Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-10-18   Company's Recruitment Management System 1.0. - 'title' Stored Cross-Site Scripting (XSS) 30 WEB Aniket Deshmane
2021-10-18   Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read 34 WEB nam3lum
2021-10-18   Support Board 3.3.4 - 'Message' Stored Cross-Site Scripting (XSS) 25 WEB John Jefferson Li
2021-10-15   i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS) 21 WEB Forster Chiu
2021-10-14   TextPattern CMS 4.8.7 - Remote Command Execution (RCE) (Authenticated) 24 WEB Mert Daş
2021-10-13   Sonicwall SonicOS 7.0 - Host Header Injection 32 WEB Ramikan
2021-10-13   Logitech Media Server 8.2.0 - 'Title' Cross-Site Scripting (XSS) 31 WEB Mert Daş
2021-10-13   Student Quarterly Grading System 1.0 - 'grade' Stored Cross-Site Scripting (XSS) 37 WEB Hüseyin Serkan Balkanli
2021-10-13   Simple Issue Tracker System 1.0 - SQLi Authentication Bypass 29 WEB Bekir Bugra TURKOGLU
2021-10-13   Online Learning System 2.0 - 'Multiple' SQLi Authentication Bypass 28 WEB Blackhan
2021-10-13   Pharmacy Point of Sale System 1.0 - 'Add New User' Cross-Site Request Forgery (CSRF) 22 WEB Murat DEMİRCİ
2021-10-13   Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE) 28 WEB Lucas Souza
2021-10-13   Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated) 20 WEB Mayank Deshmukh
2021-10-13   Company's Recruitment Management System 1.0 - 'Multiple' SQL Injection (Unauthenticated) 26 WEB Yash Mahajan
2021-10-13   Simple Payroll System 1.0 - SQLi Authentication Bypass 25 WEB Yash Mahajan
2021-10-08   Loan Management System 1.0 - SQLi Authentication Bypass 26 WEB Merve Oral
2021-10-08   Online Employees Work From Home Attendance System 1.0 - SQLi Authentication Bypass 27 WEB Merve Oral
2021-10-08   Online Enrollment Management System 1.0 - Authentication Bypass 31 WEB Amine ismail
2021-10-08   Simple Online College Entrance Exam System 1.0 - 'Multiple' SQL injection 32 WEB Amine ismail
2021-10-08   Simple Online College Entrance Exam System 1.0 - Account Takeover 24 WEB Amine ismail
2021-10-08   Simple Online College Entrance Exam System 1.0 - Unauthenticated Admin Creation 33 WEB Amine ismail
2021-10-08   WordPress Plugin Pie Register 3.7.1.4 - Admin Privilege Escalation (Unauthenticated) 27 WEB Lotfi13-DZ
2021-10-08   Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated) 28 WEB DreyAnd
2021-10-08   django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS) 25 WEB Raven Security Associates
2021-10-08   Online Traffic Offense Management System 1.0 - Privilage escalation (Unauthenticated) 23 WEB snup
2021-10-08   IFSC Code Finder Project 1.0 - SQL injection (Unauthenticated) 28 WEB Yash Mahajan
2021-10-07   Simple Online College Entrance Exam System 1.0 - SQLi Authentication Bypass 26 WEB Mevlüt Yılmaz
2021-10-07   Online Traffic Offense Management System 1.0 - Multiple RCE (Unauthenticated) 24 WEB snup
2021-10-07   Online Traffic Offense Management System 1.0 - Multiple XSS (Unauthenticated) 25 WEB snup
2021-10-07   Online Traffic Offense Management System 1.0 - Multiple SQL Injection (Unauthenticated) 31 WEB snup
2021-10-07   Online DJ Booking Management System 1.0 - 'Multiple' Blind Cross-Site Scripting 21 WEB Yash Mahajan
2021-10-06   Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE) 20 WEB Lucas Souza
2021-10-06   Wordpress Plugin BulletProof Security 5.1 - Sensitive Information Disclosure 23 WEB Ron Jost
2021-10-06   Odine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection 19 WEB Emel Basayar
2021-10-06   Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read 19 WEB Mayank Deshmukh
2021-10-05   Wordpress Plugin MStore API 2.0.6 - Arbitrary File Upload 24 WEB spacehen
2021-10-05   Wordpress Plugin TheCartPress 1.5.3.6 - Privilege Escalation (Unauthenticated) 29 WEB spacehen
2021-10-05   Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read 24 WEB Mayank Deshmukh
2021-10-05   Student Quarterly Grading System 1.0 - SQLi Authentication Bypass 24 WEB Blackhan
2021-10-04   Young Entrepreneur E-Negosyo System 1.0 - 'PRODESC' Stored Cross-Site Scripting (XSS) 26 WEB Jordan Glover
2021-10-04   Young Entrepreneur E-Negosyo System 1.0 - SQL Injection Authentication Bypass 28 WEB Jordan Glover
2021-10-04   Open Game Panel - Remote Code Execution (RCE) (Authenticated) 32 WEB prey
2021-10-04   Lodging Reservation Management System 1.0 - Authentication Bypass 25 WEB Nitin Sharma
2021-10-04   Payara Micro Community 5.2021.6 - Directory Traversal 32 WEB Yasser Khan
2021-10-01   Directory Management System 1.0 - SQL Injection Authentication Bypass 25 WEB Sanjay Singh
2021-10-01   CMSimple_XH 1.7.4 - Remote Code Execution (RCE) (Authenticated) 24 WEB Halit AKAYDIN
2021-10-01   WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS) 22 WEB Andreas Finstad
2021-10-01   Dairy Farm Shop Management System 1.0 - SQL Injection Authentication Bypass 21 WEB Sanjay Singh
2021-10-01   Vehicle Service Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 30 WEB Ghuliev
2021-10-01   Phpwcms 1.9.30 - Arbitrary File Upload 23 WEB Okan Kurtulus
2021-10-01   Blood Bank System 1.0 - Authentication Bypass 28 WEB Nitin Sharma
2021-10-01   Drupal Module MiniorangeSAML 8.x-2.22 - Privilege escalation 21 WEB Cristian \'void\' Giustini
2021-10-01   Exam Form Submission System 1.0 - SQL Injection Authentication Bypass 27 WEB Nitin Sharma
2021-09-30   Pharmacy Point of Sale System 1.0 - 'Multiple' SQL Injection (SQLi) 26 WEB Murat
2021-09-30   Cmsimple 5.4 - Remote Code Execution (RCE) (Authenticated) 26 WEB pussycat0x
2021-09-30   Cyber Cafe Management System Project (CCMS) 1.0 - SQL Injection Authentication Bypass 26 WEB Sanjay Singh
2021-09-29   Pet Shop Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 26 WEB Mr.Gedik
2021-09-29   OpenSIS 8.0 - 'cp_id_miss_attn' Reflected Cross-Site Scripting (XSS) 22 WEB Eric Salario
2021-09-29   WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting 23 WEB 0xB9
2021-09-29   WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS) 25 WEB 0xB9
2021-09-29   Storage Unit Rental Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 26 WEB Ghuliev
2021-09-28   WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS) 27 WEB 0xB9
2021-09-28   WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS) 21 WEB 0xB9
2021-09-28   WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS) 25 WEB 0xB9
2021-09-28   WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated) 27 WEB Nosa Shandy
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Remote Privilege Escalation 24 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Hidden Backdoor Account (Write Access) 21 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Config Download (Unauthenticated) 21 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP 10.2.2 - Authorization Bypass 19 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - 'Add Admin' Cross-Site Request Forgery (CSRF) 19 WEB LiquidWorm
2021-09-27   Library System 1.0 - 'student_id' SQL injection (Authenticated) 22 WEB Vinay Bhuria
2021-09-27   WordPress Plugin Wappointment 2.2.4 - Stored Cross-Site Scripting (XSS) 22 WEB Renos Nikolaou
2021-09-24   Pharmacy Point of Sale System 1.0 - SQLi Authentication BYpass 20 WEB Janik Wehrli
2021-09-24   SmarterTools SmarterTrack 7922 - 'Multiple' Information Disclosure 20 WEB Andrei Manole
2021-09-23   Police Crime Record Management Project 1.0 - Time Based SQLi 29 WEB ()t/\\/\\1
2021-09-23   Budget and Expense Tracker System 1.0 - Arbitrary File Upload 29 WEB ()t/\\/\\1
2021-09-23   WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF) 32 WEB 0xB9
2021-09-23   WordPress Plugin Advanced Order Export For WooCommerce 3.1.7 - Reflected Cross-Site Scripting (XSS) 23 WEB 0xB9
2021-09-23   Backdrop CMS 1.20.0 - 'Multiple' Cross-Site Request Forgery (CSRF) 21 WEB V1n1v131r4
2021-09-23   Wordpress Plugin 3DPrint Lite 1.9.1.4 - Arbitrary File Upload 26 WEB spacehen
2021-09-23   Gurock Testrail 7.2.0.3014 - 'files.md5' Improper Access Control 26 WEB Sick Codes
2021-09-22   Online Reviewer System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 28 WEB Abdullah Khawaja
2021-09-22   Sentry 8.2.0 - Remote Code Execution (RCE) (Authenticated) 24 WEB Mohin Paramasivam
2021-09-22   Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected) 21 WEB Akıner Kısa
2021-09-22   OpenCats 0.9.4-2 - 'docx ' XML External Entity Injection (XXE) 26 WEB Jake Ruston
2021-09-22   e107 CMS 2.3.0 - Remote Code Execution (RCE) (Authenticated) 28 WEB Halit AKAYDIN
2021-09-22   Filerun 2021.03.26 - Remote Code Execution (RCE) (Authenticated) 21 WEB syntegris information solutions GmbH
2021-09-22   Simple Attendance System 1.0 - Unauthenticated Blind SQLi 26 WEB ()t/\\/\\1
2021-09-21   WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated) 42 WEB Halit AKAYDIN
2021-09-21   Budget and Expense Tracker System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 26 WEB Abdullah Khawaja
2021-09-20   Budget and Expense Tracker System 1.0 - Authenticated Bypass 21 WEB Prunier Charles-Yves
2021-09-20   Church Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 25 WEB Abdullah Khawaja
2021-09-20   Online Food Ordering System 2.0 - Remote Code Execution (RCE) (Unauthenticated) 34 WEB Abdullah Khawaja
2021-09-20   WordPress 5.7 - 'Media Library' XML External Entity Injection (XXE) (Authenticated) 19 WEB David Utón
2021-09-20   Church Management System 1.0 - 'search' SQL Injection (Unauthenticated) 27 WEB Erwin Krazek
2021-09-20   T-Soft E-Commerce 4 - change 'admin credentials' Cross-Site Request Forgery (CSRF) 24 WEB Alperen Ergel
2021-09-17   Simple Attendance System 1.0 - Authenticated bypass 24 WEB Abdullah Khawaja
2021-09-17   Library Management System 1.0 - Blind Time-Based SQL Injection (Unauthenticated) 23 WEB boku
2021-09-17   WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass 22 WEB 0xB455
2021-09-16   ImpressCMS 1.4.2 - Remote Code Execution (RCE) (Authenticated) 21 WEB Halit AKAYDIN
2021-09-15   AlphaWeb XE - File Upload Remote Code Execution (RCE) (Authenticated) 21 WEB Ricardo Ruiz
2021-09-15   Evolution CMS 3.1.6 - Remote Code Execution (RCE) (Authenticated) 22 WEB Halit AKAYDIN
2021-09-15   Seowon 130-SLC router - 'queriesCnt' Remote Code Execution (Unauthenticated) 30 WEB Aryan Chehreghani
2021-09-15   Support Board 3.3.3 - 'Multiple' SQL Injection (Unauthenticated) 20 WEB John Jefferson Li
2021-09-14   Purchase Order Management System 1.0 - Remote File Upload 33 WEB Aryan Chehreghani
2021-09-13   Apartment Visitor Management System (AVMS) 1.0 - 'username' SQL Injection 19 WEB mari0x00
2021-09-13   Wordpress Plugin Download From Files 1.48 - Arbitrary File Upload 23 WEB spacehen
2021-09-13   ECOA Building Automation System - Arbitrary File Deletion 23 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Local File Disclosure 25 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Remote Privilege Escalation 23 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Configuration Download Information Disclosure 27 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Cookie Poisoning Authentication Bypass 21 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - 'multiple' Cross-Site Request Forgery (CSRF) 35 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Directory Traversal Content Disclosure 31 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Path Traversal Arbitrary File Upload 22 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Weak Default Credentials 29 WEB Neurogenesia
2021-09-13   Men Salon Management System 1.0 - Multiple Vulnerabilities 22 WEB Aryan Chehreghani
2021-09-09   Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS) 26 WEB Emre Aslan
2021-09-08   WordPress Plugin TablePress 1.14 - CSV Injection 36 WEB Nikhil Kapoor
2021-09-07   WordPress Plugin Survey & Poll 1.5.7.3 - 'sss_params' SQL Injection (2) 21 WEB Mohin Paramasivam
2021-09-07   WordPress Plugin WP Sitemap Page 1.6.4 - Stored Cross-Site Scripting (XSS) 30 WEB Nikhil Kapoor
2021-09-06   Antminer Monitor 0.5.0 - Authentication Bypass 25 WEB Vulnz
2021-09-06   Patient Appointment Scheduler System 1.0 - Persistent Cross-Site Scripting 34 WEB a-rey
2021-09-06   Patient Appointment Scheduler System 1.0 - Unauthenticated File Upload 36 WEB a-rey
2021-09-06   Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR) 20 WEB sudoninja