Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-11-02   Monitorr 1.7.6m - Remote Code Execution (Unauthenticated) 16 WEB Lyhin\'s Lab
2020-11-02   WordPress Plugin Simple File List 4.2.2 - Arbitrary File Upload 17 WEB H4rk3nz0
2020-11-02   Apache Flink 1.9.x - File Upload RCE (Unauthenticated) 16 WEB bigger.wing
2020-10-30   Simple College Website 1.0 - 'username' SQL Injection / Remote Code Execution 10 WEB yunaranyancat
2020-10-30   Online Job Portal 1.0 - 'userid' SQL Injection 12 WEB Akıner Kısa
2020-10-30   Citadel WebCit < 926 - Session Hijacking Exploit 11 WEB Simone Quatrini
2020-10-30   DedeCMS v.5.8 - _keyword_ Cross-Site Scripting 13 WEB Noth
2020-10-30   CSE Bookstore 1.0 - 'quantity' Persistent Cross-site Scripting 13 WEB Vyshnav nk
2020-10-29   Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot 12 WEB Mohammed Farhan
2020-10-29   WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 - Unauthenticated RCE 11 WEB Mohammed Althibyani
2020-10-29   Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS) 14 WEB Valerio Alessandroni
2020-10-29   Online Examination System 1.0 - 'name' Stored Cross Site Scripting 13 WEB Nikhil Kumar
2020-10-28   Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewIma 16 WEB Ivo Palazzolo
2020-10-28   CSE Bookstore 1.0 - Authentication Bypass 17 WEB Alper Basaran
2020-10-28   Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated) 16 WEB Matthew Aberegg
2020-10-27   Sphider Search Engine 1.3.6 - 'word_upper_bound' RCE (Authenticated) 18 WEB Gurkirat Singh
2020-10-27   Client Management System 1.0 - 'searchdata' SQL injection 16 WEB Serkan Sancar
2020-10-27   Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated) 15 WEB Gurkirat Singh
2020-10-26   ReQuest Serious Play F3 Media Server 7.0.3 - Remote Code Execution (Unauthenticated) 17 WEB LiquidWorm
2020-10-26   ReQuest Serious Play F3 Media Server 7.0.3 - Remote Denial of Service 12 WEB LiquidWorm
2020-10-26   ReQuest Serious Play F3 Media Server 7.0.3 - Debug Log Disclosure 12 WEB LiquidWorm
2020-10-26   ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure 13 WEB LiquidWorm
2020-10-26   Genexis Platinum-4410 - 'SSID' Persistent XSS 11 WEB Amal Mohandas
2020-10-26   PDW File Browser 1.3 - 'new_filename' Cross-Site Scripting (XSS) 14 WEB David Bimmel
2020-10-26   InoERP 0.7.2 - Remote Code Execution (Unauthenticated) 15 WEB Lyhin\'s Lab
2020-10-26   Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored) 12 WEB Akıner Kısa
2020-10-26   CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection 13 WEB Gurkirat Singh
2020-10-23   TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated) 11 WEB 0blio_
2020-10-23   Bludit 3.9.2 - Auth Bruteforce Bypass 12 WEB Mayank Deshmukh
2020-10-23   Gym Management System 1.0 - Stored Cross Site Scripting 12 WEB Jyotsna Adhana
2020-10-23   Gym Management System 1.0 - Authentication Bypass 12 WEB Jyotsna Adhana
2020-10-23   School Faculty Scheduling System 1.0 - 'username' SQL Injection 12 WEB Jyotsna Adhana
2020-10-23   School Faculty Scheduling System 1.0 - 'id' SQL Injection 11 WEB Jyotsna Adhana
2020-10-23   Point of Sales 1.0 - 'username' SQL Injection 11 WEB Jyotsna Adhana
2020-10-23   Gym Management System 1.0 - 'id' SQL Injection 13 WEB Jyotsna Adhana
2020-10-23   Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored) 11 WEB Ankita Pal
2020-10-23   Lot Reservation Management System 1.0 - Authentication Bypass 11 WEB Ankita Pal
2020-10-23   Point of Sales 1.0 - 'id' SQL Injection 12 WEB Ankita Pal
2020-10-23   User Registration & Login and User Management System 2.1 - SQL Injection 11 WEB Ihsan Sencan
2020-10-23   Car Rental Management System 1.0 - Arbitrary File Upload 10 WEB Jyotsna Adhana
2020-10-23   Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection 12 WEB Ihsan Sencan
2020-10-23   Ajenti 2.1.36 - Remote Code Execution (Authenticated) 13 WEB Ahmet Ümit BAYRAM
2020-10-23   Online Library Management System 1.0 - Arbitrary File Upload 11 WEB Jyotsna Adhana
2020-10-21   Tiki Wiki CMS Groupware 21.1 - Authentication Bypass 13 WEB Maximilian Barz
2020-10-21   Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting 13 WEB Adeeb Shah
2020-10-21   Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scripting 9 WEB Adeeb Shah
2020-10-21   Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scripting 11 WEB Adeeb Shah
2020-10-21   GOautodial 4.0 - Authenticated Shell Upload 11 WEB Balzabu
2020-10-21   School Faculty Scheduling System 1.0 - Authentication Bypass POC 11 WEB Jyotsna Adhana
2020-10-21   School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC 11 WEB Jyotsna Adhana
2020-10-21   Hrsale 2.0.0 - Local File Inclusion 11 WEB Sosecure
2020-10-20   WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting (Authenticated) 12 WEB n1x_
2020-10-20   WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection 10 WEB Jonatas Fil
2020-10-20   Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution 10 WEB Jonatas Fil
2020-10-20   Mobile Shop System v1.0 - SQL Injection Authentication Bypass 11 WEB Moaaz Taha
2020-10-20   RiteCMS 2.2.1 - Remote Code Execution (Authenticated) 11 WEB H0j3n
2020-10-20   User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS 12 WEB yusufmalikul
2020-10-20   WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload 15 WEB Net-Hunter
2020-10-20   Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated) 12 WEB nag0mez
2020-10-20   Visitor Management System in PHP 1.0 - SQL Injection (Authenticated) 12 WEB Rahul Ramkumar
2020-10-20   Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Courses Content Disclosure 13 WEB redtimmysec
2020-10-20   Loan Management System 1.0 - Multiple Cross Site Scripting (Stored) 11 WEB Akıner Kısa
2020-10-20   Comtrend AR-5387un router - Persistent XSS (Authenticated) 14 WEB OscarAkaElvis
2020-10-19   Textpattern CMS 4.6.2 - Cross-site Request Forgery 11 WEB Alperen Ergel
2020-10-19   Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated) 13 WEB Rodolfo Tavares
2020-10-19   Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields) 12 WEB Kokn3t
2020-10-19   Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in 10 WEB Daniel Morris
2020-10-19   HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS) 22 WEB Alexei Kojenov
2020-10-19   HiSilicon Video Encoders - Full admin access via backdoor password 12 WEB Alexei Kojenov
2020-10-19   HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware 14 WEB Alexei Kojenov
2020-10-19   HiSilicon Video Encoders - RCE via unauthenticated command injection 12 WEB Alexei Kojenov
2020-10-19   HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal 13 WEB Alexei Kojenov
2020-10-19   Online Job Portal 1.0 - Cross Site Scripting (Stored) 11 WEB Akıner Kısa
2020-10-19   Online Discussion Forum Site 1.0 - XSS in Messaging System 14 WEB j5oh
2020-10-19   Online Student's Management System 1.0 - Remote Code Execution (Authenticated) 13 WEB Akıner Kısa
2020-10-19   Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection 14 WEB Matthew Aberegg
2020-10-19   Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection 12 WEB Matthew Aberegg
2020-10-19   Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting 13 WEB Matthew Aberegg
2020-10-19   Tourism Management System 1.0 - Arbitrary File Upload 10 WEB Ankita Pal
2020-10-16   CS-Cart 1.3.3 - authenticated RCE 11 WEB 0xmmnbassel
2020-10-16   CS-Cart 1.3.3 - 'classes_dir' LFI 11 WEB 0xmmnbassel
2020-10-16   Seat Reservation System 1.0 - Unauthenticated SQL Injection 12 WEB Rahul Ramkumar
2020-10-16   Hotel Management System 1.0 - Remote Code Execution (Authenticated) 9 WEB Aporlorxl23
2020-10-16   Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated) 13 WEB Rahul Ramkumar
2020-10-16   aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated) 8 WEB Ünsal Furkan Harani
2020-10-16   Restaurant Reservation System 1.0 - 'date' SQL Injection (Authenticated) 9 WEB b1nary
2020-10-16   Company Visitor Management System (CVMS) 1.0 - Authentication Bypass 9 WEB Oğuz Türkgenç
2020-10-16   Alumni Management System 1.0 - Authentication Bypass 12 WEB Ankita Pal
2020-10-16   Employee Management System 1.0 - Authentication Bypass 8 WEB Ankita Pal
2020-10-16   Employee Management System 1.0 - Cross Site Scripting (Stored) 11 WEB Ankita Pal
2020-10-15   Zoo Management System 1.0 - Authentication Bypass 13 WEB Jyotsna Adhana
2020-10-15   Simple Grocery Store Sales And Inventory System 1.0 - Authentication Bypass 14 WEB Saurav Shukla
2020-10-15   rConfig 3.9.5 - Remote Code Execution (Unauthenticated) 25 WEB Daniel Monzón
2020-10-15   Vehicle Parking Management System 1.0 - Authentication Bypass 12 WEB BKpatron
2020-10-14   NodeBB Forum 1.12.2-1.14.2 - Account Takeover 13 WEB Muhammed Eren Uygun
2020-07-23   TimeClock Software 1.01 0 - (Authenticated) Time-Based SQL Injection 14 WEB François Bibeau
2020-10-13   berliCRM 1.0.24 - 'src_record' SQL Injection 13 WEB Ahmet Ümit BAYRAM
2020-10-12   Cisco ASA and FTD 9.6.4.42 - Path Traversal 15 WEB 3ndG4me
2020-10-12   Online Students Management System 1.0 - 'username' SQL Injections 12 WEB George Tsimpidas
2020-10-12   Liman 0.7 - Cross-Site Request Forgery (Change Password) 12 WEB George Tsimpidas
2020-10-12   MedDream PACS Server 6.8.3.751 - Remote Code Execution (Unauthenticated) 14 WEB bzyo
2020-10-12   Small CRM 2.0 - 'email' SQL Injection 14 WEB Ahmet Ümit BAYRAM
2020-10-09   openMAINT 1.1-2.4.2 - Arbitrary File Upload 14 WEB mrb3n
2020-10-09   DynPG 4.9.1 - Persistent Cross-Site Scripting (Authenticated) 15 WEB Enes Özeser
2020-10-09   Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting 12 WEB Ataberk YAVUZER
2020-10-08   D-Link DSR-250N 3.12 - Denial of Service (PoC) 14 WEB RedTeam Pentesting GmbH
2020-10-08   SEO Panel 4.6.0 - Remote Code Execution (1) 20 WEB Kiko Andreu
2020-10-07   Textpattern CMS 4.6.2 - 'body' Persistent Cross-Site Scripting 18 WEB Alperen Ergel
2020-10-06   EasyPMS 1.0.0 - Authentication Bypass 20 WEB Jok3r
2020-10-06   Karel IP Phone IP1211 Web Management Panel - Directory Traversal 21 WEB berat isler
2020-10-05   SpamTitan 7.07 - Unauthenticated Remote Code Execution 21 WEB Felipe Molina
2020-10-02   Photo Share Website 1.0 - Persistent Cross-Site Scripting 14 WEB Augkim
2020-10-02   MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated) 16 WEB bzyo
2020-10-01   Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting 13 WEB Alperen Ergel
2020-10-01   CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated) 16 WEB Roel van Beurden
2020-10-01   GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting (Authenticated) 12 WEB Roel van Beurden
2020-10-01   WebsiteBaker 2.12.2 - 'display_name' SQL Injection (authenticated) 17 WEB Roel van Beurden
2020-10-01   MonoCMS Blog 1.0 - Arbitrary File Deletion (Authenticated) 16 WEB Shahrukh Iqbal Mirza
2020-10-01   SpinetiX Fusion Digital Signage 3.4.8 - Username Enumeration 13 WEB LiquidWorm
2020-10-01   SpinetiX Fusion Digital Signage 3.4.8 - Cross-Site Request Forgery (Add Admin) 15 WEB LiquidWorm
2020-10-01   SpinetiX Fusion Digital Signage 3.4.8 - Database Backup Disclosure 14 WEB LiquidWorm
2020-10-01   BrightSign Digital Signage Diagnostic Web Server 8.2.26 - File Delete Path Traversal 14 WEB LiquidWorm
2020-10-01   BrightSign Digital Signage Diagnostic Web Server 8.2.26 - Server-Side Request Forgery (Unauthenticat 16 WEB LiquidWorm
2020-09-29   WebsiteBaker 2.12.2 - Remote Code Execution 14 WEB Enesdex
2020-09-28   Joplin 1.0.245 - Arbitrary Code Execution (PoC) 13 WEB Ademar Nowasky Junior