2021-08-10
|
|
Simple Library Management System 1.0 - 'rollno' SQL Injection
|
4 |
WEB
|
Halit AKAYDIN
|
2021-08-10
|
|
WordPress Plugin Picture Gallery 1.4.2 - 'Edit Content URL' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Aryan Chehreghani
|
2021-08-10
|
|
Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection
|
4 |
WEB
|
Brian Ombongi
|
2021-08-10
|
|
IPCop 2.1.9 - Remote Code Execution (RCE) (Authenticated)
|
5 |
WEB
|
Mücahit Saratar
|
2021-08-05
|
|
GFI Mail Archiver 15.1 - Telerik UI Component Arbitrary File Upload (Unauthenticated)
|
4 |
WEB
|
Amin Bohio
|
2021-08-05
|
|
Moodle 3.9 - Remote Code Execution (RCE) (Authenticated)
|
5 |
WEB
|
lanz
|
2021-08-05
|
|
CMSuno 1.7 - 'tgo' Stored Cross-Site Scripting (XSS) (Authenticated)
|
5 |
WEB
|
splint3rsec
|
2021-08-04
|
|
ApacheOfBiz 17.12.01 - Remote Command Execution (RCE)
|
5 |
WEB
|
Adrián Díaz
|
2021-08-04
|
|
Client Management System 1.1 - 'cname' Stored Cross-site scripting (XSS)
|
5 |
WEB
|
Mohammad Koochaki
|
2021-08-04
|
|
qdPM 9.2 - Password Exposure (Unauthenticated)
|
4 |
WEB
|
Leon Trappett
|
2021-08-04
|
|
qdPM 9.1 - Remote Code Execution (Authenticated)
|
4 |
WEB
|
Leon Trappett
|
2021-08-04
|
|
WordPress Plugin WP Customize Login 1.1 - 'Change Logo Title' Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Aryan Chehreghani
|
2021-08-03
|
|
Hotel Management System 1.0 - Cross-Site Scripting (XSS) Arbitrary File Upload Remote Code Execution
|
4 |
WEB
|
Merbin Russel
|
2021-08-02
|
|
Panasonic Sanyo CCTV Network Camera 2.03-0x - Cross-Site Request Forgery (Change Password)
|
5 |
WEB
|
LiquidWorm
|
2021-08-02
|
|
Online Hotel Reservation System 1.0 - 'Multiple' Cross-site scripting (XSS)
|
6 |
WEB
|
Mohammad Koochaki
|
2021-08-02
|
|
Men Salon Management System 1.0 - SQL Injection Authentication Bypass
|
5 |
WEB
|
Akshay Khanna
|
2021-07-29
|
|
Oracle Fatwire 6.3 - Multiple Vulnerabilities
|
5 |
WEB
|
J. Francisco Bolivar
|
2021-07-29
|
|
CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF)
|
5 |
WEB
|
niebardzo
|
2021-07-29
|
|
Care2x Integrated Hospital Info System 2.7 - 'Multiple' SQL Injection
|
4 |
WEB
|
securityforeveryone.com
|
2021-07-29
|
|
IntelliChoice eFORCE Software Suite 2.5.9 - Username Enumeration
|
5 |
WEB
|
LiquidWorm
|
2021-07-29
|
|
Longjing Technology BEMS API 1.21 - Remote Arbitrary File Download
|
4 |
WEB
|
LiquidWorm
|
2021-07-29
|
|
Denver IP Camera SHO-110 - Unauthenticated Snapshot
|
5 |
WEB
|
Ivan Nikolsky
|
2021-07-28
|
|
TripSpark VEO Transportation - Blind SQL Injection
|
4 |
WEB
|
Sedric Louissaint
|
2021-07-28
|
|
Event Registration System with QR Code 1.0 - Authentication Bypass
|
4 |
WEB
|
Javier Olmedo
|
2021-07-27
|
|
Customer Relationship Management System (CRM) 1.0 - Sql Injection Authentication Bypass
|
4 |
WEB
|
Shafique_Wasta
|
2021-07-27
|
|
PHP 7.3.15-3 - 'PHP_SESSION_UPLOAD_PROGRESS' Session Data Injection
|
6 |
WEB
|
S1lv3r
|
2021-07-26
|
|
XOS Shop 1.0.9 - 'Multiple' Arbitrary File Deletion (Authenticated)
|
5 |
WEB
|
faisalfs10x
|
2021-07-26
|
|
NoteBurner 2.35 - Denial Of Service (DoS) (PoC)
|
6 |
WEB
|
stresser
|
2021-07-26
|
|
Elasticsearch ECE 7.13.3 - Anonymous Database Dump
|
5 |
WEB
|
Joan Martinez
|
2021-07-23
|
|
Microsoft SharePoint Server 2019 - Remote Code Execution (2)
|
5 |
WEB
|
Podalirius
|
2021-07-23
|
|
WordPress Plugin Simple Post 1.1 - 'Text field' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Vikas Srivastava
|
2021-07-23
|
|
ElasticSearch 7.13.3 - Memory disclosure
|
4 |
WEB
|
r0ny
|
2021-07-21
|
|
CSZ CMS 1.2.9 - 'Multiple' Arbitrary File Deletion
|
4 |
WEB
|
faisalfs10x
|
2021-07-21
|
|
KevinLAB BEMS 1.0 - File Path Traversal Information Disclosure (Authenticated)
|
4 |
WEB
|
LiquidWorm
|
2021-07-21
|
|
KevinLAB BEMS 1.0 - Authentication Bypass
|
4 |
WEB
|
LiquidWorm
|
2021-07-20
|
|
Webmin 1.973 - 'run.cgi' Cross-Site Request Forgery (CSRF)
|
5 |
WEB
|
Mesh3l_911
|
2021-07-20
|
|
WordPress Plugin KN Fix Your Title 1.0.1 - 'Separator' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Aakash Choudhary
|
2021-07-19
|
|
PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection
|
4 |
WEB
|
faisalfs10x
|
2021-07-19
|
|
WordPress Plugin Mimetic Books 0.2.13 - 'Default Publisher ID field' Stored Cross-Site Scripting (XS
|
3 |
WEB
|
Vikas Srivastava
|
2021-07-19
|
|
WordPress Plugin LearnPress 3.2.6.8 - Privilege Escalation
|
5 |
WEB
|
nhattruong
|
2021-07-19
|
|
WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated)
|
5 |
WEB
|
nhattruong
|
2021-07-16
|
|
Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection
|
2 |
WEB
|
Metin Yunus Kandemir
|
2021-07-16
|
|
ForgeRock Access Manager 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
|
3 |
WEB
|
Photubias
|
2021-07-15
|
|
WordPress Plugin Popular Posts 5.3.2 - Remote Code Execution (RCE) (Authenticated)
|
5 |
WEB
|
Simone Cristofaro
|
2021-07-15
|
|
osCommerce 2.3.4.1 - Remote Code Execution (2)
|
6 |
WEB
|
Bryan Leong
|
2021-07-14
|
|
WordPress Plugin Current Book 1.0.1 - 'Book Title' Persistent Cross-Site Scripting
|
4 |
WEB
|
Vikas Srivastava
|
2021-07-14
|
|
Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)
|
5 |
WEB
|
Mesh3l_911
|
2021-07-13
|
|
Garbage Collection Management System 1.0 - SQL Injection + Arbitrary File Upload
|
3 |
WEB
|
Luca Bernardi
|
2021-07-13
|
|
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2)
|
5 |
WEB
|
Alexandre ZANNI
|
2021-07-13
|
|
Invoice System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Subhadip Nag
|
2021-07-13
|
|
WordPress Plugin WPFront Notification Bar 1.9.1.04012 - Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Swapnil Subhash Bodekar
|
2021-07-13
|
|
Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
|
4 |
WEB
|
Central InfoSec
|
2021-07-13
|
|
Apache Tomcat 9.0.0.M1 - Open Redirect
|
5 |
WEB
|
Central InfoSec
|
2021-07-09
|
|
Zoo Management System 1.0 - 'Multiple' Persistent Cross-Site-Scripting (XSS)
|
4 |
WEB
|
Subhadip Nag
|
2021-07-09
|
|
Church Management System 1.0 - SQL Injection (Authentication Bypass) + Arbitrary File Upload + RCE
|
5 |
WEB
|
Eleonora Guardini
|
2021-07-08
|
|
Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (RCE) (Authenticated)
|
3 |
WEB
|
Ron Jost
|
2021-07-08
|
|
Online Covid Vaccination Scheduler System 1.0 - Arbitrary File Upload to Remote Code Execution (Unau
|
3 |
WEB
|
faisalfs10x
|
2021-07-08
|
|
Wyomind Help Desk 1.3.6 - Remote Code Execution (RCE)
|
5 |
WEB
|
Patrik Lantz
|
2021-07-08
|
|
Employee Record Management System 1.2 - Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Subhadip Nag
|
2021-07-08
|
|
Exam Hall Management System 1.0 - Unrestricted File Upload + RCE (Unauthenticated)
|
3 |
WEB
|
Davide \'yth1n\' Bianchin
|
2021-07-07
|
|
WordPress Plugin Plainview Activity Monitor 20161228 - Remote Code Execution (RCE) (Authenticated) (
|
3 |
WEB
|
Beren Kuday GÖRÜN
|
2021-07-07
|
|
Online Covid Vaccination Scheduler System 1.0 - 'username' time-based blind SQL Injection
|
3 |
WEB
|
faisalfs10x
|
2021-07-07
|
|
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2)
|
4 |
WEB
|
enox
|
2021-07-06
|
|
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 - Directory Traversal
|
3 |
WEB
|
TheSmuggler
|
2021-07-06
|
|
Phone Shop Sales Managements System 1.0 - Arbitrary File Upload
|
4 |
WEB
|
faisalfs10x
|
2021-07-06
|
|
Phone Shop Sales Managements System 1.0 - Authentication Bypass (SQLi)
|
3 |
WEB
|
faisalfs10x
|
2021-07-06
|
|
Visual Tools DVR VX16 4.2.28 - Local Privilege Escalation
|
4 |
WEB
|
Andrea D\'Ubaldo
|
2021-07-06
|
|
Exam Hall Management System 1.0 - Unrestricted File Upload (Unauthenticated)
|
4 |
WEB
|
Thamer Almohammadi
|
2021-07-06
|
|
Billing System Project 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
5 |
WEB
|
Talha DEMİRSOY
|
2021-07-06
|
|
Pallets Werkzeug 0.15.4 - Path Traversal
|
5 |
WEB
|
faisalfs10x
|
2021-07-06
|
|
Black Box Kvm Extender 3.4.31307 - Local File Inclusion
|
4 |
WEB
|
Ferhat Çil
|
2021-07-06
|
|
Netgear DGN2200v1 - Remote Command Execution (RCE) (Unauthenticated)
|
3 |
WEB
|
SivertPL
|
2021-07-06
|
|
Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated)
|
3 |
WEB
|
Andrea D\'Ubaldo
|
2021-07-06
|
|
perfexcrm 1.10 - 'State' Stored Cross-site scripting (XSS)
|
4 |
WEB
|
Alhasan Abbas
|
2021-07-05
|
|
Ricon Industrial Cellular Router S9922XL - Remote Command Execution (RCE)
|
3 |
WEB
|
LiquidWorm
|
2021-07-05
|
|
TextPattern CMS 4.9.0-dev - Remote Command Execution (RCE) (Authenticated)
|
3 |
WEB
|
Mevlüt Akçam
|
2021-07-05
|
|
Simple Client Management System 1.0 - Remote Code Execution (RCE)
|
4 |
WEB
|
Ishan Saha
|
2021-07-05
|
|
Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated)
|
4 |
WEB
|
Ron Jost
|
2021-07-05
|
|
Church Management System 1.0 - 'password' SQL Injection (Authentication Bypass)
|
4 |
WEB
|
Murat DEMİRCİ
|
2021-07-05
|
|
Church Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Murat DEMİRCİ
|
2021-07-05
|
|
Church Management System 1.0 - Arbitrary File Upload (Authenticated)
|
4 |
WEB
|
Murat DEMİRCİ
|
2021-07-05
|
|
Online Birth Certificate System 1.1 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
5 |
WEB
|
Subhadip Nag
|
2021-07-05
|
|
Online Voting System 1.0 - SQLi (Authentication Bypass) + Remote Code Execution (RCE)
|
4 |
WEB
|
Geiseric
|
2021-07-05
|
|
OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) (2)
|
4 |
WEB
|
Alexandre ZANNI
|
2021-07-05
|
|
WordPress Plugin WP Learn Manager 1.1.2 - Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Mohammed Adam
|
2021-07-02
|
|
Garbage Collection Management System 1.0 - SQL Injection (Unauthenticated)
|
4 |
WEB
|
ircashem
|
2021-07-02
|
|
Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated)
|
4 |
WEB
|
Ron Jost
|
2021-07-02
|
|
Wordpress Plugin Modern Events Calendar 5.16.2 - Remote Code Execution (Authenticated)
|
3 |
WEB
|
Ron Jost
|
2021-07-02
|
|
b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF)
|
3 |
WEB
|
Alperen Ergel
|
2021-07-02
|
|
AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS)
|
5 |
WEB
|
Tyler Butler
|
2021-07-02
|
|
Scratch Desktop 3.17 - Remote Code Execution
|
4 |
WEB
|
Stig Magnus Baugstø
|
2021-07-01
|
|
Vianeos OctoPUS 5 - 'login_user' SQLi
|
5 |
WEB
|
Audencia Business SCHOOL Red Team
|
2021-07-01
|
|
Wordpress Plugin XCloner 4.2.12 - Remote Code Execution (Authenticated)
|
5 |
WEB
|
Ron Jost
|
2021-07-01
|
|
Online Voting System 1.0 - Remote Code Execution (Authenticated)
|
3 |
WEB
|
Salman Asad
|
2021-07-01
|
|
Online Voting System 1.0 - Authentication Bypass (SQLi)
|
4 |
WEB
|
Salman Asad
|
2021-06-30
|
|
Doctors Patients Management System 1.0 - SQL Injection (Authentication Bypass)
|
4 |
WEB
|
Murat DEMİRCİ
|
2021-06-30
|
|
Simple Traffic Offense System 1.0 - Stored Cross Site Scripting (XSS)
|
4 |
WEB
|
Barış Yıldızoğlu
|
2021-06-30
|
|
Apache Superset 1.1.0 - Time-Based Account Enumeration
|
3 |
WEB
|
Dolev Farhi
|
2021-06-30
|
|
phpAbook 0.9i - SQL Injection
|
4 |
WEB
|
Alejandro Perez
|
2021-06-28
|
|
Netgear WNAP320 2.0.3 - 'macAddress' Remote Code Execution (RCE) (Unauthenticated)
|
3 |
WEB
|
Bryan Leong
|
2021-06-28
|
|
Atlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
|
2 |
WEB
|
Captain_hook
|
2021-06-28
|
|
WordPress Plugin YOP Polls 6.2.7 - Stored Cross Site Scripting (XSS)
|
4 |
WEB
|
Toby Jackson
|
2021-06-25
|
|
Lightweight facebook-styled blog 1.3 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
|
3 |
WEB
|
Maide Ilkay Aydogdu
|
2021-06-25
|
|
Simple Client Management System 1.0 - 'uemail' SQL Injection (Unauthenticated)
|
5 |
WEB
|
Barış Yıldızoğlu
|
2021-06-25
|
|
Seeddms 5.1.10 - Remote Command Execution (RCE) (Authenticated)
|
4 |
WEB
|
Bryan Leong
|
2021-06-24
|
|
TP-Link TL-WR841N - Command Injection
|
3 |
WEB
|
Koh You Liang
|
2021-06-24
|
|
Adobe ColdFusion 8 - Remote Command Execution (RCE)
|
5 |
WEB
|
Pergyz
|
2021-06-24
|
|
VMware vCenter Server 7.0 - Remote Code Execution (RCE) (Unauthenticated)
|
4 |
WEB
|
CHackA0101
|
2021-06-23
|
|
Simple CRM 3.0 - 'email' SQL injection (Authentication Bypass)
|
3 |
WEB
|
Rinku Kumar
|
2021-06-23
|
|
Online Library Management System 1.0 - Arbitrary File Upload Remote Code Execution (Unauthenticated)
|
3 |
WEB
|
Berk Can Geyikci
|
2021-06-23
|
|
Online Library Management System 1.0 - 'Search' SQL Injection
|
4 |
WEB
|
Berk Can Geyikci
|
2021-06-23
|
|
WordPress Plugin Poll_ Survey_ Questionnaire and Voting system 1.5.2 - 'date_answers' Blind SQL Inje
|
4 |
WEB
|
Toby Jackson
|
2021-06-23
|
|
WordPress Plugin WP Google Maps 8.1.11 - Stored Cross-Site Scripting (XSS)
|
3 |
WEB
|
Mohammed Adam
|
2021-06-22
|
|
Phone Shop Sales Managements System 1.0 - Insecure Direct Object Reference (IDOR)
|
4 |
WEB
|
Pratik Khalane
|
2021-06-22
|
|
Responsive Tourism Website 3.1 - Remote Code Execution (RCE) (Unauthenticated)
|
3 |
WEB
|
Tagoletta
|
2021-06-21
|
|
Customer Relationship Management System (CRM) 1.0 - Remote Code Execution
|
3 |
WEB
|
Ishan Saha
|
2021-06-21
|
|
Simple CRM 3.0 - 'name' Stored Cross site scripting (XSS)
|
4 |
WEB
|
Riadh Benlamine
|
2021-06-21
|
|
Simple CRM 3.0 - 'Change user information' Cross-Site Request Forgery (CSRF)
|
5 |
WEB
|
Riadh Benlamine
|
2021-06-21
|
|
Websvn 2.6.0 - Remote Code Execution (Unauthenticated)
|
3 |
WEB
|
g0ldm45k
|
2021-06-21
|
|
OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated)
|
3 |
WEB
|
Ron Jost
|
2021-06-18
|
|
Node.JS - 'node-serialize' Remote Code Execution (3)
|
5 |
WEB
|
Beren Kuday GÖRÜN
|
2021-06-18
|
|
ICE Hrm 29.0.0.OS - 'xml upload' Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Piyush Patil
|
2021-06-18
|
|
ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Request Forgery (CSRF)
|
4 |
WEB
|
Piyush Patil
|
2021-06-17
|
|
Online Shopping Portal 3.1 - Remote Code Execution (Unauthenticated)
|
3 |
WEB
|
Tagoletta
|
2021-06-17
|
|
Zoho ManageEngine ServiceDesk Plus MSP 9.4 - User Enumeration
|
4 |
WEB
|
Ricardo Ruiz
|