| 
					2022-02-02	
				 | 
				
										 
				 | 
								
									  PHP Restaurants 1.0 - SQLi (Unauthenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Nefrit ID										
				 | 
			
            	
			
				| 
					2022-02-02	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Ron Jost										
				 | 
			
            	
			
				| 
					2022-02-02	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Ceylan BOZOĞULLARINDAN										
				 | 
			
            	
			
				| 
					2022-02-02	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Ron Jost										
				 | 
			
            	
			
				| 
					2022-02-02	
				 | 
				
										 
				 | 
								
									  Chamilo LMS 1.11.14 - Account Takeover
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												sirpedrotavares										
				 | 
			
            	
			
				| 
					2022-02-02	
				 | 
				
										 
				 | 
								
									  uBidAuction v2.0.1 - 'Multiple' Cross Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2022-02-02	
				 | 
				
										 
				 | 
								
									  Ametys CMS v4.4.1 - Cross Site Scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2022-01-27	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Ron Jost										
				 | 
			
            	
			
				| 
					2022-01-27	
				 | 
				
										 
				 | 
								
									  WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Ron Jost										
				 | 
			
            	
			
				| 
					2022-01-27	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Ceylan BOZOĞULLARINDAN										
				 | 
			
            	
			
				| 
					2022-01-25	
				 | 
				
										 
				 | 
								
									  PHPIPAM 1.4.4 - SQLi (Authenticated)
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Rodolfo Tavares										
				 | 
			
            	
			
				| 
					2022-01-25	
				 | 
				
										 
				 | 
								
									  Online Project Time Management System 1.0 - Multiple Stored Cross Site Scripting (XSS) (Authenticate
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Felipe Alcantara										
				 | 
			
            	
			
				| 
					2022-01-25	
				 | 
				
										 
				 | 
								
									  Online Project Time Management System 1.0 - SQLi (Authenticated)
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Felipe Alcantara										
				 | 
			
            	
			
				| 
					2022-01-24	
				 | 
				
										 
				 | 
								
									  Landa Driving School Management System 2.0.1 - Arbitrary File Upload
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Sohel Yousef										
				 | 
			
            	
			
				| 
					2022-01-19	
				 | 
				
										 
				 | 
								
									  Affiliate Pro 1.7 - 'Multiple' Cross Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2022-01-19	
				 | 
				
										 
				 | 
								
									  Rocket LMS 1.1 - Persistent Cross Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2022-01-19	
				 | 
				
										 
				 | 
								
									  uDoctorAppointment v2.1.1 - 'Multiple' Cross Site Scripting (XSS)
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2022-01-18	
				 | 
				
										 
				 | 
								
									  Creston Web Interface 1.0.0.2159 - Credential Disclosure
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												RedTeam Pentesting GmbH										
				 | 
			
            	
			
				| 
					2022-01-18	
				 | 
				
										 
				 | 
								
									  Nyron 1.0 - SQLi (Unauthenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Miguel Santareno										
				 | 
			
            	
			
				| 
					2022-01-18	
				 | 
				
										 
				 | 
								
									  Simple Chatbot Application 1.0 - 'message' Blind SQLi
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Saud Alenazi										
				 | 
			
            	
			
				| 
					2022-01-18	
				 | 
				
										 
				 | 
								
									  Simple Chatbot Application 1.0 - Remote Code Execution (RCE)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Saud Alenazi										
				 | 
			
            	
			
				| 
					2022-01-18	
				 | 
				
										 
				 | 
								
									  OpenBMCS 2.4 - Information Disclosure
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												LiquidWorm										
				 | 
			
            	
			
				| 
					2022-01-18	
				 | 
				
										 
				 | 
								
									  OpenBMCS 2.4 - Server Side Request Forgery (SSRF) (Unauthenticated)
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												LiquidWorm										
				 | 
			
            	
			
				| 
					2022-01-18	
				 | 
				
										 
				 | 
								
									  OpenBMCS 2.4 - Create Admin / Remote Privilege Escalation
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												LiquidWorm										
				 | 
			
            	
			
				| 
					2022-01-18	
				 | 
				
										 
				 | 
								
									  OpenBMCS 2.4 - SQLi (Authenticated)
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												LiquidWorm										
				 | 
			
            	
			
				| 
					2022-01-18	
				 | 
				
										 
				 | 
								
									  OpenBMCS 2.4 - Cross Site Request Forgery (CSRF)
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												LiquidWorm										
				 | 
			
            	
			
				| 
					2022-01-18	
				 | 
				
										 
				 | 
								
									  Online Resort Management System 1.0 - SQLi (Authenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Gaurav Grover										
				 | 
			
            	
			
				| 
					2022-01-13	
				 | 
				
										 
				 | 
								
									  WordPress Core 5.8.2 - 'WP_Query' SQL Injection
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Aryan Chehreghani										
				 | 
			
            	
			
				| 
					2022-01-13	
				 | 
				
										 
				 | 
								
									  Online Diagnostic Lab Management System 1.0 - SQL Injection (Unauthenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Himash										
				 | 
			
            	
			
				| 
					2022-01-13	
				 | 
				
										 
				 | 
								
									  Online Diagnostic Lab Management System 1.0 - Stored Cross Site Scripting (XSS)
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Himash										
				 | 
			
            	
			
				| 
					2022-01-13	
				 | 
				
										 
				 | 
								
									  Online Diagnostic Lab Management System 1.0 - Account Takeover (Unauthenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Himash										
				 | 
			
            	
			
				| 
					2022-01-13	
				 | 
				
										 
				 | 
								
									  SalonERP 3.0.1 - 'sql' SQL Injection (Authenticated)
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Betul Denizler										
				 | 
			
            	
			
				| 
					2022-01-13	
				 | 
				
										 
				 | 
								
									  Hospitals Patient Records Management System 1.0 - 'doctors' Stored Cross Site Scripting (XSS)
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Sant268										
				 | 
			
            	
			
				| 
					2022-01-13	
				 | 
				
										 
				 | 
								
									  Hospitals Patient Records Management System 1.0 - 'room_list' Stored Cross Site Scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Sant268										
				 | 
			
            	
			
				| 
					2022-01-13	
				 | 
				
										 
				 | 
								
									  Hospitals Patient Records Management System 1.0 - 'room_types' Stored Cross Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Sant268										
				 | 
			
            	
			
				| 
					2022-01-12	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Veshraj Ghimire										
				 | 
			
            	
			
				| 
					2022-01-10	
				 | 
				
										 
				 | 
								
									  Open-AudIT Community 4.2.0 - Cross-Site Scripting (XSS) (Authenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Dominic Clark										
				 | 
			
            	
			
				| 
					2022-01-10	
				 | 
				
										 
				 | 
								
									  Online Railway Reservation System 1.0 - 'Multiple' Stored Cross Site Scripting (XSS) (Unauthenticate
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Zachary Asher										
				 | 
			
            	
			
				| 
					2022-01-10	
				 | 
				
										 
				 | 
								
									  Online Railway Reservation System 1.0 - Admin Account Creation (Unauthenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Zachary Asher										
				 | 
			
            	
			
				| 
					2022-01-10	
				 | 
				
										 
				 | 
								
									  Online Railway Reservation System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Zachary Asher										
				 | 
			
            	
			
				| 
					2022-01-10	
				 | 
				
										 
				 | 
								
									  Online Railway Reservation System 1.0 - 'id' SQL Injection (Unauthenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												twseptian										
				 | 
			
            	
			
				| 
					2022-01-10	
				 | 
				
										 
				 | 
								
									  HTTP Commander 3.1.9 - Stored Cross Site Scripting (XSS)
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Oscar Sandén										
				 | 
			
            	
			
				| 
					2022-01-07	
				 | 
				
										 
				 | 
								
									  Online Veterinary Appointment System 1.0 - 'Multiple' SQL Injection
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												twseptian										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  WordPress Plugin AAWP 3.16 - 'tab' Reflected Cross Site Scripting (XSS) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Andrea Bocchetti										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Projeqtor v9.3.1 - Stored Cross Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Oscar Gil Gutierrez										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  openSIS Student Information System 8.0 - 'multiple' SQL Injection
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												securityforeveryone.com										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Vodafone H-500-s 3.5.10 - WiFi Password Disclosure
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Daniel Monzón										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Terramaster TOS 4.2.15 - Remote Code Execution (RCE) (Unauthenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												n0tme										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Virtual Airlines Manager 2.6.2 - 'multiple' SQL Injection
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Milad karimi										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  BeyondTrust Remote Support 6.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Malcrove										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Hospitals Patient Records Management System 1.0 - Account TakeOver
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												twseptian										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Hospitals Patient Records Management System 1.0 - 'id' SQL Injection (Authenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												twseptian										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Hostel Management System 2.1 - Cross Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Chinmay Divekar										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Nettmp NNT 5.1 - SQLi Authentication Bypass
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Momen Eldawakhly										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Momen Eldawakhly										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Library System in PHP 1.0 - 'publisher name' Stored Cross-Site Scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Akash Patil										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Liad Levy										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Online Admission System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Jeremiasz Pluta										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Movie Rating System 1.0 - SQLi to RCE (Unauthenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Tagoletta										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  Movie Rating System 1.0 - Broken Access Control (Admin Account Creation) (Unauthenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Tagoletta										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Ron Jost										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Contact Form Entries 1.1.6 - Cross Site Scripting (XSS) (Unauthenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Gaetano Perrone										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  RiteCMS 3.1.0 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												faisalfs10x										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  RiteCMS 3.1.0 - Arbitrary File Deletion (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												faisalfs10x										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  RiteCMS 3.1.0 - Arbitrary File Overwrite (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												faisalfs10x										
				 | 
			
            	
			
				| 
					2022-01-05	
				 | 
				
										 
				 | 
								
									  CMSimple 5.4 - Cross Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												heinjame										
				 | 
			
            	
			
				| 
					2021-12-20	
				 | 
				
										 
				 | 
								
									  Exponent CMS 2.6 - Multiple Vulnerabilities
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												heinjame										
				 | 
			
            	
			
				| 
					2021-12-20	
				 | 
				
										 
				 | 
								
									  phpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Halit AKAYDIN										
				 | 
			
            	
			
				| 
					2021-12-20	
				 | 
				
										 
				 | 
								
									  WBCE CMS 1.5.1 - Admin Password Reset
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												citril										
				 | 
			
            	
			
				| 
					2021-12-16	
				 | 
				
										 
				 | 
								
									  Arunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												=(L_L)=										
				 | 
			
            	
			
				| 
					2021-12-16	
				 | 
				
										 
				 | 
								
									  Croogo 3.0.2 - 'Multiple' Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Enes Özeser										
				 | 
			
            	
			
				| 
					2021-12-16	
				 | 
				
										 
				 | 
								
									  Croogo 3.0.2 - Unrestricted File Upload
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Enes Özeser										
				 | 
			
            	
			
				| 
					2021-12-16	
				 | 
				
										 
				 | 
								
									  Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Daniel Morales										
				 | 
			
            	
			
				| 
					2021-12-14	
				 | 
				
										 
				 | 
								
									  Online Thesis Archiving System 1.0 - SQLi Authentication Bypass
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Yehia Elghaly										
				 | 
			
            	
			
				| 
					2021-12-14	
				 | 
				
										 
				 | 
								
									  meterN v1.2.3 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												LiquidWorm										
				 | 
			
            	
			
				| 
					2021-12-14	
				 | 
				
										 
				 | 
								
									  Zucchetti Axess CLOKI Access Control 1.64 - Cross Site Request Forgery (CSRF)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												LiquidWorm										
				 | 
			
            	
			
				| 
					2021-12-14	
				 | 
				
										 
				 | 
								
									  Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												0sunday										
				 | 
			
            	
			
				| 
					2021-12-14	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Typebot 1.4.3 - Stored Cross Site Scripting (XSS) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Mansi Singh										
				 | 
			
            	
			
				| 
					2021-12-13	
				 | 
				
										 
				 | 
								
									  WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Jeremiasz Pluta										
				 | 
			
            	
			
				| 
					2021-12-10	
				 | 
				
										 
				 | 
								
									  Free School Management Software 1.0 - Remote Code Execution (RCE)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												fuzzyap1										
				 | 
			
            	
			
				| 
					2021-12-10	
				 | 
				
										 
				 | 
								
									  Free School Management Software 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												fuzzyap1										
				 | 
			
            	
			
				| 
					2021-12-10	
				 | 
				
										 
				 | 
								
									  OpenCATS 0.9.4 - Remote Code Execution (RCE)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Nicholas Ferreira										
				 | 
			
            	
			
				| 
					2021-12-09	
				 | 
				
										 
				 | 
								
									  Employees Daily Task Management System 1.0 - 'multiple' Cross Site Scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												able403										
				 | 
			
            	
			
				| 
					2021-12-09	
				 | 
				
										 
				 | 
								
									  Employees Daily Task Management System 1.0 - 'username' SQLi Authentication Bypass
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												able403										
				 | 
			
            	
			
				| 
					2021-12-09	
				 | 
				
										 
				 | 
								
									  Grafana 8.3.0 - Directory Traversal and Arbitrary File Read
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												s1gh										
				 | 
			
            	
			
				| 
					2021-12-09	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin Catch Themes Demo Import 1.6.1 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Ron Jost										
				 | 
			
            	
			
				| 
					2021-12-09	
				 | 
				
										 
				 | 
								
									  Student Management System 1.0 - SQLi Authentication Bypass
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Enes Özeser										
				 | 
			
            	
			
				| 
					2021-12-09	
				 | 
				
										 
				 | 
								
									  TestLink 1.19 - Arbitrary File Download (Unauthenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Gonzalo Villegas										
				 | 
			
            	
			
				| 
					2021-12-09	
				 | 
				
										 
				 | 
								
									  LimeSurvey 5.2.4 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Y1LD1R1M										
				 | 
			
            	
			
				| 
					2021-12-09	
				 | 
				
										 
				 | 
								
									  Chikitsa Patient Management System 2.0.2 - 'backup' Remote Code Execution (RCE) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												0z09e										
				 | 
			
            	
			
				| 
					2021-12-09	
				 | 
				
										 
				 | 
								
									  Chikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												0z09e										
				 | 
			
            	
			
				| 
					2021-12-06	
				 | 
				
										 
				 | 
								
									  Croogo 3.0.2 - Remote Code Execution (Authenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Deha Berkin Bir										
				 | 
			
            	
			
				| 
					2021-12-03	
				 | 
				
										 
				 | 
								
									  WordPress Plugin DZS Zoomsounds 6.45 - Arbitrary File Read (Unauthenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Uriel Yochpaz										
				 | 
			
            	
			
				| 
					2021-12-03	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Slider by Soliloquy 2.6.2 - 'title' Stored Cross Site Scripting (XSS) (Authenticate
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Abdurrahman Erkan										
				 | 
			
            	
			
				| 
					2021-12-03	
				 | 
				
										 
				 | 
								
									  WordPress Plugin All-in-One Video Gallery plugin 2.4.9 - Local File Inclusion (LFI)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Mohamed Magdy Abumusilm										
				 | 
			
            	
			
				| 
					2021-12-03	
				 | 
				
										 
				 | 
								
									  Online Magazine Management System 1.0 - SQLi Authentication Bypass
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Mohamed habib Smidi										
				 | 
			
            	
			
				| 
					2021-12-03	
				 | 
				
										 
				 | 
								
									  Online Pre-owned/Used Car Showroom Management System 1.0 -  SQLi Authentication Bypass
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Mohamed habib Smidi										
				 | 
			
            	
			
				| 
					2021-12-01	
				 | 
				
										 
				 | 
								
									  Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Tushar Jadhav										
				 | 
			
            	
			
				| 
					2021-11-30	
				 | 
				
										 
				 | 
								
									  Laundry Booking Management System 1.0 - Remote Code Execution (RCE)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Pablo Santiago										
				 | 
			
            	
			
				| 
					2021-11-29	
				 | 
				
										 
				 | 
								
									  opencart 3.0.3.8 - Sessjion Injection
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2021-11-29	
				 | 
				
										 
				 | 
								
									  orangescrum 1.8.0 - 'Multiple' Cross-Site Scripting (XSS) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2021-11-29	
				 | 
				
										 
				 | 
								
									  orangescrum 1.8.0 - 'Multiple' SQL Injection (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2021-11-29	
				 | 
				
										 
				 | 
								
									  orangescrum 1.8.0 - Privilege escalation (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2021-11-26	
				 | 
				
										 
				 | 
								
									  Bagisto 1.3.3 - Client-Side Template Injection
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Mohamed Abdellatif Jaber										
				 | 
			
            	
			
				| 
					2021-11-24	
				 | 
				
										 
				 | 
								
									  CMSimple 5.4 - Local file inclusion (LFI) to Remote code execution (RCE) (Authenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												S1lv3r										
				 | 
			
            	
			
				| 
					2021-11-23	
				 | 
				
										 
				 | 
								
									  FLEX 1085 Web 1.6.0 - HTML Injection
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Mr Empy										
				 | 
			
            	
			
				| 
					2021-11-23	
				 | 
				
										 
				 | 
								
									  Bus Pass Management System 1.0 - 'Search' SQL injection
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Abhijeet Singh										
				 | 
			
            	
			
				| 
					2021-11-23	
				 | 
				
										 
				 | 
								
									  Webrun 3.6.0.42 - 'P_0' SQL Injection
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Vinicius Alves										
				 | 
			
            	
			
				| 
					2021-11-23	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin WP Guppy 1.1 - WP-JSON API Sensitive Information Disclosure
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Keyvan Hardani										
				 | 
			
            	
			
				| 
					2021-11-22	
				 | 
				
										 
				 | 
								
									  Aimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Ilker Burak ADIYAMAN										
				 | 
			
            	
			
				| 
					2021-11-17	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin Smart Product Review 1.0.4 - Arbitrary File Upload
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Keyvan Hardani										
				 | 
			
            	
			
				| 
					2021-11-17	
				 | 
				
										 
				 | 
								
									  GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Jacob Baines										
				 | 
			
            	
			
				| 
					2021-11-17	
				 | 
				
										 
				 | 
								
									  SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												M. Cory Billington										
				 | 
			
            	
			
				| 
					2021-11-17	
				 | 
				
										 
				 | 
								
									  Quick.CMS 6.7 - Cross Site Request Forgery (CSRF) to Cross Site Scripting (XSS) (Authenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Rahad Chowdhury										
				 | 
			
            	
			
				| 
					2021-11-17	
				 | 
				
										 
				 | 
								
									  Bludit 3.13.1 - 'username' Cross Site Scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Vasu										
				 | 
			
            	
			
				| 
					2021-11-16	
				 | 
				
										 
				 | 
								
									  CMDBuild 3.3.2 - 'Multiple' Cross Site Scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Hosein Vita										
				 | 
			
            	
			
				| 
					2021-11-16	
				 | 
				
										 
				 | 
								
									  Online Learning System 2.0 - Remote Code Execution (RCE)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												djebbaranon										
				 | 
			
            	
			
				| 
					2021-11-15	
				 | 
				
										 
				 | 
								
									  PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Hosein Vita										
				 | 
			
            	
			
				| 
					2021-11-15	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Contact Form to Email 1.3.24 - Stored Cross Site Scripting (XSS) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Mohammed Aadhil Ashfaq										
				 | 
			
            	
			
				| 
					2021-11-15	
				 | 
				
										 
				 | 
								
									  Fuel CMS 1.4.13 - 'col' Blind SQL Injection (Authenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Rahad Chowdhury										
				 | 
			
            	
			
				| 
					2021-11-15	
				 | 
				
										 
				 | 
								
									  Simple Subscription Website 1.0 - SQLi Authentication Bypass
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Daniel Haro										
				 | 
			
            	
			
				| 
					2021-11-15	
				 | 
				
										 
				 | 
								
									  KONGA 0.14.9 - Privilege Escalation
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Fabricio Salomao										
				 | 
			
            	
			
				| 
					2021-11-15	
				 | 
				
										 
				 | 
								
									  WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Davide Taraschi										
				 | 
			
            	
			
				| 
					2021-11-12	
				 | 
				
										 
				 | 
								
									  Mumara Classic 2.93 - 'license' SQL Injection (Unauthenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Shain Lakin										
				 | 
			
            	
			
				| 
					2021-11-12	
				 | 
				
										 
				 | 
								
									  WordPress Plugin AccessPress Social Icons 1.8.2 - 'icon title' Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Murat DEMİRCİ										
				 |