Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-12-09   Wordpress Plugin Catch Themes Demo Import 1.6.1 - Remote Code Execution (RCE) (Authenticated) 23 WEB Ron Jost
2021-12-09   Student Management System 1.0 - SQLi Authentication Bypass 16 WEB Enes Özeser
2021-12-09   TestLink 1.19 - Arbitrary File Download (Unauthenticated) 22 WEB Gonzalo Villegas
2021-12-09   LimeSurvey 5.2.4 - Remote Code Execution (RCE) (Authenticated) 16 WEB Y1LD1R1M
2021-12-09   Chikitsa Patient Management System 2.0.2 - 'backup' Remote Code Execution (RCE) (Authenticated) 22 WEB 0z09e
2021-12-09   Chikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated) 22 WEB 0z09e
2021-12-06   Croogo 3.0.2 - Remote Code Execution (Authenticated) 20 WEB Deha Berkin Bir
2021-12-03   WordPress Plugin DZS Zoomsounds 6.45 - Arbitrary File Read (Unauthenticated) 22 WEB Uriel Yochpaz
2021-12-03   WordPress Plugin Slider by Soliloquy 2.6.2 - 'title' Stored Cross Site Scripting (XSS) (Authenticate 17 WEB Abdurrahman Erkan
2021-12-03   WordPress Plugin All-in-One Video Gallery plugin 2.4.9 - Local File Inclusion (LFI) 20 WEB Mohamed Magdy Abumusilm
2021-12-03   Online Magazine Management System 1.0 - SQLi Authentication Bypass 24 WEB Mohamed habib Smidi
2021-12-03   Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass 23 WEB Mohamed habib Smidi
2021-12-01   Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting 22 WEB Tushar Jadhav
2021-11-30   Laundry Booking Management System 1.0 - Remote Code Execution (RCE) 23 WEB Pablo Santiago
2021-11-29   opencart 3.0.3.8 - Sessjion Injection 20 WEB Hubert Wojciechowski
2021-11-29   orangescrum 1.8.0 - 'Multiple' Cross-Site Scripting (XSS) (Authenticated) 19 WEB Hubert Wojciechowski
2021-11-29   orangescrum 1.8.0 - 'Multiple' SQL Injection (Authenticated) 18 WEB Hubert Wojciechowski
2021-11-29   orangescrum 1.8.0 - Privilege escalation (Authenticated) 25 WEB Hubert Wojciechowski
2021-11-26   Bagisto 1.3.3 - Client-Side Template Injection 23 WEB Mohamed Abdellatif Jaber
2021-11-24   CMSimple 5.4 - Local file inclusion (LFI) to Remote code execution (RCE) (Authenticated) 18 WEB S1lv3r
2021-11-23   FLEX 1085 Web 1.6.0 - HTML Injection 18 WEB Mr Empy
2021-11-23   Bus Pass Management System 1.0 - 'Search' SQL injection 22 WEB Abhijeet Singh
2021-11-23   Webrun 3.6.0.42 - 'P_0' SQL Injection 18 WEB Vinicius Alves
2021-11-23   Wordpress Plugin WP Guppy 1.1 - WP-JSON API Sensitive Information Disclosure 17 WEB Keyvan Hardani
2021-11-22   Aimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection 18 WEB Ilker Burak ADIYAMAN
2021-11-17   Wordpress Plugin Smart Product Review 1.0.4 - Arbitrary File Upload 24 WEB Keyvan Hardani
2021-11-17   GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated) 34 WEB Jacob Baines
2021-11-17   SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit) 25 WEB M. Cory Billington
2021-11-17   Quick.CMS 6.7 - Cross Site Request Forgery (CSRF) to Cross Site Scripting (XSS) (Authenticated) 21 WEB Rahad Chowdhury
2021-11-17   Bludit 3.13.1 - 'username' Cross Site Scripting (XSS) 19 WEB Vasu
2021-11-16   CMDBuild 3.3.2 - 'Multiple' Cross Site Scripting (XSS) 30 WEB Hosein Vita
2021-11-16   Online Learning System 2.0 - Remote Code Execution (RCE) 19 WEB djebbaranon
2021-11-15   PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF) 20 WEB Hosein Vita
2021-11-15   WordPress Plugin Contact Form to Email 1.3.24 - Stored Cross Site Scripting (XSS) (Authenticated) 21 WEB Mohammed Aadhil Ashfaq
2021-11-15   Fuel CMS 1.4.13 - 'col' Blind SQL Injection (Authenticated) 23 WEB Rahad Chowdhury
2021-11-15   Simple Subscription Website 1.0 - SQLi Authentication Bypass 20 WEB Daniel Haro
2021-11-15   KONGA 0.14.9 - Privilege Escalation 20 WEB Fabricio Salomao
2021-11-15   WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS) 20 WEB Davide Taraschi
2021-11-12   Mumara Classic 2.93 - 'license' SQL Injection (Unauthenticated) 26 WEB Shain Lakin
2021-11-12   WordPress Plugin AccessPress Social Icons 1.8.2 - 'icon title' Stored Cross-Site Scripting (XSS) 17 WEB Murat DEMİRCİ
2021-11-12   WordPress Plugin WP Symposium Pro 2021.10 - 'wps_admin_forum_add_name' Stored Cross-Site Scripting ( 19 WEB Murat DEMİRCİ
2021-11-11   FormaLMS 2.4.4 - Authentication Bypass 26 WEB Cristian \'void\' Giustini
2021-11-11   Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3) 19 WEB Valentin Lobstein
2021-11-11   YeaLink SIP-TXXXP 53.84.0.15 - 'cmd' Command Injection (Authenticated) 20 WEB tahaafarooq
2021-11-10   Employee and Visitor Gate Pass Logging System 1.0 - 'name' Stored Cross-Site Scripting (XSS) 25 WEB İlhami Selamet
2021-11-10   Employee Daily Task Management System 1.0 - 'Name' Stored Cross-Site Scripting (XSS) 18 WEB Ragavender A G
2021-11-08   FusionPBX 4.5.29 - Remote Code Execution (RCE) (Authenticated) 18 WEB Luska
2021-11-08   WordPress Plugin Backup and Restore 1.0.3 - Arbitrary File Deletion 20 WEB Murat DEMİRCİ
2021-11-08   Froxlor 0.10.29.1 - SQL Injection (Authenticated) 21 WEB Martin Cernac
2021-11-08   Money Transfer Management System 1.0 - Authentication Bypass 25 WEB Aryan Chehreghani
2021-11-08   Kmaleon 1.1.0.205 - 'tipocomb' SQL Injection (Authenticated) 18 WEB Amel BOUZIANE-LEBLOND
2021-11-08   Simple Client Management System 1.0 - 'multiple' Stored Cross-Site Scripting (XSS) 26 WEB Sentinal920
2021-11-08   Simple Client Management System 1.0 - SQLi (Authentication Bypass) 22 WEB Sentinal920
2021-11-05   ImportExportTools NG 10.0.4 - HTML Injection 19 WEB Vulnerability-Lab
2021-11-05   Payment Terminal 3.1 - 'Multiple' Cross-Site Scripting (XSS) 33 WEB Vulnerability-Lab
2021-11-04   Opencart 3 Extension TMD Vendor System - Blind SQL Injection 24 WEB Muhammad Zaki Sulistya
2021-11-03   Ultimate POS 4.4 - 'name' Cross-Site Scripting (XSS) 20 WEB Vulnerability-Lab
2021-11-03   Vanguard 2.1 - 'Search' Cross-Site Scripting (XSS) 22 WEB Vulnerability-Lab
2021-11-03   Isshue Shopping Cart 3.5 - 'Title' Cross Site Scripting (XSS) 19 WEB Vulnerability-Lab
2021-11-03   Mult-e-Cart Ultimate 2.4 - 'id' SQL Injection 20 WEB Vulnerability-Lab
2021-11-03   PHP Melody 3.0 - Persistent Cross-Site Scripting (XSS) 19 WEB Vulnerability-Lab
2021-11-03   PHP Melody 3.0 - 'vid' SQL Injection 21 WEB Vulnerability-Lab
2021-11-03   PHP Melody 3.0 - 'Multiple' Cross-Site Scripting (XSS) 20 WEB Vulnerability-Lab
2021-11-03   Sonicwall SonicOS 6.5.4 - 'Common Name' Cross-Site Scripting (XSS) 27 WEB Vulnerability-Lab
2021-11-03   Simplephpscripts Simple CMS 2.1 - 'Multiple' SQL Injection 19 WEB Vulnerability-Lab
2021-11-03   Simplephpscripts Simple CMS 2.1 - 'Multiple' Stored Cross-Site Scripting (XSS) 17 WEB Vulnerability-Lab
2021-11-03   OpenAM 13.0 - LDAP Injection 16 WEB Charlton Trezevant
2021-11-03   WordPress Plugin Popup Anything 2.0.3 - 'Multiple' Stored Cross-Site Scripting (XSS) 20 WEB Luca Schembri
2021-11-03   Eclipse Jetty 11.0.5 - Sensitive File Disclosure 22 WEB Mayank Deshmukh
2021-11-03   Fuel CMS 1.4.1 - Remote Code Execution (3) 16 WEB Padsala Trushal
2021-11-03   WordPress Plugin Hotel Listing 3 - 'Multiple' Cross-Site Scripting (XSS) 19 WEB Vulnerability-Lab
2021-11-03   PHPJabbers Simple CMS 5 - 'name' Persistent Cross-Site Scripting (XSS) 24 WEB Vulnerability-Lab
2021-11-02   Codiad 2.8.4 - Remote Code Execution (Authenticated) (4) 18 WEB P4p4_M4n3
2021-11-02   i3 International Annexxus Cameras Ax-n 5.2.0 - Application Logic Flaw 19 WEB LiquidWorm
2021-11-02   Ericsson Network Location MPS GMPC21 - Privilege Escalation (Metasploit) 18 WEB AkkuS
2021-11-02   Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit) 18 WEB AkkuS
2021-11-02   Employee Record Management System 1.2 - 'empid' SQL injection (Unauthenticated) 19 WEB Anubhav Singh
2021-10-29   Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit) 17 WEB Charl-Alexandre Le Brun
2021-10-29   WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS) 18 WEB 3ndG4me
2021-10-29   Umbraco v8.14.1 - 'baseUrl' SSRF 14 WEB NgoAnhDuc
2021-10-28   PHPGurukul Hostel Management System 2.1 - Cross-site request forgery (CSRF) to Cross-site Scripting 21 WEB Anubhav Singh
2021-10-28   WordPress Plugin Supsystic Contact Form 1.7.18 - 'label' Stored Cross-Site Scripting (XSS) 19 WEB Murat DEMİRCİ
2021-10-26   WordPress Plugin Filterable Portfolio Gallery 1.0 - 'title' Stored Cross-Site Scripting (XSS) 23 WEB Murat DEMİRCİ
2021-10-25   phpMyAdmin 4.8.1 - Remote Code Execution (RCE) 24 WEB samguy
2021-10-25   Wordpress 4.9.6 - Arbitrary File Deletion (Authenticated) (2) 26 WEB samguy
2021-10-25   WordPress Plugin Ninja Tables 4.1.7 - Stored Cross-Site Scripting (XSS) 31 WEB Akash Patil
2021-10-25   WordPress Plugin Media-Tags 3.2.0.2 - Stored Cross-Site Scripting (XSS) 25 WEB Akash Patil
2021-10-25   Engineers Online Portal 1.0 - 'id' SQL Injection 20 WEB Alon Leviev
2021-10-25   Engineers Online Portal 1.0 - 'multiple' Authentication Bypass 26 WEB Alon Leviev
2021-10-25   Engineers Online Portal 1.0 - 'multiple' Stored Cross-Site Scripting (XSS) 25 WEB Alon Leviev
2021-10-25   Online Event Booking and Reservation System 1.0 - 'reason' Stored Cross-Site Scripting (XSS) 20 WEB Alon Leviev
2021-10-25   Balbooa Joomla Forms Builder 2.0.6 - SQL Injection (Unauthenticated) 23 WEB blockomat2100
2021-10-25   Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2) 19 WEB ThelastVvV
2021-10-25   Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated) 21 WEB Nehru Sethuraman
2021-10-25   Engineers Online Portal 1.0 - File Upload Remote Code Execution (RCE) 18 WEB SadKris
2021-10-25   WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated) 19 WEB Akash Patil
2021-10-25   Hikvision Web Server Build 210702 - Command Injection 23 WEB bashis
2021-10-22   Online Course Registration 1.0 - Blind Boolean-Based SQL Injection (Authenticated) 23 WEB Sam Ferguson
2021-10-22   Clinic Management System 1.0 - SQL injection to Remote Code Execution 17 WEB Pablo Santiago
2021-10-22   Jetty 9.4.37.v20210219 - Information Disclosure 23 WEB Mayank Deshmukh
2021-10-21   Easy Chat Server 3.1 - Directory Traversal and Arbitrary File Read 19 WEB z4nd3r
2021-10-21   Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS) 17 WEB Ghuliev
2021-10-20   Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation 22 WEB Oscar Gil Gutierrez
2021-10-20   SonicWall SMA 10.2.1.0-17sv - Password Reset 21 WEB Jacob Baines
2021-10-19   Online Motorcycle (Bike) Rental System 1.0 - Blind Time-Based SQL Injection (Unauthenticated) 22 WEB Chase Comardelle
2021-10-19   myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS) 14 WEB RedTeam Pentesting GmbH
2021-10-19   WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS) 18 WEB David Álvarez Robles
2021-10-18   Plastic SCM 10.0.16.5622 - WebAdmin Server Access 18 WEB Basavaraj Banakar
2021-10-18   Company's Recruitment Management System 1.0 - 'Add New user' Cross-Site Request Forgery (CSRF) 18 WEB Aniket Deshmane
2021-10-18   Company's Recruitment Management System 1.0 - 'description' Stored Cross-Site Scripting (XSS) 20 WEB Aniket Deshmane
2021-10-18   Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS) 17 WEB Hamit CİBO
2021-10-18   Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure 21 WEB Hamit CİBO
2021-10-18   Company's Recruitment Management System 1.0. - 'title' Stored Cross-Site Scripting (XSS) 27 WEB Aniket Deshmane
2021-10-18   Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read 28 WEB nam3lum
2021-10-18   Support Board 3.3.4 - 'Message' Stored Cross-Site Scripting (XSS) 20 WEB John Jefferson Li
2021-10-15   i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS) 18 WEB Forster Chiu
2021-10-14   TextPattern CMS 4.8.7 - Remote Command Execution (RCE) (Authenticated) 20 WEB Mert Daş
2021-10-13   Sonicwall SonicOS 7.0 - Host Header Injection 29 WEB Ramikan
2021-10-13   Logitech Media Server 8.2.0 - 'Title' Cross-Site Scripting (XSS) 26 WEB Mert Daş
2021-10-13   Student Quarterly Grading System 1.0 - 'grade' Stored Cross-Site Scripting (XSS) 30 WEB Hüseyin Serkan Balkanli
2021-10-13   Simple Issue Tracker System 1.0 - SQLi Authentication Bypass 26 WEB Bekir Bugra TURKOGLU
2021-10-13   Online Learning System 2.0 - 'Multiple' SQLi Authentication Bypass 23 WEB Blackhan
2021-10-13   Pharmacy Point of Sale System 1.0 - 'Add New User' Cross-Site Request Forgery (CSRF) 18 WEB Murat DEMİRCİ
2021-10-13   Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE) 23 WEB Lucas Souza
2021-10-13   Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated) 17 WEB Mayank Deshmukh