|
2021-10-06
|
|
Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)
|
12 |
WEB
|
Lucas Souza
|
|
2021-10-06
|
|
Wordpress Plugin BulletProof Security 5.1 - Sensitive Information Disclosure
|
12 |
WEB
|
Ron Jost
|
|
2021-10-06
|
|
Odine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection
|
9 |
WEB
|
Emel Basayar
|
|
2021-10-06
|
|
Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read
|
11 |
WEB
|
Mayank Deshmukh
|
|
2021-10-05
|
|
Wordpress Plugin MStore API 2.0.6 - Arbitrary File Upload
|
12 |
WEB
|
spacehen
|
|
2021-10-05
|
|
Wordpress Plugin TheCartPress 1.5.3.6 - Privilege Escalation (Unauthenticated)
|
17 |
WEB
|
spacehen
|
|
2021-10-05
|
|
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
|
10 |
WEB
|
Mayank Deshmukh
|
|
2021-10-05
|
|
Student Quarterly Grading System 1.0 - SQLi Authentication Bypass
|
8 |
WEB
|
Blackhan
|
|
2021-10-04
|
|
Young Entrepreneur E-Negosyo System 1.0 - 'PRODESC' Stored Cross-Site Scripting (XSS)
|
9 |
WEB
|
Jordan Glover
|
|
2021-10-04
|
|
Young Entrepreneur E-Negosyo System 1.0 - SQL Injection Authentication Bypass
|
10 |
WEB
|
Jordan Glover
|
|
2021-10-04
|
|
Open Game Panel - Remote Code Execution (RCE) (Authenticated)
|
11 |
WEB
|
prey
|
|
2021-10-04
|
|
Lodging Reservation Management System 1.0 - Authentication Bypass
|
14 |
WEB
|
Nitin Sharma
|
|
2021-10-04
|
|
Payara Micro Community 5.2021.6 - Directory Traversal
|
16 |
WEB
|
Yasser Khan
|
|
2021-10-01
|
|
Directory Management System 1.0 - SQL Injection Authentication Bypass
|
16 |
WEB
|
Sanjay Singh
|
|
2021-10-01
|
|
CMSimple_XH 1.7.4 - Remote Code Execution (RCE) (Authenticated)
|
13 |
WEB
|
Halit AKAYDIN
|
|
2021-10-01
|
|
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
|
9 |
WEB
|
Andreas Finstad
|
|
2021-10-01
|
|
Dairy Farm Shop Management System 1.0 - SQL Injection Authentication Bypass
|
10 |
WEB
|
Sanjay Singh
|
|
2021-10-01
|
|
Vehicle Service Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
16 |
WEB
|
Ghuliev
|
|
2021-10-01
|
|
Phpwcms 1.9.30 - Arbitrary File Upload
|
12 |
WEB
|
Okan Kurtulus
|
|
2021-10-01
|
|
Blood Bank System 1.0 - Authentication Bypass
|
12 |
WEB
|
Nitin Sharma
|
|
2021-10-01
|
|
Drupal Module MiniorangeSAML 8.x-2.22 - Privilege escalation
|
12 |
WEB
|
Cristian \'void\' Giustini
|
|
2021-10-01
|
|
Exam Form Submission System 1.0 - SQL Injection Authentication Bypass
|
11 |
WEB
|
Nitin Sharma
|
|
2021-09-30
|
|
Pharmacy Point of Sale System 1.0 - 'Multiple' SQL Injection (SQLi)
|
12 |
WEB
|
Murat
|
|
2021-09-30
|
|
Cmsimple 5.4 - Remote Code Execution (RCE) (Authenticated)
|
14 |
WEB
|
pussycat0x
|
|
2021-09-30
|
|
Cyber Cafe Management System Project (CCMS) 1.0 - SQL Injection Authentication Bypass
|
15 |
WEB
|
Sanjay Singh
|
|
2021-09-29
|
|
Pet Shop Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
18 |
WEB
|
Mr.Gedik
|
|
2021-09-29
|
|
OpenSIS 8.0 - 'cp_id_miss_attn' Reflected Cross-Site Scripting (XSS)
|
13 |
WEB
|
Eric Salario
|
|
2021-09-29
|
|
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
|
13 |
WEB
|
0xB9
|
|
2021-09-29
|
|
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
|
13 |
WEB
|
0xB9
|
|
2021-09-29
|
|
Storage Unit Rental Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
15 |
WEB
|
Ghuliev
|
|
2021-09-28
|
|
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
|
14 |
WEB
|
0xB9
|
|
2021-09-28
|
|
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
|
13 |
WEB
|
0xB9
|
|
2021-09-28
|
|
WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
|
15 |
WEB
|
0xB9
|
|
2021-09-28
|
|
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
16 |
WEB
|
Nosa Shandy
|
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Remote Privilege Escalation
|
12 |
WEB
|
LiquidWorm
|
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Hidden Backdoor Account (Write Access)
|
10 |
WEB
|
LiquidWorm
|
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Config Download (Unauthenticated)
|
13 |
WEB
|
LiquidWorm
|
|
2021-09-28
|
|
FatPipe Networks WARP 10.2.2 - Authorization Bypass
|
12 |
WEB
|
LiquidWorm
|
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - 'Add Admin' Cross-Site Request Forgery (CSRF)
|
11 |
WEB
|
LiquidWorm
|
|
2021-09-27
|
|
Library System 1.0 - 'student_id' SQL injection (Authenticated)
|
12 |
WEB
|
Vinay Bhuria
|
|
2021-09-27
|
|
WordPress Plugin Wappointment 2.2.4 - Stored Cross-Site Scripting (XSS)
|
14 |
WEB
|
Renos Nikolaou
|
|
2021-09-24
|
|
Pharmacy Point of Sale System 1.0 - SQLi Authentication BYpass
|
10 |
WEB
|
Janik Wehrli
|
|
2021-09-24
|
|
SmarterTools SmarterTrack 7922 - 'Multiple' Information Disclosure
|
10 |
WEB
|
Andrei Manole
|
|
2021-09-23
|
|
Police Crime Record Management Project 1.0 - Time Based SQLi
|
12 |
WEB
|
()t/\\/\\1
|
|
2021-09-23
|
|
Budget and Expense Tracker System 1.0 - Arbitrary File Upload
|
12 |
WEB
|
()t/\\/\\1
|
|
2021-09-23
|
|
WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF)
|
11 |
WEB
|
0xB9
|
|
2021-09-23
|
|
WordPress Plugin Advanced Order Export For WooCommerce 3.1.7 - Reflected Cross-Site Scripting (XSS)
|
11 |
WEB
|
0xB9
|
|
2021-09-23
|
|
Backdrop CMS 1.20.0 - 'Multiple' Cross-Site Request Forgery (CSRF)
|
11 |
WEB
|
V1n1v131r4
|
|
2021-09-23
|
|
Wordpress Plugin 3DPrint Lite 1.9.1.4 - Arbitrary File Upload
|
14 |
WEB
|
spacehen
|
|
2021-09-23
|
|
Gurock Testrail 7.2.0.3014 - 'files.md5' Improper Access Control
|
12 |
WEB
|
Sick Codes
|
|
2021-09-22
|
|
Online Reviewer System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
18 |
WEB
|
Abdullah Khawaja
|
|
2021-09-22
|
|
Sentry 8.2.0 - Remote Code Execution (RCE) (Authenticated)
|
11 |
WEB
|
Mohin Paramasivam
|
|
2021-09-22
|
|
Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)
|
9 |
WEB
|
Akıner Kısa
|
|
2021-09-22
|
|
OpenCats 0.9.4-2 - 'docx ' XML External Entity Injection (XXE)
|
14 |
WEB
|
Jake Ruston
|
|
2021-09-22
|
|
e107 CMS 2.3.0 - Remote Code Execution (RCE) (Authenticated)
|
18 |
WEB
|
Halit AKAYDIN
|
|
2021-09-22
|
|
Filerun 2021.03.26 - Remote Code Execution (RCE) (Authenticated)
|
11 |
WEB
|
syntegris information solutions GmbH
|
|
2021-09-22
|
|
Simple Attendance System 1.0 - Unauthenticated Blind SQLi
|
13 |
WEB
|
()t/\\/\\1
|
|
2021-09-21
|
|
WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)
|
14 |
WEB
|
Halit AKAYDIN
|
|
2021-09-21
|
|
Budget and Expense Tracker System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
12 |
WEB
|
Abdullah Khawaja
|
|
2021-09-20
|
|
Budget and Expense Tracker System 1.0 - Authenticated Bypass
|
12 |
WEB
|
Prunier Charles-Yves
|
|
2021-09-20
|
|
Church Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
15 |
WEB
|
Abdullah Khawaja
|
|
2021-09-20
|
|
Online Food Ordering System 2.0 - Remote Code Execution (RCE) (Unauthenticated)
|
17 |
WEB
|
Abdullah Khawaja
|
|
2021-09-20
|
|
WordPress 5.7 - 'Media Library' XML External Entity Injection (XXE) (Authenticated)
|
10 |
WEB
|
David Utón
|
|
2021-09-20
|
|
Church Management System 1.0 - 'search' SQL Injection (Unauthenticated)
|
12 |
WEB
|
Erwin Krazek
|
|
2021-09-20
|
|
T-Soft E-Commerce 4 - change 'admin credentials' Cross-Site Request Forgery (CSRF)
|
10 |
WEB
|
Alperen Ergel
|
|
2021-09-17
|
|
Simple Attendance System 1.0 - Authenticated bypass
|
11 |
WEB
|
Abdullah Khawaja
|
|
2021-09-17
|
|
Library Management System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
|
10 |
WEB
|
boku
|
|
2021-09-17
|
|
WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass
|
11 |
WEB
|
0xB455
|
|
2021-09-16
|
|
ImpressCMS 1.4.2 - Remote Code Execution (RCE) (Authenticated)
|
9 |
WEB
|
Halit AKAYDIN
|
|
2021-09-15
|
|
AlphaWeb XE - File Upload Remote Code Execution (RCE) (Authenticated)
|
11 |
WEB
|
Ricardo Ruiz
|
|
2021-09-15
|
|
Evolution CMS 3.1.6 - Remote Code Execution (RCE) (Authenticated)
|
11 |
WEB
|
Halit AKAYDIN
|
|
2021-09-15
|
|
Seowon 130-SLC router - 'queriesCnt' Remote Code Execution (Unauthenticated)
|
20 |
WEB
|
Aryan Chehreghani
|
|
2021-09-15
|
|
Support Board 3.3.3 - 'Multiple' SQL Injection (Unauthenticated)
|
13 |
WEB
|
John Jefferson Li
|
|
2021-09-14
|
|
Purchase Order Management System 1.0 - Remote File Upload
|
12 |
WEB
|
Aryan Chehreghani
|
|
2021-09-13
|
|
Apartment Visitor Management System (AVMS) 1.0 - 'username' SQL Injection
|
10 |
WEB
|
mari0x00
|
|
2021-09-13
|
|
Wordpress Plugin Download From Files 1.48 - Arbitrary File Upload
|
15 |
WEB
|
spacehen
|
|
2021-09-13
|
|
ECOA Building Automation System - Arbitrary File Deletion
|
11 |
WEB
|
Neurogenesia
|
|
2021-09-13
|
|
ECOA Building Automation System - Local File Disclosure
|
12 |
WEB
|
Neurogenesia
|
|
2021-09-13
|
|
ECOA Building Automation System - Remote Privilege Escalation
|
10 |
WEB
|
Neurogenesia
|
|
2021-09-13
|
|
ECOA Building Automation System - Configuration Download Information Disclosure
|
12 |
WEB
|
Neurogenesia
|
|
2021-09-13
|
|
ECOA Building Automation System - Cookie Poisoning Authentication Bypass
|
9 |
WEB
|
Neurogenesia
|
|
2021-09-13
|
|
ECOA Building Automation System - 'multiple' Cross-Site Request Forgery (CSRF)
|
13 |
WEB
|
Neurogenesia
|
|
2021-09-13
|
|
ECOA Building Automation System - Directory Traversal Content Disclosure
|
10 |
WEB
|
Neurogenesia
|
|
2021-09-13
|
|
ECOA Building Automation System - Path Traversal Arbitrary File Upload
|
11 |
WEB
|
Neurogenesia
|
|
2021-09-13
|
|
ECOA Building Automation System - Weak Default Credentials
|
10 |
WEB
|
Neurogenesia
|
|
2021-09-13
|
|
Men Salon Management System 1.0 - Multiple Vulnerabilities
|
11 |
WEB
|
Aryan Chehreghani
|
|
2021-09-09
|
|
Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
|
12 |
WEB
|
Emre Aslan
|
|
2021-09-08
|
|
WordPress Plugin TablePress 1.14 - CSV Injection
|
18 |
WEB
|
Nikhil Kapoor
|
|
2021-09-07
|
|
WordPress Plugin Survey & Poll 1.5.7.3 - 'sss_params' SQL Injection (2)
|
10 |
WEB
|
Mohin Paramasivam
|
|
2021-09-07
|
|
WordPress Plugin WP Sitemap Page 1.6.4 - Stored Cross-Site Scripting (XSS)
|
14 |
WEB
|
Nikhil Kapoor
|
|
2021-09-06
|
|
Antminer Monitor 0.5.0 - Authentication Bypass
|
12 |
WEB
|
Vulnz
|
|
2021-09-06
|
|
Patient Appointment Scheduler System 1.0 - Persistent Cross-Site Scripting
|
12 |
WEB
|
a-rey
|
|
2021-09-06
|
|
Patient Appointment Scheduler System 1.0 - Unauthenticated File Upload
|
21 |
WEB
|
a-rey
|
|
2021-09-06
|
|
Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
|
11 |
WEB
|
sudoninja
|
|
2021-09-06
|
|
FlatCore CMS 2.0.7 - Remote Code Execution (RCE) (Authenticated)
|
10 |
WEB
|
Mason Soroka-Gill
|
|
2021-09-06
|
|
OpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR)
|
11 |
WEB
|
Allen Enosh Upputori
|
|
2021-09-03
|
|
OpenSIS 8.0 'modname' - Directory Traversal
|
11 |
WEB
|
Eric Salario
|
|
2021-09-02
|
|
WordPress Plugin Duplicate Page 4.4.1 - Stored Cross-Site Scripting (XSS)
|
14 |
WEB
|
Nikhil Kapoor
|
|
2021-09-02
|
|
WPanel 4.3.1 - Remote Code Execution (RCE) (Authenticated)
|
9 |
WEB
|
Sentinal920
|
|
2021-09-02
|
|
Compro Technology IP Camera - ' mjpegStreamer.cgi' Screenshot Disclosure
|
10 |
WEB
|
icekam
|
|
2021-09-02
|
|
Compro Technology IP Camera - ' index_MJpeg.cgi' Stream Disclosure
|
17 |
WEB
|
icekam
|
|
2021-09-02
|
|
Compro Technology IP Camera - 'Multiple' Credential Disclosure
|
9 |
WEB
|
icekam
|
|
2021-09-02
|
|
Compro Technology IP Camera - RTSP stream disclosure (Unauthenticated)
|
11 |
WEB
|
icekam
|
|
2021-09-02
|
|
Compro Technology IP Camera - 'killps.cgi' Denial of Service (DoS)
|
10 |
WEB
|
icekam
|
|
2021-09-02
|
|
OpenSIS Community 8.0 - 'cp_id_miss_attn' SQL Injection
|
12 |
WEB
|
Eric Salario
|
|
2021-09-02
|
|
Dolibarr ERP 14.0.1 - Privilege Escalation
|
13 |
WEB
|
Vishwaraj Bhattrai
|
|
2021-09-01
|
|
WordPress Plugin Payments Plugin | GetPaid 2.4.6 - HTML Injection
|
15 |
WEB
|
Niraj Mahajan
|
|
2021-09-01
|
|
Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
14 |
WEB
|
Tagoletta
|
|
2021-09-01
|
|
Confluence Server 7.12.4 - 'OGNL injection' Remote Code Execution (RCE) (Unauthenticated)
|
14 |
WEB
|
Fellipe Oliveira
|
|
2021-08-31
|
|
WordPress Plugin ProfilePress 3.1.3 - Privilege Escalation (Unauthenticated)
|
18 |
WEB
|
Numan Rajkotiya
|
|
2021-08-31
|
|
Umbraco CMS 8.9.1 - Directory Traversal
|
9 |
WEB
|
BitTheByte
|
|
2021-08-30
|
|
Projectsend r1295 - 'name' Stored XSS
|
10 |
WEB
|
Abdullah Kala
|
|
2021-08-30
|
|
Strapi CMS 3.0.0-beta.17.4 - Remote Code Execution (RCE) (Unauthenticated)
|
18 |
WEB
|
Musyoka Ian
|
|
2021-08-30
|
|
Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated)
|
13 |
WEB
|
David Utón
|
|
2021-08-30
|
|
Strapi 3.0.0-beta - Set Password (Unauthenticated)
|
15 |
WEB
|
David Anglada
|
|
2021-08-30
|
|
Bus Pass Management System 1.0 - 'viewid' SQL Injection
|
11 |
WEB
|
Aryan Chehreghani
|
|
2021-08-30
|
|
Usermin 1.820 - Remote Code Execution (RCE) (Authenticated)
|
11 |
WEB
|
numan türle
|
|
2021-08-30
|
|
ZesleCP 3.1.9 - Remote Code Execution (RCE) (Authenticated)
|
12 |
WEB
|
numan türle
|
|
2021-08-27
|
|
COMMAX UMS Client ActiveX Control 1.7.0.2 - 'CNC_Ctrl.dll' Heap Buffer Overflow
|
8 |
WEB
|
LiquidWorm
|
|
2021-08-27
|
|
COMMAX WebViewer ActiveX Control 2.1.4.5 - 'Commax_WebViewer.ocx' Buffer Overflow
|
8 |
WEB
|
LiquidWorm
|
|
2021-08-27
|
|
CyberPanel 2.1 - Remote Code Execution (RCE) (Authenticated)
|
9 |
WEB
|
numan türle
|
|
2021-08-26
|
|
ProcessMaker 3.5.4 - Local File inclusion
|
8 |
WEB
|
Ai Ho
|
|
2021-08-25
|
|
Online Leave Management System 1.0 - Arbitrary File Upload to Shell (Unauthenticated)
|
14 |
WEB
|
Justin White
|
|
2021-08-25
|
|
HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS)
|
10 |
WEB
|
Tyler Butler
|
|
2021-08-25
|
|
WordPress Plugin Mail Masta 1.0 - Local File Inclusion (2)
|
9 |
WEB
|
Matheus Alexandre
|