Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-04-01   phpPgAdmin 7.13.0 - COPY FROM PROGRAM Command Execution (Authenticated) 22 WEB Valerio Severini
2021-04-01   ScadaBR 1.0 - Arbitrary File Upload (Authenticated) (2) 25 WEB Fellipe Oliveira
2021-04-01   ScadaBR 1.0 - Arbitrary File Upload (Authenticated) (1) 20 WEB Fellipe Oliveira
2021-04-01   Latrix 0.6.0 - 'txtaccesscode' SQL Injection 25 WEB cptsticky
2021-03-31   CourseMS 2.1 - 'name' Stored XSS 30 WEB cptsticky
2021-03-31   Zabbix 3.4.7 - Stored XSS 28 WEB Radmil Gazizov
2021-03-30   Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting 27 WEB cmOs
2021-03-30   GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting 26 WEB boku
2021-03-29   SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow 24 WEB Filipe Oliveira
2021-03-29   Novel Boutique House-plus 3.5.1 - Arbitrary File Download 22 WEB tuyiqiang
2021-03-29   Budget Management System 1.0 - 'Budget title' Stored XSS 21 WEB Jitendra Kumar Tripathi
2021-03-29   Equipment Inventory System 1.0 - 'multiple' Stored XSS 22 WEB Jitendra Kumar Tripathi
2021-03-29   Concrete5 8.5.4 - 'name' Stored XSS 23 WEB Quadron Research Lab
2021-03-29   TP-Link Devices - 'setDefaultHostname' Stored Cross-site Scripting (Unauthenticated) 30 WEB Smriti Gaba
2021-03-29   WordPress Plugin WP Super Cache 1.7.1 - Remote Code Execution (Authenticated) 28 WEB m0ze
2021-03-26   Moodle 3.10.3 - 'label' Persistent Cross Site Scripting 22 WEB Vincent666
2021-03-26   Regis Inventory And Monitoring System 1.0 - 'Item List' Persistent Cross-Site Scripting 25 WEB George Tsimpidas
2021-03-26   'customhs_js_content' - 'customhs_js_content' Cross-Site Request Forgery 24 WEB Abhishek Joshi
2021-03-25   Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE) 25 WEB Andrea Gonzalez
2021-03-25   Genexis Platinum-4410 P4410-V2-1.31A - 'start_addr' Persistent Cross-Site Scripting 19 WEB Jithin KS
2021-03-25   Linksys EA7500 2.0.8.194281 - Cross-Site Scripting 22 WEB MiningOmerta
2021-03-25   Ovidentia 6 - 'id' SQL injection (Authenticated) 22 WEB Felipe Prates Donato
2021-03-23   Codiad 2.8.4 - Remote Code Execution (Authenticated) 21 WEB WangYihang
2021-03-23   Hotel And Lodge Management System 1.0 - 'Customer Details' Stored XSS 24 WEB Jitendra Kumar Tripathi
2021-03-23   MyBB 1.8.25 - Poll Vote Count SQL Injection 23 WEB SivertPL
2021-03-22   MyBB 1.8.25 - Chained Remote Command Execution 25 WEB SivertPL
2021-03-22   WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal 28 WEB Nicholas Ferreira
2021-03-19   Online News Portal 1.0 - 'Multiple' Stored Cross-Site Scripting 22 WEB Richard Jones
2021-03-19   Online News Portal 1.0 - 'name' SQL Injection 29 WEB Richard Jones
2021-03-19   KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Config Download (Unauthenticated) 28 WEB LiquidWorm
2021-03-19   KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Factory Reset (Unauthenticated) 25 WEB LiquidWorm
2021-03-19   KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Remote Code Execution 25 WEB LiquidWorm
2021-03-19   KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Authentication Bypass 22 WEB LiquidWorm
2021-03-19   KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Command Injection (Authenticated) 25 WEB LiquidWorm
2021-03-19   SOYAL Biometric Access Control System 5.0 - 'Change Admin Password' CSRF 20 WEB LiquidWorm
2021-03-19   SOYAL Biometric Access Control System 5.0 - Master Code Disclosure 35 WEB LiquidWorm
2021-03-19   CouchCMS 2.2.1 - Server-Side Request Forgery 24 WEB xxcdd
2021-03-19   VestaCP 0.9.8 - 'v_sftp_licence' Command Injection 20 WEB numan türle
2021-03-19   Profiling System for Human Resource Management 1.0 - Remote Code Execution (Unauthenticated) 26 WEB Christian Vierschilling
2021-03-19   Boonex Dolphin 7.4.2 - 'width' Stored XSS 18 WEB Piyush Patil
2021-03-19   LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS 22 WEB Clément Cruchet
2021-03-19   Plone CMS 5.2.3 - 'Title' Stored XSS 23 WEB Piyush Patil
2021-03-18   Hestia Control Panel 1.3.2 - Arbitrary File Write 25 WEB numan türle
2021-03-18   SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (1) 31 WEB Piyush Patil
2021-03-18   rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (1) 23 WEB Murat ŞEKER
2021-03-18   VestaCP 0.9.8 - 'v_interface' Add IP Stored XSS 22 WEB numan türle
2021-03-17   VestaCP 0.9.8 - File Upload CSRF 28 WEB Fady Mohammed Osman
2021-03-17   WoWonder Social Network Platform 3.1 - 'event_id' SQL Injection 21 WEB securityforeveryone.com
2021-03-16   Alphaware E-Commerce System 1.0 - Unauthenicated Remote Code Execution (File Upload + SQL injection) 29 WEB Christian Vierschilling
2021-03-15   SonLogger 4.2.3.3 - Unauthenticated Arbitrary File Upload (Metasploit) 25 WEB Berkan Er
2021-03-15   Sonlogger 4.2.3.3 - SuperAdmin Account Creation / Information Disclosure 24 WEB Berkan Er
2021-03-15   openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scripting 22 WEB Hosein Vita
2021-03-15   rConfig 3.9.6 - 'path' Local File Inclusion (Authenticated) 24 WEB Murat ŞEKER
2021-03-15   MagpieRSS 0.72 - 'url' Command Injection 21 WEB bl4ckh4ck5
2021-03-15   Zenario CMS 8.8.53370 - 'id' Blind SQL Injection 30 WEB Balaji Ayyasamy
2021-03-12   Monitoring System (Dashboard) 1.0 - File Upload RCE (Authenticated) 24 WEB Richard Jones
2021-03-12   Monitoring System (Dashboard) 1.0 - 'uname' SQL Injection 28 WEB Richard Jones
2021-03-11   Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC) 27 WEB testanull
2021-03-11   CouchCMS 2.2.1 - Persistent Cross-Site Scripting 25 WEB xxcdd
2021-03-11   MyBB OUGC Feedback Plugin 1.8.22 - Cross-Site Scripting 23 WEB 0xB9
2021-03-11   NuCom 11N Wireless Router 5.07.90 - Remote Privilege Escalation 28 WEB LiquidWorm
2021-03-10   Atlassian JIRA 8.11.1 - User Enumeration 26 WEB Dolev Farhi
2021-03-08   GLPI 9.5.3 - 'fromtype' Unsafe Reflection 25 WEB Vadym Soroka
2021-03-08   Joomla JCK Editor 6.4.4 - 'parent' SQL Injection (2) 24 WEB Nicholas Ferreira
2021-03-08   Hotel and Lodge Management System 1.0 - Remote Code Execution (Unauthenticated) 25 WEB Christian Vierschilling
2021-03-05   Fluig 1.7.0 - Path Traversal 35 WEB Lucas Souza
2021-03-04   Textpattern 4.8.3 - Remote code execution (Authenticated) (2) 24 WEB Ricardo Ruiz
2021-03-04   Web Based Quiz System 1.0 - 'eid' Union Based Sql Injection (Authenticated) 27 WEB Deepak Kumar Bharti
2021-03-04   Online Ordering System 1.0 - Blind SQL Injection (Unauthenticated) 28 WEB Suraj Bhosale
2021-03-04   Textpattern CMS 4.9.0-dev - 'Excerpt' Persistent Cross-Site Scripting (XSS) 27 WEB Tushar Vaidya
2021-03-04   Textpattern CMS 4.8.4 - 'Comments' Persistent Cross-Site Scripting (XSS) 24 WEB Tushar Vaidya
2021-03-04   Online Ordering System 1.0 - Arbitrary File Upload 26 WEB Suraj Bhosale
2021-03-04   e107 CMS 2.3.0 - CSRF 32 WEB Tadjmen
2021-03-03   Local Services Search Engine Management System (LSSMES) 1.0 - Blind & Error based SQL injection (Aut 26 WEB Tushar Vaidya
2021-03-03   Local Services Search Engine Management System (LSSMES) 1.0 - 'name' Persistent Cross-Site Scripting 24 WEB Tushar Vaidya
2021-03-02   Zen Cart 1.5.7b - Remote Code Execution (Authenticated) 25 WEB Mücahit Saratar
2021-03-02   Web Based Quiz System 1.0 - 'name' Persistent Cross-Site Scripting 21 WEB P.Naveen Kumar
2021-03-02   Tiny Tiny RSS - Remote Code Execution 24 WEB Daniel Neagaru
2021-03-02   Web Based Quiz System 1.0 - 'MCQ options' Persistent Cross-Site Scripting 25 WEB Praharsh Kumar Singh
2021-03-01   Covid-19 Contact Tracing System 1.0 - Remote Code Execution (Unauthenticated) 41 WEB Christian Vierschilling
2021-03-01   Online Catering Reservation System 1.0 - Remote Code Execution (Unauthenticated) 27 WEB Christian Vierschilling
2021-03-01   VMware vCenter Server 7.0 - Unauthenticated File Upload 23 WEB Photubias
2021-03-01   FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit) 26 WEB Berkan Er
2021-02-26   LightCMS 1.3.4 - 'exclusive' Stored XSS 27 WEB Peithon
2021-02-26   Triconsole 3.75 - Reflected XSS 27 WEB Akash Chathoth
2021-02-26   Simple Employee Records System 1.0 - File Upload RCE (Unauthenticated) 28 WEB sml
2021-02-25   Vehicle Parking Management System 1.0 - 'catename' Persistent Cross-Site Scripting (XSS) 27 WEB Tushar Vaidya
2021-02-24   LayerBB 1.1.4 - 'search_query' SQL Injection 24 WEB Görkem Haşin
2021-02-23   Batflat CMS 1.3.6 - 'multiple' Stored XSS 26 WEB Tadjmen
2021-02-23   Monica 2.19.1 - 'last_name' Stored XSS 24 WEB BouSalman
2021-02-19   Beauty Parlour Management System 1.0 - 'sername' SQL Injection 29 WEB Thinkland Security Team
2021-02-19   OpenText Content Server 20.3 - 'multiple' Stored Cross-Site Scripting 23 WEB Kamil Breński
2021-02-19   Online Exam System With Timer 1.0 - 'email' SQL injection Auth Bypass 27 WEB Suresh Kumar
2021-02-19   Comment System 1.0 - 'multiple' Stored Cross-Site Scripting 29 WEB Pintu Solanki
2021-02-19   PEEL Shopping 9.3.0 - 'Comments' Persistent Cross-Site Scripting 26 WEB Anmol K Sachan
2021-02-18   Batflat CMS 1.3.6 - Remote Code Execution (Authenticated) 33 WEB mari0x00
2021-02-18   Gitea 1.12.5 - Remote Code Execution (Authenticated) 40 WEB Podalirius
2021-02-17   Billing Management System 2.0 - 'email' SQL injection Auth Bypass 33 WEB Pintu Solanki
2021-02-17   Faulty Evaluation System 1.0 - 'multiple' Stored Cross-Site Scripting 25 WEB Suresh Kumar
2021-02-16   BlackCat CMS 1.3.6 - 'Display name' Cross Site Scripting (XSS) 22 WEB Kamaljeet Kumar
2021-02-16   Online Internship Management System 1.0 - 'email' SQL injection Auth Bypass 19 WEB Christian Vierschilling
2021-02-15   Teachers Record Management System 1.0 - 'searchteacher' SQL Injection 26 WEB Soham Bakore
2021-02-15   TestLink 1.9.20 - Unrestricted File Upload (Authenticated) 24 WEB snovvcrash
2021-02-12   School Event Attendance Monitoring System 1.0 - 'Item Name' Stored Cross-Site Scripting 29 WEB Suresh Kumar
2021-02-12   School File Management System 1.0 - 'multiple' Stored Cross-Site Scripting 21 WEB Pintu Solanki
2021-02-11   Online Marriage Registration System (OMRS) 1.0 - Remote code execution (3) 22 WEB Ricardo Ruiz
2021-02-11   Openlitespeed WebServer 1.7.8 - Command Injection (Authenticated) (2) 25 WEB Metin Yunus Kandemir
2021-02-11   b2evolution 6.11.6 - 'tab3' Reflected XSS 25 WEB Nakul Ratti
2021-02-11   b2evolution 6.11.6 - 'redirect_to' Open Redirect 27 WEB Nakul Ratti
2021-02-11   PEEL Shopping 9.3.0 - 'address' Stored Cross-Site Scripting 22 WEB Anmol K Sachan
2021-02-10   Node.JS - 'node-serialize' Remote Code Execution (2) 22 WEB UndeadLarva
2021-02-10   b2evolution 6.11.6 - 'plugin name' Stored XSS 26 WEB Soham Bakore
2021-02-09   Adobe Connect 10 - Username Disclosure 26 WEB h4shur
2021-02-09   Online Car Rental System 1.0 - Stored Cross Site Scripting 25 WEB Naved Shaikh
2021-02-08   WordPress Plugin Supsystic Backup 2.3.9 - Local File Inclusion 28 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Contact Form 1.7.5 - Multiple Vulnerabilities 30 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Data Tables Generator 1.9.96 - Multiple Vulnerabilities 29 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Digital Publications 1.6.9 - Multiple Vulnerabilities 27 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Membership 1.4.7 - 'sidx' SQL injection 20 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Newsletter 1.5.5 - 'sidx' SQL injection 28 WEB Erik David Martin
2021-02-08   Alt-N MDaemon webmail 20.0.0 - 'file name' Stored Cross Site Scripting (XSS) 21 WEB Kailash Bohara
2021-02-08   Alt-N MDaemon webmail 20.0.0 - 'Contact name' Stored Cross Site Scripting (XSS) 20 WEB Kailash Bohara
2021-02-08   YetiShare File Hosting Script 5.1.0 - 'url' Server-Side Request Forgery 20 WEB numan türle
2021-02-08   WordPress Plugin Supsystic Pricing Table 1.8.7 - Multiple Vulnerabilities 28 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Ultimate Maps 1.1.12 - 'sidx' SQL injection 25 WEB Erik David Martin