Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-09-28   WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS) 5 WEB 0xB9
2021-09-28   WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS) 5 WEB 0xB9
2021-09-28   WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS) 4 WEB 0xB9
2021-09-28   WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated) 4 WEB Nosa Shandy
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Remote Privilege Escalation 6 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Hidden Backdoor Account (Write Access) 5 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Config Download (Unauthenticated) 5 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP 10.2.2 - Authorization Bypass 5 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - 'Add Admin' Cross-Site Request Forgery (CSRF) 3 WEB LiquidWorm
2021-09-27   Library System 1.0 - 'student_id' SQL injection (Authenticated) 5 WEB Vinay Bhuria
2021-09-27   WordPress Plugin Wappointment 2.2.4 - Stored Cross-Site Scripting (XSS) 5 WEB Renos Nikolaou
2021-09-24   Pharmacy Point of Sale System 1.0 - SQLi Authentication BYpass 4 WEB Janik Wehrli
2021-09-24   SmarterTools SmarterTrack 7922 - 'Multiple' Information Disclosure 5 WEB Andrei Manole
2021-09-23   Police Crime Record Management Project 1.0 - Time Based SQLi 7 WEB ()t/\\/\\1
2021-09-23   Budget and Expense Tracker System 1.0 - Arbitrary File Upload 5 WEB ()t/\\/\\1
2021-09-23   WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF) 4 WEB 0xB9
2021-09-23   WordPress Plugin Advanced Order Export For WooCommerce 3.1.7 - Reflected Cross-Site Scripting (XSS) 4 WEB 0xB9
2021-09-23   Backdrop CMS 1.20.0 - 'Multiple' Cross-Site Request Forgery (CSRF) 4 WEB V1n1v131r4
2021-09-23   Wordpress Plugin 3DPrint Lite 1.9.1.4 - Arbitrary File Upload 4 WEB spacehen
2021-09-23   Gurock Testrail 7.2.0.3014 - 'files.md5' Improper Access Control 4 WEB Sick Codes
2021-09-22   Online Reviewer System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 4 WEB Abdullah Khawaja
2021-09-22   Sentry 8.2.0 - Remote Code Execution (RCE) (Authenticated) 4 WEB Mohin Paramasivam
2021-09-22   Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected) 4 WEB Akıner Kısa
2021-09-22   OpenCats 0.9.4-2 - 'docx ' XML External Entity Injection (XXE) 5 WEB Jake Ruston
2021-09-22   e107 CMS 2.3.0 - Remote Code Execution (RCE) (Authenticated) 5 WEB Halit AKAYDIN
2021-09-22   Filerun 2021.03.26 - Remote Code Execution (RCE) (Authenticated) 4 WEB syntegris information solutions GmbH
2021-09-22   Simple Attendance System 1.0 - Unauthenticated Blind SQLi 5 WEB ()t/\\/\\1
2021-09-21   WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated) 7 WEB Halit AKAYDIN
2021-09-21   Budget and Expense Tracker System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 3 WEB Abdullah Khawaja
2021-09-20   Budget and Expense Tracker System 1.0 - Authenticated Bypass 5 WEB Prunier Charles-Yves
2021-09-20   Church Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 5 WEB Abdullah Khawaja
2021-09-20   Online Food Ordering System 2.0 - Remote Code Execution (RCE) (Unauthenticated) 5 WEB Abdullah Khawaja
2021-09-20   WordPress 5.7 - 'Media Library' XML External Entity Injection (XXE) (Authenticated) 5 WEB David Utón
2021-09-20   Church Management System 1.0 - 'search' SQL Injection (Unauthenticated) 5 WEB Erwin Krazek
2021-09-20   T-Soft E-Commerce 4 - change 'admin credentials' Cross-Site Request Forgery (CSRF) 4 WEB Alperen Ergel
2021-09-17   Simple Attendance System 1.0 - Authenticated bypass 5 WEB Abdullah Khawaja
2021-09-17   Library Management System 1.0 - Blind Time-Based SQL Injection (Unauthenticated) 4 WEB boku
2021-09-17   WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass 4 WEB 0xB455
2021-09-16   ImpressCMS 1.4.2 - Remote Code Execution (RCE) (Authenticated) 3 WEB Halit AKAYDIN
2021-09-15   AlphaWeb XE - File Upload Remote Code Execution (RCE) (Authenticated) 4 WEB Ricardo Ruiz
2021-09-15   Evolution CMS 3.1.6 - Remote Code Execution (RCE) (Authenticated) 4 WEB Halit AKAYDIN
2021-09-15   Seowon 130-SLC router - 'queriesCnt' Remote Code Execution (Unauthenticated) 6 WEB Aryan Chehreghani
2021-09-15   Support Board 3.3.3 - 'Multiple' SQL Injection (Unauthenticated) 7 WEB John Jefferson Li
2021-09-14   Purchase Order Management System 1.0 - Remote File Upload 3 WEB Aryan Chehreghani
2021-09-13   Apartment Visitor Management System (AVMS) 1.0 - 'username' SQL Injection 3 WEB mari0x00
2021-09-13   Wordpress Plugin Download From Files 1.48 - Arbitrary File Upload 6 WEB spacehen
2021-09-13   ECOA Building Automation System - Arbitrary File Deletion 5 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Local File Disclosure 5 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Remote Privilege Escalation 3 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Configuration Download Information Disclosure 5 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Cookie Poisoning Authentication Bypass 4 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - 'multiple' Cross-Site Request Forgery (CSRF) 5 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Directory Traversal Content Disclosure 5 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Path Traversal Arbitrary File Upload 5 WEB Neurogenesia
2021-09-13   ECOA Building Automation System - Weak Default Credentials 4 WEB Neurogenesia
2021-09-13   Men Salon Management System 1.0 - Multiple Vulnerabilities 3 WEB Aryan Chehreghani
2021-09-09   Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS) 4 WEB Emre Aslan
2021-09-08   WordPress Plugin TablePress 1.14 - CSV Injection 6 WEB Nikhil Kapoor
2021-09-07   WordPress Plugin Survey & Poll 1.5.7.3 - 'sss_params' SQL Injection (2) 3 WEB Mohin Paramasivam
2021-09-07   WordPress Plugin WP Sitemap Page 1.6.4 - Stored Cross-Site Scripting (XSS) 4 WEB Nikhil Kapoor
2021-09-06   Antminer Monitor 0.5.0 - Authentication Bypass 4 WEB Vulnz
2021-09-06   Patient Appointment Scheduler System 1.0 - Persistent Cross-Site Scripting 5 WEB a-rey
2021-09-06   Patient Appointment Scheduler System 1.0 - Unauthenticated File Upload 5 WEB a-rey
2021-09-06   Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR) 4 WEB sudoninja
2021-09-06   FlatCore CMS 2.0.7 - Remote Code Execution (RCE) (Authenticated) 4 WEB Mason Soroka-Gill
2021-09-06   OpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR) 3 WEB Allen Enosh Upputori
2021-09-03   OpenSIS 8.0 'modname' - Directory Traversal 5 WEB Eric Salario
2021-09-02   WordPress Plugin Duplicate Page 4.4.1 - Stored Cross-Site Scripting (XSS) 4 WEB Nikhil Kapoor
2021-09-02   WPanel 4.3.1 - Remote Code Execution (RCE) (Authenticated) 4 WEB Sentinal920
2021-09-02   Compro Technology IP Camera - ' mjpegStreamer.cgi' Screenshot Disclosure 4 WEB icekam
2021-09-02   Compro Technology IP Camera - ' index_MJpeg.cgi' Stream Disclosure 5 WEB icekam
2021-09-02   Compro Technology IP Camera - 'Multiple' Credential Disclosure 5 WEB icekam
2021-09-02   Compro Technology IP Camera - RTSP stream disclosure (Unauthenticated) 5 WEB icekam
2021-09-02   Compro Technology IP Camera - 'killps.cgi' Denial of Service (DoS) 4 WEB icekam
2021-09-02   OpenSIS Community 8.0 - 'cp_id_miss_attn' SQL Injection 4 WEB Eric Salario
2021-09-02   Dolibarr ERP 14.0.1 - Privilege Escalation 5 WEB Vishwaraj Bhattrai
2021-09-01   WordPress Plugin Payments Plugin | GetPaid 2.4.6 - HTML Injection 5 WEB Niraj Mahajan
2021-09-01   Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 5 WEB Tagoletta
2021-09-01   Confluence Server 7.12.4 - 'OGNL injection' Remote Code Execution (RCE) (Unauthenticated) 4 WEB Fellipe Oliveira
2021-08-31   WordPress Plugin ProfilePress 3.1.3 - Privilege Escalation (Unauthenticated) 5 WEB Numan Rajkotiya
2021-08-31   Umbraco CMS 8.9.1 - Directory Traversal 3 WEB BitTheByte
2021-08-30   Projectsend r1295 - 'name' Stored XSS 4 WEB Abdullah Kala
2021-08-30   Strapi CMS 3.0.0-beta.17.4 - Remote Code Execution (RCE) (Unauthenticated) 6 WEB Musyoka Ian
2021-08-30   Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated) 6 WEB David Utón
2021-08-30   Strapi 3.0.0-beta - Set Password (Unauthenticated) 4 WEB David Anglada
2021-08-30   Bus Pass Management System 1.0 - 'viewid' SQL Injection 4 WEB Aryan Chehreghani
2021-08-30   Usermin 1.820 - Remote Code Execution (RCE) (Authenticated) 4 WEB numan türle
2021-08-30   ZesleCP 3.1.9 - Remote Code Execution (RCE) (Authenticated) 5 WEB numan türle
2021-08-27   COMMAX UMS Client ActiveX Control 1.7.0.2 - 'CNC_Ctrl.dll' Heap Buffer Overflow 2 WEB LiquidWorm
2021-08-27   COMMAX WebViewer ActiveX Control 2.1.4.5 - 'Commax_WebViewer.ocx' Buffer Overflow 3 WEB LiquidWorm
2021-08-27   CyberPanel 2.1 - Remote Code Execution (RCE) (Authenticated) 4 WEB numan türle
2021-08-26   ProcessMaker 3.5.4 - Local File inclusion 2 WEB Ai Ho
2021-08-25   Online Leave Management System 1.0 - Arbitrary File Upload to Shell (Unauthenticated) 3 WEB Justin White
2021-08-25   HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS) 4 WEB Tyler Butler
2021-08-25   WordPress Plugin Mail Masta 1.0 - Local File Inclusion (2) 3 WEB Matheus Alexandre
2021-08-23   RaspAP 2.6.6 - Remote Code Execution (RCE) (Authenticated) 3 WEB Moritz Gruber
2021-08-23   Simple Phone Book 1.0 - 'Username' SQL Injection (Unauthenticated) 3 WEB Justin White
2021-08-23   Online Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 3 WEB Halit AKAYDIN
2021-08-20   Laundry Booking Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 4 WEB Azumah Foresight Xorlali
2021-08-20   Laundry Booking Management System 1.0 - 'Multiple' SQL Injection 2 WEB Azumah Foresight Xorlali
2021-08-20   Online Traffic Offense Management System 1.0 - 'id' SQL Injection (Authenticated) 4 WEB Justin White
2021-08-19   Charity Management System CMS 1.0 - Multiple Vulnerabilities 5 WEB Davide Taraschi
2021-08-18   COVID19 Testing Management System 1.0 - 'Multiple' SQL Injections 4 WEB Halit AKAYDIN
2021-08-18   Simple Image Gallery 1.0 - Remote Code Execution (RCE) (Unauthenticated) 4 WEB Tagoletta
2021-08-18   Crime records Management System 1.0 - 'Multiple' SQL Injection (Authenticated) 4 WEB Davide Taraschi
2021-08-17   GeoVision Geowebserver 5.3.3 - Local FIle Inclusion 3 WEB Ken Pyle
2021-08-16   COMMAX CVD-Axx DVR 5.1.4 - Weak Default Credentials Stream Disclosure 4 WEB LiquidWorm
2021-08-16   COMMAX Smart Home Ruvie CCTV Bridge DVR Service - Config Write / DoS (Unauthenticated) 5 WEB LiquidWorm
2021-08-16   COMMAX Smart Home Ruvie CCTV Bridge DVR Service - RTSP Credentials Disclosure 4 WEB LiquidWorm
2021-08-16   COMMAX Smart Home IoT Control System CDP-1020n - SQL Injection Authentication Bypass 3 WEB LiquidWorm
2021-08-16   COMMAX Biometric Access Control System 1.0.0 - Authentication Bypass 4 WEB LiquidWorm
2021-08-16   Simple Water Refilling Station Management System 1.0 - Remote Code Execution (RCE) through File Uplo 4 WEB Matt Sorrell
2021-08-16   Simple Water Refilling Station Management System 1.0 - Authentication Bypass 4 WEB Matt Sorrell
2021-08-16   NetGear D1500 V1.0.0.21_1.0.1PE - 'Wireless Repeater' Stored Cross-Site Scripting (XSS) 3 WEB Securityium
2021-08-16   CentOS Web Panel 0.9.8.1081 - Stored Cross-Site Scripting (XSS) 3 WEB Dinesh Mohanty
2021-08-13   RATES SYSTEM 1.0 - Authentication Bypass 3 WEB Azumah Foresight Xorlali
2021-08-13   Simple Image Gallery System 1.0 - 'id' SQL Injection 2 WEB Azumah Foresight Xorlali
2021-08-13   Care2x Open Source Hospital Information Management 2.7 Alpha - 'Multiple' Stored XSS 2 WEB securityforeveryone.com
2021-08-13   Police Crime Record Management System 1.0 - 'casedetails' SQL Injection 3 WEB Ömer Hasan Durmuş
2021-08-13   Police Crime Record Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 3 WEB Ömer Hasan Durmuş
2021-08-13   easy-mock 1.6.0 - Remote Code Execution (RCE) (Authenticated) 5 WEB LionTree
2021-08-13   4images 1.8 - 'limitnumber' SQL Injection (Authenticated) 4 WEB Andrey Stoykov
2021-08-12   RATES SYSTEM 1.0 - 'Multiple' SQL Injections 4 WEB Halit AKAYDIN
2021-08-12   Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE) 4 WEB RedTeam Pentesting GmbH
2021-08-12   COVID19 Testing Management System 1.0 - 'searchdata' SQL Injection 5 WEB Ashish Upsham