Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-11-17   WordPress Plugin Buddypress 6.2.0 - Persistent Cross-Site Scripting 3 WEB Vulnerability-Lab
2020-11-17   SugarCRM 6.5.18 - Persistent Cross-Site Scripting 4 WEB Vulnerability-Lab
2020-11-17   Online Doctor Appointment Booking System PHP and Mysql 1.0 - 'q' SQL Injection 4 WEB Ramil Mustafayev
2020-11-17   EgavilanMedia User Registration & Login System with Admin Panel Exploit - SQLi Auth Bypass 4 WEB Kislay Kumar
2020-11-16   Car Rental Management System 1.0 - 'car_id' Sql Injection 3 WEB Mehmet Kelepçe
2020-11-16   Car Rental Management System 1.0 - Remote Code Execution (Authenticated) 4 WEB Mehmet Kelepçe
2020-11-16   PMB 5.6 - 'chemin' Local File Disclosure 2 WEB 41-trk
2020-11-16   User Registration & Login and User Management System 2.1 - Login Bypass SQL Injection 2 WEB Mayur Parmar
2020-11-16   Water Billing System 1.0 - 'id' SQL Injection (Authenticated) 1 WEB Mehmet Kelepçe
2020-11-16   Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated) 2 WEB Matthew Aberegg
2020-11-13   October CMS Build 465 - Arbitrary File Read Exploit (Authenticated) 3 WEB Sivanesh Ashok
2020-11-13   OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure 1 WEB Jinson Varghese Behanan
2020-11-13   Touchbase.io 1.10 - Stored Cross Site Scripting 1 WEB Simran Sankhala
2020-11-13   Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit) 2 WEB SunCSR
2020-11-13   Citrix ADC NetScaler - Local File Inclusion (Metasploit) 2 WEB RAMELLA Sebastien
2020-11-13   Bludit 3.9.2 - Authentication Bruteforce Bypass (Metasploit) 2 WEB Aporlorxl23
2020-11-13   ASUS TM-AC1900 - Arbitrary Command Execution (Metasploit) 1 WEB b1ack0wl
2020-11-12   Wordpress Plugin Good LMS 2.1.4 - 'id' Unauthenticated SQL Injection 1 WEB Abdulazeez Alaseeri
2020-11-12   Water Billing System 1.0 - 'username' and 'password' parameters SQL Injection 2 WEB Sarang Tumne
2020-11-11   CMSUno 1.6.2 - 'user' Remote Code Execution (Authenticated) 2 WEB Fatih Çelik
2020-11-11   Customer Support System 1.0 - 'username' Authentication Bypass 2 WEB Ahmed Abbas
2020-11-11   Customer Support System 1.0 - Cross-Site Request Forgery 1 WEB Ahmed Abbas
2020-11-11   Customer Support System 1.0 - 'description' Stored XSS in The Admin Panel 1 WEB Ahmed Abbas
2020-11-10   Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection 2 WEB Mufaddal Masalawala
2020-11-10   ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting 2 WEB Joe Helle
2020-11-10   Car Rental Management System 1.0 - SQL injection + Arbitrary File Upload 2 WEB Fortunato Lodari
2020-11-09   Joplin 1.2.6 - 'link' Cross Site Scripting 1 WEB Philip Holbrook
2020-11-09   SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated) 1 WEB M. Cory Billington
2020-11-09   Genexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRF 2 WEB Jinson Varghese Behanan
2020-11-06   BlogEngine 3.3.8 - 'Content' Stored XSS 2 WEB Andrey Stoykov
2020-11-06   Sentrifugo Version 3.2 - 'announcements' Remote Code Execution (Authenticated) 2 WEB Fatih Çelik
2020-11-06   Sentrifugo 3.2 - 'assets' Remote Code Execution (Authenticated) 2 WEB Fatih Çelik
2020-11-06   CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated) 2 WEB Fatih Çelik
2020-11-06   SmartBlog 2.0.1 - 'id_post' Blind SQL injection 2 WEB C0wnuts
2020-11-05   iDS6 DSSPro Digital Signage System 6.2 - Improper Access Control Privilege Escalation 1 WEB LiquidWorm
2020-11-05   iDS6 DSSPro Digital Signage System 6.2 - CAPTCHA Security Bypass 2 WEB LiquidWorm
2020-11-05   iDS6 DSSPro Digital Signage System 6.2 - Cross-Site Request Forgery (CSRF) 2 WEB LiquidWorm
2020-11-04   Student Attendance Management System 1.0 - 'username' SQL Injection / Remote Code Execution 2 WEB Mosaaed
2020-11-04   School Log Management System 1.0 - 'username' SQL Injection / Remote Code Execution 1 WEB Mosaaed
2020-11-04   PDW File Browser 1.3 - Remote Code Execution 2 WEB David Bimmel
2020-11-04   Processwire CMS 2.4.0 - 'download' Local File Inclusion 2 WEB Y1LD1R1M
2020-11-03   Complaints Report Management System 1.0 - 'username' SQL Injection / Remote Code Execution 2 WEB Mosaaed
2020-11-03   Multi Restaurant Table Reservation System 1.0 - 'table_id' Unauthenticated SQL Injection 1 WEB yunaranyancat
2020-11-02   Monitorr 1.7.6m - Authorization Bypass 1 WEB Lyhin\'s Lab
2020-11-02   Monitorr 1.7.6m - Remote Code Execution (Unauthenticated) 2 WEB Lyhin\'s Lab
2020-11-02   WordPress Plugin Simple File List 4.2.2 - Arbitrary File Upload 2 WEB H4rk3nz0
2020-11-02   Apache Flink 1.9.x - File Upload RCE (Unauthenticated) 2 WEB bigger.wing
2020-10-30   Simple College Website 1.0 - 'username' SQL Injection / Remote Code Execution 1 WEB yunaranyancat
2020-10-30   Online Job Portal 1.0 - 'userid' SQL Injection 2 WEB Akıner Kısa
2020-10-30   Citadel WebCit < 926 - Session Hijacking Exploit 2 WEB Simone Quatrini
2020-10-30   DedeCMS v.5.8 - _keyword_ Cross-Site Scripting 2 WEB Noth
2020-10-30   CSE Bookstore 1.0 - 'quantity' Persistent Cross-site Scripting 1 WEB Vyshnav nk
2020-10-29   Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot 2 WEB Mohammed Farhan
2020-10-29   WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 - Unauthenticated RCE 2 WEB Mohammed Althibyani
2020-10-29   Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS) 2 WEB Valerio Alessandroni
2020-10-29   Online Examination System 1.0 - 'name' Stored Cross Site Scripting 1 WEB Nikhil Kumar
2020-10-28   Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewIma 1 WEB Ivo Palazzolo
2020-10-28   CSE Bookstore 1.0 - Authentication Bypass 3 WEB Alper Basaran
2020-10-28   Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated) 2 WEB Matthew Aberegg
2020-10-27   Sphider Search Engine 1.3.6 - 'word_upper_bound' RCE (Authenticated) 2 WEB Gurkirat Singh
2020-10-27   Client Management System 1.0 - 'searchdata' SQL injection 2 WEB Serkan Sancar
2020-10-27   Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated) 2 WEB Gurkirat Singh
2020-10-26   ReQuest Serious Play F3 Media Server 7.0.3 - Remote Code Execution (Unauthenticated) 1 WEB LiquidWorm
2020-10-26   ReQuest Serious Play F3 Media Server 7.0.3 - Remote Denial of Service 1 WEB LiquidWorm
2020-10-26   ReQuest Serious Play F3 Media Server 7.0.3 - Debug Log Disclosure 2 WEB LiquidWorm
2020-10-26   ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure 2 WEB LiquidWorm
2020-10-26   Genexis Platinum-4410 - 'SSID' Persistent XSS 1 WEB Amal Mohandas
2020-10-26   PDW File Browser 1.3 - 'new_filename' Cross-Site Scripting (XSS) 2 WEB David Bimmel
2020-10-26   InoERP 0.7.2 - Remote Code Execution (Unauthenticated) 2 WEB Lyhin\'s Lab
2020-10-26   Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored) 2 WEB Akıner Kısa
2020-10-26   CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection 2 WEB Gurkirat Singh
2020-10-23   TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated) 2 WEB 0blio_
2020-10-23   Bludit 3.9.2 - Auth Bruteforce Bypass 2 WEB Mayank Deshmukh
2020-10-23   Gym Management System 1.0 - Stored Cross Site Scripting 2 WEB Jyotsna Adhana
2020-10-23   Gym Management System 1.0 - Authentication Bypass 2 WEB Jyotsna Adhana
2020-10-23   School Faculty Scheduling System 1.0 - 'username' SQL Injection 2 WEB Jyotsna Adhana
2020-10-23   School Faculty Scheduling System 1.0 - 'id' SQL Injection 1 WEB Jyotsna Adhana
2020-10-23   Point of Sales 1.0 - 'username' SQL Injection 2 WEB Jyotsna Adhana
2020-10-23   Gym Management System 1.0 - 'id' SQL Injection 1 WEB Jyotsna Adhana
2020-10-23   Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored) 2 WEB Ankita Pal
2020-10-23   Lot Reservation Management System 1.0 - Authentication Bypass 2 WEB Ankita Pal
2020-10-23   Point of Sales 1.0 - 'id' SQL Injection 2 WEB Ankita Pal
2020-10-23   User Registration & Login and User Management System 2.1 - SQL Injection 2 WEB Ihsan Sencan
2020-10-23   Car Rental Management System 1.0 - Arbitrary File Upload 2 WEB Jyotsna Adhana
2020-10-23   Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection 2 WEB Ihsan Sencan
2020-10-23   Ajenti 2.1.36 - Remote Code Execution (Authenticated) 1 WEB Ahmet Ümit BAYRAM
2020-10-23   Online Library Management System 1.0 - Arbitrary File Upload 1 WEB Jyotsna Adhana
2020-10-21   Tiki Wiki CMS Groupware 21.1 - Authentication Bypass 1 WEB Maximilian Barz
2020-10-21   Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting 1 WEB Adeeb Shah
2020-10-21   Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scripting 0 WEB Adeeb Shah
2020-10-21   Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scripting 1 WEB Adeeb Shah
2020-10-21   GOautodial 4.0 - Authenticated Shell Upload 1 WEB Balzabu
2020-10-21   School Faculty Scheduling System 1.0 - Authentication Bypass POC 1 WEB Jyotsna Adhana
2020-10-21   School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC 1 WEB Jyotsna Adhana
2020-10-21   Hrsale 2.0.0 - Local File Inclusion 1 WEB Sosecure
2020-10-20   WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting (Authenticated) 1 WEB n1x_
2020-10-20   WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection 1 WEB Jonatas Fil
2020-10-20   Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution 1 WEB Jonatas Fil
2020-10-20   Mobile Shop System v1.0 - SQL Injection Authentication Bypass 1 WEB Moaaz Taha
2020-10-20   RiteCMS 2.2.1 - Remote Code Execution (Authenticated) 1 WEB H0j3n
2020-10-20   User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS 1 WEB yusufmalikul
2020-10-20   WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload 1 WEB Net-Hunter
2020-10-20   Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated) 1 WEB nag0mez
2020-10-20   Visitor Management System in PHP 1.0 - SQL Injection (Authenticated) 0 WEB Rahul Ramkumar
2020-10-20   Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Courses Content Disclosure 1 WEB redtimmysec
2020-10-20   Loan Management System 1.0 - Multiple Cross Site Scripting (Stored) 1 WEB Akıner Kısa
2020-10-20   Comtrend AR-5387un router - Persistent XSS (Authenticated) 1 WEB OscarAkaElvis
2020-10-19   Textpattern CMS 4.6.2 - Cross-site Request Forgery 1 WEB Alperen Ergel
2020-10-19   Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated) 1 WEB Rodolfo Tavares
2020-10-19   Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields) 1 WEB Kokn3t
2020-10-19   Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in 1 WEB Daniel Morris
2020-10-19   HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS) 1 WEB Alexei Kojenov
2020-10-19   HiSilicon Video Encoders - Full admin access via backdoor password 1 WEB Alexei Kojenov
2020-10-19   HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware 1 WEB Alexei Kojenov
2020-10-19   HiSilicon Video Encoders - RCE via unauthenticated command injection 0 WEB Alexei Kojenov
2020-10-19   HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal 1 WEB Alexei Kojenov
2020-10-19   Online Job Portal 1.0 - Cross Site Scripting (Stored) 1 WEB Akıner Kısa
2020-10-19   Online Discussion Forum Site 1.0 - XSS in Messaging System 1 WEB j5oh
2020-10-19   Online Student's Management System 1.0 - Remote Code Execution (Authenticated) 1 WEB Akıner Kısa
2020-10-19   Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection 1 WEB Matthew Aberegg
2020-10-19   Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection 1 WEB Matthew Aberegg
2020-10-19   Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting 1 WEB Matthew Aberegg
2020-10-19   Tourism Management System 1.0 - Arbitrary File Upload 0 WEB Ankita Pal
2020-10-16   CS-Cart 1.3.3 - authenticated RCE 0 WEB 0xmmnbassel
2020-10-16   CS-Cart 1.3.3 - 'classes_dir' LFI 1 WEB 0xmmnbassel