2020-12-11
|
|
Courier Management System 1.0 - 'MULTIPART street ((custom) ' SQL Injection
|
3 |
WEB
|
Zhaiyi
|
2020-12-11
|
|
Courier Management System 1.0 - 'First Name' Stored XSS
|
2 |
WEB
|
Zhaiyi
|
2020-12-11
|
|
Dolibarr 12.0.3 - SQLi to RCE
|
1 |
WEB
|
coiffeur
|
2020-12-11
|
|
Supply Chain Management System - Auth Bypass SQL Injection
|
1 |
WEB
|
Piyush Malviya
|
2020-12-11
|
|
Rukovoditel 2.6.1 - RCE (1)
|
1 |
WEB
|
coiffeur
|
2020-12-11
|
|
Jenkins 2.235.3 - 'Description' Stored XSS
|
1 |
WEB
|
gx1
|
2020-12-11
|
|
Medical Center Portal Management System 1.0 - Multiple Stored XSS
|
1 |
WEB
|
Saeed Bala Ahmed
|
2020-12-11
|
|
Openfire 4.6.0 - 'sql' Stored XSS
|
1 |
WEB
|
j5s
|
2020-12-11
|
|
Openfire 4.6.0 - 'users' Stored XSS
|
1 |
WEB
|
j5s
|
2020-12-11
|
|
Openfire 4.6.0 - 'groupchatJID' Stored XSS
|
1 |
WEB
|
j5s
|
2020-12-11
|
|
Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting
|
3 |
WEB
|
gx1
|
2020-12-10
|
|
WordPress Plugin Popup Builder 3.69.6 - Multiple Stored Cross Site Scripting
|
2 |
WEB
|
Ilca Lucian Florin
|
2020-12-10
|
|
Library Management System 2.0 - Auth Bypass SQL Injection
|
3 |
WEB
|
Manish Solanki
|
2020-12-10
|
|
Openfire 4.6.0 - 'path' Stored XSS
|
3 |
WEB
|
j5s
|
2020-12-10
|
|
OpenCart 3.0.3.6 - Cross Site Request Forgery
|
4 |
WEB
|
Mahendra Purbia
|
2020-12-10
|
|
Barcodes generator 1.0 - 'name' Stored Cross Site Scripting
|
3 |
WEB
|
Nikhil Kumar
|
2020-12-09
|
|
Task Management System 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Saeed Bala Ahmed
|
2020-12-09
|
|
Task Management System 1.0 - Unrestricted File Upload to Remote Code Execution
|
3 |
WEB
|
Saeed Bala Ahmed
|
2020-12-09
|
|
Task Management System 1.0 - 'First Name and Last Name' Stored XSS
|
3 |
WEB
|
Saeed Bala Ahmed
|
2020-12-09
|
|
VestaCP 0.9.8-26 - 'backup' Information Disclosure
|
3 |
WEB
|
Vulnerability-Lab
|
2020-12-09
|
|
VestaCP 0.9.8-26 - 'LoginAs' Insufficient Session Validation
|
4 |
WEB
|
Vulnerability-Lab
|
2020-12-08
|
|
Employee Performance Evaluation System 1.0 - 'Task and Description' Persistent Cross Site Scripting
|
2 |
WEB
|
Ritesh Gohil
|
2020-12-08
|
|
Online Bus Ticket Reservation 1.0 - SQL Injection
|
2 |
WEB
|
Sakshi Sharma
|
2020-12-07
|
|
vBulletin 5.6.3 - 'group' Cross Site Scripting
|
2 |
WEB
|
Vincent666
|
2020-12-07
|
|
Savsoft Quiz 5 - 'Skype ID' Stored XSS
|
3 |
WEB
|
Dipak Panchal
|
2020-12-07
|
|
Cyber Cafe Management System Project (CCMS) 1.0 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Pruthvi Nekkanti
|
2020-12-04
|
|
Zabbix 5.0.0 - Stored XSS via URL Widget Iframe
|
2 |
WEB
|
Shwetabh Vishnoi
|
2020-12-04
|
|
CMS Made Simple 2.2.15 - Stored Cross-Site Scripting via SVG File Upload (Authenticated)
|
4 |
WEB
|
Eshan Singh
|
2020-12-04
|
|
Laravel Nova 3.7.0 - 'range' DoS
|
3 |
WEB
|
iqzer0
|
2020-12-04
|
|
Forma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting
|
4 |
WEB
|
Hemant Patidar
|
2020-12-04
|
|
Savsoft Quiz 5 - 'field_title' Stored Cross-Site Scripting
|
2 |
WEB
|
Dhruv Patel
|
2020-12-04
|
|
Testa Online Test Management System 3.4.7 - 'q' SQL Injection
|
3 |
WEB
|
Ultra Security Team
|
2020-12-04
|
|
MiniCMS 1.10 - 'content box' Stored XSS
|
3 |
WEB
|
yudp
|
2020-12-04
|
|
Phpscript-sgh 0.1.0 - Time Based Blind SQL Injection
|
2 |
WEB
|
KeopssGroup0day_Inc
|
2020-12-04
|
|
Composr CMS 10.0.34 - 'banners' Persistent Cross Site Scripting
|
3 |
WEB
|
Parshwa Bhavsar
|
2020-12-04
|
|
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
|
3 |
WEB
|
Pankaj Verma
|
2020-12-03
|
|
Invision Community 4.5.4 - 'Field Name' Stored Cross-Site Scripting
|
3 |
WEB
|
Hemant Patidar
|
2020-12-03
|
|
Sony BRAVIA Digital Signage 1.7.8 - System API Information Disclosure
|
3 |
WEB
|
LiquidWorm
|
2020-12-03
|
|
Sony BRAVIA Digital Signage 1.7.8 - Unauthenticated Remote File Inclusion
|
2 |
WEB
|
LiquidWorm
|
2020-12-03
|
|
mojoPortal forums 2.7.0.0 - 'Title' Persistent Cross-Site Scripting
|
2 |
WEB
|
Sagar Banwa
|
2020-12-03
|
|
Online Matrimonial Project 1.0 - Authenticated Remote Code Execution
|
3 |
WEB
|
Valerio Alessandroni
|
2020-12-03
|
|
EgavilanMedia Address Book 1.0 Exploit - SQLi Auth Bypass
|
3 |
WEB
|
Mayur Parmar
|
2020-12-03
|
|
Coastercms 5.8.18 - Stored XSS
|
3 |
WEB
|
Hardik Solanki
|
2020-12-03
|
|
User Registration & Login and User Management System 2.1 - Cross Site Request Forgery
|
3 |
WEB
|
Dipak Panchal
|
2020-12-02
|
|
WordPress Plugin Wp-FileManager 6.8 - RCE
|
2 |
WEB
|
Mansoor R
|
2020-12-02
|
|
Car Rental Management System 1.0 - SQL Injection / Local File include
|
3 |
WEB
|
Mosaaed
|
2020-12-02
|
|
Simple College Website 1.0 - 'page' Local File Inclusion
|
2 |
WEB
|
Mosaaed
|
2020-12-02
|
|
Anuko Time Tracker 1.19.23.5311 - Password Reset leading to Account Takeover
|
3 |
WEB
|
Mufaddal Masalawala
|
2020-12-02
|
|
Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality
|
2 |
WEB
|
Mufaddal Masalawala
|
2020-12-02
|
|
ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)
|
2 |
WEB
|
Mufaddal Masalawala
|
2020-12-02
|
|
ChurchCRM 4.2.0 - CSV/Formula Injection
|
2 |
WEB
|
Mufaddal Masalawala
|
2020-12-02
|
|
WebDamn User Registration & Login System with User Panel - SQLi Auth Bypass
|
2 |
WEB
|
Aakash Madaan
|
2020-12-02
|
|
DotCMS 20.11 - Stored Cross-Site Scripting
|
3 |
WEB
|
Hardik Solanki
|
2020-12-02
|
|
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile
|
3 |
WEB
|
Shahrukh Iqbal Mirza
|
2020-12-02
|
|
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Add Artwork
|
2 |
WEB
|
Shahrukh Iqbal Mirza
|
2020-12-02
|
|
Employee Record Management System 1.1 - Login Bypass SQL Injection
|
2 |
WEB
|
Anurag Kumar
|
2020-12-02
|
|
WonderCMS 3.1.3 - 'Menu' Persistent Cross-Site Scripting
|
2 |
WEB
|
Hemant Patidar
|
2020-12-02
|
|
Local Service Search Engine Management System 1.0 - SQLi Authentication Bypass
|
2 |
WEB
|
Aditya Wakhlu
|
2020-12-02
|
|
Online News Portal System 1.0 - 'Title' Stored Cross Site Scripting
|
3 |
WEB
|
Parshwa Bhavsar
|
2020-12-02
|
|
Bakeshop Online Ordering System 1.0 - 'Owner' Persistent Cross-site scripting
|
5 |
WEB
|
Parshwa Bhavsar
|
2020-12-02
|
|
NewsLister - Authenticated Persistent Cross-Site Scripting
|
3 |
WEB
|
Emre Aslan
|
2020-12-02
|
|
Online Voting System Project in PHP - 'username' Persistent Cross-Site Scripting
|
2 |
WEB
|
Sagar Banwa
|
2020-12-02
|
|
PRTG Network Monitor 20.4.63.1412 - 'maps' Stored XSS
|
3 |
WEB
|
Amin Rawah
|
2020-12-02
|
|
WonderCMS 3.1.3 - Authenticated Remote Code Execution
|
3 |
WEB
|
zetc0de
|
2020-12-02
|
|
WonderCMS 3.1.3 - Authenticated SSRF to Remote Remote Code Execution
|
2 |
WEB
|
zetc0de
|
2020-12-02
|
|
EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Stored Cross Site Scripting
|
3 |
WEB
|
Soushikta Chowdhury
|
2020-12-02
|
|
Student Result Management System 1.0 - Authentication Bypass SQL Injection
|
3 |
WEB
|
Ritesh Gohil
|
2020-12-02
|
|
EgavilanMedia User Registration & Login System with Admin Panel 1.0 - CSRF
|
3 |
WEB
|
Hardik Solanki
|
2020-12-02
|
|
Under Construction Page with CPanel 1.0 - SQL injection
|
3 |
WEB
|
Mayur Parmar
|
2020-12-02
|
|
Pharmacy Store Management System 1.0 - 'id' SQL Injection
|
3 |
WEB
|
Aydın Baran Ertemir
|
2020-12-02
|
|
ILIAS Learning Management System 4.3 - SSRF
|
2 |
WEB
|
Dot
|
2020-12-02
|
|
Expense Management System - 'description' Stored Cross Site Scripting
|
2 |
WEB
|
Nikhil Kumar
|
2020-12-01
|
|
Tendenci 12.3.1 - CSV/ Formula Injection
|
2 |
WEB
|
Mufaddal Masalawala
|
2020-12-01
|
|
Social Networking Site - Authentication Bypass (SQli)
|
2 |
WEB
|
gh1mau
|
2020-12-01
|
|
Pandora FMS 7.0 NG 749 - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Matthew Aberegg
|
2020-12-01
|
|
Medical Center Portal Management System 1.0 - 'login' SQL Injection
|
4 |
WEB
|
Aydın Baran Ertemir
|
2020-12-01
|
|
LEPTON CMS 4.7.0 - 'URL' Persistent Cross-Site Scripting
|
3 |
WEB
|
Sagar Banwa
|
2020-12-01
|
|
Tailor Management System 1.0 - Unrestricted File Upload to Remote Code Execution
|
4 |
WEB
|
Saeed Bala Ahmed
|
2020-12-01
|
|
Multi Restaurant Table Reservation System 1.0 - Multiple Persistent XSS
|
2 |
WEB
|
yunaranyancat
|
2020-12-01
|
|
Setelsa Conacwin 3.7.1.2 - Local File Inclusion
|
2 |
WEB
|
Bryan Rodriguez Martin
|
2020-12-01
|
|
Pharmacy/Medical Store & Sale Point 1.0 - 'email' SQL Injection
|
3 |
WEB
|
naivenom
|
2020-12-01
|
|
Online Shopping Alphaware 1.0 - Error Based SQL injection
|
3 |
WEB
|
Moaaz Taha
|
2020-12-01
|
|
Wordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site Scripting
|
4 |
WEB
|
B3KC4T
|
2020-12-01
|
|
Joomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File Upload
|
3 |
WEB
|
ThelastVvV
|
2020-12-01
|
|
TypeSetter 5.1 - CSRF (Change admin e-mail)
|
3 |
WEB
|
Alperen Ergel
|
2020-11-30
|
|
Intelbras Router RF 301K 1.1.2 - Authentication Bypass
|
3 |
WEB
|
Kaio Amaral
|
2020-11-30
|
|
Rejetto HttpFileServer 2.3.x - Remote Command Execution (3)
|
5 |
WEB
|
Óscar Andreu
|
2020-11-30
|
|
ATX MiniCMTS200a Broadband Gateway 2.0 - Credential Disclosure
|
4 |
WEB
|
Zagros Bingol
|
2020-11-27
|
|
Best Support System 3.0.4 - 'ticket_body' Persistent XSS (Authenticated)
|
3 |
WEB
|
Ex.Mi
|
2020-11-27
|
|
ElkarBackup 1.3.3 - 'Policy[name]' and 'Policy[Description]' Stored Cross-site Scripting
|
3 |
WEB
|
Vyshnav nk
|
2020-11-27
|
|
House Rental 1.0 - 'keywords' SQL Injection
|
3 |
WEB
|
boku
|
2020-11-27
|
|
Wordpress Theme Accesspress Social Icons 1.7.9 - SQL injection (Authenticated)
|
2 |
WEB
|
SunCSR
|
2020-11-27
|
|
Moodle 3.8 - Unrestricted File Upload
|
2 |
WEB
|
Sirwan Veisi
|
2020-11-27
|
|
Acronis Cyber Backup 12.5 Build 16341 - Unauthenticated SSRF
|
4 |
WEB
|
Julien Ahrens
|
2020-11-27
|
|
Laravel Administrator 4 - Unrestricted File Upload (Authenticated)
|
3 |
WEB
|
Xavi Beltran
|
2020-11-27
|
|
Ruckus IoT Controller (Ruckus vRIoT) 1.5.1.0.21 - Remote Code Execution
|
4 |
WEB
|
Emre SUREN
|
2020-11-27
|
|
WonderCMS 3.1.3 - 'uploadFile' Stored Cross-Site Scripting
|
2 |
WEB
|
Sun* Cyber Security Research Team
|
2020-11-27
|
|
Wordpress Theme Wibar 1.1.8 - 'Brand Component' Stored Cross Site Scripting
|
3 |
WEB
|
Ilca Lucian Florin
|
2020-11-25
|
|
SyncBreeze 10.0.28 - 'password' Remote Buffer Overflow
|
3 |
WEB
|
Abdessalam king
|
2020-11-25
|
|
osCommerce 2.3.4.1 - 'title' Persistent Cross-Site Scripting
|
3 |
WEB
|
Emre Aslan
|
2020-11-25
|
|
WonderCMS 3.1.3 - 'page' Persistent Cross-Site Scripting
|
4 |
WEB
|
Mayur Parmar
|
2020-11-24
|
|
OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
|
2 |
WEB
|
Hemant Patidar
|
2020-11-24
|
|
OpenCart 3.0.3.6 - 'Profile Image' Stored Cross-Site Scripting (Authenticated)
|
4 |
WEB
|
Hemant Patidar
|
2020-11-24
|
|
Seowon 130-SLC router 1.0.11 - 'ipAddr' RCE (Authenticated)
|
3 |
WEB
|
maj0rmil4d
|
2020-11-24
|
|
ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit)
|
3 |
WEB
|
Giuseppe Fuggiano
|
2020-11-24
|
|
Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service
|
2 |
WEB
|
SunCSR
|
2020-11-24
|
|
nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting
|
4 |
WEB
|
Hemant Patidar
|
2020-11-23
|
|
TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass
|
3 |
WEB
|
malwrforensics
|
2020-11-23
|
|
LifeRay 7.2.1 GA2 - Stored XSS
|
3 |
WEB
|
3ndG4me
|
2020-11-23
|
|
VTiger v7.0 CRM - 'To' Persistent XSS
|
2 |
WEB
|
Vulnerability-Lab
|
2020-11-20
|
|
WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting
|
3 |
WEB
|
Hemant Patidar
|
2020-11-19
|
|
Nagios Log Server 2.1.7 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Emre ÖVÜNÇ
|
2020-11-19
|
|
M/Monit 3.7.4 - Password Disclosure
|
3 |
WEB
|
Dolev Farhi
|
2020-11-19
|
|
M/Monit 3.7.4 - Privilege Escalation
|
4 |
WEB
|
Dolev Farhi
|
2020-11-19
|
|
Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection
|
3 |
WEB
|
Gabriele Zuddas
|
2020-11-19
|
|
TestBox CFML Test Framework 4.1.0 - Directory Traversal
|
3 |
WEB
|
Darren King
|
2020-11-19
|
|
TestBox CFML Test Framework 4.1.0 - Arbitrary File Write and Remote Code Execution
|
3 |
WEB
|
Darren King
|
2020-11-19
|
|
Gitlab 12.9.0 - Arbitrary File Read (Authenticated)
|
4 |
WEB
|
Jasper Rasenberg
|
2020-11-19
|
|
Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification
|
3 |
WEB
|
Ricardo Longatto
|
2020-11-19
|
|
xuucms 3 - 'keywords' SQL Injection
|
2 |
WEB
|
icekam
|
2020-11-19
|
|
PESCMS TEAM 2.3.2 - Multiple Reflected XSS
|
2 |
WEB
|
icekam
|
2020-11-18
|
|
BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery
|
2 |
WEB
|
RedTeam Pentesting GmbH
|
2020-11-18
|
|
Wordpress Plugin WPForms 1.6.3.1 - Persistent Cross Site Scripting (Authenticated)
|
4 |
WEB
|
ZwX
|
2020-11-17
|
|
Joomla Plugin Simple Image Gallery Extended (SIGE) 3.5.3 - Multiple Vulnerabilities
|
2 |
WEB
|
Vulnerability-Lab
|
2020-11-17
|
|
Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|