2020-11-17
|
|
WordPress Plugin Buddypress 6.2.0 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2020-11-17
|
|
SugarCRM 6.5.18 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Vulnerability-Lab
|
2020-11-17
|
|
Online Doctor Appointment Booking System PHP and Mysql 1.0 - 'q' SQL Injection
|
4 |
WEB
|
Ramil Mustafayev
|
2020-11-17
|
|
EgavilanMedia User Registration & Login System with Admin Panel Exploit - SQLi Auth Bypass
|
4 |
WEB
|
Kislay Kumar
|
2020-11-16
|
|
Car Rental Management System 1.0 - 'car_id' Sql Injection
|
3 |
WEB
|
Mehmet Kelepçe
|
2020-11-16
|
|
Car Rental Management System 1.0 - Remote Code Execution (Authenticated)
|
4 |
WEB
|
Mehmet Kelepçe
|
2020-11-16
|
|
PMB 5.6 - 'chemin' Local File Disclosure
|
2 |
WEB
|
41-trk
|
2020-11-16
|
|
User Registration & Login and User Management System 2.1 - Login Bypass SQL Injection
|
2 |
WEB
|
Mayur Parmar
|
2020-11-16
|
|
Water Billing System 1.0 - 'id' SQL Injection (Authenticated)
|
1 |
WEB
|
Mehmet Kelepçe
|
2020-11-16
|
|
Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated)
|
2 |
WEB
|
Matthew Aberegg
|
2020-11-13
|
|
October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
|
3 |
WEB
|
Sivanesh Ashok
|
2020-11-13
|
|
OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
|
1 |
WEB
|
Jinson Varghese Behanan
|
2020-11-13
|
|
Touchbase.io 1.10 - Stored Cross Site Scripting
|
1 |
WEB
|
Simran Sankhala
|
2020-11-13
|
|
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
|
2 |
WEB
|
SunCSR
|
2020-11-13
|
|
Citrix ADC NetScaler - Local File Inclusion (Metasploit)
|
2 |
WEB
|
RAMELLA Sebastien
|
2020-11-13
|
|
Bludit 3.9.2 - Authentication Bruteforce Bypass (Metasploit)
|
2 |
WEB
|
Aporlorxl23
|
2020-11-13
|
|
ASUS TM-AC1900 - Arbitrary Command Execution (Metasploit)
|
1 |
WEB
|
b1ack0wl
|
2020-11-12
|
|
Wordpress Plugin Good LMS 2.1.4 - 'id' Unauthenticated SQL Injection
|
1 |
WEB
|
Abdulazeez Alaseeri
|
2020-11-12
|
|
Water Billing System 1.0 - 'username' and 'password' parameters SQL Injection
|
2 |
WEB
|
Sarang Tumne
|
2020-11-11
|
|
CMSUno 1.6.2 - 'user' Remote Code Execution (Authenticated)
|
2 |
WEB
|
Fatih Çelik
|
2020-11-11
|
|
Customer Support System 1.0 - 'username' Authentication Bypass
|
2 |
WEB
|
Ahmed Abbas
|
2020-11-11
|
|
Customer Support System 1.0 - Cross-Site Request Forgery
|
1 |
WEB
|
Ahmed Abbas
|
2020-11-11
|
|
Customer Support System 1.0 - 'description' Stored XSS in The Admin Panel
|
1 |
WEB
|
Ahmed Abbas
|
2020-11-10
|
|
Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection
|
2 |
WEB
|
Mufaddal Masalawala
|
2020-11-10
|
|
ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting
|
2 |
WEB
|
Joe Helle
|
2020-11-10
|
|
Car Rental Management System 1.0 - SQL injection + Arbitrary File Upload
|
2 |
WEB
|
Fortunato Lodari
|
2020-11-09
|
|
Joplin 1.2.6 - 'link' Cross Site Scripting
|
1 |
WEB
|
Philip Holbrook
|
2020-11-09
|
|
SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)
|
1 |
WEB
|
M. Cory Billington
|
2020-11-09
|
|
Genexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRF
|
2 |
WEB
|
Jinson Varghese Behanan
|
2020-11-06
|
|
BlogEngine 3.3.8 - 'Content' Stored XSS
|
2 |
WEB
|
Andrey Stoykov
|
2020-11-06
|
|
Sentrifugo Version 3.2 - 'announcements' Remote Code Execution (Authenticated)
|
2 |
WEB
|
Fatih Çelik
|
2020-11-06
|
|
Sentrifugo 3.2 - 'assets' Remote Code Execution (Authenticated)
|
2 |
WEB
|
Fatih Çelik
|
2020-11-06
|
|
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
|
2 |
WEB
|
Fatih Çelik
|
2020-11-06
|
|
SmartBlog 2.0.1 - 'id_post' Blind SQL injection
|
2 |
WEB
|
C0wnuts
|
2020-11-05
|
|
iDS6 DSSPro Digital Signage System 6.2 - Improper Access Control Privilege Escalation
|
1 |
WEB
|
LiquidWorm
|
2020-11-05
|
|
iDS6 DSSPro Digital Signage System 6.2 - CAPTCHA Security Bypass
|
2 |
WEB
|
LiquidWorm
|
2020-11-05
|
|
iDS6 DSSPro Digital Signage System 6.2 - Cross-Site Request Forgery (CSRF)
|
2 |
WEB
|
LiquidWorm
|
2020-11-04
|
|
Student Attendance Management System 1.0 - 'username' SQL Injection / Remote Code Execution
|
2 |
WEB
|
Mosaaed
|
2020-11-04
|
|
School Log Management System 1.0 - 'username' SQL Injection / Remote Code Execution
|
1 |
WEB
|
Mosaaed
|
2020-11-04
|
|
PDW File Browser 1.3 - Remote Code Execution
|
2 |
WEB
|
David Bimmel
|
2020-11-04
|
|
Processwire CMS 2.4.0 - 'download' Local File Inclusion
|
2 |
WEB
|
Y1LD1R1M
|
2020-11-03
|
|
Complaints Report Management System 1.0 - 'username' SQL Injection / Remote Code Execution
|
2 |
WEB
|
Mosaaed
|
2020-11-03
|
|
Multi Restaurant Table Reservation System 1.0 - 'table_id' Unauthenticated SQL Injection
|
1 |
WEB
|
yunaranyancat
|
2020-11-02
|
|
Monitorr 1.7.6m - Authorization Bypass
|
1 |
WEB
|
Lyhin\'s Lab
|
2020-11-02
|
|
Monitorr 1.7.6m - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
Lyhin\'s Lab
|
2020-11-02
|
|
WordPress Plugin Simple File List 4.2.2 - Arbitrary File Upload
|
2 |
WEB
|
H4rk3nz0
|
2020-11-02
|
|
Apache Flink 1.9.x - File Upload RCE (Unauthenticated)
|
2 |
WEB
|
bigger.wing
|
2020-10-30
|
|
Simple College Website 1.0 - 'username' SQL Injection / Remote Code Execution
|
1 |
WEB
|
yunaranyancat
|
2020-10-30
|
|
Online Job Portal 1.0 - 'userid' SQL Injection
|
2 |
WEB
|
Akıner Kısa
|
2020-10-30
|
|
Citadel WebCit < 926 - Session Hijacking Exploit
|
2 |
WEB
|
Simone Quatrini
|
2020-10-30
|
|
DedeCMS v.5.8 - _keyword_ Cross-Site Scripting
|
2 |
WEB
|
Noth
|
2020-10-30
|
|
CSE Bookstore 1.0 - 'quantity' Persistent Cross-site Scripting
|
1 |
WEB
|
Vyshnav nk
|
2020-10-29
|
|
Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot
|
2 |
WEB
|
Mohammed Farhan
|
2020-10-29
|
|
WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 - Unauthenticated RCE
|
2 |
WEB
|
Mohammed Althibyani
|
2020-10-29
|
|
Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS)
|
2 |
WEB
|
Valerio Alessandroni
|
2020-10-29
|
|
Online Examination System 1.0 - 'name' Stored Cross Site Scripting
|
1 |
WEB
|
Nikhil Kumar
|
2020-10-28
|
|
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewIma
|
1 |
WEB
|
Ivo Palazzolo
|
2020-10-28
|
|
CSE Bookstore 1.0 - Authentication Bypass
|
3 |
WEB
|
Alper Basaran
|
2020-10-28
|
|
Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
|
2 |
WEB
|
Matthew Aberegg
|
2020-10-27
|
|
Sphider Search Engine 1.3.6 - 'word_upper_bound' RCE (Authenticated)
|
2 |
WEB
|
Gurkirat Singh
|
2020-10-27
|
|
Client Management System 1.0 - 'searchdata' SQL injection
|
2 |
WEB
|
Serkan Sancar
|
2020-10-27
|
|
Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
|
2 |
WEB
|
Gurkirat Singh
|
2020-10-26
|
|
ReQuest Serious Play F3 Media Server 7.0.3 - Remote Code Execution (Unauthenticated)
|
1 |
WEB
|
LiquidWorm
|
2020-10-26
|
|
ReQuest Serious Play F3 Media Server 7.0.3 - Remote Denial of Service
|
1 |
WEB
|
LiquidWorm
|
2020-10-26
|
|
ReQuest Serious Play F3 Media Server 7.0.3 - Debug Log Disclosure
|
2 |
WEB
|
LiquidWorm
|
2020-10-26
|
|
ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure
|
2 |
WEB
|
LiquidWorm
|
2020-10-26
|
|
Genexis Platinum-4410 - 'SSID' Persistent XSS
|
1 |
WEB
|
Amal Mohandas
|
2020-10-26
|
|
PDW File Browser 1.3 - 'new_filename' Cross-Site Scripting (XSS)
|
2 |
WEB
|
David Bimmel
|
2020-10-26
|
|
InoERP 0.7.2 - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
Lyhin\'s Lab
|
2020-10-26
|
|
Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored)
|
2 |
WEB
|
Akıner Kısa
|
2020-10-26
|
|
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
|
2 |
WEB
|
Gurkirat Singh
|
2020-10-23
|
|
TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated)
|
2 |
WEB
|
0blio_
|
2020-10-23
|
|
Bludit 3.9.2 - Auth Bruteforce Bypass
|
2 |
WEB
|
Mayank Deshmukh
|
2020-10-23
|
|
Gym Management System 1.0 - Stored Cross Site Scripting
|
2 |
WEB
|
Jyotsna Adhana
|
2020-10-23
|
|
Gym Management System 1.0 - Authentication Bypass
|
2 |
WEB
|
Jyotsna Adhana
|
2020-10-23
|
|
School Faculty Scheduling System 1.0 - 'username' SQL Injection
|
2 |
WEB
|
Jyotsna Adhana
|
2020-10-23
|
|
School Faculty Scheduling System 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Jyotsna Adhana
|
2020-10-23
|
|
Point of Sales 1.0 - 'username' SQL Injection
|
2 |
WEB
|
Jyotsna Adhana
|
2020-10-23
|
|
Gym Management System 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Jyotsna Adhana
|
2020-10-23
|
|
Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored)
|
2 |
WEB
|
Ankita Pal
|
2020-10-23
|
|
Lot Reservation Management System 1.0 - Authentication Bypass
|
2 |
WEB
|
Ankita Pal
|
2020-10-23
|
|
Point of Sales 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Ankita Pal
|
2020-10-23
|
|
User Registration & Login and User Management System 2.1 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2020-10-23
|
|
Car Rental Management System 1.0 - Arbitrary File Upload
|
2 |
WEB
|
Jyotsna Adhana
|
2020-10-23
|
|
Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2020-10-23
|
|
Ajenti 2.1.36 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Ahmet Ümit BAYRAM
|
2020-10-23
|
|
Online Library Management System 1.0 - Arbitrary File Upload
|
1 |
WEB
|
Jyotsna Adhana
|
2020-10-21
|
|
Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
|
1 |
WEB
|
Maximilian Barz
|
2020-10-21
|
|
Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
|
1 |
WEB
|
Adeeb Shah
|
2020-10-21
|
|
Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scripting
|
0 |
WEB
|
Adeeb Shah
|
2020-10-21
|
|
Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scripting
|
1 |
WEB
|
Adeeb Shah
|
2020-10-21
|
|
GOautodial 4.0 - Authenticated Shell Upload
|
1 |
WEB
|
Balzabu
|
2020-10-21
|
|
School Faculty Scheduling System 1.0 - Authentication Bypass POC
|
1 |
WEB
|
Jyotsna Adhana
|
2020-10-21
|
|
School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
|
1 |
WEB
|
Jyotsna Adhana
|
2020-10-21
|
|
Hrsale 2.0.0 - Local File Inclusion
|
1 |
WEB
|
Sosecure
|
2020-10-20
|
|
WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting (Authenticated)
|
1 |
WEB
|
n1x_
|
2020-10-20
|
|
WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection
|
1 |
WEB
|
Jonatas Fil
|
2020-10-20
|
|
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
|
1 |
WEB
|
Jonatas Fil
|
2020-10-20
|
|
Mobile Shop System v1.0 - SQL Injection Authentication Bypass
|
1 |
WEB
|
Moaaz Taha
|
2020-10-20
|
|
RiteCMS 2.2.1 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
H0j3n
|
2020-10-20
|
|
User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS
|
1 |
WEB
|
yusufmalikul
|
2020-10-20
|
|
WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload
|
1 |
WEB
|
Net-Hunter
|
2020-10-20
|
|
Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated)
|
1 |
WEB
|
nag0mez
|
2020-10-20
|
|
Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
|
0 |
WEB
|
Rahul Ramkumar
|
2020-10-20
|
|
Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Courses Content Disclosure
|
1 |
WEB
|
redtimmysec
|
2020-10-20
|
|
Loan Management System 1.0 - Multiple Cross Site Scripting (Stored)
|
1 |
WEB
|
Akıner Kısa
|
2020-10-20
|
|
Comtrend AR-5387un router - Persistent XSS (Authenticated)
|
1 |
WEB
|
OscarAkaElvis
|
2020-10-19
|
|
Textpattern CMS 4.6.2 - Cross-site Request Forgery
|
1 |
WEB
|
Alperen Ergel
|
2020-10-19
|
|
Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
|
1 |
WEB
|
Rodolfo Tavares
|
2020-10-19
|
|
Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
|
1 |
WEB
|
Kokn3t
|
2020-10-19
|
|
Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
|
1 |
WEB
|
Daniel Morris
|
2020-10-19
|
|
HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
|
1 |
WEB
|
Alexei Kojenov
|
2020-10-19
|
|
HiSilicon Video Encoders - Full admin access via backdoor password
|
1 |
WEB
|
Alexei Kojenov
|
2020-10-19
|
|
HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware
|
1 |
WEB
|
Alexei Kojenov
|
2020-10-19
|
|
HiSilicon Video Encoders - RCE via unauthenticated command injection
|
0 |
WEB
|
Alexei Kojenov
|
2020-10-19
|
|
HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal
|
1 |
WEB
|
Alexei Kojenov
|
2020-10-19
|
|
Online Job Portal 1.0 - Cross Site Scripting (Stored)
|
1 |
WEB
|
Akıner Kısa
|
2020-10-19
|
|
Online Discussion Forum Site 1.0 - XSS in Messaging System
|
1 |
WEB
|
j5oh
|
2020-10-19
|
|
Online Student's Management System 1.0 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Akıner Kısa
|
2020-10-19
|
|
Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection
|
1 |
WEB
|
Matthew Aberegg
|
2020-10-19
|
|
Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection
|
1 |
WEB
|
Matthew Aberegg
|
2020-10-19
|
|
Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting
|
1 |
WEB
|
Matthew Aberegg
|
2020-10-19
|
|
Tourism Management System 1.0 - Arbitrary File Upload
|
0 |
WEB
|
Ankita Pal
|
2020-10-16
|
|
CS-Cart 1.3.3 - authenticated RCE
|
0 |
WEB
|
0xmmnbassel
|
2020-10-16
|
|
CS-Cart 1.3.3 - 'classes_dir' LFI
|
1 |
WEB
|
0xmmnbassel
|