Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-11-03   OpenAM 13.0 - LDAP Injection 24 WEB Charlton Trezevant
2021-11-03   WordPress Plugin Popup Anything 2.0.3 - 'Multiple' Stored Cross-Site Scripting (XSS) 34 WEB Luca Schembri
2021-11-03   Eclipse Jetty 11.0.5 - Sensitive File Disclosure 40 WEB Mayank Deshmukh
2021-11-03   Fuel CMS 1.4.1 - Remote Code Execution (3) 24 WEB Padsala Trushal
2021-11-03   WordPress Plugin Hotel Listing 3 - 'Multiple' Cross-Site Scripting (XSS) 27 WEB Vulnerability-Lab
2021-11-03   PHPJabbers Simple CMS 5 - 'name' Persistent Cross-Site Scripting (XSS) 32 WEB Vulnerability-Lab
2021-11-02   Codiad 2.8.4 - Remote Code Execution (Authenticated) (4) 26 WEB P4p4_M4n3
2021-11-02   i3 International Annexxus Cameras Ax-n 5.2.0 - Application Logic Flaw 25 WEB LiquidWorm
2021-11-02   Ericsson Network Location MPS GMPC21 - Privilege Escalation (Metasploit) 44 WEB AkkuS
2021-11-02   Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit) 39 WEB AkkuS
2021-11-02   Employee Record Management System 1.2 - 'empid' SQL injection (Unauthenticated) 26 WEB Anubhav Singh
2021-10-29   Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit) 26 WEB Charl-Alexandre Le Brun
2021-10-29   WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS) 30 WEB 3ndG4me
2021-10-29   Umbraco v8.14.1 - 'baseUrl' SSRF 22 WEB NgoAnhDuc
2021-10-28   PHPGurukul Hostel Management System 2.1 - Cross-site request forgery (CSRF) to Cross-site Scripting 29 WEB Anubhav Singh
2021-10-28   WordPress Plugin Supsystic Contact Form 1.7.18 - 'label' Stored Cross-Site Scripting (XSS) 32 WEB Murat DEMİRCİ
2021-10-26   WordPress Plugin Filterable Portfolio Gallery 1.0 - 'title' Stored Cross-Site Scripting (XSS) 31 WEB Murat DEMİRCİ
2021-10-25   phpMyAdmin 4.8.1 - Remote Code Execution (RCE) 37 WEB samguy
2021-10-25   Wordpress 4.9.6 - Arbitrary File Deletion (Authenticated) (2) 34 WEB samguy
2021-10-25   WordPress Plugin Ninja Tables 4.1.7 - Stored Cross-Site Scripting (XSS) 48 WEB Akash Patil
2021-10-25   WordPress Plugin Media-Tags 3.2.0.2 - Stored Cross-Site Scripting (XSS) 36 WEB Akash Patil
2021-10-25   Engineers Online Portal 1.0 - 'id' SQL Injection 35 WEB Alon Leviev
2021-10-25   Engineers Online Portal 1.0 - 'multiple' Authentication Bypass 35 WEB Alon Leviev
2021-10-25   Engineers Online Portal 1.0 - 'multiple' Stored Cross-Site Scripting (XSS) 32 WEB Alon Leviev
2021-10-25   Online Event Booking and Reservation System 1.0 - 'reason' Stored Cross-Site Scripting (XSS) 28 WEB Alon Leviev
2021-10-25   Balbooa Joomla Forms Builder 2.0.6 - SQL Injection (Unauthenticated) 30 WEB blockomat2100
2021-10-25   Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2) 25 WEB ThelastVvV
2021-10-25   Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated) 28 WEB Nehru Sethuraman
2021-10-25   Engineers Online Portal 1.0 - File Upload Remote Code Execution (RCE) 24 WEB SadKris
2021-10-25   WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated) 26 WEB Akash Patil
2021-10-25   Hikvision Web Server Build 210702 - Command Injection 31 WEB bashis
2021-10-22   Online Course Registration 1.0 - Blind Boolean-Based SQL Injection (Authenticated) 37 WEB Sam Ferguson
2021-10-22   Clinic Management System 1.0 - SQL injection to Remote Code Execution 25 WEB Pablo Santiago
2021-10-22   Jetty 9.4.37.v20210219 - Information Disclosure 31 WEB Mayank Deshmukh
2021-10-21   Easy Chat Server 3.1 - Directory Traversal and Arbitrary File Read 26 WEB z4nd3r
2021-10-21   Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS) 25 WEB Ghuliev
2021-10-20   Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation 29 WEB Oscar Gil Gutierrez
2021-10-20   SonicWall SMA 10.2.1.0-17sv - Password Reset 30 WEB Jacob Baines
2021-10-19   Online Motorcycle (Bike) Rental System 1.0 - Blind Time-Based SQL Injection (Unauthenticated) 30 WEB Chase Comardelle
2021-10-19   myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS) 23 WEB RedTeam Pentesting GmbH
2021-10-19   WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS) 24 WEB David Álvarez Robles
2021-10-18   Plastic SCM 10.0.16.5622 - WebAdmin Server Access 25 WEB Basavaraj Banakar
2021-10-18   Company's Recruitment Management System 1.0 - 'Add New user' Cross-Site Request Forgery (CSRF) 27 WEB Aniket Deshmane
2021-10-18   Company's Recruitment Management System 1.0 - 'description' Stored Cross-Site Scripting (XSS) 29 WEB Aniket Deshmane
2021-10-18   Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS) 25 WEB Hamit CİBO
2021-10-18   Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure 27 WEB Hamit CİBO
2021-10-18   Company's Recruitment Management System 1.0. - 'title' Stored Cross-Site Scripting (XSS) 35 WEB Aniket Deshmane
2021-10-18   Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read 40 WEB nam3lum
2021-10-18   Support Board 3.3.4 - 'Message' Stored Cross-Site Scripting (XSS) 29 WEB John Jefferson Li
2021-10-15   i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS) 24 WEB Forster Chiu
2021-10-14   TextPattern CMS 4.8.7 - Remote Command Execution (RCE) (Authenticated) 27 WEB Mert Daş
2021-10-13   Sonicwall SonicOS 7.0 - Host Header Injection 35 WEB Ramikan
2021-10-13   Logitech Media Server 8.2.0 - 'Title' Cross-Site Scripting (XSS) 35 WEB Mert Daş
2021-10-13   Student Quarterly Grading System 1.0 - 'grade' Stored Cross-Site Scripting (XSS) 42 WEB Hüseyin Serkan Balkanli
2021-10-13   Simple Issue Tracker System 1.0 - SQLi Authentication Bypass 33 WEB Bekir Bugra TURKOGLU
2021-10-13   Online Learning System 2.0 - 'Multiple' SQLi Authentication Bypass 31 WEB Blackhan
2021-10-13   Pharmacy Point of Sale System 1.0 - 'Add New User' Cross-Site Request Forgery (CSRF) 26 WEB Murat DEMİRCİ
2021-10-13   Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE) 31 WEB Lucas Souza
2021-10-13   Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated) 23 WEB Mayank Deshmukh
2021-10-13   Company's Recruitment Management System 1.0 - 'Multiple' SQL Injection (Unauthenticated) 29 WEB Yash Mahajan
2021-10-13   Simple Payroll System 1.0 - SQLi Authentication Bypass 28 WEB Yash Mahajan
2021-10-08   Loan Management System 1.0 - SQLi Authentication Bypass 29 WEB Merve Oral
2021-10-08   Online Employees Work From Home Attendance System 1.0 - SQLi Authentication Bypass 31 WEB Merve Oral
2021-10-08   Online Enrollment Management System 1.0 - Authentication Bypass 34 WEB Amine ismail
2021-10-08   Simple Online College Entrance Exam System 1.0 - 'Multiple' SQL injection 37 WEB Amine ismail
2021-10-08   Simple Online College Entrance Exam System 1.0 - Account Takeover 28 WEB Amine ismail
2021-10-08   Simple Online College Entrance Exam System 1.0 - Unauthenticated Admin Creation 36 WEB Amine ismail
2021-10-08   WordPress Plugin Pie Register 3.7.1.4 - Admin Privilege Escalation (Unauthenticated) 30 WEB Lotfi13-DZ
2021-10-08   Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated) 32 WEB DreyAnd
2021-10-08   django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS) 30 WEB Raven Security Associates
2021-10-08   Online Traffic Offense Management System 1.0 - Privilage escalation (Unauthenticated) 26 WEB snup
2021-10-08   IFSC Code Finder Project 1.0 - SQL injection (Unauthenticated) 31 WEB Yash Mahajan
2021-10-07   Simple Online College Entrance Exam System 1.0 - SQLi Authentication Bypass 28 WEB Mevlüt Yılmaz
2021-10-07   Online Traffic Offense Management System 1.0 - Multiple RCE (Unauthenticated) 26 WEB snup
2021-10-07   Online Traffic Offense Management System 1.0 - Multiple XSS (Unauthenticated) 27 WEB snup
2021-10-07   Online Traffic Offense Management System 1.0 - Multiple SQL Injection (Unauthenticated) 33 WEB snup
2021-10-07   Online DJ Booking Management System 1.0 - 'Multiple' Blind Cross-Site Scripting 24 WEB Yash Mahajan
2021-10-06   Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE) 26 WEB Lucas Souza
2021-10-06   Wordpress Plugin BulletProof Security 5.1 - Sensitive Information Disclosure 26 WEB Ron Jost
2021-10-06   Odine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection 23 WEB Emel Basayar
2021-10-06   Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read 23 WEB Mayank Deshmukh
2021-10-05   Wordpress Plugin MStore API 2.0.6 - Arbitrary File Upload 28 WEB spacehen
2021-10-05   Wordpress Plugin TheCartPress 1.5.3.6 - Privilege Escalation (Unauthenticated) 33 WEB spacehen
2021-10-05   Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read 28 WEB Mayank Deshmukh
2021-10-05   Student Quarterly Grading System 1.0 - SQLi Authentication Bypass 30 WEB Blackhan
2021-10-04   Young Entrepreneur E-Negosyo System 1.0 - 'PRODESC' Stored Cross-Site Scripting (XSS) 29 WEB Jordan Glover
2021-10-04   Young Entrepreneur E-Negosyo System 1.0 - SQL Injection Authentication Bypass 32 WEB Jordan Glover
2021-10-04   Open Game Panel - Remote Code Execution (RCE) (Authenticated) 37 WEB prey
2021-10-04   Lodging Reservation Management System 1.0 - Authentication Bypass 28 WEB Nitin Sharma
2021-10-04   Payara Micro Community 5.2021.6 - Directory Traversal 35 WEB Yasser Khan
2021-10-01   Directory Management System 1.0 - SQL Injection Authentication Bypass 28 WEB Sanjay Singh
2021-10-01   CMSimple_XH 1.7.4 - Remote Code Execution (RCE) (Authenticated) 28 WEB Halit AKAYDIN
2021-10-01   WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS) 25 WEB Andreas Finstad
2021-10-01   Dairy Farm Shop Management System 1.0 - SQL Injection Authentication Bypass 24 WEB Sanjay Singh
2021-10-01   Vehicle Service Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 34 WEB Ghuliev
2021-10-01   Phpwcms 1.9.30 - Arbitrary File Upload 26 WEB Okan Kurtulus
2021-10-01   Blood Bank System 1.0 - Authentication Bypass 34 WEB Nitin Sharma
2021-10-01   Drupal Module MiniorangeSAML 8.x-2.22 - Privilege escalation 29 WEB Cristian \'void\' Giustini
2021-10-01   Exam Form Submission System 1.0 - SQL Injection Authentication Bypass 30 WEB Nitin Sharma
2021-09-30   Pharmacy Point of Sale System 1.0 - 'Multiple' SQL Injection (SQLi) 32 WEB Murat
2021-09-30   Cmsimple 5.4 - Remote Code Execution (RCE) (Authenticated) 30 WEB pussycat0x
2021-09-30   Cyber Cafe Management System Project (CCMS) 1.0 - SQL Injection Authentication Bypass 30 WEB Sanjay Singh
2021-09-29   Pet Shop Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 30 WEB Mr.Gedik
2021-09-29   OpenSIS 8.0 - 'cp_id_miss_attn' Reflected Cross-Site Scripting (XSS) 25 WEB Eric Salario
2021-09-29   WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting 27 WEB 0xB9
2021-09-29   WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS) 28 WEB 0xB9
2021-09-29   Storage Unit Rental Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 29 WEB Ghuliev
2021-09-28   WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS) 30 WEB 0xB9
2021-09-28   WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS) 24 WEB 0xB9
2021-09-28   WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS) 28 WEB 0xB9
2021-09-28   WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated) 31 WEB Nosa Shandy
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Remote Privilege Escalation 29 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Hidden Backdoor Account (Write Access) 24 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Config Download (Unauthenticated) 24 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP 10.2.2 - Authorization Bypass 25 WEB LiquidWorm
2021-09-28   FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - 'Add Admin' Cross-Site Request Forgery (CSRF) 22 WEB LiquidWorm
2021-09-27   Library System 1.0 - 'student_id' SQL injection (Authenticated) 25 WEB Vinay Bhuria
2021-09-27   WordPress Plugin Wappointment 2.2.4 - Stored Cross-Site Scripting (XSS) 26 WEB Renos Nikolaou
2021-09-24   Pharmacy Point of Sale System 1.0 - SQLi Authentication BYpass 23 WEB Janik Wehrli
2021-09-24   SmarterTools SmarterTrack 7922 - 'Multiple' Information Disclosure 23 WEB Andrei Manole
2021-09-23   Police Crime Record Management Project 1.0 - Time Based SQLi 35 WEB ()t/\\/\\1
2021-09-23   Budget and Expense Tracker System 1.0 - Arbitrary File Upload 32 WEB ()t/\\/\\1
2021-09-23   WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF) 37 WEB 0xB9
2021-09-23   WordPress Plugin Advanced Order Export For WooCommerce 3.1.7 - Reflected Cross-Site Scripting (XSS) 28 WEB 0xB9
2021-09-23   Backdrop CMS 1.20.0 - 'Multiple' Cross-Site Request Forgery (CSRF) 24 WEB V1n1v131r4