|
2020-10-29
|
|
WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 - Unauthenticated RCE
|
9 |
WEB
|
Mohammed Althibyani
|
|
2020-10-29
|
|
Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS)
|
10 |
WEB
|
Valerio Alessandroni
|
|
2020-10-29
|
|
Online Examination System 1.0 - 'name' Stored Cross Site Scripting
|
9 |
WEB
|
Nikhil Kumar
|
|
2020-10-28
|
|
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewIma
|
12 |
WEB
|
Ivo Palazzolo
|
|
2020-10-28
|
|
CSE Bookstore 1.0 - Authentication Bypass
|
13 |
WEB
|
Alper Basaran
|
|
2020-10-28
|
|
Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
|
12 |
WEB
|
Matthew Aberegg
|
|
2020-10-27
|
|
Sphider Search Engine 1.3.6 - 'word_upper_bound' RCE (Authenticated)
|
12 |
WEB
|
Gurkirat Singh
|
|
2020-10-27
|
|
Client Management System 1.0 - 'searchdata' SQL injection
|
12 |
WEB
|
Serkan Sancar
|
|
2020-10-27
|
|
Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
|
11 |
WEB
|
Gurkirat Singh
|
|
2020-10-26
|
|
ReQuest Serious Play F3 Media Server 7.0.3 - Remote Code Execution (Unauthenticated)
|
14 |
WEB
|
LiquidWorm
|
|
2020-10-26
|
|
ReQuest Serious Play F3 Media Server 7.0.3 - Remote Denial of Service
|
9 |
WEB
|
LiquidWorm
|
|
2020-10-26
|
|
ReQuest Serious Play F3 Media Server 7.0.3 - Debug Log Disclosure
|
8 |
WEB
|
LiquidWorm
|
|
2020-10-26
|
|
ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure
|
8 |
WEB
|
LiquidWorm
|
|
2020-10-26
|
|
Genexis Platinum-4410 - 'SSID' Persistent XSS
|
7 |
WEB
|
Amal Mohandas
|
|
2020-10-26
|
|
PDW File Browser 1.3 - 'new_filename' Cross-Site Scripting (XSS)
|
8 |
WEB
|
David Bimmel
|
|
2020-10-26
|
|
InoERP 0.7.2 - Remote Code Execution (Unauthenticated)
|
11 |
WEB
|
Lyhin\'s Lab
|
|
2020-10-26
|
|
Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored)
|
8 |
WEB
|
Akıner Kısa
|
|
2020-10-26
|
|
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
|
9 |
WEB
|
Gurkirat Singh
|
|
2020-10-23
|
|
TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated)
|
8 |
WEB
|
0blio_
|
|
2020-10-23
|
|
Bludit 3.9.2 - Auth Bruteforce Bypass
|
7 |
WEB
|
Mayank Deshmukh
|
|
2020-10-23
|
|
Gym Management System 1.0 - Stored Cross Site Scripting
|
7 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
Gym Management System 1.0 - Authentication Bypass
|
8 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
School Faculty Scheduling System 1.0 - 'username' SQL Injection
|
8 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
School Faculty Scheduling System 1.0 - 'id' SQL Injection
|
8 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
Point of Sales 1.0 - 'username' SQL Injection
|
8 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
Gym Management System 1.0 - 'id' SQL Injection
|
7 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored)
|
7 |
WEB
|
Ankita Pal
|
|
2020-10-23
|
|
Lot Reservation Management System 1.0 - Authentication Bypass
|
7 |
WEB
|
Ankita Pal
|
|
2020-10-23
|
|
Point of Sales 1.0 - 'id' SQL Injection
|
7 |
WEB
|
Ankita Pal
|
|
2020-10-23
|
|
User Registration & Login and User Management System 2.1 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2020-10-23
|
|
Car Rental Management System 1.0 - Arbitrary File Upload
|
7 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2020-10-23
|
|
Ajenti 2.1.36 - Remote Code Execution (Authenticated)
|
7 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2020-10-23
|
|
Online Library Management System 1.0 - Arbitrary File Upload
|
6 |
WEB
|
Jyotsna Adhana
|
|
2020-10-21
|
|
Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
|
7 |
WEB
|
Maximilian Barz
|
|
2020-10-21
|
|
Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
|
7 |
WEB
|
Adeeb Shah
|
|
2020-10-21
|
|
Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scripting
|
6 |
WEB
|
Adeeb Shah
|
|
2020-10-21
|
|
Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scripting
|
7 |
WEB
|
Adeeb Shah
|
|
2020-10-21
|
|
GOautodial 4.0 - Authenticated Shell Upload
|
8 |
WEB
|
Balzabu
|
|
2020-10-21
|
|
School Faculty Scheduling System 1.0 - Authentication Bypass POC
|
7 |
WEB
|
Jyotsna Adhana
|
|
2020-10-21
|
|
School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
|
7 |
WEB
|
Jyotsna Adhana
|
|
2020-10-21
|
|
Hrsale 2.0.0 - Local File Inclusion
|
7 |
WEB
|
Sosecure
|
|
2020-10-20
|
|
WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting (Authenticated)
|
7 |
WEB
|
n1x_
|
|
2020-10-20
|
|
WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection
|
6 |
WEB
|
Jonatas Fil
|
|
2020-10-20
|
|
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
|
7 |
WEB
|
Jonatas Fil
|
|
2020-10-20
|
|
Mobile Shop System v1.0 - SQL Injection Authentication Bypass
|
7 |
WEB
|
Moaaz Taha
|
|
2020-10-20
|
|
RiteCMS 2.2.1 - Remote Code Execution (Authenticated)
|
7 |
WEB
|
H0j3n
|
|
2020-10-20
|
|
User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS
|
9 |
WEB
|
yusufmalikul
|
|
2020-10-20
|
|
WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload
|
11 |
WEB
|
Net-Hunter
|
|
2020-10-20
|
|
Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated)
|
8 |
WEB
|
nag0mez
|
|
2020-10-20
|
|
Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
|
8 |
WEB
|
Rahul Ramkumar
|
|
2020-10-20
|
|
Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Courses Content Disclosure
|
9 |
WEB
|
redtimmysec
|
|
2020-10-20
|
|
Loan Management System 1.0 - Multiple Cross Site Scripting (Stored)
|
7 |
WEB
|
Akıner Kısa
|
|
2020-10-20
|
|
Comtrend AR-5387un router - Persistent XSS (Authenticated)
|
9 |
WEB
|
OscarAkaElvis
|
|
2020-10-19
|
|
Textpattern CMS 4.6.2 - Cross-site Request Forgery
|
8 |
WEB
|
Alperen Ergel
|
|
2020-10-19
|
|
Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
|
9 |
WEB
|
Rodolfo Tavares
|
|
2020-10-19
|
|
Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
|
7 |
WEB
|
Kokn3t
|
|
2020-10-19
|
|
Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
|
8 |
WEB
|
Daniel Morris
|
|
2020-10-19
|
|
HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
|
17 |
WEB
|
Alexei Kojenov
|
|
2020-10-19
|
|
HiSilicon Video Encoders - Full admin access via backdoor password
|
8 |
WEB
|
Alexei Kojenov
|
|
2020-10-19
|
|
HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware
|
10 |
WEB
|
Alexei Kojenov
|
|
2020-10-19
|
|
HiSilicon Video Encoders - RCE via unauthenticated command injection
|
8 |
WEB
|
Alexei Kojenov
|
|
2020-10-19
|
|
HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal
|
9 |
WEB
|
Alexei Kojenov
|
|
2020-10-19
|
|
Online Job Portal 1.0 - Cross Site Scripting (Stored)
|
7 |
WEB
|
Akıner Kısa
|
|
2020-10-19
|
|
Online Discussion Forum Site 1.0 - XSS in Messaging System
|
10 |
WEB
|
j5oh
|
|
2020-10-19
|
|
Online Student's Management System 1.0 - Remote Code Execution (Authenticated)
|
8 |
WEB
|
Akıner Kısa
|
|
2020-10-19
|
|
Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection
|
9 |
WEB
|
Matthew Aberegg
|
|
2020-10-19
|
|
Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection
|
8 |
WEB
|
Matthew Aberegg
|
|
2020-10-19
|
|
Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting
|
7 |
WEB
|
Matthew Aberegg
|
|
2020-10-19
|
|
Tourism Management System 1.0 - Arbitrary File Upload
|
6 |
WEB
|
Ankita Pal
|
|
2020-10-16
|
|
CS-Cart 1.3.3 - authenticated RCE
|
6 |
WEB
|
0xmmnbassel
|
|
2020-10-16
|
|
CS-Cart 1.3.3 - 'classes_dir' LFI
|
7 |
WEB
|
0xmmnbassel
|
|
2020-10-16
|
|
Seat Reservation System 1.0 - Unauthenticated SQL Injection
|
8 |
WEB
|
Rahul Ramkumar
|
|
2020-10-16
|
|
Hotel Management System 1.0 - Remote Code Execution (Authenticated)
|
6 |
WEB
|
Aporlorxl23
|
|
2020-10-16
|
|
Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated)
|
9 |
WEB
|
Rahul Ramkumar
|
|
2020-10-16
|
|
aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated)
|
5 |
WEB
|
Ünsal Furkan Harani
|
|
2020-10-16
|
|
Restaurant Reservation System 1.0 - 'date' SQL Injection (Authenticated)
|
6 |
WEB
|
b1nary
|
|
2020-10-16
|
|
Company Visitor Management System (CVMS) 1.0 - Authentication Bypass
|
6 |
WEB
|
Oğuz Türkgenç
|
|
2020-10-16
|
|
Alumni Management System 1.0 - Authentication Bypass
|
8 |
WEB
|
Ankita Pal
|
|
2020-10-16
|
|
Employee Management System 1.0 - Authentication Bypass
|
6 |
WEB
|
Ankita Pal
|
|
2020-10-16
|
|
Employee Management System 1.0 - Cross Site Scripting (Stored)
|
7 |
WEB
|
Ankita Pal
|
|
2020-10-15
|
|
Zoo Management System 1.0 - Authentication Bypass
|
9 |
WEB
|
Jyotsna Adhana
|
|
2020-10-15
|
|
Simple Grocery Store Sales And Inventory System 1.0 - Authentication Bypass
|
9 |
WEB
|
Saurav Shukla
|
|
2020-10-15
|
|
rConfig 3.9.5 - Remote Code Execution (Unauthenticated)
|
18 |
WEB
|
Daniel Monzón
|
|
2020-10-15
|
|
Vehicle Parking Management System 1.0 - Authentication Bypass
|
9 |
WEB
|
BKpatron
|
|
2020-10-14
|
|
NodeBB Forum 1.12.2-1.14.2 - Account Takeover
|
9 |
WEB
|
Muhammed Eren Uygun
|
|
2020-07-23
|
|
TimeClock Software 1.01 0 - (Authenticated) Time-Based SQL Injection
|
10 |
WEB
|
François Bibeau
|
|
2020-10-13
|
|
berliCRM 1.0.24 - 'src_record' SQL Injection
|
10 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2020-10-12
|
|
Cisco ASA and FTD 9.6.4.42 - Path Traversal
|
11 |
WEB
|
3ndG4me
|
|
2020-10-12
|
|
Online Students Management System 1.0 - 'username' SQL Injections
|
8 |
WEB
|
George Tsimpidas
|
|
2020-10-12
|
|
Liman 0.7 - Cross-Site Request Forgery (Change Password)
|
7 |
WEB
|
George Tsimpidas
|
|
2020-10-12
|
|
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Unauthenticated)
|
9 |
WEB
|
bzyo
|
|
2020-10-12
|
|
Small CRM 2.0 - 'email' SQL Injection
|
7 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2020-10-09
|
|
openMAINT 1.1-2.4.2 - Arbitrary File Upload
|
8 |
WEB
|
mrb3n
|
|
2020-10-09
|
|
DynPG 4.9.1 - Persistent Cross-Site Scripting (Authenticated)
|
9 |
WEB
|
Enes Özeser
|
|
2020-10-09
|
|
Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
|
7 |
WEB
|
Ataberk YAVUZER
|
|
2020-10-08
|
|
D-Link DSR-250N 3.12 - Denial of Service (PoC)
|
9 |
WEB
|
RedTeam Pentesting GmbH
|
|
2020-10-08
|
|
SEO Panel 4.6.0 - Remote Code Execution (1)
|
14 |
WEB
|
Kiko Andreu
|
|
2020-10-07
|
|
Textpattern CMS 4.6.2 - 'body' Persistent Cross-Site Scripting
|
15 |
WEB
|
Alperen Ergel
|
|
2020-10-06
|
|
EasyPMS 1.0.0 - Authentication Bypass
|
16 |
WEB
|
Jok3r
|
|
2020-10-06
|
|
Karel IP Phone IP1211 Web Management Panel - Directory Traversal
|
16 |
WEB
|
berat isler
|
|
2020-10-05
|
|
SpamTitan 7.07 - Unauthenticated Remote Code Execution
|
15 |
WEB
|
Felipe Molina
|
|
2020-10-02
|
|
Photo Share Website 1.0 - Persistent Cross-Site Scripting
|
12 |
WEB
|
Augkim
|
|
2020-10-02
|
|
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated)
|
10 |
WEB
|
bzyo
|
|
2020-10-01
|
|
Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting
|
9 |
WEB
|
Alperen Ergel
|
|
2020-10-01
|
|
CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)
|
12 |
WEB
|
Roel van Beurden
|
|
2020-10-01
|
|
GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting (Authenticated)
|
8 |
WEB
|
Roel van Beurden
|
|
2020-10-01
|
|
WebsiteBaker 2.12.2 - 'display_name' SQL Injection (authenticated)
|
12 |
WEB
|
Roel van Beurden
|
|
2020-10-01
|
|
MonoCMS Blog 1.0 - Arbitrary File Deletion (Authenticated)
|
11 |
WEB
|
Shahrukh Iqbal Mirza
|
|
2020-10-01
|
|
SpinetiX Fusion Digital Signage 3.4.8 - Username Enumeration
|
8 |
WEB
|
LiquidWorm
|
|
2020-10-01
|
|
SpinetiX Fusion Digital Signage 3.4.8 - Cross-Site Request Forgery (Add Admin)
|
9 |
WEB
|
LiquidWorm
|
|
2020-10-01
|
|
SpinetiX Fusion Digital Signage 3.4.8 - Database Backup Disclosure
|
9 |
WEB
|
LiquidWorm
|
|
2020-10-01
|
|
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - File Delete Path Traversal
|
11 |
WEB
|
LiquidWorm
|
|
2020-10-01
|
|
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - Server-Side Request Forgery (Unauthenticat
|
11 |
WEB
|
LiquidWorm
|
|
2020-09-29
|
|
WebsiteBaker 2.12.2 - Remote Code Execution
|
11 |
WEB
|
Enesdex
|
|
2020-09-28
|
|
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
|
9 |
WEB
|
Ademar Nowasky Junior
|
|
2020-09-28
|
|
Mida eFramework 2.8.9 - Remote Code Execution
|
9 |
WEB
|
elbae
|
|
2020-09-25
|
|
B-swiss 3 Digital Signage System 3.6.5 - Database Disclosure
|
10 |
WEB
|
LiquidWorm
|
|
2020-09-25
|
|
B-swiss 3 Digital Signage System 3.6.5 - Cross-Site Request Forgery (Add Maintenance Admin)
|
7 |
WEB
|
LiquidWorm
|
|
2020-09-25
|
|
Anchor CMS 0.12.7 - Persistent Cross-Site Scripting (Authenticated)
|
9 |
WEB
|
Sinem Şahin
|
|
2020-09-25
|
|
BigTree CMS 4.4.10 - Remote Code Execution
|
8 |
WEB
|
SunCSR
|
|
2020-09-24
|
|
Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
|
7 |
WEB
|
Rahul Ramkumar
|
|
2020-09-24
|
|
Simple Online Food Ordering System 1.0 - 'id' SQL Injection (Unauthenticated)
|
8 |
WEB
|
Aporlorxl23
|
|
2020-09-23
|
|
Online Food Ordering System 1.0 - Remote Code Execution
|
7 |
WEB
|
Eren Şimşek
|
|
2020-09-22
|
|
Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting
|
7 |
WEB
|
Alperen Ergel
|