|
2020-11-24
|
|
OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
|
25 |
WEB
|
Hemant Patidar
|
|
2020-11-24
|
|
OpenCart 3.0.3.6 - 'Profile Image' Stored Cross-Site Scripting (Authenticated)
|
26 |
WEB
|
Hemant Patidar
|
|
2020-11-24
|
|
Seowon 130-SLC router 1.0.11 - 'ipAddr' RCE (Authenticated)
|
26 |
WEB
|
maj0rmil4d
|
|
2020-11-24
|
|
ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit)
|
22 |
WEB
|
Giuseppe Fuggiano
|
|
2020-11-24
|
|
Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service
|
25 |
WEB
|
SunCSR
|
|
2020-11-24
|
|
nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting
|
28 |
WEB
|
Hemant Patidar
|
|
2020-11-23
|
|
TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass
|
25 |
WEB
|
malwrforensics
|
|
2020-11-23
|
|
LifeRay 7.2.1 GA2 - Stored XSS
|
34 |
WEB
|
3ndG4me
|
|
2020-11-23
|
|
VTiger v7.0 CRM - 'To' Persistent XSS
|
26 |
WEB
|
Vulnerability-Lab
|
|
2020-11-20
|
|
WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting
|
30 |
WEB
|
Hemant Patidar
|
|
2020-11-19
|
|
Nagios Log Server 2.1.7 - Persistent Cross-Site Scripting
|
31 |
WEB
|
Emre ÖVÜNÇ
|
|
2020-11-19
|
|
M/Monit 3.7.4 - Password Disclosure
|
33 |
WEB
|
Dolev Farhi
|
|
2020-11-19
|
|
M/Monit 3.7.4 - Privilege Escalation
|
31 |
WEB
|
Dolev Farhi
|
|
2020-11-19
|
|
Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection
|
26 |
WEB
|
Gabriele Zuddas
|
|
2020-11-19
|
|
TestBox CFML Test Framework 4.1.0 - Directory Traversal
|
31 |
WEB
|
Darren King
|
|
2020-11-19
|
|
TestBox CFML Test Framework 4.1.0 - Arbitrary File Write and Remote Code Execution
|
33 |
WEB
|
Darren King
|
|
2020-11-19
|
|
Gitlab 12.9.0 - Arbitrary File Read (Authenticated)
|
36 |
WEB
|
Jasper Rasenberg
|
|
2020-11-19
|
|
Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification
|
33 |
WEB
|
Ricardo Longatto
|
|
2020-11-19
|
|
xuucms 3 - 'keywords' SQL Injection
|
30 |
WEB
|
icekam
|
|
2020-11-19
|
|
PESCMS TEAM 2.3.2 - Multiple Reflected XSS
|
36 |
WEB
|
icekam
|
|
2020-11-18
|
|
BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery
|
30 |
WEB
|
RedTeam Pentesting GmbH
|
|
2020-11-18
|
|
Wordpress Plugin WPForms 1.6.3.1 - Persistent Cross Site Scripting (Authenticated)
|
32 |
WEB
|
ZwX
|
|
2020-11-17
|
|
Joomla Plugin Simple Image Gallery Extended (SIGE) 3.5.3 - Multiple Vulnerabilities
|
27 |
WEB
|
Vulnerability-Lab
|
|
2020-11-17
|
|
Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scripting
|
32 |
WEB
|
Vulnerability-Lab
|
|
2020-11-17
|
|
WordPress Plugin Buddypress 6.2.0 - Persistent Cross-Site Scripting
|
29 |
WEB
|
Vulnerability-Lab
|
|
2020-11-17
|
|
SugarCRM 6.5.18 - Persistent Cross-Site Scripting
|
29 |
WEB
|
Vulnerability-Lab
|
|
2020-11-17
|
|
Online Doctor Appointment Booking System PHP and Mysql 1.0 - 'q' SQL Injection
|
26 |
WEB
|
Ramil Mustafayev
|
|
2020-11-17
|
|
EgavilanMedia User Registration & Login System with Admin Panel Exploit - SQLi Auth Bypass
|
28 |
WEB
|
Kislay Kumar
|
|
2020-11-16
|
|
Car Rental Management System 1.0 - 'car_id' Sql Injection
|
25 |
WEB
|
Mehmet Kelepçe
|
|
2020-11-16
|
|
Car Rental Management System 1.0 - Remote Code Execution (Authenticated)
|
28 |
WEB
|
Mehmet Kelepçe
|
|
2020-11-16
|
|
PMB 5.6 - 'chemin' Local File Disclosure
|
24 |
WEB
|
41-trk
|
|
2020-11-16
|
|
User Registration & Login and User Management System 2.1 - Login Bypass SQL Injection
|
24 |
WEB
|
Mayur Parmar
|
|
2020-11-16
|
|
Water Billing System 1.0 - 'id' SQL Injection (Authenticated)
|
24 |
WEB
|
Mehmet Kelepçe
|
|
2020-11-16
|
|
Pandora FMS 7.0 NG 749 - 'CG Items' SQL Injection (Authenticated)
|
24 |
WEB
|
Matthew Aberegg
|
|
2020-11-13
|
|
October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
|
28 |
WEB
|
Sivanesh Ashok
|
|
2020-11-13
|
|
OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
|
24 |
WEB
|
Jinson Varghese Behanan
|
|
2020-11-13
|
|
Touchbase.io 1.10 - Stored Cross Site Scripting
|
24 |
WEB
|
Simran Sankhala
|
|
2020-11-13
|
|
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
|
26 |
WEB
|
SunCSR
|
|
2020-11-13
|
|
Citrix ADC NetScaler - Local File Inclusion (Metasploit)
|
27 |
WEB
|
RAMELLA Sebastien
|
|
2020-11-13
|
|
Bludit 3.9.2 - Authentication Bruteforce Bypass (Metasploit)
|
25 |
WEB
|
Aporlorxl23
|
|
2020-11-13
|
|
ASUS TM-AC1900 - Arbitrary Command Execution (Metasploit)
|
25 |
WEB
|
b1ack0wl
|
|
2020-11-12
|
|
Wordpress Plugin Good LMS 2.1.4 - 'id' Unauthenticated SQL Injection
|
27 |
WEB
|
Abdulazeez Alaseeri
|
|
2020-11-12
|
|
Water Billing System 1.0 - 'username' and 'password' parameters SQL Injection
|
24 |
WEB
|
Sarang Tumne
|
|
2020-11-11
|
|
CMSUno 1.6.2 - 'user' Remote Code Execution (Authenticated)
|
20 |
WEB
|
Fatih Çelik
|
|
2020-11-11
|
|
Customer Support System 1.0 - 'username' Authentication Bypass
|
24 |
WEB
|
Ahmed Abbas
|
|
2020-11-11
|
|
Customer Support System 1.0 - Cross-Site Request Forgery
|
24 |
WEB
|
Ahmed Abbas
|
|
2020-11-11
|
|
Customer Support System 1.0 - 'description' Stored XSS in The Admin Panel
|
22 |
WEB
|
Ahmed Abbas
|
|
2020-11-10
|
|
Anuko Time Tracker 1.19.23.5325 - CSV/Formula Injection
|
22 |
WEB
|
Mufaddal Masalawala
|
|
2020-11-10
|
|
ShoreTel Conferencing 19.46.1802.0 - Reflected Cross-Site Scripting
|
24 |
WEB
|
Joe Helle
|
|
2020-11-10
|
|
Car Rental Management System 1.0 - SQL injection + Arbitrary File Upload
|
25 |
WEB
|
Fortunato Lodari
|
|
2020-11-09
|
|
Joplin 1.2.6 - 'link' Cross Site Scripting
|
24 |
WEB
|
Philip Holbrook
|
|
2020-11-09
|
|
SuiteCRM 7.11.15 - 'last_name' Remote Code Execution (Authenticated)
|
28 |
WEB
|
M. Cory Billington
|
|
2020-11-09
|
|
Genexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRF
|
29 |
WEB
|
Jinson Varghese Behanan
|
|
2020-11-06
|
|
BlogEngine 3.3.8 - 'Content' Stored XSS
|
29 |
WEB
|
Andrey Stoykov
|
|
2020-11-06
|
|
Sentrifugo Version 3.2 - 'announcements' Remote Code Execution (Authenticated)
|
24 |
WEB
|
Fatih Çelik
|
|
2020-11-06
|
|
Sentrifugo 3.2 - 'assets' Remote Code Execution (Authenticated)
|
23 |
WEB
|
Fatih Çelik
|
|
2020-11-06
|
|
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
|
30 |
WEB
|
Fatih Çelik
|
|
2020-11-06
|
|
SmartBlog 2.0.1 - 'id_post' Blind SQL injection
|
29 |
WEB
|
C0wnuts
|
|
2020-11-05
|
|
iDS6 DSSPro Digital Signage System 6.2 - Improper Access Control Privilege Escalation
|
28 |
WEB
|
LiquidWorm
|
|
2020-11-05
|
|
iDS6 DSSPro Digital Signage System 6.2 - CAPTCHA Security Bypass
|
28 |
WEB
|
LiquidWorm
|
|
2020-11-05
|
|
iDS6 DSSPro Digital Signage System 6.2 - Cross-Site Request Forgery (CSRF)
|
21 |
WEB
|
LiquidWorm
|
|
2020-11-04
|
|
Student Attendance Management System 1.0 - 'username' SQL Injection / Remote Code Execution
|
21 |
WEB
|
Mosaaed
|
|
2020-11-04
|
|
School Log Management System 1.0 - 'username' SQL Injection / Remote Code Execution
|
20 |
WEB
|
Mosaaed
|
|
2020-11-04
|
|
PDW File Browser 1.3 - Remote Code Execution
|
24 |
WEB
|
David Bimmel
|
|
2020-11-04
|
|
Processwire CMS 2.4.0 - 'download' Local File Inclusion
|
24 |
WEB
|
Y1LD1R1M
|
|
2020-11-03
|
|
Complaints Report Management System 1.0 - 'username' SQL Injection / Remote Code Execution
|
27 |
WEB
|
Mosaaed
|
|
2020-11-03
|
|
Multi Restaurant Table Reservation System 1.0 - 'table_id' Unauthenticated SQL Injection
|
28 |
WEB
|
yunaranyancat
|
|
2020-11-02
|
|
Monitorr 1.7.6m - Authorization Bypass
|
23 |
WEB
|
Lyhin\'s Lab
|
|
2020-11-02
|
|
Monitorr 1.7.6m - Remote Code Execution (Unauthenticated)
|
26 |
WEB
|
Lyhin\'s Lab
|
|
2020-11-02
|
|
WordPress Plugin Simple File List 4.2.2 - Arbitrary File Upload
|
30 |
WEB
|
H4rk3nz0
|
|
2020-11-02
|
|
Apache Flink 1.9.x - File Upload RCE (Unauthenticated)
|
27 |
WEB
|
bigger.wing
|
|
2020-10-30
|
|
Simple College Website 1.0 - 'username' SQL Injection / Remote Code Execution
|
22 |
WEB
|
yunaranyancat
|
|
2020-10-30
|
|
Online Job Portal 1.0 - 'userid' SQL Injection
|
23 |
WEB
|
Akıner Kısa
|
|
2020-10-30
|
|
Citadel WebCit < 926 - Session Hijacking Exploit
|
24 |
WEB
|
Simone Quatrini
|
|
2020-10-30
|
|
DedeCMS v.5.8 - _keyword_ Cross-Site Scripting
|
25 |
WEB
|
Noth
|
|
2020-10-30
|
|
CSE Bookstore 1.0 - 'quantity' Persistent Cross-site Scripting
|
25 |
WEB
|
Vyshnav nk
|
|
2020-10-29
|
|
Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot
|
23 |
WEB
|
Mohammed Farhan
|
|
2020-10-29
|
|
WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 - Unauthenticated RCE
|
24 |
WEB
|
Mohammed Althibyani
|
|
2020-10-29
|
|
Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS)
|
26 |
WEB
|
Valerio Alessandroni
|
|
2020-10-29
|
|
Online Examination System 1.0 - 'name' Stored Cross Site Scripting
|
23 |
WEB
|
Nikhil Kumar
|
|
2020-10-28
|
|
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewIma
|
25 |
WEB
|
Ivo Palazzolo
|
|
2020-10-28
|
|
CSE Bookstore 1.0 - Authentication Bypass
|
27 |
WEB
|
Alper Basaran
|
|
2020-10-28
|
|
Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
|
27 |
WEB
|
Matthew Aberegg
|
|
2020-10-27
|
|
Sphider Search Engine 1.3.6 - 'word_upper_bound' RCE (Authenticated)
|
27 |
WEB
|
Gurkirat Singh
|
|
2020-10-27
|
|
Client Management System 1.0 - 'searchdata' SQL injection
|
25 |
WEB
|
Serkan Sancar
|
|
2020-10-27
|
|
Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
|
26 |
WEB
|
Gurkirat Singh
|
|
2020-10-26
|
|
ReQuest Serious Play F3 Media Server 7.0.3 - Remote Code Execution (Unauthenticated)
|
31 |
WEB
|
LiquidWorm
|
|
2020-10-26
|
|
ReQuest Serious Play F3 Media Server 7.0.3 - Remote Denial of Service
|
26 |
WEB
|
LiquidWorm
|
|
2020-10-26
|
|
ReQuest Serious Play F3 Media Server 7.0.3 - Debug Log Disclosure
|
24 |
WEB
|
LiquidWorm
|
|
2020-10-26
|
|
ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure
|
23 |
WEB
|
LiquidWorm
|
|
2020-10-26
|
|
Genexis Platinum-4410 - 'SSID' Persistent XSS
|
21 |
WEB
|
Amal Mohandas
|
|
2020-10-26
|
|
PDW File Browser 1.3 - 'new_filename' Cross-Site Scripting (XSS)
|
26 |
WEB
|
David Bimmel
|
|
2020-10-26
|
|
InoERP 0.7.2 - Remote Code Execution (Unauthenticated)
|
27 |
WEB
|
Lyhin\'s Lab
|
|
2020-10-26
|
|
Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored)
|
25 |
WEB
|
Akıner Kısa
|
|
2020-10-26
|
|
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
|
27 |
WEB
|
Gurkirat Singh
|
|
2020-10-23
|
|
TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated)
|
22 |
WEB
|
0blio_
|
|
2020-10-23
|
|
Bludit 3.9.2 - Auth Bruteforce Bypass
|
24 |
WEB
|
Mayank Deshmukh
|
|
2020-10-23
|
|
Gym Management System 1.0 - Stored Cross Site Scripting
|
23 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
Gym Management System 1.0 - Authentication Bypass
|
23 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
School Faculty Scheduling System 1.0 - 'username' SQL Injection
|
24 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
School Faculty Scheduling System 1.0 - 'id' SQL Injection
|
27 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
Point of Sales 1.0 - 'username' SQL Injection
|
24 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
Gym Management System 1.0 - 'id' SQL Injection
|
28 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored)
|
22 |
WEB
|
Ankita Pal
|
|
2020-10-23
|
|
Lot Reservation Management System 1.0 - Authentication Bypass
|
22 |
WEB
|
Ankita Pal
|
|
2020-10-23
|
|
Point of Sales 1.0 - 'id' SQL Injection
|
23 |
WEB
|
Ankita Pal
|
|
2020-10-23
|
|
User Registration & Login and User Management System 2.1 - SQL Injection
|
22 |
WEB
|
Ihsan Sencan
|
|
2020-10-23
|
|
Car Rental Management System 1.0 - Arbitrary File Upload
|
23 |
WEB
|
Jyotsna Adhana
|
|
2020-10-23
|
|
Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection
|
25 |
WEB
|
Ihsan Sencan
|
|
2020-10-23
|
|
Ajenti 2.1.36 - Remote Code Execution (Authenticated)
|
25 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2020-10-23
|
|
Online Library Management System 1.0 - Arbitrary File Upload
|
24 |
WEB
|
Jyotsna Adhana
|
|
2020-10-21
|
|
Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
|
26 |
WEB
|
Maximilian Barz
|
|
2020-10-21
|
|
Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
|
27 |
WEB
|
Adeeb Shah
|
|
2020-10-21
|
|
Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scripting
|
22 |
WEB
|
Adeeb Shah
|
|
2020-10-21
|
|
Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scripting
|
26 |
WEB
|
Adeeb Shah
|
|
2020-10-21
|
|
GOautodial 4.0 - Authenticated Shell Upload
|
24 |
WEB
|
Balzabu
|
|
2020-10-21
|
|
School Faculty Scheduling System 1.0 - Authentication Bypass POC
|
25 |
WEB
|
Jyotsna Adhana
|
|
2020-10-21
|
|
School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
|
23 |
WEB
|
Jyotsna Adhana
|
|
2020-10-21
|
|
Hrsale 2.0.0 - Local File Inclusion
|
28 |
WEB
|
Sosecure
|
|
2020-10-20
|
|
WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting (Authenticated)
|
27 |
WEB
|
n1x_
|
|
2020-10-20
|
|
WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection
|
21 |
WEB
|
Jonatas Fil
|
|
2020-10-20
|
|
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
|
25 |
WEB
|
Jonatas Fil
|
|
2020-10-20
|
|
Mobile Shop System v1.0 - SQL Injection Authentication Bypass
|
22 |
WEB
|
Moaaz Taha
|
|
2020-10-20
|
|
RiteCMS 2.2.1 - Remote Code Execution (Authenticated)
|
21 |
WEB
|
H0j3n
|
|
2020-10-20
|
|
User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS
|
27 |
WEB
|
yusufmalikul
|