Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2022-02-02   PHP Restaurants 1.0 - SQLi (Unauthenticated) 6 WEB Nefrit ID
2022-02-02   Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated) 5 WEB Ron Jost
2022-02-02   WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated) 6 WEB Ceylan BOZOĞULLARINDAN
2022-02-02   Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated) 5 WEB Ron Jost
2022-02-02   Chamilo LMS 1.11.14 - Account Takeover 6 WEB sirpedrotavares
2022-02-02   uBidAuction v2.0.1 - 'Multiple' Cross Site Scripting (XSS) 6 WEB Vulnerability-Lab
2022-02-02   Ametys CMS v4.4.1 - Cross Site Scripting (XSS) 5 WEB Vulnerability-Lab
2022-01-27   WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated) 8 WEB Ron Jost
2022-01-27   WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated) 7 WEB Ron Jost
2022-01-27   WordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated) 8 WEB Ceylan BOZOĞULLARINDAN
2022-01-25   PHPIPAM 1.4.4 - SQLi (Authenticated) 9 WEB Rodolfo Tavares
2022-01-25   Online Project Time Management System 1.0 - Multiple Stored Cross Site Scripting (XSS) (Authenticate 8 WEB Felipe Alcantara
2022-01-25   Online Project Time Management System 1.0 - SQLi (Authenticated) 9 WEB Felipe Alcantara
2022-01-24   Landa Driving School Management System 2.0.1 - Arbitrary File Upload 7 WEB Sohel Yousef
2022-01-19   Affiliate Pro 1.7 - 'Multiple' Cross Site Scripting (XSS) 7 WEB Vulnerability-Lab
2022-01-19   Rocket LMS 1.1 - Persistent Cross Site Scripting (XSS) 7 WEB Vulnerability-Lab
2022-01-19   uDoctorAppointment v2.1.1 - 'Multiple' Cross Site Scripting (XSS) 9 WEB Vulnerability-Lab
2022-01-18   Creston Web Interface 1.0.0.2159 - Credential Disclosure 9 WEB RedTeam Pentesting GmbH
2022-01-18   Nyron 1.0 - SQLi (Unauthenticated) 7 WEB Miguel Santareno
2022-01-18   Simple Chatbot Application 1.0 - 'message' Blind SQLi 7 WEB Saud Alenazi
2022-01-18   Simple Chatbot Application 1.0 - Remote Code Execution (RCE) 7 WEB Saud Alenazi
2022-01-18   OpenBMCS 2.4 - Information Disclosure 8 WEB LiquidWorm
2022-01-18   OpenBMCS 2.4 - Server Side Request Forgery (SSRF) (Unauthenticated) 10 WEB LiquidWorm
2022-01-18   OpenBMCS 2.4 - Create Admin / Remote Privilege Escalation 8 WEB LiquidWorm
2022-01-18   OpenBMCS 2.4 - SQLi (Authenticated) 10 WEB LiquidWorm
2022-01-18   OpenBMCS 2.4 - Cross Site Request Forgery (CSRF) 10 WEB LiquidWorm
2022-01-18   Online Resort Management System 1.0 - SQLi (Authenticated) 8 WEB Gaurav Grover
2022-01-13   WordPress Core 5.8.2 - 'WP_Query' SQL Injection 8 WEB Aryan Chehreghani
2022-01-13   Online Diagnostic Lab Management System 1.0 - SQL Injection (Unauthenticated) 7 WEB Himash
2022-01-13   Online Diagnostic Lab Management System 1.0 - Stored Cross Site Scripting (XSS) 9 WEB Himash
2022-01-13   Online Diagnostic Lab Management System 1.0 - Account Takeover (Unauthenticated) 8 WEB Himash
2022-01-13   SalonERP 3.0.1 - 'sql' SQL Injection (Authenticated) 9 WEB Betul Denizler
2022-01-13   Hospitals Patient Records Management System 1.0 - 'doctors' Stored Cross Site Scripting (XSS) 9 WEB Sant268
2022-01-13   Hospitals Patient Records Management System 1.0 - 'room_list' Stored Cross Site Scripting (XSS) 8 WEB Sant268
2022-01-13   Hospitals Patient Records Management System 1.0 - 'room_types' Stored Cross Site Scripting (XSS) 6 WEB Sant268
2022-01-12   WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated) 5 WEB Veshraj Ghimire
2022-01-10   Open-AudIT Community 4.2.0 - Cross-Site Scripting (XSS) (Authenticated) 8 WEB Dominic Clark
2022-01-10   Online Railway Reservation System 1.0 - 'Multiple' Stored Cross Site Scripting (XSS) (Unauthenticate 6 WEB Zachary Asher
2022-01-10   Online Railway Reservation System 1.0 - Admin Account Creation (Unauthenticated) 8 WEB Zachary Asher
2022-01-10   Online Railway Reservation System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 7 WEB Zachary Asher
2022-01-10   Online Railway Reservation System 1.0 - 'id' SQL Injection (Unauthenticated) 7 WEB twseptian
2022-01-10   HTTP Commander 3.1.9 - Stored Cross Site Scripting (XSS) 9 WEB Oscar Sandén
2022-01-07   Online Veterinary Appointment System 1.0 - 'Multiple' SQL Injection 8 WEB twseptian
2022-01-05   WordPress Plugin AAWP 3.16 - 'tab' Reflected Cross Site Scripting (XSS) (Authenticated) 6 WEB Andrea Bocchetti
2022-01-05   Projeqtor v9.3.1 - Stored Cross Site Scripting (XSS) 6 WEB Oscar Gil Gutierrez
2022-01-05   openSIS Student Information System 8.0 - 'multiple' SQL Injection 9 WEB securityforeveryone.com
2022-01-05   Vodafone H-500-s 3.5.10 - WiFi Password Disclosure 9 WEB Daniel Monzón
2022-01-05   Terramaster TOS 4.2.15 - Remote Code Execution (RCE) (Unauthenticated) 7 WEB n0tme
2022-01-05   Virtual Airlines Manager 2.6.2 - 'multiple' SQL Injection 8 WEB Milad karimi
2022-01-05   BeyondTrust Remote Support 6.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated) 7 WEB Malcrove
2022-01-05   Hospitals Patient Records Management System 1.0 - Account TakeOver 7 WEB twseptian
2022-01-05   Hospitals Patient Records Management System 1.0 - 'id' SQL Injection (Authenticated) 7 WEB twseptian
2022-01-05   Hostel Management System 2.1 - Cross Site Scripting (XSS) 6 WEB Chinmay Divekar
2022-01-05   Nettmp NNT 5.1 - SQLi Authentication Bypass 7 WEB Momen Eldawakhly
2022-01-05   SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS) 7 WEB Momen Eldawakhly
2022-01-05   Library System in PHP 1.0 - 'publisher name' Stored Cross-Site Scripting (XSS) 5 WEB Akash Patil
2022-01-05   WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated) 6 WEB Liad Levy
2022-01-05   Online Admission System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 6 WEB Jeremiasz Pluta
2022-01-05   Movie Rating System 1.0 - SQLi to RCE (Unauthenticated) 6 WEB Tagoletta
2022-01-05   Movie Rating System 1.0 - Broken Access Control (Admin Account Creation) (Unauthenticated) 6 WEB Tagoletta
2022-01-05   WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection 6 WEB Ron Jost
2022-01-05   WordPress Plugin Contact Form Entries 1.1.6 - Cross Site Scripting (XSS) (Unauthenticated) 6 WEB Gaetano Perrone
2022-01-05   RiteCMS 3.1.0 - Remote Code Execution (RCE) (Authenticated) 5 WEB faisalfs10x
2022-01-05   RiteCMS 3.1.0 - Arbitrary File Deletion (Authenticated) 6 WEB faisalfs10x
2022-01-05   RiteCMS 3.1.0 - Arbitrary File Overwrite (Authenticated) 6 WEB faisalfs10x
2022-01-05   CMSimple 5.4 - Cross Site Scripting (XSS) 7 WEB heinjame
2021-12-20   Exponent CMS 2.6 - Multiple Vulnerabilities 6 WEB heinjame
2021-12-20   phpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated) 6 WEB Halit AKAYDIN
2021-12-20   WBCE CMS 1.5.1 - Admin Password Reset 8 WEB citril
2021-12-16   Arunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF) 6 WEB =(L_L)=
2021-12-16   Croogo 3.0.2 - 'Multiple' Stored Cross-Site Scripting (XSS) 6 WEB Enes Özeser
2021-12-16   Croogo 3.0.2 - Unrestricted File Upload 8 WEB Enes Özeser
2021-12-16   Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration 7 WEB Daniel Morales
2021-12-14   Online Thesis Archiving System 1.0 - SQLi Authentication Bypass 7 WEB Yehia Elghaly
2021-12-14   meterN v1.2.3 - Remote Code Execution (RCE) (Authenticated) 6 WEB LiquidWorm
2021-12-14   Zucchetti Axess CLOKI Access Control 1.64 - Cross Site Request Forgery (CSRF) 8 WEB LiquidWorm
2021-12-14   Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated) 6 WEB 0sunday
2021-12-14   WordPress Plugin Typebot 1.4.3 - Stored Cross Site Scripting (XSS) (Authenticated) 6 WEB Mansi Singh
2021-12-13   WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated) 6 WEB Jeremiasz Pluta
2021-12-10   Free School Management Software 1.0 - Remote Code Execution (RCE) 8 WEB fuzzyap1
2021-12-10   Free School Management Software 1.0 - 'multiple' Stored Cross-Site Scripting (XSS) 7 WEB fuzzyap1
2021-12-10   OpenCATS 0.9.4 - Remote Code Execution (RCE) 8 WEB Nicholas Ferreira
2021-12-09   Employees Daily Task Management System 1.0 - 'multiple' Cross Site Scripting (XSS) 8 WEB able403
2021-12-09   Employees Daily Task Management System 1.0 - 'username' SQLi Authentication Bypass 8 WEB able403
2021-12-09   Grafana 8.3.0 - Directory Traversal and Arbitrary File Read 8 WEB s1gh
2021-12-09   Wordpress Plugin Catch Themes Demo Import 1.6.1 - Remote Code Execution (RCE) (Authenticated) 9 WEB Ron Jost
2021-12-09   Student Management System 1.0 - SQLi Authentication Bypass 5 WEB Enes Özeser
2021-12-09   TestLink 1.19 - Arbitrary File Download (Unauthenticated) 8 WEB Gonzalo Villegas
2021-12-09   LimeSurvey 5.2.4 - Remote Code Execution (RCE) (Authenticated) 6 WEB Y1LD1R1M
2021-12-09   Chikitsa Patient Management System 2.0.2 - 'backup' Remote Code Execution (RCE) (Authenticated) 6 WEB 0z09e
2021-12-09   Chikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated) 8 WEB 0z09e
2021-12-06   Croogo 3.0.2 - Remote Code Execution (Authenticated) 7 WEB Deha Berkin Bir
2021-12-03   WordPress Plugin DZS Zoomsounds 6.45 - Arbitrary File Read (Unauthenticated) 7 WEB Uriel Yochpaz
2021-12-03   WordPress Plugin Slider by Soliloquy 2.6.2 - 'title' Stored Cross Site Scripting (XSS) (Authenticate 6 WEB Abdurrahman Erkan
2021-12-03   WordPress Plugin All-in-One Video Gallery plugin 2.4.9 - Local File Inclusion (LFI) 6 WEB Mohamed Magdy Abumusilm
2021-12-03   Online Magazine Management System 1.0 - SQLi Authentication Bypass 8 WEB Mohamed habib Smidi
2021-12-03   Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass 6 WEB Mohamed habib Smidi
2021-12-01   Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting 6 WEB Tushar Jadhav
2021-11-30   Laundry Booking Management System 1.0 - Remote Code Execution (RCE) 8 WEB Pablo Santiago
2021-11-29   opencart 3.0.3.8 - Sessjion Injection 7 WEB Hubert Wojciechowski
2021-11-29   orangescrum 1.8.0 - 'Multiple' Cross-Site Scripting (XSS) (Authenticated) 6 WEB Hubert Wojciechowski
2021-11-29   orangescrum 1.8.0 - 'Multiple' SQL Injection (Authenticated) 6 WEB Hubert Wojciechowski
2021-11-29   orangescrum 1.8.0 - Privilege escalation (Authenticated) 6 WEB Hubert Wojciechowski
2021-11-26   Bagisto 1.3.3 - Client-Side Template Injection 7 WEB Mohamed Abdellatif Jaber
2021-11-24   CMSimple 5.4 - Local file inclusion (LFI) to Remote code execution (RCE) (Authenticated) 8 WEB S1lv3r
2021-11-23   FLEX 1085 Web 1.6.0 - HTML Injection 7 WEB Mr Empy
2021-11-23   Bus Pass Management System 1.0 - 'Search' SQL injection 6 WEB Abhijeet Singh
2021-11-23   Webrun 3.6.0.42 - 'P_0' SQL Injection 7 WEB Vinicius Alves
2021-11-23   Wordpress Plugin WP Guppy 1.1 - WP-JSON API Sensitive Information Disclosure 5 WEB Keyvan Hardani
2021-11-22   Aimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection 7 WEB Ilker Burak ADIYAMAN
2021-11-17   Wordpress Plugin Smart Product Review 1.0.4 - Arbitrary File Upload 6 WEB Keyvan Hardani
2021-11-17   GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated) 7 WEB Jacob Baines
2021-11-17   SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit) 7 WEB M. Cory Billington
2021-11-17   Quick.CMS 6.7 - Cross Site Request Forgery (CSRF) to Cross Site Scripting (XSS) (Authenticated) 7 WEB Rahad Chowdhury
2021-11-17   Bludit 3.13.1 - 'username' Cross Site Scripting (XSS) 5 WEB Vasu
2021-11-16   CMDBuild 3.3.2 - 'Multiple' Cross Site Scripting (XSS) 5 WEB Hosein Vita
2021-11-16   Online Learning System 2.0 - Remote Code Execution (RCE) 6 WEB djebbaranon
2021-11-15   PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF) 6 WEB Hosein Vita
2021-11-15   WordPress Plugin Contact Form to Email 1.3.24 - Stored Cross Site Scripting (XSS) (Authenticated) 6 WEB Mohammed Aadhil Ashfaq
2021-11-15   Fuel CMS 1.4.13 - 'col' Blind SQL Injection (Authenticated) 7 WEB Rahad Chowdhury
2021-11-15   Simple Subscription Website 1.0 - SQLi Authentication Bypass 6 WEB Daniel Haro
2021-11-15   KONGA 0.14.9 - Privilege Escalation 6 WEB Fabricio Salomao
2021-11-15   WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS) 7 WEB Davide Taraschi
2021-11-12   Mumara Classic 2.93 - 'license' SQL Injection (Unauthenticated) 6 WEB Shain Lakin
2021-11-12   WordPress Plugin AccessPress Social Icons 1.8.2 - 'icon title' Stored Cross-Site Scripting (XSS) 6 WEB Murat DEMİRCİ