Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-01-15   Online Hotel Reservation System 1.0 - 'person' time-based SQL Injection 24 WEB Mesut Cetin
2021-01-15   Online Hotel Reservation System 1.0 - Cross-site request forgery (CSRF) 22 WEB Mesut Cetin
2021-01-15   Online Hotel Reservation System 1.0 - 'id' Time-based SQL Injection 23 WEB Mesut Cetin
2021-01-15   Online Hotel Reservation System 1.0 - 'description' Stored Cross-site Scripting 23 WEB Mesut Cetin
2021-01-15   WordPress Plugin Easy Contact Form 1.1.7 - 'Name' Stored Cross-Site Scripting (XSS) 27 WEB Rahul Ramakant Singh
2021-01-15   PHP-Fusion CMS 9.03.90 - Cross-Site Request Forgery (Delete admin shoutbox message) 23 WEB Mohamed Oosman
2021-01-14   Laravel 8.4.2 debug mode - Remote code execution 23 WEB SunCSR Team
2021-01-14   Online Shopping Cart System 1.0 - 'id' SQL Injection 25 WEB Aydın Baran Ertemir
2021-01-14   Nagios XI 5.7.X - Remote Code Execution RCE (Authenticated) 24 WEB Haboob Team
2021-01-14   Online Movie Streaming 1.0 - Admin Authentication Bypass 21 WEB Richard Jones
2021-01-13   Online Hotel Reservation System 1.0 - Admin Authentication Bypass 25 WEB Richard Jones
2021-01-12   SmartAgent 3.1.0 - Privilege Escalation 30 WEB Orion Hridoy
2021-01-12   Cemetry Mapping and Information System 1.0 - Multiple SQL Injections 28 WEB Mesut Cetin
2021-01-12   Gila CMS 2.0.0 - Remote Code Execution (Unauthenticated) 30 WEB Enesdex
2021-01-11   Prestashop 1.7.7.0 - 'id_product' Time Based Blind SQL Injection 26 WEB Jaimin Gondaliya
2021-01-11   OpenCart 3.0.36 - ATO via Cross Site Request Forgery 26 WEB Mahendra Purbia
2021-01-11   WordPress Plugin Custom Global Variables 1.0.5 - 'name' Stored Cross-Site Scripting (XSS) 26 WEB Swapnil Subhash Bodekar
2021-01-11   Cemetry Mapping and Information System 1.0 - Multiple Stored Cross-Site Scripting 27 WEB Mesut Cetin
2021-01-11   EyesOfNetwork 5.3 - LFI 26 WEB Audencia Business SCHOOL Red Team
2021-01-11   Anchor CMS 0.12.7 - 'markdown' Stored Cross-Site Scripting 28 WEB Ramazan Mert GÖKTEN
2021-01-11   EyesOfNetwork 5.3 - RCE & PrivEsc 28 WEB Audencia Business SCHOOL Red Team
2021-01-08   Wordpress Plugin wpDiscuz 7.0.4 - Unauthenticated Arbitrary File Upload (Metasploit) 31 WEB SunCSR Team
2021-01-08   WordPress Plugin Autoptimize 2.7.6 - Authenticated Arbitrary File Upload (Metasploit) 23 WEB SunCSR Team
2021-01-08   Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit) 27 WEB SunCSR Team
2021-01-08   Cockpit Version 234 - Server-Side Request Forgery (Unauthenticated) 23 WEB Metin Yunus Kandemir
2021-01-08   Online Doctor Appointment System 1.0 - 'Multiple' Stored XSS 24 WEB Mohamed habib Smidi
2021-01-08   Life Insurance Management System 1.0 - Multiple Stored XSS 25 WEB Arnav Tripathy
2021-01-07   CRUD Operation 1.0 - Multiple Stored XSS 23 WEB Arnav Tripathy
2021-01-07   ECSIMAGING PACS 6.21.5 - SQL injection 26 WEB shoxxdj
2021-01-07   Curfew e-Pass Management System 1.0 - Stored XSS 26 WEB Arnav Tripathy
2021-01-07   Cockpit CMS 0.6.1 - Remote Code Execution 25 WEB Rafael Resende
2021-01-07   Employee Record System 1.0 - Unrestricted File Upload to Remote Code Execution 27 WEB Saeed Bala Ahmed
2021-01-07   ECSIMAGING PACS 6.21.5 - Remote code execution 24 WEB shoxxdj
2021-01-07   iBall-Baton WRA150N Rom-0 Backup - File Disclosure (Sensitive Information) 24 WEB h4cks1n
2021-01-06   Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated) 30 WEB 1F98D
2021-01-06   Gitea 1.7.5 - Remote Code Execution 41 WEB 1F98D
2021-01-06   Resumes Management and Job Application Website 1.0 - RCE (Unauthenticated) 26 WEB Arnav Tripathy
2021-01-06   Newgen Correspondence Management System (corms) eGov 12.0 - IDOR 30 WEB ALI AL SINAN
2021-01-06   WordPress Plugin WP24 Domain Check 1.6.2 - 'fieldnameDomain' Stored Cross Site Scripting 27 WEB Mehmet Kelepçe
2021-01-06   Responsive E-Learning System 1.0 - Stored Cross Site Scripting 25 WEB Kshitiz Raj
2021-01-06   Responsive E-Learning System 1.0 - Unrestricted File Upload to RCE 28 WEB Kshitiz Raj
2021-01-06   WordPress Plugin litespeed cache 3.6 - 'server_ip' Cross-Site Scripting 28 WEB Nhat Ha
2021-01-06   Expense Tracker 1.0 - 'Expense Name' Stored Cross-Site Scripting 30 WEB Shivam Verma
2021-01-06   IPeakCMS 3.5 - Boolean-based blind SQLi 28 WEB MoeAlBarbari
2021-01-06   Advanced Webhost Billing System 3.7.0 - Cross-Site Request Forgery (CSRF) 25 WEB Rahul Ramakant Singh
2021-01-05   EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Persistent Cross-Site Scriptin 29 WEB Mesut Cetin
2021-01-05   Klog Server 2.4.1 - Command Injection (Unauthenticated) 24 WEB B3KC4T
2021-01-05   Online Learning Management System 1.0 - RCE (Authenticated) 30 WEB Bedri Sertkaya
2021-01-05   CSZ CMS 1.2.9 - Multiple Cross-Site Scripting 26 WEB SunCSR
2021-01-05   Cassandra Web 0.5.0 - Remote File Read 25 WEB Jeremy Brown
2021-01-05   HPE Edgeline Infrastructure Manager 1.0 - Multiple Remote Vulnerabilities 23 WEB Jeremy Brown
2021-01-05   Zoom Meeting Connector 4.6.239.20200613 - Remote Root Exploit (Authenticated) 28 WEB Jeremy Brown
2021-01-05   Responsive FileManager 9.13.4 - 'path' Path Traversal 24 WEB Sun* Cyber Security Research Team
2021-01-05   Baby Care System 1.0 - 'Post title' Stored XSS 23 WEB Hardik Solanki
2021-01-05   Responsive E-Learning System 1.0 - 'id' Sql Injection 28 WEB Kshitiz Raj
2021-01-05   Online Movie Streaming 1.0 - Authentication Bypass 27 WEB Kshitiz Raj
2021-01-05   WordPress Plugin WP-Paginate 2.1.3 - 'preset' Stored XSS 26 WEB Park Won Seok
2021-01-05   WordPress Plugin Stripe Payments 2.0.39 - 'AcceptStripePayments-settings[currency_code]' Stored XSS 28 WEB Park Won Seok
2021-01-05   Resumes Management and Job Application Website 1.0 - Authentication Bypass 23 WEB Kshitiz Raj
2021-01-05   IncomCMS 2.0 - Insecure File Upload 26 WEB MoeAlBarbari
2021-01-04   Arteco Web Client DVR/NVR - 'SessionId' Brute Force 26 WEB LiquidWorm
2021-01-04   Click2Magic 1.1.5 - Stored Cross-Site Scripting 30 WEB Shivam Verma
2021-01-04   Subrion CMS 4.2.1 - 'avatar[path]' XSS 26 WEB icekam
2021-01-04   CMS Made Simple 2.2.15 - RCE (Authenticated) 23 WEB Andrey Stoykov
2021-01-04   sar2html 3.2.1 - 'plot' Remote Code Execution 27 WEB Musyoka Ian
2021-01-04   Advanced Comment System 1.0 - 'ACS_path' Path Traversal 26 WEB Francisco Javier Santiago Vázquez
2021-01-04   Mantis Bug Tracker 2.24.3 - 'access' SQL Injection 26 WEB EthicalHCOP
2021-01-04   4images v1.7.11 - 'Profile Image' Stored Cross-Site Scripting 29 WEB Ritesh Gohil
2021-01-04   Wordpress Core 5.2.2 - 'post previews' XSS 32 WEB gx1
2020-12-24   Apartment Visitors Management System 1.0 - Authentication Bypass 29 WEB Kshitiz Raj
2020-12-24   GitLab 11.4.7 - RCE (Authenticated) (2) 26 WEB Norbert Hofmann
2020-12-24   WordPress Plugin WP-PostRatings 1.86 - 'postratings_image' Cross-Site Scripting 29 WEB Park Won Seok
2020-12-24   WordPress Plugin Adning Advertising 1.5.5 - Arbitrary File Upload 28 WEB spacehen
2020-12-23   Baby Care System 1.0 - 'roleid' SQL Injection 25 WEB Vijay Sachdeva
2020-12-23   TerraMaster TOS 4.2.06 - Unauthenticated Remote Code Execution (Metasploit) 26 WEB AkkuS
2020-12-23   Sales and Inventory System for Grocery Store 1.0 - Multiple Stored XSS 23 WEB Vijay Sachdeva
2020-12-23   Wordpress Epsilon Framework Multiple Themes - Unauthenticated Function Injection 45 WEB gx1
2020-12-23   Online Learning Management System 1.0 - 'id' SQL Injection 28 WEB Aakash Madaan
2020-12-23   Online Learning Management System 1.0 - Multiple Stored XSS 24 WEB Aakash Madaan
2020-12-23   Online Learning Management System 1.0 - Authentication Bypass 27 WEB Aakash Madaan
2020-12-23   Class Scheduling System 1.0 - Multiple Stored XSS 29 WEB Aakash Madaan
2020-12-22   TerraMaster TOS 4.2.06 - RCE (Unauthenticated) 30 WEB IHTeam
2020-12-22   Faculty Evaluation System 1.0 - Stored XSS 27 WEB Vijay Sachdeva
2020-12-22   Artworks Gallery Management System 1.0 - 'id' SQL Injection 26 WEB Vijay Sachdeva
2020-12-22   Webmin 1.962 - 'Package Updates' Escape Bypass RCE (Metasploit) 27 WEB AkkuS
2020-12-22   WordPress Plugin W3 Total Cache - Unauthenticated Arbitrary File Read (Metasploit) 24 WEB SunCSR Team
2020-12-22   Multi Branch School Management System 3.5 - _Create Branch_ Stored XSS 34 WEB Kislay Kumar
2020-12-22   Library Management System 3.0 - _Add Category_ Stored XSS 27 WEB Kislay Kumar
2020-12-22   CSE Bookstore 1.0 - Multiple SQL Injection 38 WEB Musyoka Ian
2020-12-22   Pandora FMS 7.0 NG 750 - 'Network Scan' SQL Injection (Authenticated) 30 WEB Matthew Aberegg
2020-12-22   Victor CMS 1.0 - File Upload To RCE 31 WEB Mosaaed
2020-12-16   Sony Playstation 4 (PS4) < 7.02 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code 25 WEB ChendoChap
2020-11-12   Sony Playstation 4 (PS4) < 6.72 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code 21 WEB Synacktiv
2020-12-21   Online Marriage Registration System 1.0 - 'searchdata' SQL Injection 26 WEB Raffaele Sabato
2020-12-21   Point of Sale System 1.0 - Multiple Stored XSS 23 WEB Saeed Bala Ahmed
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS 23 WEB Marco Nappi
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS 25 WEB Marco Nappi
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS 24 WEB Marco Nappi
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS 26 WEB Marco Nappi
2020-12-21   SCO Openserver 5.0.7 - 'outputform' Command Injection 25 WEB Ramikan
2020-12-21   SCO Openserver 5.0.7 - 'section' Reflected XSS 22 WEB Ramikan
2020-12-21   Spiceworks 7.5 - HTTP Header Injection 29 WEB Ramikan
2020-12-21   Academy-LMS 4.3 - Stored XSS 23 WEB Vinicius Alves
2020-12-21   Spotweb 1.4.9 - 'search' SQL Injection 29 WEB BouSalman
2020-12-21   Queue Management System 4.0.0 - _Add User_ Stored XSS 28 WEB Kislay Kumar
2020-12-18   Xeroneit Library Management System 3.1 - _Add Book Category _ Stored XSS 28 WEB Kislay Kumar
2020-12-18   SyncBreeze 10.0.28 - 'login' Denial of Service (Poc) 27 WEB Ahmed Elkhressy
2020-12-18   Smart Hospital 3.1 - _Add Patient_ Stored XSS 32 WEB Kislay Kumar
2020-12-18   Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read (Metasploit) 28 WEB SunCSR Team
2020-12-18   Alumni Management System 1.0 - 'id' SQL Injection 29 WEB Aakash Madaan
2020-12-18   Alumni Management System 1.0 - _Course Form_ Stored XSS 32 WEB Aakash Madaan
2020-12-18   Alumni Management System 1.0 - Unrestricted File Upload To RCE 32 WEB Aakash Madaan
2020-12-18   Point of Sale System 1.0 - Authentication Bypass 29 WEB Saeed Bala Ahmed
2020-12-17   Victor CMS 1.0 - Multiple SQL Injection (Authenticated) 31 WEB Furkan Göksel
2020-12-17   PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting) 33 WEB Andrea Intilangelo
2020-12-17   Employee Record System 1.0 - Multiple Stored XSS 29 WEB Saeed Bala Ahmed
2020-12-17   Interview Management System 1.0 - 'id' SQL Injection 28 WEB Saeed Bala Ahmed
2020-12-17   Interview Management System 1.0 - Stored XSS in Add New Question 22 WEB Saeed Bala Ahmed
2020-12-17   Online Tours & Travels Management System 1.0 - _id_ SQL Injection 29 WEB Saeed Bala Ahmed
2020-12-17   Customer Support System 1.0 - 'id' SQL Injection 25 WEB Saeed Bala Ahmed
2020-12-17   Customer Support System 1.0 - _First Name_ & _Last Name_ Stored XSS 28 WEB Saeed Bala Ahmed
2020-12-17   Medical Center Portal Management System 1.0 - 'id' SQL Injection 28 WEB Saeed Bala Ahmed
2020-12-17   Content Management System 1.0 - 'id' SQL Injection 26 WEB Zhaiyi
2020-12-17   Content Management System 1.0 - 'email' SQL Injection 27 WEB Zhaiyi
2020-12-17   Content Management System 1.0 - 'First Name' Stored XSS 28 WEB Zhaiyi