Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-07-06   Phone Shop Sales Managements System 1.0 - Arbitrary File Upload 23 WEB faisalfs10x
2021-07-06   Phone Shop Sales Managements System 1.0 - Authentication Bypass (SQLi) 17 WEB faisalfs10x
2021-07-06   Visual Tools DVR VX16 4.2.28 - Local Privilege Escalation 20 WEB Andrea D\'Ubaldo
2021-07-06   Exam Hall Management System 1.0 - Unrestricted File Upload (Unauthenticated) 19 WEB Thamer Almohammadi
2021-07-06   Billing System Project 1.0 - Remote Code Execution (RCE) (Unauthenticated) 27 WEB Talha DEMİRSOY
2021-07-06   Pallets Werkzeug 0.15.4 - Path Traversal 21 WEB faisalfs10x
2021-07-06   Black Box Kvm Extender 3.4.31307 - Local File Inclusion 19 WEB Ferhat Çil
2021-07-06   Netgear DGN2200v1 - Remote Command Execution (RCE) (Unauthenticated) 19 WEB SivertPL
2021-07-06   Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated) 18 WEB Andrea D\'Ubaldo
2021-07-06   perfexcrm 1.10 - 'State' Stored Cross-site scripting (XSS) 19 WEB Alhasan Abbas
2021-07-05   Ricon Industrial Cellular Router S9922XL - Remote Command Execution (RCE) 19 WEB LiquidWorm
2021-07-05   TextPattern CMS 4.9.0-dev - Remote Command Execution (RCE) (Authenticated) 18 WEB Mevlüt Akçam
2021-07-05   Simple Client Management System 1.0 - Remote Code Execution (RCE) 24 WEB Ishan Saha
2021-07-05   Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated) 21 WEB Ron Jost
2021-07-05   Church Management System 1.0 - 'password' SQL Injection (Authentication Bypass) 29 WEB Murat DEMİRCİ
2021-07-05   Church Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 23 WEB Murat DEMİRCİ
2021-07-05   Church Management System 1.0 - Arbitrary File Upload (Authenticated) 26 WEB Murat DEMİRCİ
2021-07-05   Online Birth Certificate System 1.1 - 'Multiple' Stored Cross-Site Scripting (XSS) 26 WEB Subhadip Nag
2021-07-05   Online Voting System 1.0 - SQLi (Authentication Bypass) + Remote Code Execution (RCE) 22 WEB Geiseric
2021-07-05   OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) (2) 22 WEB Alexandre ZANNI
2021-07-05   WordPress Plugin WP Learn Manager 1.1.2 - Stored Cross-Site Scripting (XSS) 25 WEB Mohammed Adam
2021-07-02   Garbage Collection Management System 1.0 - SQL Injection (Unauthenticated) 20 WEB ircashem
2021-07-02   Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated) 23 WEB Ron Jost
2021-07-02   Wordpress Plugin Modern Events Calendar 5.16.2 - Remote Code Execution (Authenticated) 20 WEB Ron Jost
2021-07-02   b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF) 21 WEB Alperen Ergel
2021-07-02   AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS) 21 WEB Tyler Butler
2021-07-02   Scratch Desktop 3.17 - Remote Code Execution 21 WEB Stig Magnus Baugstø
2021-07-01   Vianeos OctoPUS 5 - 'login_user' SQLi 22 WEB Audencia Business SCHOOL Red Team
2021-07-01   Wordpress Plugin XCloner 4.2.12 - Remote Code Execution (Authenticated) 23 WEB Ron Jost
2021-07-01   Online Voting System 1.0 - Remote Code Execution (Authenticated) 25 WEB Salman Asad
2021-07-01   Online Voting System 1.0 - Authentication Bypass (SQLi) 19 WEB Salman Asad
2021-06-30   Doctors Patients Management System 1.0 - SQL Injection (Authentication Bypass) 22 WEB Murat DEMİRCİ
2021-06-30   Simple Traffic Offense System 1.0 - Stored Cross Site Scripting (XSS) 21 WEB Barış Yıldızoğlu
2021-06-30   Apache Superset 1.1.0 - Time-Based Account Enumeration 26 WEB Dolev Farhi
2021-06-30   phpAbook 0.9i - SQL Injection 24 WEB Alejandro Perez
2021-06-28   Netgear WNAP320 2.0.3 - 'macAddress' Remote Code Execution (RCE) (Unauthenticated) 27 WEB Bryan Leong
2021-06-28   Atlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS) 19 WEB Captain_hook
2021-06-28   WordPress Plugin YOP Polls 6.2.7 - Stored Cross Site Scripting (XSS) 26 WEB Toby Jackson
2021-06-25   Lightweight facebook-styled blog 1.3 - Remote Code Execution (RCE) (Authenticated) (Metasploit) 22 WEB Maide Ilkay Aydogdu
2021-06-25   Simple Client Management System 1.0 - 'uemail' SQL Injection (Unauthenticated) 23 WEB Barış Yıldızoğlu
2021-06-25   Seeddms 5.1.10 - Remote Command Execution (RCE) (Authenticated) 24 WEB Bryan Leong
2021-06-24   TP-Link TL-WR841N - Command Injection 22 WEB Koh You Liang
2021-06-24   Adobe ColdFusion 8 - Remote Command Execution (RCE) 29 WEB Pergyz
2021-06-24   VMware vCenter Server 7.0 - Remote Code Execution (RCE) (Unauthenticated) 25 WEB CHackA0101
2021-06-23   Simple CRM 3.0 - 'email' SQL injection (Authentication Bypass) 23 WEB Rinku Kumar
2021-06-23   Online Library Management System 1.0 - Arbitrary File Upload Remote Code Execution (Unauthenticated) 40 WEB Berk Can Geyikci
2021-06-23   Online Library Management System 1.0 - 'Search' SQL Injection 21 WEB Berk Can Geyikci
2021-06-23   WordPress Plugin Poll_ Survey_ Questionnaire and Voting system 1.5.2 - 'date_answers' Blind SQL Inje 24 WEB Toby Jackson
2021-06-23   WordPress Plugin WP Google Maps 8.1.11 - Stored Cross-Site Scripting (XSS) 25 WEB Mohammed Adam
2021-06-22   Phone Shop Sales Managements System 1.0 - Insecure Direct Object Reference (IDOR) 22 WEB Pratik Khalane
2021-06-22   Responsive Tourism Website 3.1 - Remote Code Execution (RCE) (Unauthenticated) 22 WEB Tagoletta
2021-06-21   Customer Relationship Management System (CRM) 1.0 - Remote Code Execution 25 WEB Ishan Saha
2021-06-21   Simple CRM 3.0 - 'name' Stored Cross site scripting (XSS) 23 WEB Riadh Benlamine
2021-06-21   Simple CRM 3.0 - 'Change user information' Cross-Site Request Forgery (CSRF) 25 WEB Riadh Benlamine
2021-06-21   Websvn 2.6.0 - Remote Code Execution (Unauthenticated) 25 WEB g0ldm45k
2021-06-21   OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) 22 WEB Ron Jost
2021-06-18   Node.JS - 'node-serialize' Remote Code Execution (3) 23 WEB Beren Kuday GÖRÜN
2021-06-18   ICE Hrm 29.0.0.OS - 'xml upload' Stored Cross-Site Scripting (XSS) 23 WEB Piyush Patil
2021-06-18   ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Request Forgery (CSRF) 21 WEB Piyush Patil
2021-06-17   Online Shopping Portal 3.1 - Remote Code Execution (Unauthenticated) 24 WEB Tagoletta
2021-06-17   Zoho ManageEngine ServiceDesk Plus MSP 9.4 - User Enumeration 22 WEB Ricardo Ruiz
2021-06-17   Unified Office Total Connect Now 1.0 - 'data' SQL Injection 23 WEB Ajaikumar Nadar
2021-06-16   CKEditor 3 - Server-Side Request Forgery (SSRF) 22 WEB ahmed
2021-06-16   Teachers Record Management System 1.0 - 'email' Stored Cross-site Scripting (XSS) 21 WEB nhattruong
2021-06-16   Teachers Record Management System 1.0 - 'Multiple' SQL Injection (Authenticated) 20 WEB nhattruong
2021-06-16   OpenEMR 5.0.1.3 - Authentication Bypass 32 WEB Ron Jost
2021-06-16   Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting 21 WEB Fatih İLGİN
2021-06-15   Client Management System 1.1 - 'Search' SQL Injection 27 WEB BHAVESH KAUL
2021-06-15   Client Management System 1.1 - 'username' Stored Cross-Site Scripting (XSS) 23 WEB BHAVESH KAUL
2021-06-14   OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) 23 WEB Ron Jost
2021-06-14   TextPattern CMS 4.8.7 - Remote Command Execution (Authenticated) 24 WEB Mert Daş
2021-06-14   Small CRM 3.0 - 'Authentication Bypass' SQL Injection 30 WEB BHAVESH KAUL
2021-06-14   Stock Management System 1.0 - 'user_id' Blind SQL injection (Authenticated) 30 WEB Riadh Benlamine
2021-06-14   COVID19 Testing Management System 1.0 - 'State' Stored Cross-Site-Scripting (XSS) 27 WEB BHAVESH KAUL
2021-06-14   GLPI 9.4.5 - Remote Code Execution (RCE) 22 WEB Brian Peters
2021-06-14   Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure Direct Object References (IDOR) 20 WEB Abdulazeez Alaseeri
2021-06-14   Accela Civic Platform 21.1 - 'successURL' Cross-Site-Scripting (XSS) 19 WEB Abdulazeez Alaseeri
2021-06-11   WoWonder Social Network Platform 3.1 - Authentication Bypass 20 WEB securityforeveryone.com
2021-06-11   Zenario CMS 8.8.52729 - 'cID' SQL injection (Authenticated) 22 WEB Avinash R
2021-06-11   Solar-Log 500 2.8.2 - Unprotected Storage of Credentials 25 WEB Luca.Chiou
2021-06-11   Solar-Log 500 2.8.2 - Incorrect Access Control 20 WEB Luca.Chiou
2021-06-11   Grocery crud 1.6.4 - 'order_by' SQL Injection 26 WEB TonyShavez
2021-06-11   WordPress Plugin Database Backups 1.2.2.6 - 'Database Backup Download' CSRF 30 WEB 0xB9
2021-06-11   OpenEMR 5.0.0 - Remote Code Execution (Authenticated) 35 WEB Ron Jost
2021-06-11   Microsoft SharePoint Server 16.0.10372.20060 - 'GetXmlDataFromDataSource' Server-Side Request Forger 27 WEB Alex Birnberg
2021-06-11   Cerberus FTP Web Service 11 - 'svg' Stored Cross-Site Scripting (XSS) 30 WEB Mohammad Hossein Kaviyany
2021-06-11   Accela Civic Platform 21.1 - 'servProvCode' Cross-Site-Scripting (XSS) 30 WEB Abdulazeez Alaseeri
2021-06-10   TextPattern CMS 4.8.7 - Stored Cross-Site Scripting (XSS) 31 WEB Mert Daş
2021-06-10   Student Result Management System 1.0 - 'class' SQL Injection 30 WEB Riadh Benlamine
2021-06-09   GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2) 34 WEB legend
2021-06-09   WordPress Plugin visitors-app 0.3 - 'user-agent' Stored Cross-Site Scripting (XSS) 23 WEB Mesut Cetin
2021-06-09   OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting 21 WEB Mert Daş
2021-06-09   OpenCart 3.0.3.7 - 'Change Password' Cross-Site Request Forgery (CSRF) 25 WEB Mert Daş
2021-06-09   Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF) 28 WEB Rodolfo Mariano
2021-06-08   WordPress Plugin wpDiscuz 7.0.4 - Remote Code Execution (Unauthenticated) 27 WEB Fellipe Oliveira
2021-06-07   Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated) 33 WEB UnD3sc0n0c1d0
2021-06-07   Grav CMS 1.7.10 - Server-Side Template Injection (SSTI) (Authenticated) 27 WEB enox
2021-06-07   Rocket.Chat 3.12.1 - NoSQL Injection (Unauthenticated) 23 WEB enox
2021-06-07   WordPress Plugin Smart Slider-3 3.5.0.8 - 'name' Stored Cross-Site Scripting (XSS) 26 WEB Hardik Solanki
2021-06-07   OptiLink ONT1GEW GPON 2.1.11_X101 Build 1127.190306 - Remote Code Execution (Authenticated) 24 WEB SecNigma
2021-06-04   Gitlab 13.10.2 - Remote Code Execution (Authenticated) 35 WEB enox
2021-06-04   Monstra CMS 3.0.4 - Remote Code Execution (Authenticated) 26 WEB Ron Jost
2021-06-03   4Images 1.8 - 'redirect' Reflected XSS 26 WEB Piyush Patil
2021-06-03   Gitlab 13.9.3 - Remote Code Execution (Authenticated) 31 WEB enox
2021-06-03   FUDForum 3.1.0 - 'author' Reflected XSS 22 WEB Piyush Patil
2021-06-03   FUDForum 3.1.0 - 'srch' Reflected XSS 26 WEB Piyush Patil
2021-06-03   CHIYU IoT Devices - Denial of Service (DoS) 23 WEB sirpedrotavares
2021-06-03   Seo Panel 4.8.0 - 'from_time' Reflected XSS 25 WEB Piyush Patil
2021-06-03   PHP 8.1.0-dev - 'User-Agentt' Remote Code Execution 22 WEB flast101
2021-06-02   Seo Panel 4.8.0 - 'category' Reflected XSS 21 WEB Piyush Patil
2021-06-02   Seo Panel 4.8.0 - 'search_name' Reflected XSS 24 WEB Piyush Patil
2021-06-02   Products.PluggableAuthService 2.6.0 - Open Redirect 22 WEB Piyush Patil
2021-06-02   GetSimple CMS 3.3.4 - Information Disclosure 28 WEB Ron Jost
2021-06-02   Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution 25 WEB Pepe Berba
2021-06-02   Thecus N4800Eco Nas Server Control Panel - Comand Injection 25 WEB Metin Yunus Kandemir
2021-06-01   Atlassian Jira 8.15.0 - Information Disclosure (Username Enumeration) 26 WEB Mohammed Aloraimi
2021-06-01   CHIYU TCP/IP Converter devices - CRLF injection 34 WEB sirpedrotavares
2021-06-01   CHIYU IoT devices - 'Multiple' Cross-Site Scripting (XSS) 41 WEB sirpedrotavares
2021-06-01   WordPress Plugin WP Prayer version 1.6.1 - 'prayer_messages' Stored Cross-Site Scripting (XSS) (Auth 27 WEB Bastijn Ouwendijk
2021-06-01   Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF) 27 WEB lated
2021-06-01   ProjeQtOr Project Management 9.1.4 - Remote Code Execution 32 WEB Temel Demir
2021-06-01   LogonTracer 1.2.0 - Remote Code Execution (Unauthenticated) 31 WEB g0ldm45k
2021-05-28   Selenium 3.141.59 - Remote Code Execution (Firefox/geckodriver) 42 WEB Jon Stratton
2021-05-28   Trixbox 2.8.0.4 - 'lang' Path Traversal 29 WEB Ron Jost
2021-05-28   Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated) 33 WEB Ron Jost