Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-12-02   Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile 13 WEB Shahrukh Iqbal Mirza
2020-12-02   Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Add Artwork 9 WEB Shahrukh Iqbal Mirza
2020-12-02   Employee Record Management System 1.1 - Login Bypass SQL Injection 8 WEB Anurag Kumar
2020-12-02   WonderCMS 3.1.3 - 'Menu' Persistent Cross-Site Scripting 8 WEB Hemant Patidar
2020-12-02   Local Service Search Engine Management System 1.0 - SQLi Authentication Bypass 8 WEB Aditya Wakhlu
2020-12-02   Online News Portal System 1.0 - 'Title' Stored Cross Site Scripting 8 WEB Parshwa Bhavsar
2020-12-02   Bakeshop Online Ordering System 1.0 - 'Owner' Persistent Cross-site scripting 11 WEB Parshwa Bhavsar
2020-12-02   NewsLister - Authenticated Persistent Cross-Site Scripting 11 WEB Emre Aslan
2020-12-02   Online Voting System Project in PHP - 'username' Persistent Cross-Site Scripting 9 WEB Sagar Banwa
2020-12-02   PRTG Network Monitor 20.4.63.1412 - 'maps' Stored XSS 12 WEB Amin Rawah
2020-12-02   WonderCMS 3.1.3 - Authenticated Remote Code Execution 11 WEB zetc0de
2020-12-02   WonderCMS 3.1.3 - Authenticated SSRF to Remote Remote Code Execution 9 WEB zetc0de
2020-12-02   EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Stored Cross Site Scripting 10 WEB Soushikta Chowdhury
2020-12-02   Student Result Management System 1.0 - Authentication Bypass SQL Injection 8 WEB Ritesh Gohil
2020-12-02   EgavilanMedia User Registration & Login System with Admin Panel 1.0 - CSRF 8 WEB Hardik Solanki
2020-12-02   Under Construction Page with CPanel 1.0 - SQL injection 7 WEB Mayur Parmar
2020-12-02   Pharmacy Store Management System 1.0 - 'id' SQL Injection 11 WEB Aydın Baran Ertemir
2020-12-02   ILIAS Learning Management System 4.3 - SSRF 9 WEB Dot
2020-12-02   Expense Management System - 'description' Stored Cross Site Scripting 12 WEB Nikhil Kumar
2020-12-01   Tendenci 12.3.1 - CSV/ Formula Injection 7 WEB Mufaddal Masalawala
2020-12-01   Social Networking Site - Authentication Bypass (SQli) 9 WEB gh1mau
2020-12-01   Pandora FMS 7.0 NG 749 - Multiple Persistent Cross-Site Scripting Vulnerabilities 11 WEB Matthew Aberegg
2020-12-01   Medical Center Portal Management System 1.0 - 'login' SQL Injection 12 WEB Aydın Baran Ertemir
2020-12-01   LEPTON CMS 4.7.0 - 'URL' Persistent Cross-Site Scripting 12 WEB Sagar Banwa
2020-12-01   Tailor Management System 1.0 - Unrestricted File Upload to Remote Code Execution 11 WEB Saeed Bala Ahmed
2020-12-01   Multi Restaurant Table Reservation System 1.0 - Multiple Persistent XSS 9 WEB yunaranyancat
2020-12-01   Setelsa Conacwin 3.7.1.2 - Local File Inclusion 11 WEB Bryan Rodriguez Martin
2020-12-01   Pharmacy/Medical Store & Sale Point 1.0 - 'email' SQL Injection 10 WEB naivenom
2020-12-01   Online Shopping Alphaware 1.0 - Error Based SQL injection 14 WEB Moaaz Taha
2020-12-01   Wordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site Scripting 11 WEB B3KC4T
2020-12-01   Joomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File Upload 20 WEB ThelastVvV
2020-12-01   TypeSetter 5.1 - CSRF (Change admin e-mail) 12 WEB Alperen Ergel
2020-11-30   Intelbras Router RF 301K 1.1.2 - Authentication Bypass 14 WEB Kaio Amaral
2020-11-30   Rejetto HttpFileServer 2.3.x - Remote Command Execution (3) 17 WEB Óscar Andreu
2020-11-30   ATX MiniCMTS200a Broadband Gateway 2.0 - Credential Disclosure 17 WEB Zagros Bingol
2020-11-27   Best Support System 3.0.4 - 'ticket_body' Persistent XSS (Authenticated) 14 WEB Ex.Mi
2020-11-27   ElkarBackup 1.3.3 - 'Policy[name]' and 'Policy[Description]' Stored Cross-site Scripting 17 WEB Vyshnav nk
2020-11-27   House Rental 1.0 - 'keywords' SQL Injection 13 WEB boku
2020-11-27   Wordpress Theme Accesspress Social Icons 1.7.9 - SQL injection (Authenticated) 14 WEB SunCSR
2020-11-27   Moodle 3.8 - Unrestricted File Upload 18 WEB Sirwan Veisi
2020-11-27   Acronis Cyber Backup 12.5 Build 16341 - Unauthenticated SSRF 11 WEB Julien Ahrens
2020-11-27   Laravel Administrator 4 - Unrestricted File Upload (Authenticated) 13 WEB Xavi Beltran
2020-11-27   Ruckus IoT Controller (Ruckus vRIoT) 1.5.1.0.21 - Remote Code Execution 15 WEB Emre SUREN
2020-11-27   WonderCMS 3.1.3 - 'uploadFile' Stored Cross-Site Scripting 13 WEB Sun* Cyber Security Research Team
2020-11-27   Wordpress Theme Wibar 1.1.8 - 'Brand Component' Stored Cross Site Scripting 12 WEB Ilca Lucian Florin
2020-11-25   SyncBreeze 10.0.28 - 'password' Remote Buffer Overflow 17 WEB Abdessalam king
2020-11-25   osCommerce 2.3.4.1 - 'title' Persistent Cross-Site Scripting 13 WEB Emre Aslan
2020-11-25   WonderCMS 3.1.3 - 'page' Persistent Cross-Site Scripting 13 WEB Mayur Parmar
2020-11-24   OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting 10 WEB Hemant Patidar
2020-11-24   OpenCart 3.0.3.6 - 'Profile Image' Stored Cross-Site Scripting (Authenticated) 10 WEB Hemant Patidar
2020-11-24   Seowon 130-SLC router 1.0.11 - 'ipAddr' RCE (Authenticated) 10 WEB maj0rmil4d
2020-11-24   ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit) 9 WEB Giuseppe Fuggiano
2020-11-24   Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service 8 WEB SunCSR
2020-11-24   nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting 10 WEB Hemant Patidar
2020-11-23   TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass 10 WEB malwrforensics
2020-11-23   LifeRay 7.2.1 GA2 - Stored XSS 11 WEB 3ndG4me
2020-11-23   VTiger v7.0 CRM - 'To' Persistent XSS 9 WEB Vulnerability-Lab
2020-11-20   WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting 11 WEB Hemant Patidar
2020-11-19   Nagios Log Server 2.1.7 - Persistent Cross-Site Scripting 16 WEB Emre ÖVÜNÇ
2020-11-19   M/Monit 3.7.4 - Password Disclosure 15 WEB Dolev Farhi
2020-11-19   M/Monit 3.7.4 - Privilege Escalation 11 WEB Dolev Farhi
2020-11-19   Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection 9 WEB Gabriele Zuddas
2020-11-19   TestBox CFML Test Framework 4.1.0 - Directory Traversal 12 WEB Darren King
2020-11-19   TestBox CFML Test Framework 4.1.0 - Arbitrary File Write and Remote Code Execution 15 WEB Darren King
2020-11-19   Gitlab 12.9.0 - Arbitrary File Read (Authenticated) 16 WEB Jasper Rasenberg
2020-11-19   Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification 17 WEB Ricardo Longatto
2020-11-19   xuucms 3 - 'keywords' SQL Injection 15 WEB icekam
2020-11-19   PESCMS TEAM 2.3.2 - Multiple Reflected XSS 13 WEB icekam
2020-11-18   BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery 13 WEB RedTeam Pentesting GmbH
2020-11-18   Wordpress Plugin WPForms 1.6.3.1 - Persistent Cross Site Scripting (Authenticated) 16 WEB ZwX
2020-11-17   Joomla Plugin Simple Image Gallery Extended (SIGE) 3.5.3 - Multiple Vulnerabilities 11 WEB Vulnerability-Lab
2020-11-17   Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scripting 10 WEB Vulnerability-Lab
2020-11-17   WordPress Plugin Buddypress 6.2.0 - Persistent Cross-Site Scripting 12 WEB Vulnerability-Lab
2020-11-17   SugarCRM 6.5.18 - Persistent Cross-Site Scripting 12 WEB Vulnerability-Lab
2020-11-17   Online Doctor Appointment Booking System PHP and Mysql 1.0 - 'q' SQL Injection 11 WEB Ramil Mustafayev
2020-11-17   EgavilanMedia User Registration & Login System with Admin Panel Exploit - SQLi Auth Bypass 13 WEB Kislay Kumar
2020-11-16   Car Rental Management System 1.0 - 'car_id' Sql Injection 11 WEB Mehmet Kelepçe
2020-11-16   Car Rental Management System 1.0 - Remote Code Execution (Authenticated) 12 WEB Mehmet Kelepçe
2020-11-16   PMB 5.6 - 'chemin' Local File Disclosure 9 WEB 41-trk
2020-11-16   User Registration & Login and User Management System 2.1 - Login Bypass SQL Injection 10 WEB Mayur Parmar
2020-11-16   Water Billing System 1.0 - 'id' SQL Injection (Authenticated) 9 WEB Mehmet Kelepçe
2020-11-16   Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated) 8 WEB Matthew Aberegg
2020-11-13   October CMS Build 465 - Arbitrary File Read Exploit (Authenticated) 9 WEB Sivanesh Ashok
2020-11-13   OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure 8 WEB Jinson Varghese Behanan
2020-11-13   Touchbase.io 1.10 - Stored Cross Site Scripting 9 WEB Simran Sankhala
2020-11-13   Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit) 10 WEB SunCSR
2020-11-13   Citrix ADC NetScaler - Local File Inclusion (Metasploit) 11 WEB RAMELLA Sebastien
2020-11-13   Bludit 3.9.2 - Authentication Bruteforce Bypass (Metasploit) 8 WEB Aporlorxl23
2020-11-13   ASUS TM-AC1900 - Arbitrary Command Execution (Metasploit) 8 WEB b1ack0wl
2020-11-12   Wordpress Plugin Good LMS 2.1.4 - 'id' Unauthenticated SQL Injection 8 WEB Abdulazeez Alaseeri
2020-11-12   Water Billing System 1.0 - 'username' and 'password' parameters SQL Injection 9 WEB Sarang Tumne
2020-11-11   CMSUno 1.6.2 - 'user' Remote Code Execution (Authenticated) 8 WEB Fatih Çelik
2020-11-11   Customer Support System 1.0 - 'username' Authentication Bypass 9 WEB Ahmed Abbas
2020-11-11   Customer Support System 1.0 - Cross-Site Request Forgery 7 WEB Ahmed Abbas
2020-11-11   Customer Support System 1.0 - 'description' Stored XSS in The Admin Panel 6 WEB Ahmed Abbas
2020-11-10   Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection 8 WEB Mufaddal Masalawala
2020-11-10   ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting 8 WEB Joe Helle
2020-11-10   Car Rental Management System 1.0 - SQL injection + Arbitrary File Upload 10 WEB Fortunato Lodari
2020-11-09   Joplin 1.2.6 - 'link' Cross Site Scripting 9 WEB Philip Holbrook
2020-11-09   SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated) 9 WEB M. Cory Billington
2020-11-09   Genexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRF 11 WEB Jinson Varghese Behanan
2020-11-06   BlogEngine 3.3.8 - 'Content' Stored XSS 10 WEB Andrey Stoykov
2020-11-06   Sentrifugo Version 3.2 - 'announcements' Remote Code Execution (Authenticated) 7 WEB Fatih Çelik
2020-11-06   Sentrifugo 3.2 - 'assets' Remote Code Execution (Authenticated) 8 WEB Fatih Çelik
2020-11-06   CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated) 9 WEB Fatih Çelik
2020-11-06   SmartBlog 2.0.1 - 'id_post' Blind SQL injection 10 WEB C0wnuts
2020-11-05   iDS6 DSSPro Digital Signage System 6.2 - Improper Access Control Privilege Escalation 11 WEB LiquidWorm
2020-11-05   iDS6 DSSPro Digital Signage System 6.2 - CAPTCHA Security Bypass 10 WEB LiquidWorm
2020-11-05   iDS6 DSSPro Digital Signage System 6.2 - Cross-Site Request Forgery (CSRF) 9 WEB LiquidWorm
2020-11-04   Student Attendance Management System 1.0 - 'username' SQL Injection / Remote Code Execution 8 WEB Mosaaed
2020-11-04   School Log Management System 1.0 - 'username' SQL Injection / Remote Code Execution 7 WEB Mosaaed
2020-11-04   PDW File Browser 1.3 - Remote Code Execution 8 WEB David Bimmel
2020-11-04   Processwire CMS 2.4.0 - 'download' Local File Inclusion 10 WEB Y1LD1R1M
2020-11-03   Complaints Report Management System 1.0 - 'username' SQL Injection / Remote Code Execution 11 WEB Mosaaed
2020-11-03   Multi Restaurant Table Reservation System 1.0 - 'table_id' Unauthenticated SQL Injection 10 WEB yunaranyancat
2020-11-02   Monitorr 1.7.6m - Authorization Bypass 9 WEB Lyhin\'s Lab
2020-11-02   Monitorr 1.7.6m - Remote Code Execution (Unauthenticated) 13 WEB Lyhin\'s Lab
2020-11-02   WordPress Plugin Simple File List 4.2.2 - Arbitrary File Upload 15 WEB H4rk3nz0
2020-11-02   Apache Flink 1.9.x - File Upload RCE (Unauthenticated) 13 WEB bigger.wing
2020-10-30   Simple College Website 1.0 - 'username' SQL Injection / Remote Code Execution 6 WEB yunaranyancat
2020-10-30   Online Job Portal 1.0 - 'userid' SQL Injection 7 WEB Akıner Kısa
2020-10-30   Citadel WebCit < 926 - Session Hijacking Exploit 6 WEB Simone Quatrini
2020-10-30   DedeCMS v.5.8 - _keyword_ Cross-Site Scripting 10 WEB Noth
2020-10-30   CSE Bookstore 1.0 - 'quantity' Persistent Cross-site Scripting 9 WEB Vyshnav nk
2020-10-29   Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot 8 WEB Mohammed Farhan