2021-09-28
|
|
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
|
5 |
WEB
|
0xB9
|
2021-09-28
|
|
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
|
5 |
WEB
|
0xB9
|
2021-09-28
|
|
WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
|
4 |
WEB
|
0xB9
|
2021-09-28
|
|
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
4 |
WEB
|
Nosa Shandy
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Remote Privilege Escalation
|
6 |
WEB
|
LiquidWorm
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Hidden Backdoor Account (Write Access)
|
5 |
WEB
|
LiquidWorm
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Config Download (Unauthenticated)
|
5 |
WEB
|
LiquidWorm
|
2021-09-28
|
|
FatPipe Networks WARP 10.2.2 - Authorization Bypass
|
5 |
WEB
|
LiquidWorm
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - 'Add Admin' Cross-Site Request Forgery (CSRF)
|
3 |
WEB
|
LiquidWorm
|
2021-09-27
|
|
Library System 1.0 - 'student_id' SQL injection (Authenticated)
|
5 |
WEB
|
Vinay Bhuria
|
2021-09-27
|
|
WordPress Plugin Wappointment 2.2.4 - Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Renos Nikolaou
|
2021-09-24
|
|
Pharmacy Point of Sale System 1.0 - SQLi Authentication BYpass
|
4 |
WEB
|
Janik Wehrli
|
2021-09-24
|
|
SmarterTools SmarterTrack 7922 - 'Multiple' Information Disclosure
|
5 |
WEB
|
Andrei Manole
|
2021-09-23
|
|
Police Crime Record Management Project 1.0 - Time Based SQLi
|
7 |
WEB
|
()t/\\/\\1
|
2021-09-23
|
|
Budget and Expense Tracker System 1.0 - Arbitrary File Upload
|
5 |
WEB
|
()t/\\/\\1
|
2021-09-23
|
|
WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF)
|
4 |
WEB
|
0xB9
|
2021-09-23
|
|
WordPress Plugin Advanced Order Export For WooCommerce 3.1.7 - Reflected Cross-Site Scripting (XSS)
|
4 |
WEB
|
0xB9
|
2021-09-23
|
|
Backdrop CMS 1.20.0 - 'Multiple' Cross-Site Request Forgery (CSRF)
|
4 |
WEB
|
V1n1v131r4
|
2021-09-23
|
|
Wordpress Plugin 3DPrint Lite 1.9.1.4 - Arbitrary File Upload
|
4 |
WEB
|
spacehen
|
2021-09-23
|
|
Gurock Testrail 7.2.0.3014 - 'files.md5' Improper Access Control
|
4 |
WEB
|
Sick Codes
|
2021-09-22
|
|
Online Reviewer System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
4 |
WEB
|
Abdullah Khawaja
|
2021-09-22
|
|
Sentry 8.2.0 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
Mohin Paramasivam
|
2021-09-22
|
|
Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)
|
4 |
WEB
|
Akıner Kısa
|
2021-09-22
|
|
OpenCats 0.9.4-2 - 'docx ' XML External Entity Injection (XXE)
|
5 |
WEB
|
Jake Ruston
|
2021-09-22
|
|
e107 CMS 2.3.0 - Remote Code Execution (RCE) (Authenticated)
|
5 |
WEB
|
Halit AKAYDIN
|
2021-09-22
|
|
Filerun 2021.03.26 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
syntegris information solutions GmbH
|
2021-09-22
|
|
Simple Attendance System 1.0 - Unauthenticated Blind SQLi
|
5 |
WEB
|
()t/\\/\\1
|
2021-09-21
|
|
WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)
|
7 |
WEB
|
Halit AKAYDIN
|
2021-09-21
|
|
Budget and Expense Tracker System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
3 |
WEB
|
Abdullah Khawaja
|
2021-09-20
|
|
Budget and Expense Tracker System 1.0 - Authenticated Bypass
|
5 |
WEB
|
Prunier Charles-Yves
|
2021-09-20
|
|
Church Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
5 |
WEB
|
Abdullah Khawaja
|
2021-09-20
|
|
Online Food Ordering System 2.0 - Remote Code Execution (RCE) (Unauthenticated)
|
5 |
WEB
|
Abdullah Khawaja
|
2021-09-20
|
|
WordPress 5.7 - 'Media Library' XML External Entity Injection (XXE) (Authenticated)
|
5 |
WEB
|
David Utón
|
2021-09-20
|
|
Church Management System 1.0 - 'search' SQL Injection (Unauthenticated)
|
5 |
WEB
|
Erwin Krazek
|
2021-09-20
|
|
T-Soft E-Commerce 4 - change 'admin credentials' Cross-Site Request Forgery (CSRF)
|
4 |
WEB
|
Alperen Ergel
|
2021-09-17
|
|
Simple Attendance System 1.0 - Authenticated bypass
|
5 |
WEB
|
Abdullah Khawaja
|
2021-09-17
|
|
Library Management System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
|
4 |
WEB
|
boku
|
2021-09-17
|
|
WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass
|
4 |
WEB
|
0xB455
|
2021-09-16
|
|
ImpressCMS 1.4.2 - Remote Code Execution (RCE) (Authenticated)
|
3 |
WEB
|
Halit AKAYDIN
|
2021-09-15
|
|
AlphaWeb XE - File Upload Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
Ricardo Ruiz
|
2021-09-15
|
|
Evolution CMS 3.1.6 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
Halit AKAYDIN
|
2021-09-15
|
|
Seowon 130-SLC router - 'queriesCnt' Remote Code Execution (Unauthenticated)
|
6 |
WEB
|
Aryan Chehreghani
|
2021-09-15
|
|
Support Board 3.3.3 - 'Multiple' SQL Injection (Unauthenticated)
|
7 |
WEB
|
John Jefferson Li
|
2021-09-14
|
|
Purchase Order Management System 1.0 - Remote File Upload
|
3 |
WEB
|
Aryan Chehreghani
|
2021-09-13
|
|
Apartment Visitor Management System (AVMS) 1.0 - 'username' SQL Injection
|
3 |
WEB
|
mari0x00
|
2021-09-13
|
|
Wordpress Plugin Download From Files 1.48 - Arbitrary File Upload
|
6 |
WEB
|
spacehen
|
2021-09-13
|
|
ECOA Building Automation System - Arbitrary File Deletion
|
5 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Local File Disclosure
|
5 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Remote Privilege Escalation
|
3 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Configuration Download Information Disclosure
|
5 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Cookie Poisoning Authentication Bypass
|
4 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - 'multiple' Cross-Site Request Forgery (CSRF)
|
5 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Directory Traversal Content Disclosure
|
5 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Path Traversal Arbitrary File Upload
|
5 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Weak Default Credentials
|
4 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
Men Salon Management System 1.0 - Multiple Vulnerabilities
|
3 |
WEB
|
Aryan Chehreghani
|
2021-09-09
|
|
Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Emre Aslan
|
2021-09-08
|
|
WordPress Plugin TablePress 1.14 - CSV Injection
|
6 |
WEB
|
Nikhil Kapoor
|
2021-09-07
|
|
WordPress Plugin Survey & Poll 1.5.7.3 - 'sss_params' SQL Injection (2)
|
3 |
WEB
|
Mohin Paramasivam
|
2021-09-07
|
|
WordPress Plugin WP Sitemap Page 1.6.4 - Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Nikhil Kapoor
|
2021-09-06
|
|
Antminer Monitor 0.5.0 - Authentication Bypass
|
4 |
WEB
|
Vulnz
|
2021-09-06
|
|
Patient Appointment Scheduler System 1.0 - Persistent Cross-Site Scripting
|
5 |
WEB
|
a-rey
|
2021-09-06
|
|
Patient Appointment Scheduler System 1.0 - Unauthenticated File Upload
|
5 |
WEB
|
a-rey
|
2021-09-06
|
|
Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
|
4 |
WEB
|
sudoninja
|
2021-09-06
|
|
FlatCore CMS 2.0.7 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
Mason Soroka-Gill
|
2021-09-06
|
|
OpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR)
|
3 |
WEB
|
Allen Enosh Upputori
|
2021-09-03
|
|
OpenSIS 8.0 'modname' - Directory Traversal
|
5 |
WEB
|
Eric Salario
|
2021-09-02
|
|
WordPress Plugin Duplicate Page 4.4.1 - Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Nikhil Kapoor
|
2021-09-02
|
|
WPanel 4.3.1 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
Sentinal920
|
2021-09-02
|
|
Compro Technology IP Camera - ' mjpegStreamer.cgi' Screenshot Disclosure
|
4 |
WEB
|
icekam
|
2021-09-02
|
|
Compro Technology IP Camera - ' index_MJpeg.cgi' Stream Disclosure
|
5 |
WEB
|
icekam
|
2021-09-02
|
|
Compro Technology IP Camera - 'Multiple' Credential Disclosure
|
5 |
WEB
|
icekam
|
2021-09-02
|
|
Compro Technology IP Camera - RTSP stream disclosure (Unauthenticated)
|
5 |
WEB
|
icekam
|
2021-09-02
|
|
Compro Technology IP Camera - 'killps.cgi' Denial of Service (DoS)
|
4 |
WEB
|
icekam
|
2021-09-02
|
|
OpenSIS Community 8.0 - 'cp_id_miss_attn' SQL Injection
|
4 |
WEB
|
Eric Salario
|
2021-09-02
|
|
Dolibarr ERP 14.0.1 - Privilege Escalation
|
5 |
WEB
|
Vishwaraj Bhattrai
|
2021-09-01
|
|
WordPress Plugin Payments Plugin | GetPaid 2.4.6 - HTML Injection
|
5 |
WEB
|
Niraj Mahajan
|
2021-09-01
|
|
Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
5 |
WEB
|
Tagoletta
|
2021-09-01
|
|
Confluence Server 7.12.4 - 'OGNL injection' Remote Code Execution (RCE) (Unauthenticated)
|
4 |
WEB
|
Fellipe Oliveira
|
2021-08-31
|
|
WordPress Plugin ProfilePress 3.1.3 - Privilege Escalation (Unauthenticated)
|
5 |
WEB
|
Numan Rajkotiya
|
2021-08-31
|
|
Umbraco CMS 8.9.1 - Directory Traversal
|
3 |
WEB
|
BitTheByte
|
2021-08-30
|
|
Projectsend r1295 - 'name' Stored XSS
|
4 |
WEB
|
Abdullah Kala
|
2021-08-30
|
|
Strapi CMS 3.0.0-beta.17.4 - Remote Code Execution (RCE) (Unauthenticated)
|
6 |
WEB
|
Musyoka Ian
|
2021-08-30
|
|
Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated)
|
6 |
WEB
|
David Utón
|
2021-08-30
|
|
Strapi 3.0.0-beta - Set Password (Unauthenticated)
|
4 |
WEB
|
David Anglada
|
2021-08-30
|
|
Bus Pass Management System 1.0 - 'viewid' SQL Injection
|
4 |
WEB
|
Aryan Chehreghani
|
2021-08-30
|
|
Usermin 1.820 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
numan türle
|
2021-08-30
|
|
ZesleCP 3.1.9 - Remote Code Execution (RCE) (Authenticated)
|
5 |
WEB
|
numan türle
|
2021-08-27
|
|
COMMAX UMS Client ActiveX Control 1.7.0.2 - 'CNC_Ctrl.dll' Heap Buffer Overflow
|
2 |
WEB
|
LiquidWorm
|
2021-08-27
|
|
COMMAX WebViewer ActiveX Control 2.1.4.5 - 'Commax_WebViewer.ocx' Buffer Overflow
|
3 |
WEB
|
LiquidWorm
|
2021-08-27
|
|
CyberPanel 2.1 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
numan türle
|
2021-08-26
|
|
ProcessMaker 3.5.4 - Local File inclusion
|
2 |
WEB
|
Ai Ho
|
2021-08-25
|
|
Online Leave Management System 1.0 - Arbitrary File Upload to Shell (Unauthenticated)
|
3 |
WEB
|
Justin White
|
2021-08-25
|
|
HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Tyler Butler
|
2021-08-25
|
|
WordPress Plugin Mail Masta 1.0 - Local File Inclusion (2)
|
3 |
WEB
|
Matheus Alexandre
|
2021-08-23
|
|
RaspAP 2.6.6 - Remote Code Execution (RCE) (Authenticated)
|
3 |
WEB
|
Moritz Gruber
|
2021-08-23
|
|
Simple Phone Book 1.0 - 'Username' SQL Injection (Unauthenticated)
|
3 |
WEB
|
Justin White
|
2021-08-23
|
|
Online Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
3 |
WEB
|
Halit AKAYDIN
|
2021-08-20
|
|
Laundry Booking Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Azumah Foresight Xorlali
|
2021-08-20
|
|
Laundry Booking Management System 1.0 - 'Multiple' SQL Injection
|
2 |
WEB
|
Azumah Foresight Xorlali
|
2021-08-20
|
|
Online Traffic Offense Management System 1.0 - 'id' SQL Injection (Authenticated)
|
4 |
WEB
|
Justin White
|
2021-08-19
|
|
Charity Management System CMS 1.0 - Multiple Vulnerabilities
|
5 |
WEB
|
Davide Taraschi
|
2021-08-18
|
|
COVID19 Testing Management System 1.0 - 'Multiple' SQL Injections
|
4 |
WEB
|
Halit AKAYDIN
|
2021-08-18
|
|
Simple Image Gallery 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
4 |
WEB
|
Tagoletta
|
2021-08-18
|
|
Crime records Management System 1.0 - 'Multiple' SQL Injection (Authenticated)
|
4 |
WEB
|
Davide Taraschi
|
2021-08-17
|
|
GeoVision Geowebserver 5.3.3 - Local FIle Inclusion
|
3 |
WEB
|
Ken Pyle
|
2021-08-16
|
|
COMMAX CVD-Axx DVR 5.1.4 - Weak Default Credentials Stream Disclosure
|
4 |
WEB
|
LiquidWorm
|
2021-08-16
|
|
COMMAX Smart Home Ruvie CCTV Bridge DVR Service - Config Write / DoS (Unauthenticated)
|
5 |
WEB
|
LiquidWorm
|
2021-08-16
|
|
COMMAX Smart Home Ruvie CCTV Bridge DVR Service - RTSP Credentials Disclosure
|
4 |
WEB
|
LiquidWorm
|
2021-08-16
|
|
COMMAX Smart Home IoT Control System CDP-1020n - SQL Injection Authentication Bypass
|
3 |
WEB
|
LiquidWorm
|
2021-08-16
|
|
COMMAX Biometric Access Control System 1.0.0 - Authentication Bypass
|
4 |
WEB
|
LiquidWorm
|
2021-08-16
|
|
Simple Water Refilling Station Management System 1.0 - Remote Code Execution (RCE) through File Uplo
|
4 |
WEB
|
Matt Sorrell
|
2021-08-16
|
|
Simple Water Refilling Station Management System 1.0 - Authentication Bypass
|
4 |
WEB
|
Matt Sorrell
|
2021-08-16
|
|
NetGear D1500 V1.0.0.21_1.0.1PE - 'Wireless Repeater' Stored Cross-Site Scripting (XSS)
|
3 |
WEB
|
Securityium
|
2021-08-16
|
|
CentOS Web Panel 0.9.8.1081 - Stored Cross-Site Scripting (XSS)
|
3 |
WEB
|
Dinesh Mohanty
|
2021-08-13
|
|
RATES SYSTEM 1.0 - Authentication Bypass
|
3 |
WEB
|
Azumah Foresight Xorlali
|
2021-08-13
|
|
Simple Image Gallery System 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Azumah Foresight Xorlali
|
2021-08-13
|
|
Care2x Open Source Hospital Information Management 2.7 Alpha - 'Multiple' Stored XSS
|
2 |
WEB
|
securityforeveryone.com
|
2021-08-13
|
|
Police Crime Record Management System 1.0 - 'casedetails' SQL Injection
|
3 |
WEB
|
Ömer Hasan Durmuş
|
2021-08-13
|
|
Police Crime Record Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
3 |
WEB
|
Ömer Hasan Durmuş
|
2021-08-13
|
|
easy-mock 1.6.0 - Remote Code Execution (RCE) (Authenticated)
|
5 |
WEB
|
LionTree
|
2021-08-13
|
|
4images 1.8 - 'limitnumber' SQL Injection (Authenticated)
|
4 |
WEB
|
Andrey Stoykov
|
2021-08-12
|
|
RATES SYSTEM 1.0 - 'Multiple' SQL Injections
|
4 |
WEB
|
Halit AKAYDIN
|
2021-08-12
|
|
Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)
|
4 |
WEB
|
RedTeam Pentesting GmbH
|
2021-08-12
|
|
COVID19 Testing Management System 1.0 - 'searchdata' SQL Injection
|
5 |
WEB
|
Ashish Upsham
|