Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-06-11   Solar-Log 500 2.8.2 - Unprotected Storage of Credentials 30 WEB Luca.Chiou
2021-06-11   Solar-Log 500 2.8.2 - Incorrect Access Control 28 WEB Luca.Chiou
2021-06-11   Grocery crud 1.6.4 - 'order_by' SQL Injection 29 WEB TonyShavez
2021-06-11   WordPress Plugin Database Backups 1.2.2.6 - 'Database Backup Download' CSRF 41 WEB 0xB9
2021-06-11   OpenEMR 5.0.0 - Remote Code Execution (Authenticated) 39 WEB Ron Jost
2021-06-11   Microsoft SharePoint Server 16.0.10372.20060 - 'GetXmlDataFromDataSource' Server-Side Request Forger 30 WEB Alex Birnberg
2021-06-11   Cerberus FTP Web Service 11 - 'svg' Stored Cross-Site Scripting (XSS) 33 WEB Mohammad Hossein Kaviyany
2021-06-11   Accela Civic Platform 21.1 - 'servProvCode' Cross-Site-Scripting (XSS) 33 WEB Abdulazeez Alaseeri
2021-06-10   TextPattern CMS 4.8.7 - Stored Cross-Site Scripting (XSS) 35 WEB Mert Daş
2021-06-10   Student Result Management System 1.0 - 'class' SQL Injection 36 WEB Riadh Benlamine
2021-06-09   GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2) 43 WEB legend
2021-06-09   WordPress Plugin visitors-app 0.3 - 'user-agent' Stored Cross-Site Scripting (XSS) 27 WEB Mesut Cetin
2021-06-09   OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting 27 WEB Mert Daş
2021-06-09   OpenCart 3.0.3.7 - 'Change Password' Cross-Site Request Forgery (CSRF) 31 WEB Mert Daş
2021-06-09   Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF) 31 WEB Rodolfo Mariano
2021-06-08   WordPress Plugin wpDiscuz 7.0.4 - Remote Code Execution (Unauthenticated) 34 WEB Fellipe Oliveira
2021-06-07   Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated) 36 WEB UnD3sc0n0c1d0
2021-06-07   Grav CMS 1.7.10 - Server-Side Template Injection (SSTI) (Authenticated) 30 WEB enox
2021-06-07   Rocket.Chat 3.12.1 - NoSQL Injection (Unauthenticated) 26 WEB enox
2021-06-07   WordPress Plugin Smart Slider-3 3.5.0.8 - 'name' Stored Cross-Site Scripting (XSS) 31 WEB Hardik Solanki
2021-06-07   OptiLink ONT1GEW GPON 2.1.11_X101 Build 1127.190306 - Remote Code Execution (Authenticated) 27 WEB SecNigma
2021-06-04   Gitlab 13.10.2 - Remote Code Execution (Authenticated) 41 WEB enox
2021-06-04   Monstra CMS 3.0.4 - Remote Code Execution (Authenticated) 30 WEB Ron Jost
2021-06-03   4Images 1.8 - 'redirect' Reflected XSS 29 WEB Piyush Patil
2021-06-03   Gitlab 13.9.3 - Remote Code Execution (Authenticated) 38 WEB enox
2021-06-03   FUDForum 3.1.0 - 'author' Reflected XSS 26 WEB Piyush Patil
2021-06-03   FUDForum 3.1.0 - 'srch' Reflected XSS 30 WEB Piyush Patil
2021-06-03   CHIYU IoT Devices - Denial of Service (DoS) 26 WEB sirpedrotavares
2021-06-03   Seo Panel 4.8.0 - 'from_time' Reflected XSS 30 WEB Piyush Patil
2021-06-03   PHP 8.1.0-dev - 'User-Agentt' Remote Code Execution 25 WEB flast101
2021-06-02   Seo Panel 4.8.0 - 'category' Reflected XSS 27 WEB Piyush Patil
2021-06-02   Seo Panel 4.8.0 - 'search_name' Reflected XSS 31 WEB Piyush Patil
2021-06-02   Products.PluggableAuthService 2.6.0 - Open Redirect 26 WEB Piyush Patil
2021-06-02   GetSimple CMS 3.3.4 - Information Disclosure 33 WEB Ron Jost
2021-06-02   Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution 29 WEB Pepe Berba
2021-06-02   Thecus N4800Eco Nas Server Control Panel - Comand Injection 30 WEB Metin Yunus Kandemir
2021-06-01   Atlassian Jira 8.15.0 - Information Disclosure (Username Enumeration) 33 WEB Mohammed Aloraimi
2021-06-01   CHIYU TCP/IP Converter devices - CRLF injection 38 WEB sirpedrotavares
2021-06-01   CHIYU IoT devices - 'Multiple' Cross-Site Scripting (XSS) 50 WEB sirpedrotavares
2021-06-01   WordPress Plugin WP Prayer version 1.6.1 - 'prayer_messages' Stored Cross-Site Scripting (XSS) (Auth 34 WEB Bastijn Ouwendijk
2021-06-01   Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF) 32 WEB lated
2021-06-01   ProjeQtOr Project Management 9.1.4 - Remote Code Execution 37 WEB Temel Demir
2021-06-01   LogonTracer 1.2.0 - Remote Code Execution (Unauthenticated) 34 WEB g0ldm45k
2021-05-28   Selenium 3.141.59 - Remote Code Execution (Firefox/geckodriver) 47 WEB Jon Stratton
2021-05-28   Trixbox 2.8.0.4 - 'lang' Path Traversal 39 WEB Ron Jost
2021-05-28   Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated) 39 WEB Ron Jost
2021-05-28   WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS) 28 WEB Captain_hook
2021-05-28   PHPFusion 9.03.50 - Remote Code Execution 35 WEB g0ldm45k
2021-05-27   Postbird 0.8.4 - Javascript Injection 31 WEB Debshubra Chakraborty
2021-05-26   Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated) 49 WEB Ron Jost
2021-05-26   Codiad 2.8.4 - Remote Code Execution (Authenticated) (3) 41 WEB Ron Jost
2021-05-25   WordPress Plugin Cookie Law Bar 1.2.1 - 'clb_bar_msg' Stored Cross-Site Scripting (XSS) 31 WEB Mesut Cetin
2021-05-25   Gadget Works Online Ordering System 1.0 - 'Category' Persistent Cross-Site Scripting (XSS) 35 WEB Vinay H C
2021-05-24   WordPress Plugin ReDi Restaurant Reservation 21.0307 - 'Comment' Stored Cross-Site Scripting (XSS) 28 WEB Bastijn Ouwendijk
2021-05-24   Codiad 2.8.4 - Remote Code Execution (Authenticated) (2) 34 WEB Ron Jost
2021-05-24   Shopizer 2.16.0 - 'Multiple' Cross-Site Scripting (XSS) 28 WEB Marek Toth
2021-05-24   Schlix CMS 2.2.6-6 - Arbitary File Upload (Authenticated) 31 WEB Emir Polat
2021-05-21   Microsoft Exchange 2019 - Unauthenticated Email Download (Metasploit) 36 WEB mekhalleh
2021-05-21   WordPress Plugin WP Statistics 13.0.7 - Time-Based Blind SQL Injection (Unauthenticated) 28 WEB Mansoor R
2021-05-21   Spotweb 1.4.9 - DOM Based Cross-Site Scripting (XSS) 28 WEB nu11secur1ty
2021-05-19   COVID19 Testing Management System 1.0 - 'Admin name' Cross-Site Scripting (XSS) 33 WEB Rohit Burke
2021-05-19   COVID19 Testing Management System 1.0 - SQL Injection (Auth Bypass) 29 WEB Rohit Burke
2021-05-19   ManageEngine ADSelfService Plus 6.1 - CSV Injection 36 WEB Metin Yunus Kandemir
2021-05-19   In4Suit ERP 3.2.74.1370 - 'txtLoginId' SQL injection 30 WEB Gulab Mondal
2021-05-19   WordPress Plugin Stop Spammers 2021.8 - 'log' Reflected Cross-site Scripting (XSS) 27 WEB Hosein Vita
2021-05-18   Microsoft Exchange 2019 - Unauthenticated Email Download 36 WEB Gonzalo Villegas
2021-05-18   EgavilanMedia PHPCRUD 1.0 - 'First Name' SQL Injection 28 WEB Dimitrios Mitakos
2021-05-17   Printable Staff ID Card Creator System 1.0 - 'email' SQL Injection 34 WEB bwnz
2021-05-17   Subrion CMS 4.2.1 - Arbitrary File Upload 53 WEB Fellipe Oliveira
2021-05-17   Advanced Guestbook 2.4.4 - 'Smilies' Persistent Cross-Site Scripting (XSS) 28 WEB Abdulkadir AYDOGAN
2021-05-17   Billing Management System 2.0 - Union based SQL injection (Authenticated) 29 WEB Mohammad Koochaki
2021-05-17   Simple Chatbot Application 1.0 - 'Category' Stored Cross site Scripting 29 WEB Vani K G
2021-05-17   Dental Clinic Appointment Reservation System 1.0 - Cross Site Request Forgery (Add Admin) 27 WEB Reza Afsahi
2021-05-17   Dental Clinic Appointment Reservation System 1.0 - 'Firstname' Persistent Cross Site Scripting (Auth 29 WEB Reza Afsahi
2021-05-17   IPFire 2.25 - Remote Code Execution (Authenticated) 29 WEB Mücahit Saratar
2021-05-17   Customer Relationship Management (CRM) System 1.0 - 'Category' Persistent Cross site Scripting 35 WEB Vani K G
2021-05-14   Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated) 33 WEB M. Cory Billington
2021-05-14   Podcast Generator 3.1 - 'Long Description' Persistent Cross-Site Scripting (XSS) 37 WEB Ayşenur KARAASLAN
2021-05-14   Student Management System 1.0 - 'message' Persistent Cross-Site Scripting (Authenticated) 28 WEB mohsen khashei
2021-05-13   ZeroShell 3.9.0 - Remote Command Execution 36 WEB Fellipe Oliveira
2021-05-13   Dental Clinic Appointment Reservation System 1.0 - 'date' UNION based SQL Injection (Authenticated) 31 WEB Mesut Cetin
2021-05-13   Dental Clinic Appointment Reservation System 1.0 - Authentication Bypass (SQLi) 27 WEB Mesut Cetin
2021-05-12   Chevereto 3.17.1 - Cross Site Scripting (Stored) 33 WEB Akıner Kısa
2021-05-10   Microweber CMS 1.1.20 - Remote Code Execution (Authenticated) 42 WEB sl1nki
2021-05-10   Human Resource Information System 0.1 - 'First Name' Persistent Cross-Site Scripting (Authenticate 29 WEB Reza Afsahi
2021-05-10   PHP Timeclock 1.04 - 'Multiple' Cross Site Scripting (XSS) 25 WEB Tyler Butler
2021-05-07   PHP Timeclock 1.04 - Time and Boolean Based Blind SQL Injection 29 WEB Tyler Butler
2021-05-07   Human Resource Information System 0.1 - Remote Code Execution (Unauthenticated) 44 WEB Reza Afsahi
2021-05-07   Voting System 1.0 - Remote Code Execution (Unauthenticated) 38 WEB secure77
2021-05-07   Voting System 1.0 - Authentication Bypass (SQLI) 28 WEB secure77
2021-05-06   b2evolution 7-2-2 - 'cf_name' SQL Injection 32 WEB nu11secur1ty
2021-05-06   Wordpress Plugin WP Super Edit 2.5.4 - Remote File Upload 38 WEB h4shur
2021-05-06   Schlix CMS 2.2.6-6 - Remote Code Execution (Authenticated) 41 WEB Eren Saraç
2021-05-06   Schlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated) 32 WEB Emircan Baş
2021-05-05   Anote 1.0 - Persistent Cross-Site Scripting 32 WEB TaurusOmar
2021-05-05   Markdownify 1.2.0 - Persistent Cross-Site Scripting 38 WEB TaurusOmar
2021-05-05   Markright 1.0 - Persistent Cross-Site Scripting 26 WEB TaurusOmar
2021-05-05   Freeter 1.2.1 - Persistent Cross-Site Scripting 37 WEB TaurusOmar
2021-05-05   StudyMD 0.3.2 - Persistent Cross-Site Scripting 33 WEB TaurusOmar
2021-05-05   Marky 0.0.1 - Persistent Cross-Site Scripting 30 WEB TaurusOmar
2021-05-05   Moeditor 0.2.0 - Persistent Cross-Site Scripting 31 WEB TaurusOmar
2021-05-05   SnipCommand 0.1.0 - Persistent Cross-Site Scripting 32 WEB TaurusOmar
2021-05-05   Tagstoo 2.0.1 - Persistent Cross-Site Scripting 35 WEB TaurusOmar
2021-05-05   Xmind 2020 - Persistent Cross-Site Scripting 37 WEB TaurusOmar
2021-05-05   Markdown Explorer 0.1.1 - Persistent Cross-Site Scripting 28 WEB Taurus Omar
2021-05-05   Savsoft Quiz 5 - 'User Account Settings' Persistent Cross-Site Scripting 31 WEB strider
2021-05-04   Internship Portal Management System 1.0 - Remote Code Execution(Unauthenticated) 28 WEB argenestel
2021-05-03   GitLab Community Edition (CE) 13.10.3 - 'Sign_Up' User Enumeration 35 WEB 4D0niiS
2021-05-03   GitLab Community Edition (CE) 13.10.3 - User Enumeration 30 WEB 4D0niiS
2021-05-03   Piwigo 11.3.0 - 'language' SQL 29 WEB nu11secur1ty
2021-05-03   Voting System 1.0 - Time based SQLI (Unauthenticated SQL injection) 31 WEB Syed Sheeraz Ali
2021-05-03   GetSimple CMS Custom JS 0.1 - Cross-Site Request Forgery 27 WEB boku
2021-04-30   Moodle 3.6.1 - Persistent Cross-Site Scripting (XSS) 31 WEB Fariskhi Vidyan
2021-04-29   NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write 28 WEB 1F98D
2021-04-29   FOGProject 1.5.9 - File Upload RCE (Authenticated) 37 WEB sml
2021-04-29   Cacti 1.2.12 - 'filter' SQL Injection 37 WEB Leonardo Paiva
2021-04-28   Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS) 32 WEB Sreenath Raghunathan
2021-04-27   Montiorr 1.7.6m - Persistent Cross-Site Scripting 35 WEB Ahmad Shakla
2021-04-27   Kimai 1.14 - CSV Injection 33 WEB Mohammed Aloraimi
2021-04-26   SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (2) 32 WEB nu11secur1ty
2021-04-26   OpenPLC 3 - Remote Code Execution (Authenticated) 35 WEB Fellipe Oliveira
2021-04-26   Hasura GraphQL 1.3.3 - Remote Code Execution 28 WEB Dolev Farhi
2021-04-23   Sipwise C5 NGCP CSC - Click2Dial Cross-Site Request Forgery (CSRF) 24 WEB LiquidWorm
2021-04-23   Sipwise C5 NGCP CSC - 'Multiple' Persistent Cross-Site Scripting (XSS) 27 WEB LiquidWorm
2021-04-23   DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS) 29 WEB nu11secur1ty