Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-08-23   RaspAP 2.6.6 - Remote Code Execution (RCE) (Authenticated) 8 WEB Moritz Gruber
2021-08-23   Simple Phone Book 1.0 - 'Username' SQL Injection (Unauthenticated) 8 WEB Justin White
2021-08-23   Online Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) 11 WEB Halit AKAYDIN
2021-08-20   Laundry Booking Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 9 WEB Azumah Foresight Xorlali
2021-08-20   Laundry Booking Management System 1.0 - 'Multiple' SQL Injection 9 WEB Azumah Foresight Xorlali
2021-08-20   Online Traffic Offense Management System 1.0 - 'id' SQL Injection (Authenticated) 11 WEB Justin White
2021-08-19   Charity Management System CMS 1.0 - Multiple Vulnerabilities 13 WEB Davide Taraschi
2021-08-18   COVID19 Testing Management System 1.0 - 'Multiple' SQL Injections 12 WEB Halit AKAYDIN
2021-08-18   Simple Image Gallery 1.0 - Remote Code Execution (RCE) (Unauthenticated) 16 WEB Tagoletta
2021-08-18   Crime records Management System 1.0 - 'Multiple' SQL Injection (Authenticated) 11 WEB Davide Taraschi
2021-08-17   GeoVision Geowebserver 5.3.3 - Local FIle Inclusion 11 WEB Ken Pyle
2021-08-16   COMMAX CVD-Axx DVR 5.1.4 - Weak Default Credentials Stream Disclosure 9 WEB LiquidWorm
2021-08-16   COMMAX Smart Home Ruvie CCTV Bridge DVR Service - Config Write / DoS (Unauthenticated) 10 WEB LiquidWorm
2021-08-16   COMMAX Smart Home Ruvie CCTV Bridge DVR Service - RTSP Credentials Disclosure 9 WEB LiquidWorm
2021-08-16   COMMAX Smart Home IoT Control System CDP-1020n - SQL Injection Authentication Bypass 8 WEB LiquidWorm
2021-08-16   COMMAX Biometric Access Control System 1.0.0 - Authentication Bypass 10 WEB LiquidWorm
2021-08-16   Simple Water Refilling Station Management System 1.0 - Remote Code Execution (RCE) through File Uplo 10 WEB Matt Sorrell
2021-08-16   Simple Water Refilling Station Management System 1.0 - Authentication Bypass 10 WEB Matt Sorrell
2021-08-16   NetGear D1500 V1.0.0.21_1.0.1PE - 'Wireless Repeater' Stored Cross-Site Scripting (XSS) 9 WEB Securityium
2021-08-16   CentOS Web Panel 0.9.8.1081 - Stored Cross-Site Scripting (XSS) 9 WEB Dinesh Mohanty
2021-08-13   RATES SYSTEM 1.0 - Authentication Bypass 9 WEB Azumah Foresight Xorlali
2021-08-13   Simple Image Gallery System 1.0 - 'id' SQL Injection 8 WEB Azumah Foresight Xorlali
2021-08-13   Care2x Open Source Hospital Information Management 2.7 Alpha - 'Multiple' Stored XSS 7 WEB securityforeveryone.com
2021-08-13   Police Crime Record Management System 1.0 - 'casedetails' SQL Injection 8 WEB Ömer Hasan Durmuş
2021-08-13   Police Crime Record Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 8 WEB Ömer Hasan Durmuş
2021-08-13   easy-mock 1.6.0 - Remote Code Execution (RCE) (Authenticated) 9 WEB LionTree
2021-08-13   4images 1.8 - 'limitnumber' SQL Injection (Authenticated) 9 WEB Andrey Stoykov
2021-08-12   RATES SYSTEM 1.0 - 'Multiple' SQL Injections 9 WEB Halit AKAYDIN
2021-08-12   Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE) 9 WEB RedTeam Pentesting GmbH
2021-08-12   COVID19 Testing Management System 1.0 - 'searchdata' SQL Injection 12 WEB Ashish Upsham
2021-08-10   Simple Library Management System 1.0 - 'rollno' SQL Injection 13 WEB Halit AKAYDIN
2021-08-10   WordPress Plugin Picture Gallery 1.4.2 - 'Edit Content URL' Stored Cross-Site Scripting (XSS) 9 WEB Aryan Chehreghani
2021-08-10   Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection 11 WEB Brian Ombongi
2021-08-10   IPCop 2.1.9 - Remote Code Execution (RCE) (Authenticated) 12 WEB Mücahit Saratar
2021-08-05   GFI Mail Archiver 15.1 - Telerik UI Component Arbitrary File Upload (Unauthenticated) 15 WEB Amin Bohio
2021-08-05   Moodle 3.9 - Remote Code Execution (RCE) (Authenticated) 9 WEB lanz
2021-08-05   CMSuno 1.7 - 'tgo' Stored Cross-Site Scripting (XSS) (Authenticated) 9 WEB splint3rsec
2021-08-04   ApacheOfBiz 17.12.01 - Remote Command Execution (RCE) 9 WEB Adrián Díaz
2021-08-04   Client Management System 1.1 - 'cname' Stored Cross-site scripting (XSS) 9 WEB Mohammad Koochaki
2021-08-04   qdPM 9.2 - Password Exposure (Unauthenticated) 8 WEB Leon Trappett
2021-08-04   qdPM 9.1 - Remote Code Execution (Authenticated) 9 WEB Leon Trappett
2021-08-04   WordPress Plugin WP Customize Login 1.1 - 'Change Logo Title' Stored Cross-Site Scripting (XSS) 10 WEB Aryan Chehreghani
2021-08-03   Hotel Management System 1.0 - Cross-Site Scripting (XSS) Arbitrary File Upload Remote Code Execution 12 WEB Merbin Russel
2021-08-02   Panasonic Sanyo CCTV Network Camera 2.03-0x - Cross-Site Request Forgery (Change Password) 12 WEB LiquidWorm
2021-08-02   Online Hotel Reservation System 1.0 - 'Multiple' Cross-site scripting (XSS) 15 WEB Mohammad Koochaki
2021-08-02   Men Salon Management System 1.0 - SQL Injection Authentication Bypass 13 WEB Akshay Khanna
2021-07-29   Oracle Fatwire 6.3 - Multiple Vulnerabilities 12 WEB J. Francisco Bolivar
2021-07-29   CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF) 10 WEB niebardzo
2021-07-29   Care2x Integrated Hospital Info System 2.7 - 'Multiple' SQL Injection 10 WEB securityforeveryone.com
2021-07-29   IntelliChoice eFORCE Software Suite 2.5.9 - Username Enumeration 12 WEB LiquidWorm
2021-07-29   Longjing Technology BEMS API 1.21 - Remote Arbitrary File Download 9 WEB LiquidWorm
2021-07-29   Denver IP Camera SHO-110 - Unauthenticated Snapshot 12 WEB Ivan Nikolsky
2021-07-28   TripSpark VEO Transportation - Blind SQL Injection 11 WEB Sedric Louissaint
2021-07-28   Event Registration System with QR Code 1.0 - Authentication Bypass 12 WEB Javier Olmedo
2021-07-27   Customer Relationship Management System (CRM) 1.0 - Sql Injection Authentication Bypass 13 WEB Shafique_Wasta
2021-07-27   PHP 7.3.15-3 - 'PHP_SESSION_UPLOAD_PROGRESS' Session Data Injection 12 WEB S1lv3r
2021-07-26   XOS Shop 1.0.9 - 'Multiple' Arbitrary File Deletion (Authenticated) 13 WEB faisalfs10x
2021-07-26   NoteBurner 2.35 - Denial Of Service (DoS) (PoC) 17 WEB stresser
2021-07-26   Elasticsearch ECE 7.13.3 - Anonymous Database Dump 18 WEB Joan Martinez
2021-07-23   Microsoft SharePoint Server 2019 - Remote Code Execution (2) 14 WEB Podalirius
2021-07-23   WordPress Plugin Simple Post 1.1 - 'Text field' Stored Cross-Site Scripting (XSS) 11 WEB Vikas Srivastava
2021-07-23   ElasticSearch 7.13.3 - Memory disclosure 16 WEB r0ny
2021-07-21   CSZ CMS 1.2.9 - 'Multiple' Arbitrary File Deletion 13 WEB faisalfs10x
2021-07-21   KevinLAB BEMS 1.0 - File Path Traversal Information Disclosure (Authenticated) 14 WEB LiquidWorm
2021-07-21   KevinLAB BEMS 1.0 - Authentication Bypass 13 WEB LiquidWorm
2021-07-20   Webmin 1.973 - 'run.cgi' Cross-Site Request Forgery (CSRF) 13 WEB Mesh3l_911
2021-07-20   WordPress Plugin KN Fix Your Title 1.0.1 - 'Separator' Stored Cross-Site Scripting (XSS) 12 WEB Aakash Choudhary
2021-07-19   PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection 13 WEB faisalfs10x
2021-07-19   WordPress Plugin Mimetic Books 0.2.13 - 'Default Publisher ID field' Stored Cross-Site Scripting (XS 10 WEB Vikas Srivastava
2021-07-19   WordPress Plugin LearnPress 3.2.6.8 - Privilege Escalation 14 WEB nhattruong
2021-07-19   WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated) 11 WEB nhattruong
2021-07-16   Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection 12 WEB Metin Yunus Kandemir
2021-07-16   ForgeRock Access Manager 14.6.3 - Remote Code Execution (RCE) (Unauthenticated) 16 WEB Photubias
2021-07-15   WordPress Plugin Popular Posts 5.3.2 - Remote Code Execution (RCE) (Authenticated) 13 WEB Simone Cristofaro
2021-07-15   osCommerce 2.3.4.1 - Remote Code Execution (2) 17 WEB Bryan Leong
2021-07-14   WordPress Plugin Current Book 1.0.1 - 'Book Title' Persistent Cross-Site Scripting 14 WEB Vikas Srivastava
2021-07-14   Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF) 15 WEB Mesh3l_911
2021-07-13   Garbage Collection Management System 1.0 - SQL Injection + Arbitrary File Upload 13 WEB Luca Bernardi
2021-07-13   OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2) 13 WEB Alexandre ZANNI
2021-07-13   Invoice System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 13 WEB Subhadip Nag
2021-07-13   WordPress Plugin WPFront Notification Bar 1.9.1.04012 - Stored Cross-Site Scripting (XSS) 13 WEB Swapnil Subhash Bodekar
2021-07-13   Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS) 11 WEB Central InfoSec
2021-07-13   Apache Tomcat 9.0.0.M1 - Open Redirect 12 WEB Central InfoSec
2021-07-09   Zoo Management System 1.0 - 'Multiple' Persistent Cross-Site-Scripting (XSS) 12 WEB Subhadip Nag
2021-07-09   Church Management System 1.0 - SQL Injection (Authentication Bypass) + Arbitrary File Upload + RCE 12 WEB Eleonora Guardini
2021-07-08   Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (RCE) (Authenticated) 10 WEB Ron Jost
2021-07-08   Online Covid Vaccination Scheduler System 1.0 - Arbitrary File Upload to Remote Code Execution (Unau 10 WEB faisalfs10x
2021-07-08   Wyomind Help Desk 1.3.6 - Remote Code Execution (RCE) 11 WEB Patrik Lantz
2021-07-08   Employee Record Management System 1.2 - Stored Cross-Site Scripting (XSS) 9 WEB Subhadip Nag
2021-07-08   Exam Hall Management System 1.0 - Unrestricted File Upload + RCE (Unauthenticated) 12 WEB Davide \'yth1n\' Bianchin
2021-07-07   WordPress Plugin Plainview Activity Monitor 20161228 - Remote Code Execution (RCE) (Authenticated) ( 10 WEB Beren Kuday GÖRÜN
2021-07-07   Online Covid Vaccination Scheduler System 1.0 - 'username' time-based blind SQL Injection 9 WEB faisalfs10x
2021-07-07   Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2) 12 WEB enox
2021-07-06   WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 - Directory Traversal 9 WEB TheSmuggler
2021-07-06   Phone Shop Sales Managements System 1.0 - Arbitrary File Upload 12 WEB faisalfs10x
2021-07-06   Phone Shop Sales Managements System 1.0 - Authentication Bypass (SQLi) 9 WEB faisalfs10x
2021-07-06   Visual Tools DVR VX16 4.2.28 - Local Privilege Escalation 10 WEB Andrea D\'Ubaldo
2021-07-06   Exam Hall Management System 1.0 - Unrestricted File Upload (Unauthenticated) 10 WEB Thamer Almohammadi
2021-07-06   Billing System Project 1.0 - Remote Code Execution (RCE) (Unauthenticated) 11 WEB Talha DEMİRSOY
2021-07-06   Pallets Werkzeug 0.15.4 - Path Traversal 11 WEB faisalfs10x
2021-07-06   Black Box Kvm Extender 3.4.31307 - Local File Inclusion 10 WEB Ferhat Çil
2021-07-06   Netgear DGN2200v1 - Remote Command Execution (RCE) (Unauthenticated) 12 WEB SivertPL
2021-07-06   Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated) 9 WEB Andrea D\'Ubaldo
2021-07-06   perfexcrm 1.10 - 'State' Stored Cross-site scripting (XSS) 8 WEB Alhasan Abbas
2021-07-05   Ricon Industrial Cellular Router S9922XL - Remote Command Execution (RCE) 8 WEB LiquidWorm
2021-07-05   TextPattern CMS 4.9.0-dev - Remote Command Execution (RCE) (Authenticated) 7 WEB Mevlüt Akçam
2021-07-05   Simple Client Management System 1.0 - Remote Code Execution (RCE) 9 WEB Ishan Saha
2021-07-05   Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated) 9 WEB Ron Jost
2021-07-05   Church Management System 1.0 - 'password' SQL Injection (Authentication Bypass) 10 WEB Murat DEMİRCİ
2021-07-05   Church Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 11 WEB Murat DEMİRCİ
2021-07-05   Church Management System 1.0 - Arbitrary File Upload (Authenticated) 12 WEB Murat DEMİRCİ
2021-07-05   Online Birth Certificate System 1.1 - 'Multiple' Stored Cross-Site Scripting (XSS) 10 WEB Subhadip Nag
2021-07-05   Online Voting System 1.0 - SQLi (Authentication Bypass) + Remote Code Execution (RCE) 10 WEB Geiseric
2021-07-05   OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) (2) 10 WEB Alexandre ZANNI
2021-07-05   WordPress Plugin WP Learn Manager 1.1.2 - Stored Cross-Site Scripting (XSS) 11 WEB Mohammed Adam
2021-07-02   Garbage Collection Management System 1.0 - SQL Injection (Unauthenticated) 10 WEB ircashem
2021-07-02   Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated) 14 WEB Ron Jost
2021-07-02   Wordpress Plugin Modern Events Calendar 5.16.2 - Remote Code Execution (Authenticated) 9 WEB Ron Jost
2021-07-02   b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF) 11 WEB Alperen Ergel
2021-07-02   AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS) 12 WEB Tyler Butler
2021-07-02   Scratch Desktop 3.17 - Remote Code Execution 11 WEB Stig Magnus Baugstø
2021-07-01   Vianeos OctoPUS 5 - 'login_user' SQLi 11 WEB Audencia Business SCHOOL Red Team
2021-07-01   Wordpress Plugin XCloner 4.2.12 - Remote Code Execution (Authenticated) 12 WEB Ron Jost
2021-07-01   Online Voting System 1.0 - Remote Code Execution (Authenticated) 10 WEB Salman Asad
2021-07-01   Online Voting System 1.0 - Authentication Bypass (SQLi) 10 WEB Salman Asad