Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-04-23   GetSimple CMS My SMTP Contact Plugin 1.1.2 - Persistent Cross-Site Scripting 30 WEB boku
2021-04-23   Moodle 3.10.3 - 'url' Persistent Cross Site Scripting 29 WEB UVision
2021-04-22   RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS) 26 WEB Saud Ahmad
2021-04-22   OTRS 6.0.1 - Remote Command Execution (2) 25 WEB Hex_26
2021-04-22   CMS Made Simple 2.2.15 - 'title' Cross-Site Scripting (XSS) 24 WEB bt0
2021-04-21   Hasura GraphQL 1.3.3 - Service Side Request Forgery (SSRF) 34 WEB Dolev Farhi
2021-04-21   Hasura GraphQL 1.3.3 - Local File Read 35 WEB Dolev Farhi
2021-04-21   GravCMS 1.10.7 - Unauthenticated Arbitrary File Write (Metasploit) 33 WEB Mehmet Ince
2021-04-21   Adtran Personal Phone Manager 10.8.1 - DNS Exfiltration 33 WEB 3ndG4me
2021-04-21   Adtran Personal Phone Manager 10.8.1 - 'Multiple' Reflected Cross-Site Scripting (XSS) 37 WEB 3ndG4me
2021-04-21   Adtran Personal Phone Manager 10.8.1 - 'emailAddress' Stored Cross-Site Scripting (XSS) 27 WEB 3ndG4me
2021-04-21   OpenEMR 5.0.2.1 - Remote Code Execution 35 WEB Hato0
2021-04-21   rconfig 3.9.6 - Arbitrary File Upload 29 WEB Vishwaraj Bhattrai
2021-04-21   RemoteClinic 2 - 'Multiple' Cross-Site Scripting (XSS) 29 WEB nu11secur1ty
2021-04-21   BlackCat CMS 1.3.6 - 'Multiple' Stored Cross-Site Scripting (XSS) 27 WEB Ömer Hasan Durmuş
2021-04-21   WordPress Plugin RSS for Yandex Turbo 1.29 - Stored Cross-Site Scripting (XSS) 31 WEB Himamshu Dilip Kulkarni
2021-04-21   Fast PHP Chat 1.3 - 'my_item_search' SQL Injection 30 WEB Fatih Coskun
2021-04-21   Multilaser Router RE018 AC1200 - Cross-Site Request Forgery (Enable Remote Access) 26 WEB Rodolfo Mariano
2021-04-16   GetSimple CMS My SMTP Contact Plugin 1.1.1 - Cross-Site Request Forgery 40 WEB boku
2021-04-15   htmly 2.8.0 - 'description' Stored Cross-Site Scripting (XSS) 32 WEB nu11secur1ty
2021-04-15   Tileserver-gl 3.0.0 - 'key' Reflected Cross-Site Scripting (XSS) 34 WEB Akash Chathoth
2021-04-15   Horde Groupware Webmail 5.2.22 - Stored XSS 28 WEB nu11secur1ty
2021-04-14   jQuery 1.0.3 - Cross-Site Scripting (XSS) 30 WEB Central InfoSec
2021-04-14   jQuery 1.2 - Cross-Site Scripting (XSS) 30 WEB Central InfoSec
2021-04-14   Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE 27 WEB Jay Sharma
2021-04-14   CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated) 29 WEB skysbsb
2021-04-14   CITSmart ITSM 9.1.2.22 - LDAP Injection 28 WEB skysbsb
2021-04-14   Digital Crime Report Management System 1.0 - SQL Injection (Authentication Bypass) 25 WEB GaluhID
2021-04-13   ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow 27 WEB Jai Kumar Sharma
2021-04-13   Blitar Tourism 1.0 - Authentication Bypass SQLi 28 WEB sigeri94
2021-04-13   Simple Student Information System 1.0 - SQL Injection (Authentication Bypass) 26 WEB GaluhID
2021-04-09   PrestaShop 1.7.6.7 - 'location' Blind Sql Injection 31 WEB Vanshal Gaur
2021-04-08   Composr 10.0.36 - Remote Code Execution 30 WEB Orion Hridoy
2021-04-08   DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF) 23 WEB Issac Briones
2021-04-08   CMSimple 5.2 - 'External' Stored XSS 28 WEB Quadron Research Lab
2021-04-07   Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read 26 WEB Rhino Security Labs
2021-04-07   Composr CMS 10.0.36 - Cross Site Scripting 25 WEB Orion Hridoy
2021-04-07   Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS 30 WEB Captain_hook
2021-04-06   Mini Mouse 9.3.0 - Local File inclusion 27 WEB gosh
2021-04-05   Mini Mouse 9.2.0 - Path Traversal 21 WEB gosh
2021-04-05   Mini Mouse 9.2.0 - Remote Code Execution 26 WEB gosh
2021-04-05   OpenEMR 4.1.0 - 'u' SQL Injection 29 WEB Michael Ikua
2021-04-05   Basic Shopping Cart 1.0 - Authentication Bypass 31 WEB Viren Saroha
2021-04-05   Simple Food Website 1.0 - Authentication Bypass 29 WEB Viren Saroha
2021-04-02   F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated) 30 WEB Al1ex
2021-04-02   ZBL EPON ONU Broadband Router 1.0 - Remote Privilege Escalation 27 WEB LiquidWorm
2021-04-01   phpPgAdmin 7.13.0 - COPY FROM PROGRAM Command Execution (Authenticated) 27 WEB Valerio Severini
2021-04-01   ScadaBR 1.0 - Arbitrary File Upload (Authenticated) (2) 29 WEB Fellipe Oliveira
2021-04-01   ScadaBR 1.0 - Arbitrary File Upload (Authenticated) (1) 27 WEB Fellipe Oliveira
2021-04-01   Latrix 0.6.0 - 'txtaccesscode' SQL Injection 29 WEB cptsticky
2021-03-31   CourseMS 2.1 - 'name' Stored XSS 33 WEB cptsticky
2021-03-31   Zabbix 3.4.7 - Stored XSS 31 WEB Radmil Gazizov
2021-03-30   Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting 30 WEB cmOs
2021-03-30   GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting 30 WEB boku
2021-03-29   SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow 28 WEB Filipe Oliveira
2021-03-29   Novel Boutique House-plus 3.5.1 - Arbitrary File Download 26 WEB tuyiqiang
2021-03-29   Budget Management System 1.0 - 'Budget title' Stored XSS 25 WEB Jitendra Kumar Tripathi
2021-03-29   Equipment Inventory System 1.0 - 'multiple' Stored XSS 25 WEB Jitendra Kumar Tripathi
2021-03-29   Concrete5 8.5.4 - 'name' Stored XSS 26 WEB Quadron Research Lab
2021-03-29   TP-Link Devices - 'setDefaultHostname' Stored Cross-site Scripting (Unauthenticated) 33 WEB Smriti Gaba
2021-03-29   WordPress Plugin WP Super Cache 1.7.1 - Remote Code Execution (Authenticated) 31 WEB m0ze
2021-03-26   Moodle 3.10.3 - 'label' Persistent Cross Site Scripting 27 WEB Vincent666
2021-03-26   Regis Inventory And Monitoring System 1.0 - 'Item List' Persistent Cross-Site Scripting 29 WEB George Tsimpidas
2021-03-26   'customhs_js_content' - 'customhs_js_content' Cross-Site Request Forgery 28 WEB Abhishek Joshi
2021-03-25   Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE) 28 WEB Andrea Gonzalez
2021-03-25   Genexis Platinum-4410 P4410-V2-1.31A - 'start_addr' Persistent Cross-Site Scripting 26 WEB Jithin KS
2021-03-25   Linksys EA7500 2.0.8.194281 - Cross-Site Scripting 26 WEB MiningOmerta
2021-03-25   Ovidentia 6 - 'id' SQL injection (Authenticated) 28 WEB Felipe Prates Donato
2021-03-23   Codiad 2.8.4 - Remote Code Execution (Authenticated) 25 WEB WangYihang
2021-03-23   Hotel And Lodge Management System 1.0 - 'Customer Details' Stored XSS 30 WEB Jitendra Kumar Tripathi
2021-03-23   MyBB 1.8.25 - Poll Vote Count SQL Injection 26 WEB SivertPL
2021-03-22   MyBB 1.8.25 - Chained Remote Command Execution 28 WEB SivertPL
2021-03-22   WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal 31 WEB Nicholas Ferreira
2021-03-19   Online News Portal 1.0 - 'Multiple' Stored Cross-Site Scripting 29 WEB Richard Jones
2021-03-19   Online News Portal 1.0 - 'name' SQL Injection 32 WEB Richard Jones
2021-03-19   KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Config Download (Unauthenticated) 31 WEB LiquidWorm
2021-03-19   KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Factory Reset (Unauthenticated) 31 WEB LiquidWorm
2021-03-19   KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Remote Code Execution 28 WEB LiquidWorm
2021-03-19   KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Authentication Bypass 25 WEB LiquidWorm
2021-03-19   KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Command Injection (Authenticated) 29 WEB LiquidWorm
2021-03-19   SOYAL Biometric Access Control System 5.0 - 'Change Admin Password' CSRF 24 WEB LiquidWorm
2021-03-19   SOYAL Biometric Access Control System 5.0 - Master Code Disclosure 46 WEB LiquidWorm
2021-03-19   CouchCMS 2.2.1 - Server-Side Request Forgery 28 WEB xxcdd
2021-03-19   VestaCP 0.9.8 - 'v_sftp_licence' Command Injection 24 WEB numan türle
2021-03-19   Profiling System for Human Resource Management 1.0 - Remote Code Execution (Unauthenticated) 30 WEB Christian Vierschilling
2021-03-19   Boonex Dolphin 7.4.2 - 'width' Stored XSS 22 WEB Piyush Patil
2021-03-19   LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS 26 WEB Clément Cruchet
2021-03-19   Plone CMS 5.2.3 - 'Title' Stored XSS 27 WEB Piyush Patil
2021-03-18   Hestia Control Panel 1.3.2 - Arbitrary File Write 30 WEB numan türle
2021-03-18   SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (1) 36 WEB Piyush Patil
2021-03-18   rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (1) 28 WEB Murat ŞEKER
2021-03-18   VestaCP 0.9.8 - 'v_interface' Add IP Stored XSS 26 WEB numan türle
2021-03-17   VestaCP 0.9.8 - File Upload CSRF 33 WEB Fady Mohammed Osman
2021-03-17   WoWonder Social Network Platform 3.1 - 'event_id' SQL Injection 26 WEB securityforeveryone.com
2021-03-16   Alphaware E-Commerce System 1.0 - Unauthenicated Remote Code Execution (File Upload + SQL injection) 39 WEB Christian Vierschilling
2021-03-15   SonLogger 4.2.3.3 - Unauthenticated Arbitrary File Upload (Metasploit) 31 WEB Berkan Er
2021-03-15   Sonlogger 4.2.3.3 - SuperAdmin Account Creation / Information Disclosure 29 WEB Berkan Er
2021-03-15   openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scripting 27 WEB Hosein Vita
2021-03-15   rConfig 3.9.6 - 'path' Local File Inclusion (Authenticated) 29 WEB Murat ŞEKER
2021-03-15   MagpieRSS 0.72 - 'url' Command Injection 26 WEB bl4ckh4ck5
2021-03-15   Zenario CMS 8.8.53370 - 'id' Blind SQL Injection 38 WEB Balaji Ayyasamy
2021-03-12   Monitoring System (Dashboard) 1.0 - File Upload RCE (Authenticated) 27 WEB Richard Jones
2021-03-12   Monitoring System (Dashboard) 1.0 - 'uname' SQL Injection 32 WEB Richard Jones
2021-03-11   Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC) 30 WEB testanull
2021-03-11   CouchCMS 2.2.1 - Persistent Cross-Site Scripting 30 WEB xxcdd
2021-03-11   MyBB OUGC Feedback Plugin 1.8.22 - Cross-Site Scripting 29 WEB 0xB9
2021-03-11   NuCom 11N Wireless Router 5.07.90 - Remote Privilege Escalation 34 WEB LiquidWorm
2021-03-10   Atlassian JIRA 8.11.1 - User Enumeration 31 WEB Dolev Farhi
2021-03-08   GLPI 9.5.3 - 'fromtype' Unsafe Reflection 30 WEB Vadym Soroka
2021-03-08   Joomla JCK Editor 6.4.4 - 'parent' SQL Injection (2) 29 WEB Nicholas Ferreira
2021-03-08   Hotel and Lodge Management System 1.0 - Remote Code Execution (Unauthenticated) 28 WEB Christian Vierschilling
2021-03-05   Fluig 1.7.0 - Path Traversal 38 WEB Lucas Souza
2021-03-04   Textpattern 4.8.3 - Remote code execution (Authenticated) (2) 30 WEB Ricardo Ruiz
2021-03-04   Web Based Quiz System 1.0 - 'eid' Union Based Sql Injection (Authenticated) 32 WEB Deepak Kumar Bharti
2021-03-04   Online Ordering System 1.0 - Blind SQL Injection (Unauthenticated) 32 WEB Suraj Bhosale
2021-03-04   Textpattern CMS 4.9.0-dev - 'Excerpt' Persistent Cross-Site Scripting (XSS) 31 WEB Tushar Vaidya
2021-03-04   Textpattern CMS 4.8.4 - 'Comments' Persistent Cross-Site Scripting (XSS) 30 WEB Tushar Vaidya
2021-03-04   Online Ordering System 1.0 - Arbitrary File Upload 30 WEB Suraj Bhosale
2021-03-04   e107 CMS 2.3.0 - CSRF 36 WEB Tadjmen
2021-03-03   Local Services Search Engine Management System (LSSMES) 1.0 - Blind & Error based SQL injection (Aut 30 WEB Tushar Vaidya
2021-03-03   Local Services Search Engine Management System (LSSMES) 1.0 - 'name' Persistent Cross-Site Scripting 30 WEB Tushar Vaidya
2021-03-02   Zen Cart 1.5.7b - Remote Code Execution (Authenticated) 31 WEB Mücahit Saratar
2021-03-02   Web Based Quiz System 1.0 - 'name' Persistent Cross-Site Scripting 26 WEB P.Naveen Kumar
2021-03-02   Tiny Tiny RSS - Remote Code Execution 28 WEB Daniel Neagaru
2021-03-02   Web Based Quiz System 1.0 - 'MCQ options' Persistent Cross-Site Scripting 30 WEB Praharsh Kumar Singh