XSS) (Unauthenticate
|
11 |
WEB
|
Zachary Asher
|
|
2022-01-10
|
|
Online Railway Reservation System 1.0 - Admin Account Creation (Unauthenticated)
|
13 |
WEB
|
Zachary Asher
|
|
2022-01-10
|
|
Online Railway Reservation System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
12 |
WEB
|
Zachary Asher
|
|
2022-01-10
|
|
Online Railway Reservation System 1.0 - 'id' SQL Injection (Unauthenticated)
|
12 |
WEB
|
twseptian
|
|
2022-01-10
|
|
HTTP Commander 3.1.9 - Stored Cross Site Scripting (XSS)
|
14 |
WEB
|
Oscar Sandén
|
|
2022-01-07
|
|
Online Veterinary Appointment System 1.0 - 'Multiple' SQL Injection
|
15 |
WEB
|
twseptian
|
|
2022-01-05
|
|
WordPress Plugin AAWP 3.16 - 'tab' Reflected Cross Site Scripting (XSS) (Authenticated)
|
12 |
WEB
|
Andrea Bocchetti
|
|
2022-01-05
|
|
Projeqtor v9.3.1 - Stored Cross Site Scripting (XSS)
|
12 |
WEB
|
Oscar Gil Gutierrez
|
|
2022-01-05
|
|
openSIS Student Information System 8.0 - 'multiple' SQL Injection
|
12 |
WEB
|
securityforeveryone.com
|
|
2022-01-05
|
|
Vodafone H-500-s 3.5.10 - WiFi Password Disclosure
|
12 |
WEB
|
Daniel Monzón
|
|
2022-01-05
|
|
Terramaster TOS 4.2.15 - Remote Code Execution (RCE) (Unauthenticated)
|
15 |
WEB
|
n0tme
|
|
2022-01-05
|
|
Virtual Airlines Manager 2.6.2 - 'multiple' SQL Injection
|
13 |
WEB
|
Milad karimi
|
|
2022-01-05
|
|
BeyondTrust Remote Support 6.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
|
12 |
WEB
|
Malcrove
|
|
2022-01-05
|
|
Hospitals Patient Records Management System 1.0 - Account TakeOver
|
12 |
WEB
|
twseptian
|
|
2022-01-05
|
|
Hospitals Patient Records Management System 1.0 - 'id' SQL Injection (Authenticated)
|
13 |
WEB
|
twseptian
|
|
2022-01-05
|
|
Hostel Management System 2.1 - Cross Site Scripting (XSS)
|
12 |
WEB
|
Chinmay Divekar
|
|
2022-01-05
|
|
Nettmp NNT 5.1 - SQLi Authentication Bypass
|
11 |
WEB
|
Momen Eldawakhly
|
|
2022-01-05
|
|
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
|
14 |
WEB
|
Momen Eldawakhly
|
|
2022-01-05
|
|
Library System in PHP 1.0 - 'publisher name' Stored Cross-Site Scripting (XSS)
|
10 |
WEB
|
Akash Patil
|
|
2022-01-05
|
|
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
|
16 |
WEB
|
Liad Levy
|
|
2022-01-05
|
|
Online Admission System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
18 |
WEB
|
Jeremiasz Pluta
|
|
2022-01-05
|
|
Movie Rating System 1.0 - SQLi to RCE (Unauthenticated)
|
14 |
WEB
|
Tagoletta
|
|
2022-01-05
|
|
Movie Rating System 1.0 - Broken Access Control (Admin Account Creation) (Unauthenticated)
|
15 |
WEB
|
Tagoletta
|
|
2022-01-05
|
|
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
|
11 |
WEB
|
Ron Jost
|
|
2022-01-05
|
|
WordPress Plugin Contact Form Entries 1.1.6 - Cross Site Scripting (XSS) (Unauthenticated)
|
11 |
WEB
|
Gaetano Perrone
|
|
2022-01-05
|
|
RiteCMS 3.1.0 - Remote Code Execution (RCE) (Authenticated)
|
9 |
WEB
|
faisalfs10x
|
|
2022-01-05
|
|
RiteCMS 3.1.0 - Arbitrary File Deletion (Authenticated)
|
10 |
WEB
|
faisalfs10x
|
|
2022-01-05
|
|
RiteCMS 3.1.0 - Arbitrary File Overwrite (Authenticated)
|
13 |
WEB
|
faisalfs10x
|
|
2022-01-05
|
|
CMSimple 5.4 - Cross Site Scripting (XSS)
|
13 |
WEB
|
heinjame
|
|
2021-12-20
|
|
Exponent CMS 2.6 - Multiple Vulnerabilities
|
11 |
WEB
|
heinjame
|
|
2021-12-20
|
|
phpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated)
|
16 |
WEB
|
Halit AKAYDIN
|
|
2021-12-20
|
|
WBCE CMS 1.5.1 - Admin Password Reset
|
12 |
WEB
|
citril
|
|
2021-12-16
|
|
Arunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF)
|
12 |
WEB
|
=(L_L)=
|
|
2021-12-16
|
|
Croogo 3.0.2 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
10 |
WEB
|
Enes Özeser
|
|
2021-12-16
|
|
Croogo 3.0.2 - Unrestricted File Upload
|
16 |
WEB
|
Enes Özeser
|
|
2021-12-16
|
|
Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration
|
12 |
WEB
|
Daniel Morales
|
|
2021-12-14
|
|
Online Thesis Archiving System 1.0 - SQLi Authentication Bypass
|
13 |
WEB
|
Yehia Elghaly
|
|
2021-12-14
|
|
meterN v1.2.3 - Remote Code Execution (RCE) (Authenticated)
|
13 |
WEB
|
LiquidWorm
|
|
2021-12-14
|
|
Zucchetti Axess CLOKI Access Control 1.64 - Cross Site Request Forgery (CSRF)
|
13 |
WEB
|
LiquidWorm
|
|
2021-12-14
|
|
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
|
12 |
WEB
|
0sunday
|
|
2021-12-14
|
|
WordPress Plugin Typebot 1.4.3 - Stored Cross Site Scripting (XSS) (Authenticated)
|
13 |
WEB
|
Mansi Singh
|
|
2021-12-13
|
|
WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)
|
10 |
WEB
|
Jeremiasz Pluta
|
|
2021-12-10
|
|
Free School Management Software 1.0 - Remote Code Execution (RCE)
|
12 |
WEB
|
fuzzyap1
|
|
2021-12-10
|
|
Free School Management Software 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
|
11 |
WEB
|
fuzzyap1
|
|
2021-12-10
|
|
OpenCATS 0.9.4 - Remote Code Execution (RCE)
|
12 |
WEB
|
Nicholas Ferreira
|
|
2021-12-09
|
|
Employees Daily Task Management System 1.0 - 'multiple' Cross Site Scripting (XSS)
|
10 |
WEB
|
able403
|
|
2021-12-09
|
|
Employees Daily Task Management System 1.0 - 'username' SQLi Authentication Bypass
|
9 |
WEB
|
able403
|
|
2021-12-09
|
|
Grafana 8.3.0 - Directory Traversal and Arbitrary File Read
|
9 |
WEB
|
s1gh
|
|
2021-12-09
|
|
Wordpress Plugin Catch Themes Demo Import 1.6.1 - Remote Code Execution (RCE) (Authenticated)
|
11 |
WEB
|
Ron Jost
|
|
2021-12-09
|
|
Student Management System 1.0 - SQLi Authentication Bypass
|
7 |
WEB
|
Enes Özeser
|
|
2021-12-09
|
|
TestLink 1.19 - Arbitrary File Download (Unauthenticated)
|
14 |
WEB
|
Gonzalo Villegas
|
|
2021-12-09
|
|
LimeSurvey 5.2.4 - Remote Code Execution (RCE) (Authenticated)
|
10 |
WEB
|
Y1LD1R1M
|
|
2021-12-09
|
|
Chikitsa Patient Management System 2.0.2 - 'backup' Remote Code Execution (RCE) (Authenticated)
|
10 |
WEB
|
0z09e
|
|
2021-12-09
|
|
Chikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated)
|
13 |
WEB
|
0z09e
|
|
2021-12-06
|
|
Croogo 3.0.2 - Remote Code Execution (Authenticated)
|
12 |
WEB
|
Deha Berkin Bir
|
|
2021-12-03
|
|
WordPress Plugin DZS Zoomsounds 6.45 - Arbitrary File Read (Unauthenticated)
|
16 |
WEB
|
Uriel Yochpaz
|
|
2021-12-03
|
|
WordPress Plugin Slider by Soliloquy 2.6.2 - 'title' Stored Cross Site Scripting (XSS) (Authenticate
|
10 |
WEB
|
Abdurrahman Erkan
|
|
2021-12-03
|
|
WordPress Plugin All-in-One Video Gallery plugin 2.4.9 - Local File Inclusion (LFI)
|
10 |
WEB
|
Mohamed Magdy Abumusilm
|
|
2021-12-03
|
|
Online Magazine Management System 1.0 - SQLi Authentication Bypass
|
14 |
WEB
|
Mohamed habib Smidi
|
|
2021-12-03
|
|
Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass
|
12 |
WEB
|
Mohamed habib Smidi
|
|
2021-12-01
|
|
Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting
|
11 |
WEB
|
Tushar Jadhav
|
|
2021-11-30
|
|
Laundry Booking Management System 1.0 - Remote Code Execution (RCE)
|
12 |
WEB
|
Pablo Santiago
|
|
2021-11-29
|
|
opencart 3.0.3.8 - Sessjion Injection
|
12 |
WEB
|
Hubert Wojciechowski
|
|
2021-11-29
|
|
orangescrum 1.8.0 - 'Multiple' Cross-Site Scripting (XSS) (Authenticated)
|
9 |
WEB
|
Hubert Wojciechowski
|
|
2021-11-29
|
|
orangescrum 1.8.0 - 'Multiple' SQL Injection (Authenticated)
|
10 |
WEB
|
Hubert Wojciechowski
|
|
2021-11-29
|
|
orangescrum 1.8.0 - Privilege escalation (Authenticated)
|
14 |
WEB
|
Hubert Wojciechowski
|