Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-05-19   WordPress Plugin Stop Spammers 2021.8 - 'log' Reflected Cross-site Scripting (XSS) 18 WEB Hosein Vita
2021-05-18   Microsoft Exchange 2019 - Unauthenticated Email Download 22 WEB Gonzalo Villegas
2021-05-18   EgavilanMedia PHPCRUD 1.0 - 'First Name' SQL Injection 16 WEB Dimitrios Mitakos
2021-05-17   Printable Staff ID Card Creator System 1.0 - 'email' SQL Injection 19 WEB bwnz
2021-05-17   Subrion CMS 4.2.1 - Arbitrary File Upload 34 WEB Fellipe Oliveira
2021-05-17   Advanced Guestbook 2.4.4 - 'Smilies' Persistent Cross-Site Scripting (XSS) 15 WEB Abdulkadir AYDOGAN
2021-05-17   Billing Management System 2.0 - Union based SQL injection (Authenticated) 20 WEB Mohammad Koochaki
2021-05-17   Simple Chatbot Application 1.0 - 'Category' Stored Cross site Scripting 18 WEB Vani K G
2021-05-17   Dental Clinic Appointment Reservation System 1.0 - Cross Site Request Forgery (Add Admin) 17 WEB Reza Afsahi
2021-05-17   Dental Clinic Appointment Reservation System 1.0 - 'Firstname' Persistent Cross Site Scripting (Auth 17 WEB Reza Afsahi
2021-05-17   IPFire 2.25 - Remote Code Execution (Authenticated) 16 WEB Mücahit Saratar
2021-05-17   Customer Relationship Management (CRM) System 1.0 - 'Category' Persistent Cross site Scripting 16 WEB Vani K G
2021-05-14   Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated) 25 WEB M. Cory Billington
2021-05-14   Podcast Generator 3.1 - 'Long Description' Persistent Cross-Site Scripting (XSS) 21 WEB Ayşenur KARAASLAN
2021-05-14   Student Management System 1.0 - 'message' Persistent Cross-Site Scripting (Authenticated) 18 WEB mohsen khashei
2021-05-13   ZeroShell 3.9.0 - Remote Command Execution 22 WEB Fellipe Oliveira
2021-05-13   Dental Clinic Appointment Reservation System 1.0 - 'date' UNION based SQL Injection (Authenticated) 19 WEB Mesut Cetin
2021-05-13   Dental Clinic Appointment Reservation System 1.0 - Authentication Bypass (SQLi) 18 WEB Mesut Cetin
2021-05-12   Chevereto 3.17.1 - Cross Site Scripting (Stored) 24 WEB Akıner Kısa
2021-05-10   Microweber CMS 1.1.20 - Remote Code Execution (Authenticated) 25 WEB sl1nki
2021-05-10   Human Resource Information System 0.1 - 'First Name' Persistent Cross-Site Scripting (Authenticate 20 WEB Reza Afsahi
2021-05-10   PHP Timeclock 1.04 - 'Multiple' Cross Site Scripting (XSS) 17 WEB Tyler Butler
2021-05-07   PHP Timeclock 1.04 - Time and Boolean Based Blind SQL Injection 19 WEB Tyler Butler
2021-05-07   Human Resource Information System 0.1 - Remote Code Execution (Unauthenticated) 26 WEB Reza Afsahi
2021-05-07   Voting System 1.0 - Remote Code Execution (Unauthenticated) 26 WEB secure77
2021-05-07   Voting System 1.0 - Authentication Bypass (SQLI) 20 WEB secure77
2021-05-06   b2evolution 7-2-2 - 'cf_name' SQL Injection 20 WEB nu11secur1ty
2021-05-06   Wordpress Plugin WP Super Edit 2.5.4 - Remote File Upload 24 WEB h4shur
2021-05-06   Schlix CMS 2.2.6-6 - Remote Code Execution (Authenticated) 25 WEB Eren Saraç
2021-05-06   Schlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated) 19 WEB Emircan Baş
2021-05-05   Anote 1.0 - Persistent Cross-Site Scripting 22 WEB TaurusOmar
2021-05-05   Markdownify 1.2.0 - Persistent Cross-Site Scripting 20 WEB TaurusOmar
2021-05-05   Markright 1.0 - Persistent Cross-Site Scripting 17 WEB TaurusOmar
2021-05-05   Freeter 1.2.1 - Persistent Cross-Site Scripting 25 WEB TaurusOmar
2021-05-05   StudyMD 0.3.2 - Persistent Cross-Site Scripting 21 WEB TaurusOmar
2021-05-05   Marky 0.0.1 - Persistent Cross-Site Scripting 19 WEB TaurusOmar
2021-05-05   Moeditor 0.2.0 - Persistent Cross-Site Scripting 20 WEB TaurusOmar
2021-05-05   SnipCommand 0.1.0 - Persistent Cross-Site Scripting 21 WEB TaurusOmar
2021-05-05   Tagstoo 2.0.1 - Persistent Cross-Site Scripting 20 WEB TaurusOmar
2021-05-05   Xmind 2020 - Persistent Cross-Site Scripting 22 WEB TaurusOmar
2021-05-05   Markdown Explorer 0.1.1 - Persistent Cross-Site Scripting 16 WEB Taurus Omar
2021-05-05   Savsoft Quiz 5 - 'User Account Settings' Persistent Cross-Site Scripting 19 WEB strider
2021-05-04   Internship Portal Management System 1.0 - Remote Code Execution(Unauthenticated) 21 WEB argenestel
2021-05-03   GitLab Community Edition (CE) 13.10.3 - 'Sign_Up' User Enumeration 22 WEB 4D0niiS
2021-05-03   GitLab Community Edition (CE) 13.10.3 - User Enumeration 19 WEB 4D0niiS
2021-05-03   Piwigo 11.3.0 - 'language' SQL 20 WEB nu11secur1ty
2021-05-03   Voting System 1.0 - Time based SQLI (Unauthenticated SQL injection) 20 WEB Syed Sheeraz Ali
2021-05-03   GetSimple CMS Custom JS 0.1 - Cross-Site Request Forgery 16 WEB boku
2021-04-30   Moodle 3.6.1 - Persistent Cross-Site Scripting (XSS) 20 WEB Fariskhi Vidyan
2021-04-29   NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write 21 WEB 1F98D
2021-04-29   FOGProject 1.5.9 - File Upload RCE (Authenticated) 24 WEB sml
2021-04-29   Cacti 1.2.12 - 'filter' SQL Injection 26 WEB Leonardo Paiva
2021-04-28   Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS) 24 WEB Sreenath Raghunathan
2021-04-27   Montiorr 1.7.6m - Persistent Cross-Site Scripting 24 WEB Ahmad Shakla
2021-04-27   Kimai 1.14 - CSV Injection 22 WEB Mohammed Aloraimi
2021-04-26   SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (2) 22 WEB nu11secur1ty
2021-04-26   OpenPLC 3 - Remote Code Execution (Authenticated) 24 WEB Fellipe Oliveira
2021-04-26   Hasura GraphQL 1.3.3 - Remote Code Execution 19 WEB Dolev Farhi
2021-04-23   Sipwise C5 NGCP CSC - Click2Dial Cross-Site Request Forgery (CSRF) 15 WEB LiquidWorm
2021-04-23   Sipwise C5 NGCP CSC - 'Multiple' Persistent Cross-Site Scripting (XSS) 18 WEB LiquidWorm
2021-04-23   DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS) 20 WEB nu11secur1ty
2021-04-23   GetSimple CMS My SMTP Contact Plugin 1.1.2 - Persistent Cross-Site Scripting 21 WEB boku
2021-04-23   Moodle 3.10.3 - 'url' Persistent Cross Site Scripting 18 WEB UVision
2021-04-22   RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 16 WEB Saud Ahmad
2021-04-22   OTRS 6.0.1 - Remote Command Execution (2) 17 WEB Hex_26
2021-04-22   CMS Made Simple 2.2.15 - 'title' Cross-Site Scripting (XSS) 16 WEB bt0
2021-04-21   Hasura GraphQL 1.3.3 - Service Side Request Forgery (SSRF) 22 WEB Dolev Farhi
2021-04-21   Hasura GraphQL 1.3.3 - Local File Read 19 WEB Dolev Farhi
2021-04-21   GravCMS 1.10.7 - Unauthenticated Arbitrary File Write (Metasploit) 24 WEB Mehmet Ince
2021-04-21   Adtran Personal Phone Manager 10.8.1 - DNS Exfiltration 21 WEB 3ndG4me
2021-04-21   Adtran Personal Phone Manager 10.8.1 - 'Multiple' Reflected Cross-Site Scripting (XSS) 24 WEB 3ndG4me
2021-04-21   Adtran Personal Phone Manager 10.8.1 - 'emailAddress' Stored Cross-Site Scripting (XSS) 17 WEB 3ndG4me
2021-04-21   OpenEMR 5.0.2.1 - Remote Code Execution 24 WEB Hato0
2021-04-21   rconfig 3.9.6 - Arbitrary File Upload 20 WEB Vishwaraj Bhattrai
2021-04-21   RemoteClinic 2 - 'Multiple' Cross-Site Scripting (XSS) 20 WEB nu11secur1ty
2021-04-21   BlackCat CMS 1.3.6 - 'Multiple' Stored Cross-Site Scripting (XSS) 20 WEB Ömer Hasan Durmuş
2021-04-21   WordPress Plugin RSS for Yandex Turbo 1.29 - Stored Cross-Site Scripting (XSS) 24 WEB Himamshu Dilip Kulkarni
2021-04-21   Fast PHP Chat 1.3 - 'my_item_search' SQL Injection 22 WEB Fatih Coskun
2021-04-21   Multilaser Router RE018 AC1200 - Cross-Site Request Forgery (Enable Remote Access) 17 WEB Rodolfo Mariano
2021-04-16   GetSimple CMS My SMTP Contact Plugin 1.1.1 - Cross-Site Request Forgery 26 WEB boku
2021-04-15   htmly 2.8.0 - 'description' Stored Cross-Site Scripting (XSS) 24 WEB nu11secur1ty
2021-04-15   Tileserver-gl 3.0.0 - 'key' Reflected Cross-Site Scripting (XSS) 24 WEB Akash Chathoth
2021-04-15   Horde Groupware Webmail 5.2.22 - Stored XSS 19 WEB nu11secur1ty
2021-04-14   jQuery 1.0.3 - Cross-Site Scripting (XSS) 20 WEB Central InfoSec
2021-04-14   jQuery 1.2 - Cross-Site Scripting (XSS) 23 WEB Central InfoSec
2021-04-14   Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE 17 WEB Jay Sharma
2021-04-14   CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated) 20 WEB skysbsb
2021-04-14   CITSmart ITSM 9.1.2.22 - LDAP Injection 22 WEB skysbsb
2021-04-14   Digital Crime Report Management System 1.0 - SQL Injection (Authentication Bypass) 16 WEB GaluhID
2021-04-13   ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow 18 WEB Jai Kumar Sharma
2021-04-13   Blitar Tourism 1.0 - Authentication Bypass SQLi 20 WEB sigeri94
2021-04-13   Simple Student Information System 1.0 - SQL Injection (Authentication Bypass) 18 WEB GaluhID
2021-04-09   PrestaShop 1.7.6.7 - 'location' Blind Sql Injection 20 WEB Vanshal Gaur
2021-04-08   Composr 10.0.36 - Remote Code Execution 22 WEB Orion Hridoy
2021-04-08   DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF) 17 WEB Issac Briones
2021-04-08   CMSimple 5.2 - 'External' Stored XSS 18 WEB Quadron Research Lab
2021-04-07   Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read 18 WEB Rhino Security Labs
2021-04-07   Composr CMS 10.0.36 - Cross Site Scripting 18 WEB Orion Hridoy
2021-04-07   Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS 17 WEB Captain_hook
2021-04-06   Mini Mouse 9.3.0 - Local File inclusion 20 WEB gosh
2021-04-05   Mini Mouse 9.2.0 - Path Traversal 17 WEB gosh
2021-04-05   Mini Mouse 9.2.0 - Remote Code Execution 19 WEB gosh
2021-04-05   OpenEMR 4.1.0 - 'u' SQL Injection 21 WEB Michael Ikua
2021-04-05   Basic Shopping Cart 1.0 - Authentication Bypass 26 WEB Viren Saroha
2021-04-05   Simple Food Website 1.0 - Authentication Bypass 18 WEB Viren Saroha
2021-04-02   F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated) 23 WEB Al1ex
2021-04-02   ZBL EPON ONU Broadband Router 1.0 - Remote Privilege Escalation 18 WEB LiquidWorm
2021-04-01   phpPgAdmin 7.13.0 - COPY FROM PROGRAM Command Execution (Authenticated) 18 WEB Valerio Severini
2021-04-01   ScadaBR 1.0 - Arbitrary File Upload (Authenticated) (2) 17 WEB Fellipe Oliveira
2021-04-01   ScadaBR 1.0 - Arbitrary File Upload (Authenticated) (1) 15 WEB Fellipe Oliveira
2021-04-01   Latrix 0.6.0 - 'txtaccesscode' SQL Injection 18 WEB cptsticky
2021-03-31   CourseMS 2.1 - 'name' Stored XSS 24 WEB cptsticky
2021-03-31   Zabbix 3.4.7 - Stored XSS 23 WEB Radmil Gazizov
2021-03-30   Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting 21 WEB cmOs
2021-03-30   GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting 18 WEB boku
2021-03-29   SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow 18 WEB Filipe Oliveira
2021-03-29   Novel Boutique House-plus 3.5.1 - Arbitrary File Download 19 WEB tuyiqiang
2021-03-29   Budget Management System 1.0 - 'Budget title' Stored XSS 18 WEB Jitendra Kumar Tripathi
2021-03-29   Equipment Inventory System 1.0 - 'multiple' Stored XSS 18 WEB Jitendra Kumar Tripathi
2021-03-29   Concrete5 8.5.4 - 'name' Stored XSS 19 WEB Quadron Research Lab
2021-03-29   TP-Link Devices - 'setDefaultHostname' Stored Cross-site Scripting (Unauthenticated) 22 WEB Smriti Gaba
2021-03-29   WordPress Plugin WP Super Cache 1.7.1 - Remote Code Execution (Authenticated) 22 WEB m0ze
2021-03-26   Moodle 3.10.3 - 'label' Persistent Cross Site Scripting 19 WEB Vincent666
2021-03-26   Regis Inventory And Monitoring System 1.0 - 'Item List' Persistent Cross-Site Scripting 21 WEB George Tsimpidas
2021-03-26   'customhs_js_content' - 'customhs_js_content' Cross-Site Request Forgery 20 WEB Abhishek Joshi