|
2021-11-03
|
|
OpenAM 13.0 - LDAP Injection
|
24 |
WEB
|
Charlton Trezevant
|
|
2021-11-03
|
|
WordPress Plugin Popup Anything 2.0.3 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
34 |
WEB
|
Luca Schembri
|
|
2021-11-03
|
|
Eclipse Jetty 11.0.5 - Sensitive File Disclosure
|
40 |
WEB
|
Mayank Deshmukh
|
|
2021-11-03
|
|
Fuel CMS 1.4.1 - Remote Code Execution (3)
|
24 |
WEB
|
Padsala Trushal
|
|
2021-11-03
|
|
WordPress Plugin Hotel Listing 3 - 'Multiple' Cross-Site Scripting (XSS)
|
27 |
WEB
|
Vulnerability-Lab
|
|
2021-11-03
|
|
PHPJabbers Simple CMS 5 - 'name' Persistent Cross-Site Scripting (XSS)
|
32 |
WEB
|
Vulnerability-Lab
|
|
2021-11-02
|
|
Codiad 2.8.4 - Remote Code Execution (Authenticated) (4)
|
26 |
WEB
|
P4p4_M4n3
|
|
2021-11-02
|
|
i3 International Annexxus Cameras Ax-n 5.2.0 - Application Logic Flaw
|
25 |
WEB
|
LiquidWorm
|
|
2021-11-02
|
|
Ericsson Network Location MPS GMPC21 - Privilege Escalation (Metasploit)
|
44 |
WEB
|
AkkuS
|
|
2021-11-02
|
|
Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit)
|
39 |
WEB
|
AkkuS
|
|
2021-11-02
|
|
Employee Record Management System 1.2 - 'empid' SQL injection (Unauthenticated)
|
26 |
WEB
|
Anubhav Singh
|
|
2021-10-29
|
|
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
|
26 |
WEB
|
Charl-Alexandre Le Brun
|
|
2021-10-29
|
|
WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS)
|
30 |
WEB
|
3ndG4me
|
|
2021-10-29
|
|
Umbraco v8.14.1 - 'baseUrl' SSRF
|
22 |
WEB
|
NgoAnhDuc
|
|
2021-10-28
|
|
PHPGurukul Hostel Management System 2.1 - Cross-site request forgery (CSRF) to Cross-site Scripting
|
29 |
WEB
|
Anubhav Singh
|
|
2021-10-28
|
|
WordPress Plugin Supsystic Contact Form 1.7.18 - 'label' Stored Cross-Site Scripting (XSS)
|
32 |
WEB
|
Murat DEMİRCİ
|
|
2021-10-26
|
|
WordPress Plugin Filterable Portfolio Gallery 1.0 - 'title' Stored Cross-Site Scripting (XSS)
|
31 |
WEB
|
Murat DEMİRCİ
|
|
2021-10-25
|
|
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
|
37 |
WEB
|
samguy
|
|
2021-10-25
|
|
Wordpress 4.9.6 - Arbitrary File Deletion (Authenticated) (2)
|
34 |
WEB
|
samguy
|
|
2021-10-25
|
|
WordPress Plugin Ninja Tables 4.1.7 - Stored Cross-Site Scripting (XSS)
|
48 |
WEB
|
Akash Patil
|
|
2021-10-25
|
|
WordPress Plugin Media-Tags 3.2.0.2 - Stored Cross-Site Scripting (XSS)
|
36 |
WEB
|
Akash Patil
|
|
2021-10-25
|
|
Engineers Online Portal 1.0 - 'id' SQL Injection
|
35 |
WEB
|
Alon Leviev
|
|
2021-10-25
|
|
Engineers Online Portal 1.0 - 'multiple' Authentication Bypass
|
35 |
WEB
|
Alon Leviev
|
|
2021-10-25
|
|
Engineers Online Portal 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
|
32 |
WEB
|
Alon Leviev
|
|
2021-10-25
|
|
Online Event Booking and Reservation System 1.0 - 'reason' Stored Cross-Site Scripting (XSS)
|
28 |
WEB
|
Alon Leviev
|
|
2021-10-25
|
|
Balbooa Joomla Forms Builder 2.0.6 - SQL Injection (Unauthenticated)
|
30 |
WEB
|
blockomat2100
|
|
2021-10-25
|
|
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
|
25 |
WEB
|
ThelastVvV
|
|
2021-10-25
|
|
Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)
|
28 |
WEB
|
Nehru Sethuraman
|
|
2021-10-25
|
|
Engineers Online Portal 1.0 - File Upload Remote Code Execution (RCE)
|
24 |
WEB
|
SadKris
|
|
2021-10-25
|
|
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
26 |
WEB
|
Akash Patil
|
|
2021-10-25
|
|
Hikvision Web Server Build 210702 - Command Injection
|
31 |
WEB
|
bashis
|
|
2021-10-22
|
|
Online Course Registration 1.0 - Blind Boolean-Based SQL Injection (Authenticated)
|
37 |
WEB
|
Sam Ferguson
|
|
2021-10-22
|
|
Clinic Management System 1.0 - SQL injection to Remote Code Execution
|
25 |
WEB
|
Pablo Santiago
|
|
2021-10-22
|
|
Jetty 9.4.37.v20210219 - Information Disclosure
|
31 |
WEB
|
Mayank Deshmukh
|
|
2021-10-21
|
|
Easy Chat Server 3.1 - Directory Traversal and Arbitrary File Read
|
26 |
WEB
|
z4nd3r
|
|
2021-10-21
|
|
Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS)
|
25 |
WEB
|
Ghuliev
|
|
2021-10-20
|
|
Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
|
29 |
WEB
|
Oscar Gil Gutierrez
|
|
2021-10-20
|
|
SonicWall SMA 10.2.1.0-17sv - Password Reset
|
30 |
WEB
|
Jacob Baines
|
|
2021-10-19
|
|
Online Motorcycle (Bike) Rental System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
|
30 |
WEB
|
Chase Comardelle
|
|
2021-10-19
|
|
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
|
23 |
WEB
|
RedTeam Pentesting GmbH
|
|
2021-10-19
|
|
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
|
24 |
WEB
|
David Álvarez Robles
|
|
2021-10-18
|
|
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
|
25 |
WEB
|
Basavaraj Banakar
|
|
2021-10-18
|
|
Company's Recruitment Management System 1.0 - 'Add New user' Cross-Site Request Forgery (CSRF)
|
27 |
WEB
|
Aniket Deshmane
|
|
2021-10-18
|
|
Company's Recruitment Management System 1.0 - 'description' Stored Cross-Site Scripting (XSS)
|
29 |
WEB
|
Aniket Deshmane
|
|
2021-10-18
|
|
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
|
25 |
WEB
|
Hamit CİBO
|
|
2021-10-18
|
|
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
|
27 |
WEB
|
Hamit CİBO
|
|
2021-10-18
|
|
Company's Recruitment Management System 1.0. - 'title' Stored Cross-Site Scripting (XSS)
|
35 |
WEB
|
Aniket Deshmane
|
|
2021-10-18
|
|
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
|
40 |
WEB
|
nam3lum
|
|
2021-10-18
|
|
Support Board 3.3.4 - 'Message' Stored Cross-Site Scripting (XSS)
|
29 |
WEB
|
John Jefferson Li
|
|
2021-10-15
|
|
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
|
24 |
WEB
|
Forster Chiu
|
|
2021-10-14
|
|
TextPattern CMS 4.8.7 - Remote Command Execution (RCE) (Authenticated)
|
27 |
WEB
|
Mert Daş
|
|
2021-10-13
|
|
Sonicwall SonicOS 7.0 - Host Header Injection
|
35 |
WEB
|
Ramikan
|
|
2021-10-13
|
|
Logitech Media Server 8.2.0 - 'Title' Cross-Site Scripting (XSS)
|
35 |
WEB
|
Mert Daş
|
|
2021-10-13
|
|
Student Quarterly Grading System 1.0 - 'grade' Stored Cross-Site Scripting (XSS)
|
42 |
WEB
|
Hüseyin Serkan Balkanli
|
|
2021-10-13
|
|
Simple Issue Tracker System 1.0 - SQLi Authentication Bypass
|
33 |
WEB
|
Bekir Bugra TURKOGLU
|
|
2021-10-13
|
|
Online Learning System 2.0 - 'Multiple' SQLi Authentication Bypass
|
31 |
WEB
|
Blackhan
|
|
2021-10-13
|
|
Pharmacy Point of Sale System 1.0 - 'Add New User' Cross-Site Request Forgery (CSRF)
|
26 |
WEB
|
Murat DEMİRCİ
|
|
2021-10-13
|
|
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
|
31 |
WEB
|
Lucas Souza
|
|
2021-10-13
|
|
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
|
23 |
WEB
|
Mayank Deshmukh
|
|
2021-10-13
|
|
Company's Recruitment Management System 1.0 - 'Multiple' SQL Injection (Unauthenticated)
|
29 |
WEB
|
Yash Mahajan
|
|
2021-10-13
|
|
Simple Payroll System 1.0 - SQLi Authentication Bypass
|
28 |
WEB
|
Yash Mahajan
|
|
2021-10-08
|
|
Loan Management System 1.0 - SQLi Authentication Bypass
|
29 |
WEB
|
Merve Oral
|
|
2021-10-08
|
|
Online Employees Work From Home Attendance System 1.0 - SQLi Authentication Bypass
|
31 |
WEB
|
Merve Oral
|
|
2021-10-08
|
|
Online Enrollment Management System 1.0 - Authentication Bypass
|
34 |
WEB
|
Amine ismail
|
|
2021-10-08
|
|
Simple Online College Entrance Exam System 1.0 - 'Multiple' SQL injection
|
37 |
WEB
|
Amine ismail
|
|
2021-10-08
|
|
Simple Online College Entrance Exam System 1.0 - Account Takeover
|
28 |
WEB
|
Amine ismail
|
|
2021-10-08
|
|
Simple Online College Entrance Exam System 1.0 - Unauthenticated Admin Creation
|
36 |
WEB
|
Amine ismail
|
|
2021-10-08
|
|
WordPress Plugin Pie Register 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)
|
30 |
WEB
|
Lotfi13-DZ
|
|
2021-10-08
|
|
Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)
|
32 |
WEB
|
DreyAnd
|
|
2021-10-08
|
|
django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
|
30 |
WEB
|
Raven Security Associates
|
|
2021-10-08
|
|
Online Traffic Offense Management System 1.0 - Privilage escalation (Unauthenticated)
|
26 |
WEB
|
snup
|
|
2021-10-08
|
|
IFSC Code Finder Project 1.0 - SQL injection (Unauthenticated)
|
31 |
WEB
|
Yash Mahajan
|
|
2021-10-07
|
|
Simple Online College Entrance Exam System 1.0 - SQLi Authentication Bypass
|
28 |
WEB
|
Mevlüt Yılmaz
|
|
2021-10-07
|
|
Online Traffic Offense Management System 1.0 - Multiple RCE (Unauthenticated)
|
26 |
WEB
|
snup
|
|
2021-10-07
|
|
Online Traffic Offense Management System 1.0 - Multiple XSS (Unauthenticated)
|
27 |
WEB
|
snup
|
|
2021-10-07
|
|
Online Traffic Offense Management System 1.0 - Multiple SQL Injection (Unauthenticated)
|
33 |
WEB
|
snup
|
|
2021-10-07
|
|
Online DJ Booking Management System 1.0 - 'Multiple' Blind Cross-Site Scripting
|
24 |
WEB
|
Yash Mahajan
|
|
2021-10-06
|
|
Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)
|
26 |
WEB
|
Lucas Souza
|
|
2021-10-06
|
|
Wordpress Plugin BulletProof Security 5.1 - Sensitive Information Disclosure
|
26 |
WEB
|
Ron Jost
|
|
2021-10-06
|
|
Odine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection
|
23 |
WEB
|
Emel Basayar
|
|
2021-10-06
|
|
Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read
|
23 |
WEB
|
Mayank Deshmukh
|
|
2021-10-05
|
|
Wordpress Plugin MStore API 2.0.6 - Arbitrary File Upload
|
28 |
WEB
|
spacehen
|
|
2021-10-05
|
|
Wordpress Plugin TheCartPress 1.5.3.6 - Privilege Escalation (Unauthenticated)
|
33 |
WEB
|
spacehen
|
|
2021-10-05
|
|
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
|
28 |
WEB
|
Mayank Deshmukh
|
|
2021-10-05
|
|
Student Quarterly Grading System 1.0 - SQLi Authentication Bypass
|
30 |
WEB
|
Blackhan
|
|
2021-10-04
|
|
Young Entrepreneur E-Negosyo System 1.0 - 'PRODESC' Stored Cross-Site Scripting (XSS)
|
29 |
WEB
|
Jordan Glover
|
|
2021-10-04
|
|
Young Entrepreneur E-Negosyo System 1.0 - SQL Injection Authentication Bypass
|
32 |
WEB
|
Jordan Glover
|
|
2021-10-04
|
|
Open Game Panel - Remote Code Execution (RCE) (Authenticated)
|
37 |
WEB
|
prey
|
|
2021-10-04
|
|
Lodging Reservation Management System 1.0 - Authentication Bypass
|
28 |
WEB
|
Nitin Sharma
|
|
2021-10-04
|
|
Payara Micro Community 5.2021.6 - Directory Traversal
|
35 |
WEB
|
Yasser Khan
|
|
2021-10-01
|
|
Directory Management System 1.0 - SQL Injection Authentication Bypass
|
28 |
WEB
|
Sanjay Singh
|
|
2021-10-01
|
|
CMSimple_XH 1.7.4 - Remote Code Execution (RCE) (Authenticated)
|
28 |
WEB
|
Halit AKAYDIN
|
|
2021-10-01
|
|
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
|
25 |
WEB
|
Andreas Finstad
|
|
2021-10-01
|
|
Dairy Farm Shop Management System 1.0 - SQL Injection Authentication Bypass
|
24 |
WEB
|
Sanjay Singh
|
|
2021-10-01
|
|
Vehicle Service Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
34 |
WEB
|
Ghuliev
|
|
2021-10-01
|
|
Phpwcms 1.9.30 - Arbitrary File Upload
|
26 |
WEB
|
Okan Kurtulus
|
|
2021-10-01
|
|
Blood Bank System 1.0 - Authentication Bypass
|
34 |
WEB
|
Nitin Sharma
|
|
2021-10-01
|
|
Drupal Module MiniorangeSAML 8.x-2.22 - Privilege escalation
|
29 |
WEB
|
Cristian \'void\' Giustini
|
|
2021-10-01
|
|
Exam Form Submission System 1.0 - SQL Injection Authentication Bypass
|
30 |
WEB
|
Nitin Sharma
|
|
2021-09-30
|
|
Pharmacy Point of Sale System 1.0 - 'Multiple' SQL Injection (SQLi)
|
32 |
WEB
|
Murat
|
|
2021-09-30
|
|
Cmsimple 5.4 - Remote Code Execution (RCE) (Authenticated)
|
30 |
WEB
|
pussycat0x
|
|
2021-09-30
|
|
Cyber Cafe Management System Project (CCMS) 1.0 - SQL Injection Authentication Bypass
|
30 |
WEB
|
Sanjay Singh
|
|
2021-09-29
|
|
Pet Shop Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
30 |
WEB
|
Mr.Gedik
|
|
2021-09-29
|
|
OpenSIS 8.0 - 'cp_id_miss_attn' Reflected Cross-Site Scripting (XSS)
|
25 |
WEB
|
Eric Salario
|
|
2021-09-29
|
|
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
|
27 |
WEB
|
0xB9
|
|
2021-09-29
|
|
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
|
28 |
WEB
|
0xB9
|
|
2021-09-29
|
|
Storage Unit Rental Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
29 |
WEB
|
Ghuliev
|
|
2021-09-28
|
|
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
|
30 |
WEB
|
0xB9
|
|
2021-09-28
|
|
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
|
24 |
WEB
|
0xB9
|
|
2021-09-28
|
|
WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
|
28 |
WEB
|
0xB9
|
|
2021-09-28
|
|
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
31 |
WEB
|
Nosa Shandy
|
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Remote Privilege Escalation
|
29 |
WEB
|
LiquidWorm
|
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Hidden Backdoor Account (Write Access)
|
24 |
WEB
|
LiquidWorm
|
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Config Download (Unauthenticated)
|
24 |
WEB
|
LiquidWorm
|
|
2021-09-28
|
|
FatPipe Networks WARP 10.2.2 - Authorization Bypass
|
25 |
WEB
|
LiquidWorm
|
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - 'Add Admin' Cross-Site Request Forgery (CSRF)
|
22 |
WEB
|
LiquidWorm
|
|
2021-09-27
|
|
Library System 1.0 - 'student_id' SQL injection (Authenticated)
|
25 |
WEB
|
Vinay Bhuria
|
|
2021-09-27
|
|
WordPress Plugin Wappointment 2.2.4 - Stored Cross-Site Scripting (XSS)
|
26 |
WEB
|
Renos Nikolaou
|
|
2021-09-24
|
|
Pharmacy Point of Sale System 1.0 - SQLi Authentication BYpass
|
23 |
WEB
|
Janik Wehrli
|
|
2021-09-24
|
|
SmarterTools SmarterTrack 7922 - 'Multiple' Information Disclosure
|
23 |
WEB
|
Andrei Manole
|
|
2021-09-23
|
|
Police Crime Record Management Project 1.0 - Time Based SQLi
|
35 |
WEB
|
()t/\\/\\1
|
|
2021-09-23
|
|
Budget and Expense Tracker System 1.0 - Arbitrary File Upload
|
32 |
WEB
|
()t/\\/\\1
|
|
2021-09-23
|
|
WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF)
|
37 |
WEB
|
0xB9
|
|
2021-09-23
|
|
WordPress Plugin Advanced Order Export For WooCommerce 3.1.7 - Reflected Cross-Site Scripting (XSS)
|
28 |
WEB
|
0xB9
|
|
2021-09-23
|
|
Backdrop CMS 1.20.0 - 'Multiple' Cross-Site Request Forgery (CSRF)
|
24 |
WEB
|
V1n1v131r4
|