Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2022-02-18   WordPress Plugin dzs-zoomsounds 6.60 - Remote Code Execution (RCE) (Unauthenticated) 31 WEB Overthinker1877
2022-02-18   WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation 23 WEB numan türle
2022-02-16   WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated) 33 WEB Ceylan BOZOĞULLARINDAN
2022-02-16   Network Video Recorder NVR304-16EP - Reflected Cross-Site Scripting (XSS) (Unauthenticated) 18 WEB Luis Martínez
2022-02-16   ServiceNow - Username Enumeration 23 WEB Victor Hanna
2022-02-16   Simple Student Quarterly Result/Grade System 1.0 - SQLi Authentication Bypass 23 WEB Saud Alenazi
2022-02-16   Multi-Vendor Online Groceries Management System 1.0 - 'id' Blind SQL Injection 22 WEB Saud Alenazi
2022-02-11   Kyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated) 20 WEB Luis Martínez
2022-02-11   Subrion CMS 4.2.1 - Cross Site Request Forgery (CSRF) (Add Amin) 20 WEB Aryan Chehreghani
2022-02-11   Accounting Journal Management System 1.0 - 'id' SQLi (Authenticated) 28 WEB Alperen Ergel
2022-02-10   WordPress Plugin Jetpack 9.1 - Cross Site Scripting (XSS) 21 WEB Milad karimi
2022-02-10   WordPress Plugin Contact Form Builder 1.6.1 - Cross-Site Scripting (XSS) 20 WEB Milad karimi
2022-02-10   WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthent 23 WEB Ron Jost
2022-02-10   Home Owners Collection Management System 1.0 - 'id' Blind SQL Injection 27 WEB Saud Alenazi
2022-02-10   Home Owners Collection Management System 1.0 - Remote Code Execution (RCE) (Authenticated) 24 WEB Saud Alenazi
2022-02-10   Home Owners Collection Management System 1.0 - Account Takeover (Unauthenticated) 28 WEB Saud Alenazi
2022-02-10   Hospital Management Startup 1.0 - 'Multiple' SQLi 16 WEB nu11secur1ty
2022-02-09   AtomCMS v2.0 - SQLi 17 WEB Luca Cuzzolin
2022-02-09   Exam Reviewer Management System 1.0 - Remote Code Execution (RCE) (Authenticated) 18 WEB Juli Agarwal
2022-02-09   Exam Reviewer Management System 1.0 - ‘id’ SQL Injection 26 WEB Juli Agarwal
2022-02-08   WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS) 24 WEB Shweta Mahajan
2022-02-08   WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS) 24 WEB Shweta Mahajan
2022-02-08   Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion 21 WEB Ven3xy
2022-02-08   WordPress Plugin International Sms For Contact Form 7 Integration V1.2 - Cross Site Scripting (XSS) 21 WEB Milad karimi
2022-02-08   Hospital Management System 4.0 - 'multiple' SQL Injection 18 WEB nu11secur1ty
2022-02-08   FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE) 26 WEB FEBIN MON SAJI
2022-02-08   Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit) 21 WEB WackyH4cker
2022-02-08   Hotel Reservation System 1.0 - SQLi (Unauthenticated) 23 WEB Nefrit ID
2022-02-04   Servisnet Tessa - Add sysAdmin User (Unauthenticated) (Metasploit) 20 WEB AkkuS
2022-02-04   Servisnet Tessa - MQTT Credentials Dump (Unauthenticated) (Metasploit) 20 WEB AkkuS
2022-02-04   Servisnet Tessa - Privilege Escalation (Metasploit) 21 WEB AkkuS
2022-02-04   WordPress Plugin IP2Location Country Blocker 2.26.7 - Stored Cross Site Scripting (XSS) (Authenticat 30 WEB Ahmet Serkan Ari
2022-02-04   WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated) 20 WEB Antonio Cuomo
2022-02-02   WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming 26 WEB Ceylan BOZOĞULLARINDAN
2022-02-02   WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS) 24 WEB 0xB9
2022-02-02   WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS) 18 WEB 0xB9
2022-02-02   WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control 20 WEB 0xB9
2022-02-02   PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated) 30 WEB souzo
2022-02-02   Huawei DG8045 Router 1.0 - Credential Disclosure 28 WEB Abdalrahman Gamal
2022-02-02   Moodle 3.11.4 - SQL Injection 19 WEB lavclash75
2022-02-02   PHP Restaurants 1.0 - SQLi (Unauthenticated) 19 WEB Nefrit ID
2022-02-02   Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated) 29 WEB Ron Jost
2022-02-02   WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated) 19 WEB Ceylan BOZOĞULLARINDAN
2022-02-02   Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated) 18 WEB Ron Jost
2022-02-02   Chamilo LMS 1.11.14 - Account Takeover 20 WEB sirpedrotavares
2022-02-02   uBidAuction v2.0.1 - 'Multiple' Cross Site Scripting (XSS) 19 WEB Vulnerability-Lab
2022-02-02   Ametys CMS v4.4.1 - Cross Site Scripting (XSS) 17 WEB Vulnerability-Lab
2022-01-27   WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated) 21 WEB Ron Jost
2022-01-27   WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated) 21 WEB Ron Jost
2022-01-27   WordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated) 23 WEB Ceylan BOZOĞULLARINDAN
2022-01-25   PHPIPAM 1.4.4 - SQLi (Authenticated) 26 WEB Rodolfo Tavares
2022-01-25   Online Project Time Management System 1.0 - Multiple Stored Cross Site Scripting (XSS) (Authenticate 20 WEB Felipe Alcantara
2022-01-25   Online Project Time Management System 1.0 - SQLi (Authenticated) 19 WEB Felipe Alcantara
2022-01-24   Landa Driving School Management System 2.0.1 - Arbitrary File Upload 24 WEB Sohel Yousef
2022-01-19   Affiliate Pro 1.7 - 'Multiple' Cross Site Scripting (XSS) 21 WEB Vulnerability-Lab
2022-01-19   Rocket LMS 1.1 - Persistent Cross Site Scripting (XSS) 20 WEB Vulnerability-Lab
2022-01-19   uDoctorAppointment v2.1.1 - 'Multiple' Cross Site Scripting (XSS) 21 WEB Vulnerability-Lab
2022-01-18   Creston Web Interface 1.0.0.2159 - Credential Disclosure 18 WEB RedTeam Pentesting GmbH
2022-01-18   Nyron 1.0 - SQLi (Unauthenticated) 22 WEB Miguel Santareno
2022-01-18   Simple Chatbot Application 1.0 - 'message' Blind SQLi 22 WEB Saud Alenazi
2022-01-18   Simple Chatbot Application 1.0 - Remote Code Execution (RCE) 26 WEB Saud Alenazi
2022-01-18   OpenBMCS 2.4 - Information Disclosure 22 WEB LiquidWorm
2022-01-18   OpenBMCS 2.4 - Server Side Request Forgery (SSRF) (Unauthenticated) 27 WEB LiquidWorm
2022-01-18   OpenBMCS 2.4 - Create Admin / Remote Privilege Escalation 19 WEB LiquidWorm
2022-01-18   OpenBMCS 2.4 - SQLi (Authenticated) 25 WEB LiquidWorm
2022-01-18   OpenBMCS 2.4 - Cross Site Request Forgery (CSRF) 22 WEB LiquidWorm
2022-01-18   Online Resort Management System 1.0 - SQLi (Authenticated) 20 WEB Gaurav Grover
2022-01-13   WordPress Core 5.8.2 - 'WP_Query' SQL Injection 31 WEB Aryan Chehreghani
2022-01-13   Online Diagnostic Lab Management System 1.0 - SQL Injection (Unauthenticated) 21 WEB Himash
2022-01-13   Online Diagnostic Lab Management System 1.0 - Stored Cross Site Scripting (XSS) 21 WEB Himash
2022-01-13   Online Diagnostic Lab Management System 1.0 - Account Takeover (Unauthenticated) 19 WEB Himash
2022-01-13   SalonERP 3.0.1 - 'sql' SQL Injection (Authenticated) 23 WEB Betul Denizler
2022-01-13   Hospitals Patient Records Management System 1.0 - 'doctors' Stored Cross Site Scripting (XSS) 20 WEB Sant268
2022-01-13   Hospitals Patient Records Management System 1.0 - 'room_list' Stored Cross Site Scripting (XSS) 26 WEB Sant268
2022-01-13   Hospitals Patient Records Management System 1.0 - 'room_types' Stored Cross Site Scripting (XSS) 24 WEB Sant268
2022-01-12   WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated) 17 WEB Veshraj Ghimire
2022-01-10   Open-AudIT Community 4.2.0 - Cross-Site Scripting (XSS) (Authenticated) 18 WEB Dominic Clark
2022-01-10   Online Railway Reservation System 1.0 - 'Multiple' Stored Cross Site Scripting (XSS) (Unauthenticate 20 WEB Zachary Asher
2022-01-10   Online Railway Reservation System 1.0 - Admin Account Creation (Unauthenticated) 21 WEB Zachary Asher
2022-01-10   Online Railway Reservation System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 27 WEB Zachary Asher
2022-01-10   Online Railway Reservation System 1.0 - 'id' SQL Injection (Unauthenticated) 21 WEB twseptian
2022-01-10   HTTP Commander 3.1.9 - Stored Cross Site Scripting (XSS) 22 WEB Oscar Sandén
2022-01-07   Online Veterinary Appointment System 1.0 - 'Multiple' SQL Injection 24 WEB twseptian
2022-01-05   WordPress Plugin AAWP 3.16 - 'tab' Reflected Cross Site Scripting (XSS) (Authenticated) 18 WEB Andrea Bocchetti
2022-01-05   Projeqtor v9.3.1 - Stored Cross Site Scripting (XSS) 17 WEB Oscar Gil Gutierrez
2022-01-05   openSIS Student Information System 8.0 - 'multiple' SQL Injection 22 WEB securityforeveryone.com
2022-01-05   Vodafone H-500-s 3.5.10 - WiFi Password Disclosure 20 WEB Daniel Monzón
2022-01-05   Terramaster TOS 4.2.15 - Remote Code Execution (RCE) (Unauthenticated) 25 WEB n0tme
2022-01-05   Virtual Airlines Manager 2.6.2 - 'multiple' SQL Injection 18 WEB Milad karimi
2022-01-05   BeyondTrust Remote Support 6.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated) 22 WEB Malcrove
2022-01-05   Hospitals Patient Records Management System 1.0 - Account TakeOver 18 WEB twseptian
2022-01-05   Hospitals Patient Records Management System 1.0 - 'id' SQL Injection (Authenticated) 18 WEB twseptian
2022-01-05   Hostel Management System 2.1 - Cross Site Scripting (XSS) 17 WEB Chinmay Divekar
2022-01-05   Nettmp NNT 5.1 - SQLi Authentication Bypass 20 WEB Momen Eldawakhly
2022-01-05   SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS) 28 WEB Momen Eldawakhly
2022-01-05   Library System in PHP 1.0 - 'publisher name' Stored Cross-Site Scripting (XSS) 19 WEB Akash Patil
2022-01-05   WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated) 29 WEB Liad Levy
2022-01-05   Online Admission System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 24 WEB Jeremiasz Pluta
2022-01-05   Movie Rating System 1.0 - SQLi to RCE (Unauthenticated) 21 WEB Tagoletta
2022-01-05   Movie Rating System 1.0 - Broken Access Control (Admin Account Creation) (Unauthenticated) 22 WEB Tagoletta
2022-01-05   WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection 18 WEB Ron Jost
2022-01-05   WordPress Plugin Contact Form Entries 1.1.6 - Cross Site Scripting (XSS) (Unauthenticated) 18 WEB Gaetano Perrone
2022-01-05   RiteCMS 3.1.0 - Remote Code Execution (RCE) (Authenticated) 18 WEB faisalfs10x
2022-01-05   RiteCMS 3.1.0 - Arbitrary File Deletion (Authenticated) 21 WEB faisalfs10x
2022-01-05   RiteCMS 3.1.0 - Arbitrary File Overwrite (Authenticated) 21 WEB faisalfs10x
2022-01-05   CMSimple 5.4 - Cross Site Scripting (XSS) 20 WEB heinjame
2021-12-20   Exponent CMS 2.6 - Multiple Vulnerabilities 21 WEB heinjame
2021-12-20   phpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated) 31 WEB Halit AKAYDIN
2021-12-20   WBCE CMS 1.5.1 - Admin Password Reset 18 WEB citril
2021-12-16   Arunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF) 20 WEB =(L_L)=
2021-12-16   Croogo 3.0.2 - 'Multiple' Stored Cross-Site Scripting (XSS) 16 WEB Enes Özeser
2021-12-16   Croogo 3.0.2 - Unrestricted File Upload 23 WEB Enes Özeser
2021-12-16   Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration 17 WEB Daniel Morales
2021-12-14   Online Thesis Archiving System 1.0 - SQLi Authentication Bypass 20 WEB Yehia Elghaly
2021-12-14   meterN v1.2.3 - Remote Code Execution (RCE) (Authenticated) 20 WEB LiquidWorm
2021-12-14   Zucchetti Axess CLOKI Access Control 1.64 - Cross Site Request Forgery (CSRF) 19 WEB LiquidWorm
2021-12-14   Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated) 20 WEB 0sunday
2021-12-14   WordPress Plugin Typebot 1.4.3 - Stored Cross Site Scripting (XSS) (Authenticated) 18 WEB Mansi Singh
2021-12-13   WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated) 18 WEB Jeremiasz Pluta
2021-12-10   Free School Management Software 1.0 - Remote Code Execution (RCE) 18 WEB fuzzyap1
2021-12-10   Free School Management Software 1.0 - 'multiple' Stored Cross-Site Scripting (XSS) 20 WEB fuzzyap1
2021-12-10   OpenCATS 0.9.4 - Remote Code Execution (RCE) 18 WEB Nicholas Ferreira
2021-12-09   Employees Daily Task Management System 1.0 - 'multiple' Cross Site Scripting (XSS) 20 WEB able403
2021-12-09   Employees Daily Task Management System 1.0 - 'username' SQLi Authentication Bypass 24 WEB able403
2021-12-09   Grafana 8.3.0 - Directory Traversal and Arbitrary File Read 21 WEB s1gh