2021-11-08
|
|
Froxlor 0.10.29.1 - SQL Injection (Authenticated)
|
5 |
WEB
|
Martin Cernac
|
2021-11-08
|
|
Money Transfer Management System 1.0 - Authentication Bypass
|
5 |
WEB
|
Aryan Chehreghani
|
2021-11-08
|
|
Kmaleon 1.1.0.205 - 'tipocomb' SQL Injection (Authenticated)
|
5 |
WEB
|
Amel BOUZIANE-LEBLOND
|
2021-11-08
|
|
Simple Client Management System 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Sentinal920
|
2021-11-08
|
|
Simple Client Management System 1.0 - SQLi (Authentication Bypass)
|
6 |
WEB
|
Sentinal920
|
2021-11-05
|
|
ImportExportTools NG 10.0.4 - HTML Injection
|
6 |
WEB
|
Vulnerability-Lab
|
2021-11-05
|
|
Payment Terminal 3.1 - 'Multiple' Cross-Site Scripting (XSS)
|
5 |
WEB
|
Vulnerability-Lab
|
2021-11-04
|
|
Opencart 3 Extension TMD Vendor System - Blind SQL Injection
|
3 |
WEB
|
Muhammad Zaki Sulistya
|
2021-11-03
|
|
Ultimate POS 4.4 - 'name' Cross-Site Scripting (XSS)
|
4 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Vanguard 2.1 - 'Search' Cross-Site Scripting (XSS)
|
7 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Isshue Shopping Cart 3.5 - 'Title' Cross Site Scripting (XSS)
|
5 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Mult-e-Cart Ultimate 2.4 - 'id' SQL Injection
|
3 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
PHP Melody 3.0 - Persistent Cross-Site Scripting (XSS)
|
3 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
PHP Melody 3.0 - 'vid' SQL Injection
|
4 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
PHP Melody 3.0 - 'Multiple' Cross-Site Scripting (XSS)
|
6 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Sonicwall SonicOS 6.5.4 - 'Common Name' Cross-Site Scripting (XSS)
|
9 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Simplephpscripts Simple CMS 2.1 - 'Multiple' SQL Injection
|
4 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Simplephpscripts Simple CMS 2.1 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
OpenAM 13.0 - LDAP Injection
|
4 |
WEB
|
Charlton Trezevant
|
2021-11-03
|
|
WordPress Plugin Popup Anything 2.0.3 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
3 |
WEB
|
Luca Schembri
|
2021-11-03
|
|
Eclipse Jetty 11.0.5 - Sensitive File Disclosure
|
7 |
WEB
|
Mayank Deshmukh
|
2021-11-03
|
|
Fuel CMS 1.4.1 - Remote Code Execution (3)
|
3 |
WEB
|
Padsala Trushal
|
2021-11-03
|
|
WordPress Plugin Hotel Listing 3 - 'Multiple' Cross-Site Scripting (XSS)
|
4 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
PHPJabbers Simple CMS 5 - 'name' Persistent Cross-Site Scripting (XSS)
|
6 |
WEB
|
Vulnerability-Lab
|
2021-11-02
|
|
Codiad 2.8.4 - Remote Code Execution (Authenticated) (4)
|
3 |
WEB
|
P4p4_M4n3
|
2021-11-02
|
|
i3 International Annexxus Cameras Ax-n 5.2.0 - Application Logic Flaw
|
4 |
WEB
|
LiquidWorm
|
2021-11-02
|
|
Ericsson Network Location MPS GMPC21 - Privilege Escalation (Metasploit)
|
4 |
WEB
|
AkkuS
|
2021-11-02
|
|
Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit)
|
5 |
WEB
|
AkkuS
|
2021-11-02
|
|
Employee Record Management System 1.2 - 'empid' SQL injection (Unauthenticated)
|
6 |
WEB
|
Anubhav Singh
|
2021-10-29
|
|
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
|
5 |
WEB
|
Charl-Alexandre Le Brun
|
2021-10-29
|
|
WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS)
|
5 |
WEB
|
3ndG4me
|
2021-10-29
|
|
Umbraco v8.14.1 - 'baseUrl' SSRF
|
4 |
WEB
|
NgoAnhDuc
|
2021-10-28
|
|
PHPGurukul Hostel Management System 2.1 - Cross-site request forgery (CSRF) to Cross-site Scripting
|
5 |
WEB
|
Anubhav Singh
|
2021-10-28
|
|
WordPress Plugin Supsystic Contact Form 1.7.18 - 'label' Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Murat DEMİRCİ
|
2021-10-26
|
|
WordPress Plugin Filterable Portfolio Gallery 1.0 - 'title' Stored Cross-Site Scripting (XSS)
|
3 |
WEB
|
Murat DEMİRCİ
|
2021-10-25
|
|
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
|
6 |
WEB
|
samguy
|
2021-10-25
|
|
Wordpress 4.9.6 - Arbitrary File Deletion (Authenticated) (2)
|
3 |
WEB
|
samguy
|
2021-10-25
|
|
WordPress Plugin Ninja Tables 4.1.7 - Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Akash Patil
|
2021-10-25
|
|
WordPress Plugin Media-Tags 3.2.0.2 - Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Akash Patil
|
2021-10-25
|
|
Engineers Online Portal 1.0 - 'id' SQL Injection
|
3 |
WEB
|
Alon Leviev
|
2021-10-25
|
|
Engineers Online Portal 1.0 - 'multiple' Authentication Bypass
|
6 |
WEB
|
Alon Leviev
|
2021-10-25
|
|
Engineers Online Portal 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Alon Leviev
|
2021-10-25
|
|
Online Event Booking and Reservation System 1.0 - 'reason' Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Alon Leviev
|
2021-10-25
|
|
Balbooa Joomla Forms Builder 2.0.6 - SQL Injection (Unauthenticated)
|
5 |
WEB
|
blockomat2100
|
2021-10-25
|
|
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
|
5 |
WEB
|
ThelastVvV
|
2021-10-25
|
|
Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)
|
6 |
WEB
|
Nehru Sethuraman
|
2021-10-25
|
|
Engineers Online Portal 1.0 - File Upload Remote Code Execution (RCE)
|
3 |
WEB
|
SadKris
|
2021-10-25
|
|
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
5 |
WEB
|
Akash Patil
|
2021-10-25
|
|
Hikvision Web Server Build 210702 - Command Injection
|
4 |
WEB
|
bashis
|
2021-10-22
|
|
Online Course Registration 1.0 - Blind Boolean-Based SQL Injection (Authenticated)
|
4 |
WEB
|
Sam Ferguson
|
2021-10-22
|
|
Clinic Management System 1.0 - SQL injection to Remote Code Execution
|
5 |
WEB
|
Pablo Santiago
|
2021-10-22
|
|
Jetty 9.4.37.v20210219 - Information Disclosure
|
7 |
WEB
|
Mayank Deshmukh
|
2021-10-21
|
|
Easy Chat Server 3.1 - Directory Traversal and Arbitrary File Read
|
3 |
WEB
|
z4nd3r
|
2021-10-21
|
|
Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Ghuliev
|
2021-10-20
|
|
Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
|
4 |
WEB
|
Oscar Gil Gutierrez
|
2021-10-20
|
|
SonicWall SMA 10.2.1.0-17sv - Password Reset
|
6 |
WEB
|
Jacob Baines
|
2021-10-19
|
|
Online Motorcycle (Bike) Rental System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
|
6 |
WEB
|
Chase Comardelle
|
2021-10-19
|
|
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
|
3 |
WEB
|
RedTeam Pentesting GmbH
|
2021-10-19
|
|
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
|
4 |
WEB
|
David Álvarez Robles
|
2021-10-18
|
|
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
|
5 |
WEB
|
Basavaraj Banakar
|
2021-10-18
|
|
Company's Recruitment Management System 1.0 - 'Add New user' Cross-Site Request Forgery (CSRF)
|
5 |
WEB
|
Aniket Deshmane
|
2021-10-18
|
|
Company's Recruitment Management System 1.0 - 'description' Stored Cross-Site Scripting (XSS)
|
6 |
WEB
|
Aniket Deshmane
|
2021-10-18
|
|
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
|
5 |
WEB
|
Hamit CİBO
|
2021-10-18
|
|
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
|
5 |
WEB
|
Hamit CİBO
|
2021-10-18
|
|
Company's Recruitment Management System 1.0. - 'title' Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Aniket Deshmane
|
2021-10-18
|
|
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
|
4 |
WEB
|
nam3lum
|
2021-10-18
|
|
Support Board 3.3.4 - 'Message' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
John Jefferson Li
|
2021-10-15
|
|
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
|
4 |
WEB
|
Forster Chiu
|
2021-10-14
|
|
TextPattern CMS 4.8.7 - Remote Command Execution (RCE) (Authenticated)
|
4 |
WEB
|
Mert Daş
|
2021-10-13
|
|
Sonicwall SonicOS 7.0 - Host Header Injection
|
9 |
WEB
|
Ramikan
|
2021-10-13
|
|
Logitech Media Server 8.2.0 - 'Title' Cross-Site Scripting (XSS)
|
5 |
WEB
|
Mert Daş
|
2021-10-13
|
|
Student Quarterly Grading System 1.0 - 'grade' Stored Cross-Site Scripting (XSS)
|
6 |
WEB
|
Hüseyin Serkan Balkanli
|
2021-10-13
|
|
Simple Issue Tracker System 1.0 - SQLi Authentication Bypass
|
5 |
WEB
|
Bekir Bugra TURKOGLU
|
2021-10-13
|
|
Online Learning System 2.0 - 'Multiple' SQLi Authentication Bypass
|
5 |
WEB
|
Blackhan
|
2021-10-13
|
|
Pharmacy Point of Sale System 1.0 - 'Add New User' Cross-Site Request Forgery (CSRF)
|
4 |
WEB
|
Murat DEMİRCİ
|
2021-10-13
|
|
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
|
5 |
WEB
|
Lucas Souza
|
2021-10-13
|
|
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
|
5 |
WEB
|
Mayank Deshmukh
|
2021-10-13
|
|
Company's Recruitment Management System 1.0 - 'Multiple' SQL Injection (Unauthenticated)
|
3 |
WEB
|
Yash Mahajan
|
2021-10-13
|
|
Simple Payroll System 1.0 - SQLi Authentication Bypass
|
6 |
WEB
|
Yash Mahajan
|
2021-10-08
|
|
Loan Management System 1.0 - SQLi Authentication Bypass
|
4 |
WEB
|
Merve Oral
|
2021-10-08
|
|
Online Employees Work From Home Attendance System 1.0 - SQLi Authentication Bypass
|
5 |
WEB
|
Merve Oral
|
2021-10-08
|
|
Online Enrollment Management System 1.0 - Authentication Bypass
|
6 |
WEB
|
Amine ismail
|
2021-10-08
|
|
Simple Online College Entrance Exam System 1.0 - 'Multiple' SQL injection
|
6 |
WEB
|
Amine ismail
|
2021-10-08
|
|
Simple Online College Entrance Exam System 1.0 - Account Takeover
|
6 |
WEB
|
Amine ismail
|
2021-10-08
|
|
Simple Online College Entrance Exam System 1.0 - Unauthenticated Admin Creation
|
5 |
WEB
|
Amine ismail
|
2021-10-08
|
|
WordPress Plugin Pie Register 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)
|
5 |
WEB
|
Lotfi13-DZ
|
2021-10-08
|
|
Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)
|
4 |
WEB
|
DreyAnd
|
2021-10-08
|
|
django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Raven Security Associates
|
2021-10-08
|
|
Online Traffic Offense Management System 1.0 - Privilage escalation (Unauthenticated)
|
4 |
WEB
|
snup
|
2021-10-08
|
|
IFSC Code Finder Project 1.0 - SQL injection (Unauthenticated)
|
5 |
WEB
|
Yash Mahajan
|
2021-10-07
|
|
Simple Online College Entrance Exam System 1.0 - SQLi Authentication Bypass
|
4 |
WEB
|
Mevlüt Yılmaz
|
2021-10-07
|
|
Online Traffic Offense Management System 1.0 - Multiple RCE (Unauthenticated)
|
5 |
WEB
|
snup
|
2021-10-07
|
|
Online Traffic Offense Management System 1.0 - Multiple XSS (Unauthenticated)
|
5 |
WEB
|
snup
|
2021-10-07
|
|
Online Traffic Offense Management System 1.0 - Multiple SQL Injection (Unauthenticated)
|
5 |
WEB
|
snup
|
2021-10-07
|
|
Online DJ Booking Management System 1.0 - 'Multiple' Blind Cross-Site Scripting
|
4 |
WEB
|
Yash Mahajan
|
2021-10-06
|
|
Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)
|
3 |
WEB
|
Lucas Souza
|
2021-10-06
|
|
Wordpress Plugin BulletProof Security 5.1 - Sensitive Information Disclosure
|
4 |
WEB
|
Ron Jost
|
2021-10-06
|
|
Odine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection
|
3 |
WEB
|
Emel Basayar
|
2021-10-06
|
|
Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read
|
7 |
WEB
|
Mayank Deshmukh
|
2021-10-05
|
|
Wordpress Plugin MStore API 2.0.6 - Arbitrary File Upload
|
5 |
WEB
|
spacehen
|
2021-10-05
|
|
Wordpress Plugin TheCartPress 1.5.3.6 - Privilege Escalation (Unauthenticated)
|
4 |
WEB
|
spacehen
|
2021-10-05
|
|
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
|
5 |
WEB
|
Mayank Deshmukh
|
2021-10-05
|
|
Student Quarterly Grading System 1.0 - SQLi Authentication Bypass
|
4 |
WEB
|
Blackhan
|
2021-10-04
|
|
Young Entrepreneur E-Negosyo System 1.0 - 'PRODESC' Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Jordan Glover
|
2021-10-04
|
|
Young Entrepreneur E-Negosyo System 1.0 - SQL Injection Authentication Bypass
|
5 |
WEB
|
Jordan Glover
|
2021-10-04
|
|
Open Game Panel - Remote Code Execution (RCE) (Authenticated)
|
5 |
WEB
|
prey
|
2021-10-04
|
|
Lodging Reservation Management System 1.0 - Authentication Bypass
|
6 |
WEB
|
Nitin Sharma
|
2021-10-04
|
|
Payara Micro Community 5.2021.6 - Directory Traversal
|
7 |
WEB
|
Yasser Khan
|
2021-10-01
|
|
Directory Management System 1.0 - SQL Injection Authentication Bypass
|
5 |
WEB
|
Sanjay Singh
|
2021-10-01
|
|
CMSimple_XH 1.7.4 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
Halit AKAYDIN
|
2021-10-01
|
|
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
|
3 |
WEB
|
Andreas Finstad
|
2021-10-01
|
|
Dairy Farm Shop Management System 1.0 - SQL Injection Authentication Bypass
|
4 |
WEB
|
Sanjay Singh
|
2021-10-01
|
|
Vehicle Service Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
4 |
WEB
|
Ghuliev
|
2021-10-01
|
|
Phpwcms 1.9.30 - Arbitrary File Upload
|
4 |
WEB
|
Okan Kurtulus
|
2021-10-01
|
|
Blood Bank System 1.0 - Authentication Bypass
|
4 |
WEB
|
Nitin Sharma
|
2021-10-01
|
|
Drupal Module MiniorangeSAML 8.x-2.22 - Privilege escalation
|
4 |
WEB
|
Cristian \'void\' Giustini
|
2021-10-01
|
|
Exam Form Submission System 1.0 - SQL Injection Authentication Bypass
|
4 |
WEB
|
Nitin Sharma
|
2021-09-30
|
|
Pharmacy Point of Sale System 1.0 - 'Multiple' SQL Injection (SQLi)
|
5 |
WEB
|
Murat
|
2021-09-30
|
|
Cmsimple 5.4 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
pussycat0x
|
2021-09-30
|
|
Cyber Cafe Management System Project (CCMS) 1.0 - SQL Injection Authentication Bypass
|
5 |
WEB
|
Sanjay Singh
|
2021-09-29
|
|
Pet Shop Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
4 |
WEB
|
Mr.Gedik
|
2021-09-29
|
|
OpenSIS 8.0 - 'cp_id_miss_attn' Reflected Cross-Site Scripting (XSS)
|
4 |
WEB
|
Eric Salario
|
2021-09-29
|
|
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
|
5 |
WEB
|
0xB9
|
2021-09-29
|
|
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
|
6 |
WEB
|
0xB9
|
2021-09-29
|
|
Storage Unit Rental Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
4 |
WEB
|
Ghuliev
|