Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-07-29   Care2x Integrated Hospital Info System 2.7 - 'Multiple' SQL Injection 26 WEB securityforeveryone.com
2021-07-29   IntelliChoice eFORCE Software Suite 2.5.9 - Username Enumeration 27 WEB LiquidWorm
2021-07-29   Longjing Technology BEMS API 1.21 - Remote Arbitrary File Download 28 WEB LiquidWorm
2021-07-29   Denver IP Camera SHO-110 - Unauthenticated Snapshot 27 WEB Ivan Nikolsky
2021-07-28   TripSpark VEO Transportation - Blind SQL Injection 26 WEB Sedric Louissaint
2021-07-28   Event Registration System with QR Code 1.0 - Authentication Bypass 28 WEB Javier Olmedo
2021-07-27   Customer Relationship Management System (CRM) 1.0 - Sql Injection Authentication Bypass 25 WEB Shafique_Wasta
2021-07-27   PHP 7.3.15-3 - 'PHP_SESSION_UPLOAD_PROGRESS' Session Data Injection 27 WEB S1lv3r
2021-07-26   XOS Shop 1.0.9 - 'Multiple' Arbitrary File Deletion (Authenticated) 33 WEB faisalfs10x
2021-07-26   NoteBurner 2.35 - Denial Of Service (DoS) (PoC) 34 WEB stresser
2021-07-26   Elasticsearch ECE 7.13.3 - Anonymous Database Dump 35 WEB Joan Martinez
2021-07-23   Microsoft SharePoint Server 2019 - Remote Code Execution (2) 33 WEB Podalirius
2021-07-23   WordPress Plugin Simple Post 1.1 - 'Text field' Stored Cross-Site Scripting (XSS) 34 WEB Vikas Srivastava
2021-07-23   ElasticSearch 7.13.3 - Memory disclosure 39 WEB r0ny
2021-07-21   CSZ CMS 1.2.9 - 'Multiple' Arbitrary File Deletion 28 WEB faisalfs10x
2021-07-21   KevinLAB BEMS 1.0 - File Path Traversal Information Disclosure (Authenticated) 25 WEB LiquidWorm
2021-07-21   KevinLAB BEMS 1.0 - Authentication Bypass 25 WEB LiquidWorm
2021-07-20   Webmin 1.973 - 'run.cgi' Cross-Site Request Forgery (CSRF) 30 WEB Mesh3l_911
2021-07-20   WordPress Plugin KN Fix Your Title 1.0.1 - 'Separator' Stored Cross-Site Scripting (XSS) 29 WEB Aakash Choudhary
2021-07-19   PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection 28 WEB faisalfs10x
2021-07-19   WordPress Plugin Mimetic Books 0.2.13 - 'Default Publisher ID field' Stored Cross-Site Scripting (XS 22 WEB Vikas Srivastava
2021-07-19   WordPress Plugin LearnPress 3.2.6.8 - Privilege Escalation 27 WEB nhattruong
2021-07-19   WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated) 22 WEB nhattruong
2021-07-16   Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection 25 WEB Metin Yunus Kandemir
2021-07-16   ForgeRock Access Manager 14.6.3 - Remote Code Execution (RCE) (Unauthenticated) 31 WEB Photubias
2021-07-15   WordPress Plugin Popular Posts 5.3.2 - Remote Code Execution (RCE) (Authenticated) 27 WEB Simone Cristofaro
2021-07-15   osCommerce 2.3.4.1 - Remote Code Execution (2) 31 WEB Bryan Leong
2021-07-14   WordPress Plugin Current Book 1.0.1 - 'Book Title' Persistent Cross-Site Scripting 31 WEB Vikas Srivastava
2021-07-14   Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF) 29 WEB Mesh3l_911
2021-07-13   Garbage Collection Management System 1.0 - SQL Injection + Arbitrary File Upload 28 WEB Luca Bernardi
2021-07-13   OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2) 37 WEB Alexandre ZANNI
2021-07-13   Invoice System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 40 WEB Subhadip Nag
2021-07-13   WordPress Plugin WPFront Notification Bar 1.9.1.04012 - Stored Cross-Site Scripting (XSS) 28 WEB Swapnil Subhash Bodekar
2021-07-13   Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS) 23 WEB Central InfoSec
2021-07-13   Apache Tomcat 9.0.0.M1 - Open Redirect 26 WEB Central InfoSec
2021-07-09   Zoo Management System 1.0 - 'Multiple' Persistent Cross-Site-Scripting (XSS) 31 WEB Subhadip Nag
2021-07-09   Church Management System 1.0 - SQL Injection (Authentication Bypass) + Arbitrary File Upload + RCE 29 WEB Eleonora Guardini
2021-07-08   Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (RCE) (Authenticated) 29 WEB Ron Jost
2021-07-08   Online Covid Vaccination Scheduler System 1.0 - Arbitrary File Upload to Remote Code Execution (Unau 25 WEB faisalfs10x
2021-07-08   Wyomind Help Desk 1.3.6 - Remote Code Execution (RCE) 30 WEB Patrik Lantz
2021-07-08   Employee Record Management System 1.2 - Stored Cross-Site Scripting (XSS) 26 WEB Subhadip Nag
2021-07-08   Exam Hall Management System 1.0 - Unrestricted File Upload + RCE (Unauthenticated) 32 WEB Davide \'yth1n\' Bianchin
2021-07-07   WordPress Plugin Plainview Activity Monitor 20161228 - Remote Code Execution (RCE) (Authenticated) ( 26 WEB Beren Kuday GÖRÜN
2021-07-07   Online Covid Vaccination Scheduler System 1.0 - 'username' time-based blind SQL Injection 27 WEB faisalfs10x
2021-07-07   Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2) 36 WEB enox
2021-07-06   WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 - Directory Traversal 28 WEB TheSmuggler
2021-07-06   Phone Shop Sales Managements System 1.0 - Arbitrary File Upload 27 WEB faisalfs10x
2021-07-06   Phone Shop Sales Managements System 1.0 - Authentication Bypass (SQLi) 24 WEB faisalfs10x
2021-07-06   Visual Tools DVR VX16 4.2.28 - Local Privilege Escalation 26 WEB Andrea D\'Ubaldo
2021-07-06   Exam Hall Management System 1.0 - Unrestricted File Upload (Unauthenticated) 26 WEB Thamer Almohammadi
2021-07-06   Billing System Project 1.0 - Remote Code Execution (RCE) (Unauthenticated) 33 WEB Talha DEMİRSOY
2021-07-06   Pallets Werkzeug 0.15.4 - Path Traversal 27 WEB faisalfs10x
2021-07-06   Black Box Kvm Extender 3.4.31307 - Local File Inclusion 25 WEB Ferhat Çil
2021-07-06   Netgear DGN2200v1 - Remote Command Execution (RCE) (Unauthenticated) 25 WEB SivertPL
2021-07-06   Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated) 24 WEB Andrea D\'Ubaldo
2021-07-06   perfexcrm 1.10 - 'State' Stored Cross-site scripting (XSS) 24 WEB Alhasan Abbas
2021-07-05   Ricon Industrial Cellular Router S9922XL - Remote Command Execution (RCE) 23 WEB LiquidWorm
2021-07-05   TextPattern CMS 4.9.0-dev - Remote Command Execution (RCE) (Authenticated) 23 WEB Mevlüt Akçam
2021-07-05   Simple Client Management System 1.0 - Remote Code Execution (RCE) 29 WEB Ishan Saha
2021-07-05   Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated) 27 WEB Ron Jost
2021-07-05   Church Management System 1.0 - 'password' SQL Injection (Authentication Bypass) 34 WEB Murat DEMİRCİ
2021-07-05   Church Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 31 WEB Murat DEMİRCİ
2021-07-05   Church Management System 1.0 - Arbitrary File Upload (Authenticated) 34 WEB Murat DEMİRCİ
2021-07-05   Online Birth Certificate System 1.1 - 'Multiple' Stored Cross-Site Scripting (XSS) 33 WEB Subhadip Nag
2021-07-05   Online Voting System 1.0 - SQLi (Authentication Bypass) + Remote Code Execution (RCE) 27 WEB Geiseric
2021-07-05   OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) (2) 27 WEB Alexandre ZANNI
2021-07-05   WordPress Plugin WP Learn Manager 1.1.2 - Stored Cross-Site Scripting (XSS) 30 WEB Mohammed Adam
2021-07-02   Garbage Collection Management System 1.0 - SQL Injection (Unauthenticated) 28 WEB ircashem
2021-07-02   Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated) 27 WEB Ron Jost
2021-07-02   Wordpress Plugin Modern Events Calendar 5.16.2 - Remote Code Execution (Authenticated) 24 WEB Ron Jost
2021-07-02   b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF) 25 WEB Alperen Ergel
2021-07-02   AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS) 30 WEB Tyler Butler
2021-07-02   Scratch Desktop 3.17 - Remote Code Execution 27 WEB Stig Magnus Baugstø
2021-07-01   Vianeos OctoPUS 5 - 'login_user' SQLi 27 WEB Audencia Business SCHOOL Red Team
2021-07-01   Wordpress Plugin XCloner 4.2.12 - Remote Code Execution (Authenticated) 27 WEB Ron Jost
2021-07-01   Online Voting System 1.0 - Remote Code Execution (Authenticated) 28 WEB Salman Asad
2021-07-01   Online Voting System 1.0 - Authentication Bypass (SQLi) 23 WEB Salman Asad
2021-06-30   Doctors Patients Management System 1.0 - SQL Injection (Authentication Bypass) 26 WEB Murat DEMİRCİ
2021-06-30   Simple Traffic Offense System 1.0 - Stored Cross Site Scripting (XSS) 25 WEB Barış Yıldızoğlu
2021-06-30   Apache Superset 1.1.0 - Time-Based Account Enumeration 30 WEB Dolev Farhi
2021-06-30   phpAbook 0.9i - SQL Injection 29 WEB Alejandro Perez
2021-06-28   Netgear WNAP320 2.0.3 - 'macAddress' Remote Code Execution (RCE) (Unauthenticated) 32 WEB Bryan Leong
2021-06-28   Atlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS) 24 WEB Captain_hook
2021-06-28   WordPress Plugin YOP Polls 6.2.7 - Stored Cross Site Scripting (XSS) 33 WEB Toby Jackson
2021-06-25   Lightweight facebook-styled blog 1.3 - Remote Code Execution (RCE) (Authenticated) (Metasploit) 28 WEB Maide Ilkay Aydogdu
2021-06-25   Simple Client Management System 1.0 - 'uemail' SQL Injection (Unauthenticated) 28 WEB Barış Yıldızoğlu
2021-06-25   Seeddms 5.1.10 - Remote Command Execution (RCE) (Authenticated) 28 WEB Bryan Leong
2021-06-24   TP-Link TL-WR841N - Command Injection 28 WEB Koh You Liang
2021-06-24   Adobe ColdFusion 8 - Remote Command Execution (RCE) 40 WEB Pergyz
2021-06-24   VMware vCenter Server 7.0 - Remote Code Execution (RCE) (Unauthenticated) 31 WEB CHackA0101
2021-06-23   Simple CRM 3.0 - 'email' SQL injection (Authentication Bypass) 27 WEB Rinku Kumar
2021-06-23   Online Library Management System 1.0 - Arbitrary File Upload Remote Code Execution (Unauthenticated) 45 WEB Berk Can Geyikci
2021-06-23   Online Library Management System 1.0 - 'Search' SQL Injection 27 WEB Berk Can Geyikci
2021-06-23   WordPress Plugin Poll_ Survey_ Questionnaire and Voting system 1.5.2 - 'date_answers' Blind SQL Inje 27 WEB Toby Jackson
2021-06-23   WordPress Plugin WP Google Maps 8.1.11 - Stored Cross-Site Scripting (XSS) 29 WEB Mohammed Adam
2021-06-22   Phone Shop Sales Managements System 1.0 - Insecure Direct Object Reference (IDOR) 26 WEB Pratik Khalane
2021-06-22   Responsive Tourism Website 3.1 - Remote Code Execution (RCE) (Unauthenticated) 30 WEB Tagoletta
2021-06-21   Customer Relationship Management System (CRM) 1.0 - Remote Code Execution 29 WEB Ishan Saha
2021-06-21   Simple CRM 3.0 - 'name' Stored Cross site scripting (XSS) 28 WEB Riadh Benlamine
2021-06-21   Simple CRM 3.0 - 'Change user information' Cross-Site Request Forgery (CSRF) 28 WEB Riadh Benlamine
2021-06-21   Websvn 2.6.0 - Remote Code Execution (Unauthenticated) 30 WEB g0ldm45k
2021-06-21   OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) 25 WEB Ron Jost
2021-06-18   Node.JS - 'node-serialize' Remote Code Execution (3) 29 WEB Beren Kuday GÖRÜN
2021-06-18   ICE Hrm 29.0.0.OS - 'xml upload' Stored Cross-Site Scripting (XSS) 27 WEB Piyush Patil
2021-06-18   ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Request Forgery (CSRF) 27 WEB Piyush Patil
2021-06-17   Online Shopping Portal 3.1 - Remote Code Execution (Unauthenticated) 29 WEB Tagoletta
2021-06-17   Zoho ManageEngine ServiceDesk Plus MSP 9.4 - User Enumeration 26 WEB Ricardo Ruiz
2021-06-17   Unified Office Total Connect Now 1.0 - 'data' SQL Injection 27 WEB Ajaikumar Nadar
2021-06-16   CKEditor 3 - Server-Side Request Forgery (SSRF) 27 WEB ahmed
2021-06-16   Teachers Record Management System 1.0 - 'email' Stored Cross-site Scripting (XSS) 25 WEB nhattruong
2021-06-16   Teachers Record Management System 1.0 - 'Multiple' SQL Injection (Authenticated) 25 WEB nhattruong
2021-06-16   OpenEMR 5.0.1.3 - Authentication Bypass 36 WEB Ron Jost
2021-06-16   Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting 24 WEB Fatih İLGİN
2021-06-15   Client Management System 1.1 - 'Search' SQL Injection 30 WEB BHAVESH KAUL
2021-06-15   Client Management System 1.1 - 'username' Stored Cross-Site Scripting (XSS) 26 WEB BHAVESH KAUL
2021-06-14   OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) 26 WEB Ron Jost
2021-06-14   TextPattern CMS 4.8.7 - Remote Command Execution (Authenticated) 28 WEB Mert Daş
2021-06-14   Small CRM 3.0 - 'Authentication Bypass' SQL Injection 41 WEB BHAVESH KAUL
2021-06-14   Stock Management System 1.0 - 'user_id' Blind SQL injection (Authenticated) 37 WEB Riadh Benlamine
2021-06-14   COVID19 Testing Management System 1.0 - 'State' Stored Cross-Site-Scripting (XSS) 31 WEB BHAVESH KAUL
2021-06-14   GLPI 9.4.5 - Remote Code Execution (RCE) 26 WEB Brian Peters
2021-06-14   Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure Direct Object References (IDOR) 24 WEB Abdulazeez Alaseeri
2021-06-14   Accela Civic Platform 21.1 - 'successURL' Cross-Site-Scripting (XSS) 24 WEB Abdulazeez Alaseeri
2021-06-11   WoWonder Social Network Platform 3.1 - Authentication Bypass 25 WEB securityforeveryone.com
2021-06-11   Zenario CMS 8.8.52729 - 'cID' SQL injection (Authenticated) 25 WEB Avinash R