Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-10-20   WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload 27 WEB Net-Hunter
2020-10-20   Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated) 22 WEB nag0mez
2020-10-20   Visitor Management System in PHP 1.0 - SQL Injection (Authenticated) 23 WEB Rahul Ramkumar
2020-10-20   Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Courses Content Disclosure 23 WEB redtimmysec
2020-10-20   Loan Management System 1.0 - Multiple Cross Site Scripting (Stored) 22 WEB Akıner Kısa
2020-10-20   Comtrend AR-5387un router - Persistent XSS (Authenticated) 27 WEB OscarAkaElvis
2020-10-19   Textpattern CMS 4.6.2 - Cross-site Request Forgery 23 WEB Alperen Ergel
2020-10-19   Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated) 24 WEB Rodolfo Tavares
2020-10-19   Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields) 24 WEB Kokn3t
2020-10-19   Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in 22 WEB Daniel Morris
2020-10-19   HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS) 33 WEB Alexei Kojenov
2020-10-19   HiSilicon Video Encoders - Full admin access via backdoor password 24 WEB Alexei Kojenov
2020-10-19   HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware 24 WEB Alexei Kojenov
2020-10-19   HiSilicon Video Encoders - RCE via unauthenticated command injection 25 WEB Alexei Kojenov
2020-10-19   HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal 24 WEB Alexei Kojenov
2020-10-19   Online Job Portal 1.0 - Cross Site Scripting (Stored) 21 WEB Akıner Kısa
2020-10-19   Online Discussion Forum Site 1.0 - XSS in Messaging System 27 WEB j5oh
2020-10-19   Online Student's Management System 1.0 - Remote Code Execution (Authenticated) 25 WEB Akıner Kısa
2020-10-19   Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection 26 WEB Matthew Aberegg
2020-10-19   Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection 22 WEB Matthew Aberegg
2020-10-19   Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting 27 WEB Matthew Aberegg
2020-10-19   Tourism Management System 1.0 - Arbitrary File Upload 21 WEB Ankita Pal
2020-10-16   CS-Cart 1.3.3 - authenticated RCE 22 WEB 0xmmnbassel
2020-10-16   CS-Cart 1.3.3 - 'classes_dir' LFI 24 WEB 0xmmnbassel
2020-10-16   Seat Reservation System 1.0 - Unauthenticated SQL Injection 22 WEB Rahul Ramkumar
2020-10-16   Hotel Management System 1.0 - Remote Code Execution (Authenticated) 24 WEB Aporlorxl23
2020-10-16   Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated) 24 WEB Rahul Ramkumar
2020-10-16   aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated) 18 WEB Ünsal Furkan Harani
2020-10-16   Restaurant Reservation System 1.0 - 'date' SQL Injection (Authenticated) 20 WEB b1nary
2020-10-16   Company Visitor Management System (CVMS) 1.0 - Authentication Bypass 21 WEB Oğuz Türkgenç
2020-10-16   Alumni Management System 1.0 - Authentication Bypass 23 WEB Ankita Pal
2020-10-16   Employee Management System 1.0 - Authentication Bypass 19 WEB Ankita Pal
2020-10-16   Employee Management System 1.0 - Cross Site Scripting (Stored) 21 WEB Ankita Pal
2020-10-15   Zoo Management System 1.0 - Authentication Bypass 21 WEB Jyotsna Adhana
2020-10-15   Simple Grocery Store Sales And Inventory System 1.0 - Authentication Bypass 23 WEB Saurav Shukla
2020-10-15   rConfig 3.9.5 - Remote Code Execution (Unauthenticated) 38 WEB Daniel Monzón
2020-10-15   Vehicle Parking Management System 1.0 - Authentication Bypass 21 WEB BKpatron
2020-10-14   NodeBB Forum 1.12.2-1.14.2 - Account Takeover 22 WEB Muhammed Eren Uygun
2020-07-23   TimeClock Software 1.01 0 - (Authenticated) Time-Based SQL Injection 23 WEB François Bibeau
2020-10-13   berliCRM 1.0.24 - 'src_record' SQL Injection 25 WEB Ahmet Ümit BAYRAM
2020-10-12   Cisco ASA and FTD 9.6.4.42 - Path Traversal 22 WEB 3ndG4me
2020-10-12   Online Students Management System 1.0 - 'username' SQL Injections 24 WEB George Tsimpidas
2020-10-12   Liman 0.7 - Cross-Site Request Forgery (Change Password) 25 WEB George Tsimpidas
2020-10-12   MedDream PACS Server 6.8.3.751 - Remote Code Execution (Unauthenticated) 26 WEB bzyo
2020-10-12   Small CRM 2.0 - 'email' SQL Injection 25 WEB Ahmet Ümit BAYRAM
2020-10-09   openMAINT 1.1-2.4.2 - Arbitrary File Upload 26 WEB mrb3n
2020-10-09   DynPG 4.9.1 - Persistent Cross-Site Scripting (Authenticated) 26 WEB Enes Özeser
2020-10-09   Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting 23 WEB Ataberk YAVUZER
2020-10-08   D-Link DSR-250N 3.12 - Denial of Service (PoC) 23 WEB RedTeam Pentesting GmbH
2020-10-08   SEO Panel 4.6.0 - Remote Code Execution (1) 33 WEB Kiko Andreu
2020-10-07   Textpattern CMS 4.6.2 - 'body' Persistent Cross-Site Scripting 28 WEB Alperen Ergel
2020-10-06   EasyPMS 1.0.0 - Authentication Bypass 31 WEB Jok3r
2020-10-06   Karel IP Phone IP1211 Web Management Panel - Directory Traversal 35 WEB berat isler
2020-10-05   SpamTitan 7.07 - Unauthenticated Remote Code Execution 41 WEB Felipe Molina
2020-10-02   Photo Share Website 1.0 - Persistent Cross-Site Scripting 24 WEB Augkim
2020-10-02   MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated) 26 WEB bzyo
2020-10-01   Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting 26 WEB Alperen Ergel
2020-10-01   CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated) 28 WEB Roel van Beurden
2020-10-01   GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting (Authenticated) 23 WEB Roel van Beurden
2020-10-01   WebsiteBaker 2.12.2 - 'display_name' SQL Injection (authenticated) 29 WEB Roel van Beurden
2020-10-01   MonoCMS Blog 1.0 - Arbitrary File Deletion (Authenticated) 28 WEB Shahrukh Iqbal Mirza
2020-10-01   SpinetiX Fusion Digital Signage 3.4.8 - Username Enumeration 22 WEB LiquidWorm
2020-10-01   SpinetiX Fusion Digital Signage 3.4.8 - Cross-Site Request Forgery (Add Admin) 26 WEB LiquidWorm
2020-10-01   SpinetiX Fusion Digital Signage 3.4.8 - Database Backup Disclosure 25 WEB LiquidWorm
2020-10-01   BrightSign Digital Signage Diagnostic Web Server 8.2.26 - File Delete Path Traversal 24 WEB LiquidWorm
2020-10-01   BrightSign Digital Signage Diagnostic Web Server 8.2.26 - Server-Side Request Forgery (Unauthenticat 30 WEB LiquidWorm
2020-09-29   WebsiteBaker 2.12.2 - Remote Code Execution 25 WEB Enesdex
2020-09-28   Joplin 1.0.245 - Arbitrary Code Execution (PoC) 25 WEB Ademar Nowasky Junior
2020-09-28   Mida eFramework 2.8.9 - Remote Code Execution 26 WEB elbae
2020-09-25   B-swiss 3 Digital Signage System 3.6.5 - Database Disclosure 22 WEB LiquidWorm
2020-09-25   B-swiss 3 Digital Signage System 3.6.5 - Cross-Site Request Forgery (Add Maintenance Admin) 22 WEB LiquidWorm
2020-09-25   Anchor CMS 0.12.7 - Persistent Cross-Site Scripting (Authenticated) 24 WEB Sinem Şahin
2020-09-25   BigTree CMS 4.4.10 - Remote Code Execution 23 WEB SunCSR
2020-09-24   Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting 22 WEB Rahul Ramkumar
2020-09-24   Simple Online Food Ordering System 1.0 - 'id' SQL Injection (Unauthenticated) 25 WEB Aporlorxl23
2020-09-23   Online Food Ordering System 1.0 - Remote Code Execution 24 WEB Eren Şimşek
2020-09-22   Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting 23 WEB Alperen Ergel
2020-09-22   Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution 26 WEB Milad Fadavvi
2020-09-21   B-swiss 3 Digital Signage System 3.6.5 - Remote Code Execution 27 WEB LiquidWorm
2020-09-21   Mida eFramework 2.9.0 - Back Door Access 27 WEB elbae
2020-09-21   Seat Reservation System 1.0 - 'id' SQL Injection 22 WEB Augkim
2020-09-21   BlackCat CMS 1.3.6 - Cross-Site Request Forgery 27 WEB Noth
2020-09-21   Online Shop Project 1.0 - 'p' SQL Injection 27 WEB Augkim
2020-09-18   Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated) 33 WEB Nikolas Geiselman
2020-09-18   SpamTitan 7.07 - Remote Code Execution (Authenticated) 30 WEB Felipe Molina
2020-09-16   Piwigo 2.10.1 - Cross Site Scripting 25 WEB Iridium
2020-09-15   Tailor MS 1.0 - Reflected Cross-Site Scripting 31 WEB boku
2020-09-15   ThinkAdmin 6 - Arbitrarily File Read 25 WEB Hzllaga
2020-09-14   Joomla! paGO Commerce 2.5.9.0 - SQL Injection (Authenticated) 24 WEB Mehmet Kelepçe
2020-09-14   RAD SecFlow-1v SF_0290_2.3.01.26 - Cross-Site Request Forgery (Reboot) 22 WEB Jonatan Schor
2020-09-14   RAD SecFlow-1v SF_0290_2.3.01.26 - Persistent Cross-Site Scripting 19 WEB Jonatan Schor
2020-09-11   Tea LaTex 1.0 - Remote Code Execution (Unauthenticated) 27 WEB nepska
2020-09-11   VTENEXT 19 CE - Remote Code Execution 23 WEB Marco Ruela
2020-09-10   ZTE Router F602W - Captcha Bypass 26 WEB Hritik Vijay
2020-09-10   CuteNews 2.1.2 - Remote Code Execution 26 WEB Musyoka Ian
2020-09-10   Tiandy IPC and NVR 9.12.7 - Credential Disclosure 22 WEB zb3
2020-09-09   Scopia XT Desktop 8.3.915.4 - Cross-Site Request Forgery (change admin password) 23 WEB V1n1v131r4
2020-09-09   Tailor Management System - 'id' SQL Injection 25 WEB Mosaaed
2020-09-07   ManageEngine Applications Manager 14700 - Remote Code Execution (Authenticated) 26 WEB Hodorsec
2020-09-07   grocy 2.7.1 - Persistent Cross-Site Scripting 31 WEB Mufaddal Masalawala
2020-09-07   Cabot 0.11.12 - Persistent Cross-Site Scripting 25 WEB Abhiram V
2020-09-03   SiteMagic CMS 4.4.2 - Arbitrary File Upload (Authenticated) 26 WEB V1n1v131r4
2020-09-03   Daily Tracker System 1.0 - Authentication Bypass 28 WEB Adeeb Shah
2020-09-03   BloodX CMS 1.0 - Authentication Bypass 24 WEB BKpatron
2020-09-03   Savsoft Quiz Enterprise Version 5.5 - Persistent Cross-Site Scripting 24 WEB Hemant Patidar
2020-09-02   Rukovoditel 2.7.1 - Remote Code Execution (2) (Authenticated) 30 WEB danyx07
2020-09-02   Stock Management System 1.0 - Cross-Site Request Forgery (Change Username) 25 WEB boku
2020-09-01   moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated) 26 WEB Abdulkadir Kaya
2020-09-01   Mara CMS 7.5 - Remote Code Execution (Authenticated) 30 WEB 0blio_
2020-08-31   CMS Made Simple 2.2.14 - Arbitrary File Upload (Authenticated) 26 WEB Luis Noriega
2020-08-31   Fuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated) 29 WEB c0mpu7er
2020-08-31   Mara CMS 7.5 - Reflective Cross-Site Scripting 25 WEB George Tsimpidas
2020-08-31   Online Book Store 1.0 - 'id' SQL Injection 24 WEB Moaaz Taha
2020-08-28   Eibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation 25 WEB LiquidWorm
2020-08-28   SymphonyCMS 3.0.0 - Persistent Cross-Site Scripting 29 WEB SunCSR
2020-08-28   Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting 27 WEB Jinson Varghese Behanan
2020-08-28   Online Shopping Alphaware 1.0 - 'id' SQL Injection 26 WEB Moaaz Taha
2020-08-27   Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated) 33 WEB SunCSR Team
2020-08-27   Mida eFramework 2.9.0 - Remote Code Execution 29 WEB elbae
2020-08-26   Eibiz i-Media Server Digital Signage 3.8.0 - Directory Traversal 26 WEB LiquidWorm
2020-08-26   Ericom Access Server x64 9.2.0 - Server-Side Request Forgery 23 WEB hyp3rlinx
2020-08-24   Eibiz i-Media Server Digital Signage 3.8.0 - Configuration Disclosure 25 WEB LiquidWorm
2020-08-24   Eibiz i-Media Server Digital Signage 3.8.0 - Authentication Bypass 23 WEB LiquidWorm
2020-08-24   LimeSurvey 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting 26 WEB Matthew Aberegg
2017-07-24   vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit) 25 WEB Metasploit