Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-01-05   Klog Server 2.4.1 - Command Injection (Unauthenticated) 20 WEB B3KC4T
2021-01-05   Online Learning Management System 1.0 - RCE (Authenticated) 26 WEB Bedri Sertkaya
2021-01-05   CSZ CMS 1.2.9 - Multiple Cross-Site Scripting 22 WEB SunCSR
2021-01-05   Cassandra Web 0.5.0 - Remote File Read 21 WEB Jeremy Brown
2021-01-05   HPE Edgeline Infrastructure Manager 1.0 - Multiple Remote Vulnerabilities 19 WEB Jeremy Brown
2021-01-05   Zoom Meeting Connector 4.6.239.20200613 - Remote Root Exploit (Authenticated) 23 WEB Jeremy Brown
2021-01-05   Responsive FileManager 9.13.4 - 'path' Path Traversal 20 WEB Sun* Cyber Security Research Team
2021-01-05   Baby Care System 1.0 - 'Post title' Stored XSS 18 WEB Hardik Solanki
2021-01-05   Responsive E-Learning System 1.0 - 'id' Sql Injection 24 WEB Kshitiz Raj
2021-01-05   Online Movie Streaming 1.0 - Authentication Bypass 21 WEB Kshitiz Raj
2021-01-05   WordPress Plugin WP-Paginate 2.1.3 - 'preset' Stored XSS 22 WEB Park Won Seok
2021-01-05   WordPress Plugin Stripe Payments 2.0.39 - 'AcceptStripePayments-settings[currency_code]' Stored XSS 25 WEB Park Won Seok
2021-01-05   Resumes Management and Job Application Website 1.0 - Authentication Bypass 20 WEB Kshitiz Raj
2021-01-05   IncomCMS 2.0 - Insecure File Upload 22 WEB MoeAlBarbari
2021-01-04   Arteco Web Client DVR/NVR - 'SessionId' Brute Force 22 WEB LiquidWorm
2021-01-04   Click2Magic 1.1.5 - Stored Cross-Site Scripting 24 WEB Shivam Verma
2021-01-04   Subrion CMS 4.2.1 - 'avatar[path]' XSS 19 WEB icekam
2021-01-04   CMS Made Simple 2.2.15 - RCE (Authenticated) 17 WEB Andrey Stoykov
2021-01-04   sar2html 3.2.1 - 'plot' Remote Code Execution 23 WEB Musyoka Ian
2021-01-04   Advanced Comment System 1.0 - 'ACS_path' Path Traversal 21 WEB Francisco Javier Santiago Vázquez
2021-01-04   Mantis Bug Tracker 2.24.3 - 'access' SQL Injection 23 WEB EthicalHCOP
2021-01-04   4images v1.7.11 - 'Profile Image' Stored Cross-Site Scripting 26 WEB Ritesh Gohil
2021-01-04   Wordpress Core 5.2.2 - 'post previews' XSS 29 WEB gx1
2020-12-24   Apartment Visitors Management System 1.0 - Authentication Bypass 24 WEB Kshitiz Raj
2020-12-24   GitLab 11.4.7 - RCE (Authenticated) (2) 21 WEB Norbert Hofmann
2020-12-24   WordPress Plugin WP-PostRatings 1.86 - 'postratings_image' Cross-Site Scripting 24 WEB Park Won Seok
2020-12-24   WordPress Plugin Adning Advertising 1.5.5 - Arbitrary File Upload 22 WEB spacehen
2020-12-23   Baby Care System 1.0 - 'roleid' SQL Injection 20 WEB Vijay Sachdeva
2020-12-23   TerraMaster TOS 4.2.06 - Unauthenticated Remote Code Execution (Metasploit) 21 WEB AkkuS
2020-12-23   Sales and Inventory System for Grocery Store 1.0 - Multiple Stored XSS 19 WEB Vijay Sachdeva
2020-12-23   Wordpress Epsilon Framework Multiple Themes - Unauthenticated Function Injection 41 WEB gx1
2020-12-23   Online Learning Management System 1.0 - 'id' SQL Injection 23 WEB Aakash Madaan
2020-12-23   Online Learning Management System 1.0 - Multiple Stored XSS 20 WEB Aakash Madaan
2020-12-23   Online Learning Management System 1.0 - Authentication Bypass 23 WEB Aakash Madaan
2020-12-23   Class Scheduling System 1.0 - Multiple Stored XSS 23 WEB Aakash Madaan
2020-12-22   TerraMaster TOS 4.2.06 - RCE (Unauthenticated) 25 WEB IHTeam
2020-12-22   Faculty Evaluation System 1.0 - Stored XSS 23 WEB Vijay Sachdeva
2020-12-22   Artworks Gallery Management System 1.0 - 'id' SQL Injection 23 WEB Vijay Sachdeva
2020-12-22   Webmin 1.962 - 'Package Updates' Escape Bypass RCE (Metasploit) 22 WEB AkkuS
2020-12-22   WordPress Plugin W3 Total Cache - Unauthenticated Arbitrary File Read (Metasploit) 20 WEB SunCSR Team
2020-12-22   Multi Branch School Management System 3.5 - _Create Branch_ Stored XSS 26 WEB Kislay Kumar
2020-12-22   Library Management System 3.0 - _Add Category_ Stored XSS 21 WEB Kislay Kumar
2020-12-22   CSE Bookstore 1.0 - Multiple SQL Injection 33 WEB Musyoka Ian
2020-12-22   Pandora FMS 7.0 NG 750 - 'Network Scan' SQL Injection (Authenticated) 23 WEB Matthew Aberegg
2020-12-22   Victor CMS 1.0 - File Upload To RCE 26 WEB Mosaaed
2020-12-16   Sony Playstation 4 (PS4) < 7.02 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code 21 WEB ChendoChap
2020-11-12   Sony Playstation 4 (PS4) < 6.72 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code 16 WEB Synacktiv
2020-12-21   Online Marriage Registration System 1.0 - 'searchdata' SQL Injection 22 WEB Raffaele Sabato
2020-12-21   Point of Sale System 1.0 - Multiple Stored XSS 18 WEB Saeed Bala Ahmed
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS 17 WEB Marco Nappi
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS 21 WEB Marco Nappi
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS 21 WEB Marco Nappi
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS 22 WEB Marco Nappi
2020-12-21   SCO Openserver 5.0.7 - 'outputform' Command Injection 21 WEB Ramikan
2020-12-21   SCO Openserver 5.0.7 - 'section' Reflected XSS 18 WEB Ramikan
2020-12-21   Spiceworks 7.5 - HTTP Header Injection 24 WEB Ramikan
2020-12-21   Academy-LMS 4.3 - Stored XSS 19 WEB Vinicius Alves
2020-12-21   Spotweb 1.4.9 - 'search' SQL Injection 24 WEB BouSalman
2020-12-21   Queue Management System 4.0.0 - _Add User_ Stored XSS 24 WEB Kislay Kumar
2020-12-18   Xeroneit Library Management System 3.1 - _Add Book Category _ Stored XSS 24 WEB Kislay Kumar
2020-12-18   SyncBreeze 10.0.28 - 'login' Denial of Service (Poc) 24 WEB Ahmed Elkhressy
2020-12-18   Smart Hospital 3.1 - _Add Patient_ Stored XSS 28 WEB Kislay Kumar
2020-12-18   Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read (Metasploit) 24 WEB SunCSR Team
2020-12-18   Alumni Management System 1.0 - 'id' SQL Injection 26 WEB Aakash Madaan
2020-12-18   Alumni Management System 1.0 - _Course Form_ Stored XSS 29 WEB Aakash Madaan
2020-12-18   Alumni Management System 1.0 - Unrestricted File Upload To RCE 29 WEB Aakash Madaan
2020-12-18   Point of Sale System 1.0 - Authentication Bypass 26 WEB Saeed Bala Ahmed
2020-12-17   Victor CMS 1.0 - Multiple SQL Injection (Authenticated) 27 WEB Furkan Göksel
2020-12-17   PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting) 27 WEB Andrea Intilangelo
2020-12-17   Employee Record System 1.0 - Multiple Stored XSS 24 WEB Saeed Bala Ahmed
2020-12-17   Interview Management System 1.0 - 'id' SQL Injection 23 WEB Saeed Bala Ahmed
2020-12-17   Interview Management System 1.0 - Stored XSS in Add New Question 19 WEB Saeed Bala Ahmed
2020-12-17   Online Tours & Travels Management System 1.0 - _id_ SQL Injection 25 WEB Saeed Bala Ahmed
2020-12-17   Customer Support System 1.0 - 'id' SQL Injection 22 WEB Saeed Bala Ahmed
2020-12-17   Customer Support System 1.0 - _First Name_ & _Last Name_ Stored XSS 21 WEB Saeed Bala Ahmed
2020-12-17   Medical Center Portal Management System 1.0 - 'id' SQL Injection 23 WEB Saeed Bala Ahmed
2020-12-17   Content Management System 1.0 - 'id' SQL Injection 23 WEB Zhaiyi
2020-12-17   Content Management System 1.0 - 'email' SQL Injection 23 WEB Zhaiyi
2020-12-17   Content Management System 1.0 - 'First Name' Stored XSS 23 WEB Zhaiyi
2020-12-17   Linksys RE6500 1.0.11.001 - Unauthenticated RCE 27 WEB RE-Solver
2020-12-17   Dolibarr ERP-CRM 12.0.3 - Remote Code Execution (Authenticated) 23 WEB Yilmaz Degirmenci
2020-12-16   Seotoaster 3.2.0 - Stored XSS on Edit page properties 20 WEB Hardik Solanki
2020-12-16   PrestaShop ProductComments 4.2.0 - 'id_products' Time Based Blind SQL Injection 24 WEB Frederic ADAM
2020-12-16   Magic Home Pro 1.5.1 - Authentication Bypass 25 WEB Victor Hanna
2020-12-16   Raysync 3.3.3.8 - RCE 25 WEB james
2020-12-16   Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting 28 WEB Sagar Banwa
2020-12-15   Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2) 24 WEB Freakyclown
2020-12-15   Online Marriage Registration System (OMRS) 1.0 - Remote Code Execution (2) 24 WEB Andrea Bruschi
2020-12-15   Task Management System 1.0 - 'page' Local File Inclusion 25 WEB İsmail BOZKURT
2020-12-14   GitLab 11.4.7 - Remote Code Execution (Authenticated) (1) 26 WEB Fortunato Lodari
2020-12-14   Macally WIFISD2-2A82 2.000.010 - Guest to Root Privilege Escalation 24 WEB Maximilian Barz
2020-12-14   Rumble Mail Server 0.51.3135 - 'username' Stored XSS 25 WEB Mohammed Alshehri
2020-12-14   Rumble Mail Server 0.51.3135 - 'domain and path' Stored XSS 22 WEB Mohammed Alshehri
2020-12-14   Rumble Mail Server 0.51.3135 - 'servername' Stored XSS 21 WEB Mohammed Alshehri
2020-12-14   WordPress Plugin Total Upkeep 1.14.9 - Database and Files Backup Download 24 WEB Wadeek
2020-12-14   Seacms 11.1 - 'checkuser' Stored XSS 27 WEB j5s
2020-12-14   Seacms 11.1 - 'file' Local File Inclusion 29 WEB j5s
2020-12-14   Seacms 11.1 - 'ip and weburl' Remote Command Execution 31 WEB j5s
2020-12-14   MiniWeb HTTP Server 0.8.19 - Buffer Overflow (PoC) 30 WEB securityforeveryone.com
2020-12-14   LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection 21 WEB Hodorsec
2020-12-14   Rukovoditel 2.6.1 - Cross-Site Request Forgery (Change password) 24 WEB KeopssGroup0day_Inc
2020-12-14   Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS 22 WEB gx1
2020-12-11   Courier Management System 1.0 - 'ref_no' SQL Injection 21 WEB Zhaiyi
2020-12-11   Courier Management System 1.0 - 'MULTIPART street ((custom) ' SQL Injection 23 WEB Zhaiyi
2020-12-11   Courier Management System 1.0 - 'First Name' Stored XSS 20 WEB Zhaiyi
2020-12-11   Dolibarr 12.0.3 - SQLi to RCE 18 WEB coiffeur
2020-12-11   Supply Chain Management System - Auth Bypass SQL Injection 19 WEB Piyush Malviya
2020-12-11   Rukovoditel 2.6.1 - RCE (1) 18 WEB coiffeur
2020-12-11   Jenkins 2.235.3 - 'Description' Stored XSS 18 WEB gx1
2020-12-11   Medical Center Portal Management System 1.0 - Multiple Stored XSS 22 WEB Saeed Bala Ahmed
2020-12-11   Openfire 4.6.0 - 'sql' Stored XSS 20 WEB j5s
2020-12-11   Openfire 4.6.0 - 'users' Stored XSS 19 WEB j5s
2020-12-11   Openfire 4.6.0 - 'groupchatJID' Stored XSS 17 WEB j5s
2020-12-11   Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting 19 WEB gx1
2020-12-10   WordPress Plugin Popup Builder 3.69.6 - Multiple Stored Cross Site Scripting 19 WEB Ilca Lucian Florin
2020-12-10   Library Management System 2.0 - Auth Bypass SQL Injection 18 WEB Manish Solanki
2020-12-10   Openfire 4.6.0 - 'path' Stored XSS 19 WEB j5s
2020-12-10   OpenCart 3.0.3.6 - Cross Site Request Forgery 24 WEB Mahendra Purbia
2020-12-10   Barcodes generator 1.0 - 'name' Stored Cross Site Scripting 21 WEB Nikhil Kumar
2020-12-09   Task Management System 1.0 - 'id' SQL Injection 26 WEB Saeed Bala Ahmed
2020-12-09   Task Management System 1.0 - Unrestricted File Upload to Remote Code Execution 21 WEB Saeed Bala Ahmed
2020-12-09   Task Management System 1.0 - 'First Name and Last Name' Stored XSS 23 WEB Saeed Bala Ahmed
2020-12-09   VestaCP 0.9.8-26 - 'backup' Information Disclosure 22 WEB Vulnerability-Lab
2020-12-09   VestaCP 0.9.8-26 - 'LoginAs' Insufficient Session Validation 27 WEB Vulnerability-Lab
2020-12-08   Employee Performance Evaluation System 1.0 - 'Task and Description' Persistent Cross Site Scripting 22 WEB Ritesh Gohil