Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-09-06   FlatCore CMS 2.0.7 - Remote Code Execution (RCE) (Authenticated) 23 WEB Mason Soroka-Gill
2021-09-06   OpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR) 22 WEB Allen Enosh Upputori
2021-09-03   OpenSIS 8.0 'modname' - Directory Traversal 23 WEB Eric Salario
2021-09-02   WordPress Plugin Duplicate Page 4.4.1 - Stored Cross-Site Scripting (XSS) 23 WEB Nikhil Kapoor
2021-09-02   WPanel 4.3.1 - Remote Code Execution (RCE) (Authenticated) 22 WEB Sentinal920
2021-09-02   Compro Technology IP Camera - ' mjpegStreamer.cgi' Screenshot Disclosure 22 WEB icekam
2021-09-02   Compro Technology IP Camera - ' index_MJpeg.cgi' Stream Disclosure 33 WEB icekam
2021-09-02   Compro Technology IP Camera - 'Multiple' Credential Disclosure 27 WEB icekam
2021-09-02   Compro Technology IP Camera - RTSP stream disclosure (Unauthenticated) 22 WEB icekam
2021-09-02   Compro Technology IP Camera - 'killps.cgi' Denial of Service (DoS) 21 WEB icekam
2021-09-02   OpenSIS Community 8.0 - 'cp_id_miss_attn' SQL Injection 27 WEB Eric Salario
2021-09-02   Dolibarr ERP 14.0.1 - Privilege Escalation 22 WEB Vishwaraj Bhattrai
2021-09-01   WordPress Plugin Payments Plugin | GetPaid 2.4.6 - HTML Injection 27 WEB Niraj Mahajan
2021-09-01   Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 23 WEB Tagoletta
2021-09-01   Confluence Server 7.12.4 - 'OGNL injection' Remote Code Execution (RCE) (Unauthenticated) 24 WEB Fellipe Oliveira
2021-08-31   WordPress Plugin ProfilePress 3.1.3 - Privilege Escalation (Unauthenticated) 40 WEB Numan Rajkotiya
2021-08-31   Umbraco CMS 8.9.1 - Directory Traversal 22 WEB BitTheByte
2021-08-30   Projectsend r1295 - 'name' Stored XSS 18 WEB Abdullah Kala
2021-08-30   Strapi CMS 3.0.0-beta.17.4 - Remote Code Execution (RCE) (Unauthenticated) 44 WEB Musyoka Ian
2021-08-30   Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated) 22 WEB David Utón
2021-08-30   Strapi 3.0.0-beta - Set Password (Unauthenticated) 26 WEB David Anglada
2021-08-30   Bus Pass Management System 1.0 - 'viewid' SQL Injection 25 WEB Aryan Chehreghani
2021-08-30   Usermin 1.820 - Remote Code Execution (RCE) (Authenticated) 27 WEB numan türle
2021-08-30   ZesleCP 3.1.9 - Remote Code Execution (RCE) (Authenticated) 22 WEB numan türle
2021-08-27   COMMAX UMS Client ActiveX Control 1.7.0.2 - 'CNC_Ctrl.dll' Heap Buffer Overflow 21 WEB LiquidWorm
2021-08-27   COMMAX WebViewer ActiveX Control 2.1.4.5 - 'Commax_WebViewer.ocx' Buffer Overflow 32 WEB LiquidWorm
2021-08-27   CyberPanel 2.1 - Remote Code Execution (RCE) (Authenticated) 26 WEB numan türle
2021-08-26   ProcessMaker 3.5.4 - Local File inclusion 28 WEB Ai Ho
2021-08-25   Online Leave Management System 1.0 - Arbitrary File Upload to Shell (Unauthenticated) 33 WEB Justin White
2021-08-25   HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS) 25 WEB Tyler Butler
2021-08-25   WordPress Plugin Mail Masta 1.0 - Local File Inclusion (2) 20 WEB Matheus Alexandre
2021-08-23   RaspAP 2.6.6 - Remote Code Execution (RCE) (Authenticated) 22 WEB Moritz Gruber
2021-08-23   Simple Phone Book 1.0 - 'Username' SQL Injection (Unauthenticated) 18 WEB Justin White
2021-08-23   Online Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 26 WEB Halit AKAYDIN
2021-08-20   Laundry Booking Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 25 WEB Azumah Foresight Xorlali
2021-08-20   Laundry Booking Management System 1.0 - 'Multiple' SQL Injection 22 WEB Azumah Foresight Xorlali
2021-08-20   Online Traffic Offense Management System 1.0 - 'id' SQL Injection (Authenticated) 20 WEB Justin White
2021-08-19   Charity Management System CMS 1.0 - Multiple Vulnerabilities 22 WEB Davide Taraschi
2021-08-18   COVID19 Testing Management System 1.0 - 'Multiple' SQL Injections 21 WEB Halit AKAYDIN
2021-08-18   Simple Image Gallery 1.0 - Remote Code Execution (RCE) (Unauthenticated) 25 WEB Tagoletta
2021-08-18   Crime records Management System 1.0 - 'Multiple' SQL Injection (Authenticated) 19 WEB Davide Taraschi
2021-08-17   GeoVision Geowebserver 5.3.3 - Local FIle Inclusion 27 WEB Ken Pyle
2021-08-16   COMMAX CVD-Axx DVR 5.1.4 - Weak Default Credentials Stream Disclosure 21 WEB LiquidWorm
2021-08-16   COMMAX Smart Home Ruvie CCTV Bridge DVR Service - Config Write / DoS (Unauthenticated) 22 WEB LiquidWorm
2021-08-16   COMMAX Smart Home Ruvie CCTV Bridge DVR Service - RTSP Credentials Disclosure 20 WEB LiquidWorm
2021-08-16   COMMAX Smart Home IoT Control System CDP-1020n - SQL Injection Authentication Bypass 19 WEB LiquidWorm
2021-08-16   COMMAX Biometric Access Control System 1.0.0 - Authentication Bypass 23 WEB LiquidWorm
2021-08-16   Simple Water Refilling Station Management System 1.0 - Remote Code Execution (RCE) through File Uplo 22 WEB Matt Sorrell
2021-08-16   Simple Water Refilling Station Management System 1.0 - Authentication Bypass 20 WEB Matt Sorrell
2021-08-16   NetGear D1500 V1.0.0.21_1.0.1PE - 'Wireless Repeater' Stored Cross-Site Scripting (XSS) 25 WEB Securityium
2021-08-16   CentOS Web Panel 0.9.8.1081 - Stored Cross-Site Scripting (XSS) 18 WEB Dinesh Mohanty
2021-08-13   RATES SYSTEM 1.0 - Authentication Bypass 21 WEB Azumah Foresight Xorlali
2021-08-13   Simple Image Gallery System 1.0 - 'id' SQL Injection 19 WEB Azumah Foresight Xorlali
2021-08-13   Care2x Open Source Hospital Information Management 2.7 Alpha - 'Multiple' Stored XSS 19 WEB securityforeveryone.com
2021-08-13   Police Crime Record Management System 1.0 - 'casedetails' SQL Injection 25 WEB Ömer Hasan Durmuş
2021-08-13   Police Crime Record Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 21 WEB Ömer Hasan Durmuş
2021-08-13   easy-mock 1.6.0 - Remote Code Execution (RCE) (Authenticated) 21 WEB LionTree
2021-08-13   4images 1.8 - 'limitnumber' SQL Injection (Authenticated) 18 WEB Andrey Stoykov
2021-08-12   RATES SYSTEM 1.0 - 'Multiple' SQL Injections 22 WEB Halit AKAYDIN
2021-08-12   Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE) 20 WEB RedTeam Pentesting GmbH
2021-08-12   COVID19 Testing Management System 1.0 - 'searchdata' SQL Injection 19 WEB Ashish Upsham
2021-08-10   Simple Library Management System 1.0 - 'rollno' SQL Injection 22 WEB Halit AKAYDIN
2021-08-10   WordPress Plugin Picture Gallery 1.4.2 - 'Edit Content URL' Stored Cross-Site Scripting (XSS) 22 WEB Aryan Chehreghani
2021-08-10   Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection 22 WEB Brian Ombongi
2021-08-10   IPCop 2.1.9 - Remote Code Execution (RCE) (Authenticated) 21 WEB Mücahit Saratar
2021-08-05   GFI Mail Archiver 15.1 - Telerik UI Component Arbitrary File Upload (Unauthenticated) 25 WEB Amin Bohio
2021-08-05   Moodle 3.9 - Remote Code Execution (RCE) (Authenticated) 23 WEB lanz
2021-08-05   CMSuno 1.7 - 'tgo' Stored Cross-Site Scripting (XSS) (Authenticated) 20 WEB splint3rsec
2021-08-04   ApacheOfBiz 17.12.01 - Remote Command Execution (RCE) 23 WEB Adrián Díaz
2021-08-04   Client Management System 1.1 - 'cname' Stored Cross-site scripting (XSS) 27 WEB Mohammad Koochaki
2021-08-04   qdPM 9.2 - Password Exposure (Unauthenticated) 24 WEB Leon Trappett
2021-08-04   qdPM 9.1 - Remote Code Execution (Authenticated) 19 WEB Leon Trappett
2021-08-04   WordPress Plugin WP Customize Login 1.1 - 'Change Logo Title' Stored Cross-Site Scripting (XSS) 19 WEB Aryan Chehreghani
2021-08-03   Hotel Management System 1.0 - Cross-Site Scripting (XSS) Arbitrary File Upload Remote Code Execution 33 WEB Merbin Russel
2021-08-02   Panasonic Sanyo CCTV Network Camera 2.03-0x - Cross-Site Request Forgery (Change Password) 26 WEB LiquidWorm
2021-08-02   Online Hotel Reservation System 1.0 - 'Multiple' Cross-site scripting (XSS) 28 WEB Mohammad Koochaki
2021-08-02   Men Salon Management System 1.0 - SQL Injection Authentication Bypass 27 WEB Akshay Khanna
2021-07-29   Oracle Fatwire 6.3 - Multiple Vulnerabilities 22 WEB J. Francisco Bolivar
2021-07-29   CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF) 20 WEB niebardzo
2021-07-29   Care2x Integrated Hospital Info System 2.7 - 'Multiple' SQL Injection 23 WEB securityforeveryone.com
2021-07-29   IntelliChoice eFORCE Software Suite 2.5.9 - Username Enumeration 24 WEB LiquidWorm
2021-07-29   Longjing Technology BEMS API 1.21 - Remote Arbitrary File Download 24 WEB LiquidWorm
2021-07-29   Denver IP Camera SHO-110 - Unauthenticated Snapshot 24 WEB Ivan Nikolsky
2021-07-28   TripSpark VEO Transportation - Blind SQL Injection 20 WEB Sedric Louissaint
2021-07-28   Event Registration System with QR Code 1.0 - Authentication Bypass 22 WEB Javier Olmedo
2021-07-27   Customer Relationship Management System (CRM) 1.0 - Sql Injection Authentication Bypass 22 WEB Shafique_Wasta
2021-07-27   PHP 7.3.15-3 - 'PHP_SESSION_UPLOAD_PROGRESS' Session Data Injection 21 WEB S1lv3r
2021-07-26   XOS Shop 1.0.9 - 'Multiple' Arbitrary File Deletion (Authenticated) 30 WEB faisalfs10x
2021-07-26   NoteBurner 2.35 - Denial Of Service (DoS) (PoC) 30 WEB stresser
2021-07-26   Elasticsearch ECE 7.13.3 - Anonymous Database Dump 32 WEB Joan Martinez
2021-07-23   Microsoft SharePoint Server 2019 - Remote Code Execution (2) 28 WEB Podalirius
2021-07-23   WordPress Plugin Simple Post 1.1 - 'Text field' Stored Cross-Site Scripting (XSS) 30 WEB Vikas Srivastava
2021-07-23   ElasticSearch 7.13.3 - Memory disclosure 34 WEB r0ny
2021-07-21   CSZ CMS 1.2.9 - 'Multiple' Arbitrary File Deletion 24 WEB faisalfs10x
2021-07-21   KevinLAB BEMS 1.0 - File Path Traversal Information Disclosure (Authenticated) 22 WEB LiquidWorm
2021-07-21   KevinLAB BEMS 1.0 - Authentication Bypass 20 WEB LiquidWorm
2021-07-20   Webmin 1.973 - 'run.cgi' Cross-Site Request Forgery (CSRF) 26 WEB Mesh3l_911
2021-07-20   WordPress Plugin KN Fix Your Title 1.0.1 - 'Separator' Stored Cross-Site Scripting (XSS) 25 WEB Aakash Choudhary
2021-07-19   PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection 22 WEB faisalfs10x
2021-07-19   WordPress Plugin Mimetic Books 0.2.13 - 'Default Publisher ID field' Stored Cross-Site Scripting (XS 19 WEB Vikas Srivastava
2021-07-19   WordPress Plugin LearnPress 3.2.6.8 - Privilege Escalation 23 WEB nhattruong
2021-07-19   WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated) 19 WEB nhattruong
2021-07-16   Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection 22 WEB Metin Yunus Kandemir
2021-07-16   ForgeRock Access Manager 14.6.3 - Remote Code Execution (RCE) (Unauthenticated) 27 WEB Photubias
2021-07-15   WordPress Plugin Popular Posts 5.3.2 - Remote Code Execution (RCE) (Authenticated) 23 WEB Simone Cristofaro
2021-07-15   osCommerce 2.3.4.1 - Remote Code Execution (2) 26 WEB Bryan Leong
2021-07-14   WordPress Plugin Current Book 1.0.1 - 'Book Title' Persistent Cross-Site Scripting 24 WEB Vikas Srivastava
2021-07-14   Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF) 25 WEB Mesh3l_911
2021-07-13   Garbage Collection Management System 1.0 - SQL Injection + Arbitrary File Upload 26 WEB Luca Bernardi
2021-07-13   OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2) 30 WEB Alexandre ZANNI
2021-07-13   Invoice System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 34 WEB Subhadip Nag
2021-07-13   WordPress Plugin WPFront Notification Bar 1.9.1.04012 - Stored Cross-Site Scripting (XSS) 24 WEB Swapnil Subhash Bodekar
2021-07-13   Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS) 19 WEB Central InfoSec
2021-07-13   Apache Tomcat 9.0.0.M1 - Open Redirect 23 WEB Central InfoSec
2021-07-09   Zoo Management System 1.0 - 'Multiple' Persistent Cross-Site-Scripting (XSS) 24 WEB Subhadip Nag
2021-07-09   Church Management System 1.0 - SQL Injection (Authentication Bypass) + Arbitrary File Upload + RCE 24 WEB Eleonora Guardini
2021-07-08   Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (RCE) (Authenticated) 26 WEB Ron Jost
2021-07-08   Online Covid Vaccination Scheduler System 1.0 - Arbitrary File Upload to Remote Code Execution (Unau 20 WEB faisalfs10x
2021-07-08   Wyomind Help Desk 1.3.6 - Remote Code Execution (RCE) 24 WEB Patrik Lantz
2021-07-08   Employee Record Management System 1.2 - Stored Cross-Site Scripting (XSS) 22 WEB Subhadip Nag
2021-07-08   Exam Hall Management System 1.0 - Unrestricted File Upload + RCE (Unauthenticated) 27 WEB Davide \'yth1n\' Bianchin
2021-07-07   WordPress Plugin Plainview Activity Monitor 20161228 - Remote Code Execution (RCE) (Authenticated) ( 23 WEB Beren Kuday GÖRÜN
2021-07-07   Online Covid Vaccination Scheduler System 1.0 - 'username' time-based blind SQL Injection 20 WEB faisalfs10x
2021-07-07   Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2) 30 WEB enox
2021-07-06   WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 - Directory Traversal 23 WEB TheSmuggler