Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-12-22   TerraMaster TOS 4.2.06 - RCE (Unauthenticated) 37 WEB IHTeam
2020-12-22   Faculty Evaluation System 1.0 - Stored XSS 35 WEB Vijay Sachdeva
2020-12-22   Artworks Gallery Management System 1.0 - 'id' SQL Injection 34 WEB Vijay Sachdeva
2020-12-22   Webmin 1.962 - 'Package Updates' Escape Bypass RCE (Metasploit) 36 WEB AkkuS
2020-12-22   WordPress Plugin W3 Total Cache - Unauthenticated Arbitrary File Read (Metasploit) 32 WEB SunCSR Team
2020-12-22   Multi Branch School Management System 3.5 - _Create Branch_ Stored XSS 41 WEB Kislay Kumar
2020-12-22   Library Management System 3.0 - _Add Category_ Stored XSS 34 WEB Kislay Kumar
2020-12-22   CSE Bookstore 1.0 - Multiple SQL Injection 48 WEB Musyoka Ian
2020-12-22   Pandora FMS 7.0 NG 750 - 'Network Scan' SQL Injection (Authenticated) 37 WEB Matthew Aberegg
2020-12-22   Victor CMS 1.0 - File Upload To RCE 38 WEB Mosaaed
2020-12-16   Sony Playstation 4 (PS4) < 7.02 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code 32 WEB ChendoChap
2020-11-12   Sony Playstation 4 (PS4) < 6.72 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code 28 WEB Synacktiv
2020-12-21   Online Marriage Registration System 1.0 - 'searchdata' SQL Injection 34 WEB Raffaele Sabato
2020-12-21   Point of Sale System 1.0 - Multiple Stored XSS 30 WEB Saeed Bala Ahmed
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS 30 WEB Marco Nappi
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS 34 WEB Marco Nappi
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS 33 WEB Marco Nappi
2020-12-21   Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS 34 WEB Marco Nappi
2020-12-21   SCO Openserver 5.0.7 - 'outputform' Command Injection 35 WEB Ramikan
2020-12-21   SCO Openserver 5.0.7 - 'section' Reflected XSS 31 WEB Ramikan
2020-12-21   Spiceworks 7.5 - HTTP Header Injection 38 WEB Ramikan
2020-12-21   Academy-LMS 4.3 - Stored XSS 32 WEB Vinicius Alves
2020-12-21   Spotweb 1.4.9 - 'search' SQL Injection 37 WEB BouSalman
2020-12-21   Queue Management System 4.0.0 - _Add User_ Stored XSS 36 WEB Kislay Kumar
2020-12-18   Xeroneit Library Management System 3.1 - _Add Book Category _ Stored XSS 38 WEB Kislay Kumar
2020-12-18   SyncBreeze 10.0.28 - 'login' Denial of Service (Poc) 36 WEB Ahmed Elkhressy
2020-12-18   Smart Hospital 3.1 - _Add Patient_ Stored XSS 40 WEB Kislay Kumar
2020-12-18   Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read (Metasploit) 38 WEB SunCSR Team
2020-12-18   Alumni Management System 1.0 - 'id' SQL Injection 38 WEB Aakash Madaan
2020-12-18   Alumni Management System 1.0 - _Course Form_ Stored XSS 41 WEB Aakash Madaan
2020-12-18   Alumni Management System 1.0 - Unrestricted File Upload To RCE 42 WEB Aakash Madaan
2020-12-18   Point of Sale System 1.0 - Authentication Bypass 37 WEB Saeed Bala Ahmed
2020-12-17   Victor CMS 1.0 - Multiple SQL Injection (Authenticated) 39 WEB Furkan Göksel
2020-12-17   PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting) 41 WEB Andrea Intilangelo
2020-12-17   Employee Record System 1.0 - Multiple Stored XSS 38 WEB Saeed Bala Ahmed
2020-12-17   Interview Management System 1.0 - 'id' SQL Injection 37 WEB Saeed Bala Ahmed
2020-12-17   Interview Management System 1.0 - Stored XSS in Add New Question 30 WEB Saeed Bala Ahmed
2020-12-17   Online Tours & Travels Management System 1.0 - _id_ SQL Injection 37 WEB Saeed Bala Ahmed
2020-12-17   Customer Support System 1.0 - 'id' SQL Injection 33 WEB Saeed Bala Ahmed
2020-12-17   Customer Support System 1.0 - _First Name_ & _Last Name_ Stored XSS 38 WEB Saeed Bala Ahmed
2020-12-17   Medical Center Portal Management System 1.0 - 'id' SQL Injection 37 WEB Saeed Bala Ahmed
2020-12-17   Content Management System 1.0 - 'id' SQL Injection 34 WEB Zhaiyi
2020-12-17   Content Management System 1.0 - 'email' SQL Injection 36 WEB Zhaiyi
2020-12-17   Content Management System 1.0 - 'First Name' Stored XSS 38 WEB Zhaiyi
2020-12-17   Linksys RE6500 1.0.11.001 - Unauthenticated RCE 40 WEB RE-Solver
2020-12-17   Dolibarr ERP-CRM 12.0.3 - Remote Code Execution (Authenticated) 34 WEB Yilmaz Degirmenci
2020-12-16   Seotoaster 3.2.0 - Stored XSS on Edit page properties 34 WEB Hardik Solanki
2020-12-16   PrestaShop ProductComments 4.2.0 - 'id_products' Time Based Blind SQL Injection 37 WEB Frederic ADAM
2020-12-16   Magic Home Pro 1.5.1 - Authentication Bypass 41 WEB Victor Hanna
2020-12-16   Raysync 3.3.3.8 - RCE 37 WEB james
2020-12-16   Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting 39 WEB Sagar Banwa
2020-12-15   Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2) 35 WEB Freakyclown
2020-12-15   Online Marriage Registration System (OMRS) 1.0 - Remote Code Execution (2) 39 WEB Andrea Bruschi
2020-12-15   Task Management System 1.0 - 'page' Local File Inclusion 36 WEB İsmail BOZKURT
2020-12-14   GitLab 11.4.7 - Remote Code Execution (Authenticated) (1) 37 WEB Fortunato Lodari
2020-12-14   Macally WIFISD2-2A82 2.000.010 - Guest to Root Privilege Escalation 36 WEB Maximilian Barz
2020-12-14   Rumble Mail Server 0.51.3135 - 'username' Stored XSS 36 WEB Mohammed Alshehri
2020-12-14   Rumble Mail Server 0.51.3135 - 'domain and path' Stored XSS 36 WEB Mohammed Alshehri
2020-12-14   Rumble Mail Server 0.51.3135 - 'servername' Stored XSS 37 WEB Mohammed Alshehri
2020-12-14   WordPress Plugin Total Upkeep 1.14.9 - Database and Files Backup Download 37 WEB Wadeek
2020-12-14   Seacms 11.1 - 'checkuser' Stored XSS 37 WEB j5s
2020-12-14   Seacms 11.1 - 'file' Local File Inclusion 44 WEB j5s
2020-12-14   Seacms 11.1 - 'ip and weburl' Remote Command Execution 42 WEB j5s
2020-12-14   MiniWeb HTTP Server 0.8.19 - Buffer Overflow (PoC) 43 WEB securityforeveryone.com
2020-12-14   LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection 35 WEB Hodorsec
2020-12-14   Rukovoditel 2.6.1 - Cross-Site Request Forgery (Change password) 36 WEB KeopssGroup0day_Inc
2020-12-14   Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS 33 WEB gx1
2020-12-11   Courier Management System 1.0 - 'ref_no' SQL Injection 37 WEB Zhaiyi
2020-12-11   Courier Management System 1.0 - 'MULTIPART street ((custom) ' SQL Injection 35 WEB Zhaiyi
2020-12-11   Courier Management System 1.0 - 'First Name' Stored XSS 34 WEB Zhaiyi
2020-12-11   Dolibarr 12.0.3 - SQLi to RCE 33 WEB coiffeur
2020-12-11   Supply Chain Management System - Auth Bypass SQL Injection 33 WEB Piyush Malviya
2020-12-11   Rukovoditel 2.6.1 - RCE (1) 35 WEB coiffeur
2020-12-11   Jenkins 2.235.3 - 'Description' Stored XSS 32 WEB gx1
2020-12-11   Medical Center Portal Management System 1.0 - Multiple Stored XSS 35 WEB Saeed Bala Ahmed
2020-12-11   Openfire 4.6.0 - 'sql' Stored XSS 33 WEB j5s
2020-12-11   Openfire 4.6.0 - 'users' Stored XSS 32 WEB j5s
2020-12-11   Openfire 4.6.0 - 'groupchatJID' Stored XSS 33 WEB j5s
2020-12-11   Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting 32 WEB gx1
2020-12-10   WordPress Plugin Popup Builder 3.69.6 - Multiple Stored Cross Site Scripting 35 WEB Ilca Lucian Florin
2020-12-10   Library Management System 2.0 - Auth Bypass SQL Injection 34 WEB Manish Solanki
2020-12-10   Openfire 4.6.0 - 'path' Stored XSS 39 WEB j5s
2020-12-10   OpenCart 3.0.3.6 - Cross Site Request Forgery 39 WEB Mahendra Purbia
2020-12-10   Barcodes generator 1.0 - 'name' Stored Cross Site Scripting 35 WEB Nikhil Kumar
2020-12-09   Task Management System 1.0 - 'id' SQL Injection 39 WEB Saeed Bala Ahmed
2020-12-09   Task Management System 1.0 - Unrestricted File Upload to Remote Code Execution 38 WEB Saeed Bala Ahmed
2020-12-09   Task Management System 1.0 - 'First Name and Last Name' Stored XSS 34 WEB Saeed Bala Ahmed
2020-12-09   VestaCP 0.9.8-26 - 'backup' Information Disclosure 34 WEB Vulnerability-Lab
2020-12-09   VestaCP 0.9.8-26 - 'LoginAs' Insufficient Session Validation 38 WEB Vulnerability-Lab
2020-12-08   Employee Performance Evaluation System 1.0 - 'Task and Description' Persistent Cross Site Scripting 34 WEB Ritesh Gohil
2020-12-08   Online Bus Ticket Reservation 1.0 - SQL Injection 33 WEB Sakshi Sharma
2020-12-07   vBulletin 5.6.3 - 'group' Cross Site Scripting 39 WEB Vincent666
2020-12-07   Savsoft Quiz 5 - 'Skype ID' Stored XSS 45 WEB Dipak Panchal
2020-12-07   Cyber Cafe Management System Project (CCMS) 1.0 - Persistent Cross-Site Scripting 37 WEB Pruthvi Nekkanti
2020-12-04   Zabbix 5.0.0 - Stored XSS via URL Widget Iframe 42 WEB Shwetabh Vishnoi
2020-12-04   CMS Made Simple 2.2.15 - Stored Cross-Site Scripting via SVG File Upload (Authenticated) 34 WEB Eshan Singh
2020-12-04   Laravel Nova 3.7.0 - 'range' DoS 32 WEB iqzer0
2020-12-04   Forma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting 34 WEB Hemant Patidar
2020-12-04   Savsoft Quiz 5 - 'field_title' Stored Cross-Site Scripting 31 WEB Dhruv Patel
2020-12-04   Testa Online Test Management System 3.4.7 - 'q' SQL Injection 46 WEB Ultra Security Team
2020-12-04   MiniCMS 1.10 - 'content box' Stored XSS 38 WEB yudp
2020-12-04   Phpscript-sgh 0.1.0 - Time Based Blind SQL Injection 38 WEB KeopssGroup0day_Inc
2020-12-04   Composr CMS 10.0.34 - 'banners' Persistent Cross Site Scripting 32 WEB Parshwa Bhavsar
2020-12-04   Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated) 36 WEB Pankaj Verma
2020-12-03   Invision Community 4.5.4 - 'Field Name' Stored Cross-Site Scripting 40 WEB Hemant Patidar
2020-12-03   Sony BRAVIA Digital Signage 1.7.8 - System API Information Disclosure 31 WEB LiquidWorm
2020-12-03   Sony BRAVIA Digital Signage 1.7.8 - Unauthenticated Remote File Inclusion 37 WEB LiquidWorm
2020-12-03   mojoPortal forums 2.7.0.0 - 'Title' Persistent Cross-Site Scripting 34 WEB Sagar Banwa
2020-12-03   Online Matrimonial Project 1.0 - Authenticated Remote Code Execution 34 WEB Valerio Alessandroni
2020-12-03   EgavilanMedia Address Book 1.0 Exploit - SQLi Auth Bypass 30 WEB Mayur Parmar
2020-12-03   Coastercms 5.8.18 - Stored XSS 34 WEB Hardik Solanki
2020-12-03   User Registration & Login and User Management System 2.1 - Cross Site Request Forgery 35 WEB Dipak Panchal
2020-12-02   WordPress Plugin Wp-FileManager 6.8 - RCE 34 WEB Mansoor R
2020-12-02   Car Rental Management System 1.0 - SQL Injection / Local File include 36 WEB Mosaaed
2020-12-02   Simple College Website 1.0 - 'page' Local File Inclusion 32 WEB Mosaaed
2020-12-02   Anuko Time Tracker 1.19.23.5311 - Password Reset leading to Account Takeover 38 WEB Mufaddal Masalawala
2020-12-02   Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality 32 WEB Mufaddal Masalawala
2020-12-02   ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS) 45 WEB Mufaddal Masalawala
2020-12-02   ChurchCRM 4.2.0 - CSV/Formula Injection 40 WEB Mufaddal Masalawala
2020-12-02   WebDamn User Registration & Login System with User Panel - SQLi Auth Bypass 36 WEB Aakash Madaan
2020-12-02   DotCMS 20.11 - Stored Cross-Site Scripting 37 WEB Hardik Solanki
2020-12-02   Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile 36 WEB Shahrukh Iqbal Mirza
2020-12-02   Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Add Artwork 42 WEB Shahrukh Iqbal Mirza
2020-12-02   Employee Record Management System 1.1 - Login Bypass SQL Injection 33 WEB Anurag Kumar
2020-12-02   WonderCMS 3.1.3 - 'Menu' Persistent Cross-Site Scripting 33 WEB Hemant Patidar