2018-12-04
|
|
Joomla! Component JE Photo Gallery 1.1 - 'categoryid' SQL Injection
|
221 |
WEB
|
Ihsan Sencan
|
2018-12-04
|
|
PaloAlto Networks Expedition Migration Tool 1.0.106 - Information Disclosure
|
137 |
WEB
|
ParagonSec
|
2018-12-04
|
|
Fleetco Fleet Maintenance Management 1.2 - Remote Code Execution
|
142 |
WEB
|
AkkuS
|
2018-12-03
|
|
Joomla JCE 2.6.33 Arbitrary File Upload
|
533 |
WEB
|
KingSkrupellos
|
2018-12-03
|
|
Schneider Electric PLC - Session Calculation Authentication Bypass
|
165 |
WEB
|
Deneut Tijl
|
2018-11-16
|
|
PHP-Proxy 5.1.0 - Local File Inclusion
|
416 |
WEB
|
Ameer Pornillos
|
2018-11-14
|
|
TP-Link Archer C50 Wireless Router 171227 - Cross-Site Request Forgery (Configuration File Disclosur
|
183 |
WEB
|
Wadeek
|
2018-11-07
|
|
CMS Made Simple 2.2.7 - Remote Code Execution
|
230 |
WEB
|
Lucian Ioan Nitescu
|
2018-11-06
|
|
blueimp jQuery Arbitrary File Upload
|
251 |
WEB
|
wvu
|
2018-11-06
|
|
PHP Proxy 3.0.3 - Local File Inclusion
|
196 |
WEB
|
AkkuS
|
2018-11-06
|
|
Virgin Media Hub 3.0 Router - Denial of Service (PoC)
|
131 |
WEB
|
Ross Inman
|
2018-11-06
|
|
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
|
183 |
WEB
|
Chris Lyne
|
2018-11-01
|
|
Loadbalancer.org Enterprise VA MAX 8.3.2 - Remote Code Execution
|
155 |
WEB
|
Jakub Palaczynski
|
2018-10-29
|
|
WordPress Arforms 3.5.1 Arbitrary File Delete
|
252 |
WEB
|
Amir Hossein Mahboubi
|
2018-10-25
|
|
Apache OFBiz 16.11.04 - XML External Entity Injection
|
191 |
WEB
|
Jamie Parfet
|
2018-10-17
|
|
Heatmiser Wifi Thermostat 1.7 - Credential Disclosure
|
99 |
WEB
|
d0wnp0ur
|
2018-10-16
|
|
Academic Timetable Final Build 7.0 - Information Disclosure
|
116 |
WEB
|
Ihsan Sencan
|
2018-10-16
|
|
FLIR Brickstream 3D+ - RTSP Stream Disclosure
|
162 |
WEB
|
LiquidWorm
|
2018-10-16
|
|
FLIR AX8 Thermal Camera 1.32.16 - Remote Code Execution
|
186 |
WEB
|
LiquidWorm
|
2018-10-15
|
|
FluxBB < 1.5.6 - SQL Injection
|
135 |
WEB
|
secthrowaway
|
2018-10-15
|
|
Phoenix Contact WebVisit 2985725 - Authentication Bypass
|
146 |
WEB
|
Photubias
|
2018-10-12
|
|
Phoenix Contact WebVisit 6.40.00 - Password Disclosure
|
125 |
WEB
|
Photubias
|
2018-10-09
|
|
Imperva SecureSphere 13 - Remote Command Execution
|
188 |
WEB
|
rsp3ar
|
2018-10-09
|
|
FLIR Thermal Traffic Cameras 1.01-0bb5b27 - Information Disclosure
|
173 |
WEB
|
LiquidWorm
|
2018-10-08
|
|
Navigate CMS Unauthenticated Remote Code Execution
|
148 |
WEB
|
Pyriphlegethon
|
2018-10-08
|
|
Easy File Sharing Web Server 7.2 Domain Name Buffer Overflow
|
116 |
WEB
|
ZwX
|
2018-10-08
|
|
ISPConfig < 3.1.13 - Remote Command Execution
|
221 |
WEB
|
0x09AL
|
2018-10-08
|
|
H2 Database 1.4.196 - Remote Code Execution
|
225 |
WEB
|
h4ckNinja
|
2018-09-25
|
|
Joomla! Component AMGallery 1.2.3 - 'filter_category_id' SQL Injection
|
167 |
WEB
|
Ihsan Sencan
|
2018-09-25
|
|
LG SuperSign EZ CMS 2.5 - Remote Code Execution
|
146 |
WEB
|
Alejandro Fanjul
|
2018-09-20
|
|
LG SuperSign EZ CMS 2.5 - Local File Inclusion
|
169 |
WEB
|
Alejandro Fanjul
|
2018-09-17
|
|
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit)
|
157 |
WEB
|
Stephen Shkardoon
|
2018-09-13
|
|
LG Smart IP Camera 1508190 - Backup File Download
|
163 |
WEB
|
Ege Balci
|
2018-09-13
|
|
CirCarLife SCADA 4.3.0 - Credential Disclosure
|
167 |
WEB
|
SadFud
|
2018-09-13
|
|
Seagate Personal Cloud Information Disclosure
|
162 |
WEB
|
Yorick Koster
|
2018-09-12
|
|
Tor Browser 7.x NoScript Bypass
|
128 |
WEB
|
x0rz
|
2018-09-11
|
|
phpMyAdmin Credential Stealer
|
269 |
WEB
|
Dhiraj Mishra
|
2018-09-11
|
|
LW-N605R 12.20.2.1486 - Remote Code Execution
|
158 |
WEB
|
Nassim Asrir
|
2018-09-11
|
|
RPi Cam Control < 6.4.25 - 'preview.php' Remote Command Execution
|
150 |
WEB
|
Reigning Shells
|
2018-09-07
|
|
Apache Roller 5.0.3 - XML External Entity Injection (File Disclosure)
|
194 |
WEB
|
Marko Jokic
|
2018-08-30
|
|
Episerver 7 patch 4 - XML External Entity Injection
|
155 |
WEB
|
Jonas Lejon
|
2018-08-28
|
|
LiteCart 2.1.2 - Arbitrary File Upload
|
110 |
WEB
|
Haboob Team
|
2018-08-27
|
|
KingMedia 4.1 - Remote Code Execution
|
230 |
WEB
|
Efrén Díaz
|
2018-08-27
|
|
Hikvision IP Camera 5.4.0 - User Enumeration (Metasploit)
|
319 |
WEB
|
Alfie
|
2018-08-27
|
|
ADM 3.1.2RHG1 - Remote Code Execution
|
103 |
WEB
|
Matthew Fulton
|
2018-08-27
|
|
Mikrotik WinBox 6.42 - Credential Disclosure (golang)
|
103 |
WEB
|
Maxim Yefimenko
|
2018-08-16
|
|
cPanel 76 Cross Site Scripting
|
166 |
WEB
|
Numan OZDEMIR
|
2018-08-15
|
|
cgit 1.2.1 - Directory Traversal (Metasploit)
|
111 |
WEB
|
Dhiraj Mishra
|
2018-08-10
|
|
TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Information Disclosure)
|
114 |
WEB
|
Wadeek
|
2018-08-10
|
|
TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Remote Reboot)
|
114 |
WEB
|
Wadeek
|
2018-08-07
|
|
OpenEMR < 5.0.1 - Remote Code Execution
|
157 |
WEB
|
Cody Zacharias
|
2018-08-03
|
|
Seq 4.2.476 Authentication Bypass
|
136 |
WEB
|
Daniel Chactoura
|
2018-08-03
|
|
CoSoSys Endpoint Protector 4.5.0.1 - Authenticated Remote Root Command Injection
|
99 |
WEB
|
0x09AL
|
2018-08-01
|
|
SonicWall Global Management System XMLRPC
|
131 |
WEB
|
Michael Flanders
|
2018-08-01
|
|
Vtiger CRM 6.3.0 Authenticated Logo Upload Remote Command Execution
|
155 |
WEB
|
Touhid M.Shaikh
|
2018-07-31
|
|
H2 Database 1.4.197 Information Disclosure
|
142 |
WEB
|
owodelta
|
2018-07-25
|
|
Cisco Adaptive Security Appliance Path Traversal
|
156 |
WEB
|
Angelo Ruwantha
|
2018-07-25
|
|
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
|
114 |
WEB
|
Mehmet Ince
|
2018-07-25
|
|
Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
|
142 |
WEB
|
Nathu Nandwani
|
2018-07-25
|
|
Davolink DVW 3200 Router - Password Disclosure
|
118 |
WEB
|
Ankit Anubhav
|
2018-07-20
|
|
CMS Made Simple 2.2.5 Authenticated Remote Command Execution
|
156 |
WEB
|
Jacob Robles
|
2018-07-19
|
|
PrestaShop < 1.6.1.19 - AES CBC Privilege Escalation Exploit
|
114 |
WEB
|
Charles Fol
|
2018-07-19
|
|
PrestaShop < 1.6.1.19 - BlowFish ECD Privilege Escalation Exploit
|
145 |
WEB
|
Charles Fol
|
2018-07-19
|
|
Modx Revolution Remote Code Execution
|
108 |
WEB
|
Vitalii Rudnykh
|
2018-07-17
|
|
QNAP Q'Center change_passwd Command Execution
|
121 |
WEB
|
Brendan Coles
|
2018-07-13
|
|
Apache CouchDB Arbitrary Command Execution
|
122 |
WEB
|
Green-m
|
2018-07-13
|
|
phpMyAdmin Authenticated Remote Code Execution
|
201 |
WEB
|
Jacob Robles
|
2018-07-12
|
|
Instagram Clone Script 2.0 Cross Site Scripting
|
129 |
WEB
|
Borna Nematzadeh
|
2018-07-11
|
|
Monstra CMS Authenticated Arbitrary File Upload
|
182 |
WEB
|
Touhid M.Shaikh
|
2018-07-11
|
|
D-Link DIR601 2.02 - Credential Disclosure
|
146 |
WEB
|
Richard Rogerson
|
2018-07-11
|
|
Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code Execution
|
168 |
WEB
|
bobsecq
|
2018-07-11
|
|
Gitea 1.4.0 - Remote Code Execution
|
120 |
WEB
|
Kacper Szurek
|
2018-07-09
|
|
GitList 0.6.0 Argument Injection
|
135 |
WEB
|
Shelby Pace
|
2018-07-05
|
|
CMS Made Simple 2.2.5 - Remote Code Execution
|
216 |
WEB
|
Mustafa Hasan
|
2018-07-03
|
|
VMware NSX SD-WAN Edge < 3.1.2 - Command Injection
|
151 |
WEB
|
ParagonSec
|
2018-07-03
|
|
Geutebruck 5.02024 G-Cam/EFD-2250 - 'simple_loglistjs.cgi' Remote Command Execution (Metasploit)
|
112 |
WEB
|
RandoriSec
|
2018-06-29
|
|
Cisco Adaptive Security Appliance - Path Traversal
|
155 |
WEB
|
Yassine Aboukir
|
2018-06-28
|
|
HPE VAN SDN 2.7.18.0503 - Remote Root
|
116 |
WEB
|
KoreLogic
|
2018-06-28
|
|
IPConfigure Orchid VMS 2.0.5 - Directory Traversal Information Disclosure (Metasploit)
|
114 |
WEB
|
Sanjiv Kawa
|
2018-06-28
|
|
Apache CouchDB < 2.1.0 - Remote Code Execution
|
128 |
WEB
|
Cody Zacharias
|
2018-06-28
|
|
TP-Link TL-WA850RE - Remote Command Execution
|
133 |
WEB
|
yoresongo
|
2018-06-11
|
|
userSpice 4.3.24 - Username Enumeration
|
163 |
WEB
|
Dolev Farhi
|
2018-06-11
|
|
userSpice 4.3.24 - 'X-Forwarded-For' Cross-Site Scripting
|
111 |
WEB
|
Dolev Farhi
|
2018-06-11
|
|
XiongMai uc-httpd 1.0.0 - Buffer Overflow
|
191 |
WEB
|
Andrew Watson
|
2018-06-11
|
|
Monstra CMS < 3.0.4 - Cross-Site Scripting
|
143 |
WEB
|
DEEPIN2
|
2018-06-11
|
|
Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email)
|
162 |
WEB
|
Kl3_GMjq6
|
2018-06-11
|
|
Pagekit < 1.0.13 - Cross-Site Scripting Code Generator
|
145 |
WEB
|
DEEPIN2
|
2018-05-28
|
|
SAP Internet Transaction Server 6200.x - Session Fixation / Cross-Site Scripting
|
131 |
WEB
|
J. Carrillo Lencina
|
2018-05-22
|
|
GitBucket 4.23.1 - Remote Code Execution
|
120 |
WEB
|
Kacper Szurek
|
2018-05-18
|
|
Intelbras NCLOUD 300 1.0 - Authentication bypass
|
144 |
WEB
|
Pedro Aguiar
|
2018-05-10
|
|
Mantis manage_proj_page PHP Code Execution
|
156 |
WEB
|
Lars Sorenson
|
2018-05-08
|
|
Palo Alto Networks readSessionVarsFromFile() Session Corruption
|
145 |
WEB
|
hdm
|
2018-05-08
|
|
PlaySMS import.php Code Execution
|
129 |
WEB
|
Touhid M.Shaikh
|
2018-05-08
|
|
PlaySMS sendfromfile.php Code Execution
|
129 |
WEB
|
DarkS3curity
|
2018-05-07
|
|
WordPress Plugin User Role Editor < 4.25 - Privilege Escalation
|
170 |
WEB
|
Tomislav Paskalev
|
2018-05-07
|
|
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
|
201 |
WEB
|
Takeshi Terada
|
2018-05-03
|
|
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
|
146 |
WEB
|
Jared Arave
|
2018-05-03
|
|
Drupal < 7.58 - 'Drupalgeddon3' Authenticated Remote Code
|
186 |
WEB
|
SixP4ck3r
|
2018-05-03
|
|
osCommerce Installer Unauthenticated Code Execution
|
128 |
WEB
|
Daniel Teixeira
|
2018-04-27
|
|
GitList 0.6 - Unauthenticated Remote Code Execution
|
129 |
WEB
|
Kacper Szurek
|
2018-04-27
|
|
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
|
107 |
WEB
|
Sven Fassbender
|
2018-04-25
|
|
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
|
143 |
WEB
|
Berk Cem Göksel
|
2018-04-25
|
|
Interspire Email Marketer < 6.1.6 - Remote Admin Authentication Bypass
|
147 |
WEB
|
devcoinfet
|
2018-04-24
|
|
Apache CouchDB 1.7.0 and 2.x before 2.1.1 - Remote Privilege Escalation
|
102 |
WEB
|
Sebastián Castro
|
2018-04-19
|
|
Lutron Quantum 2.0 - 3.2.243 - Information Disclosure
|
134 |
WEB
|
SadFud
|
2018-04-16
|
|
MikroTik 6.41.4 - FTP daemon Denial of Service PoC
|
140 |
WEB
|
FarazPajohan
|
2018-04-16
|
|
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution
|
180 |
WEB
|
Hans Topo
|
2018-04-16
|
|
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)
|
179 |
WEB
|
Vitalii Rudnykh
|
2018-04-10
|
|
CyberArk Password Vault Web Access < 9.9.5 / < 9.10 / 10.1 - Remote Code Execution
|
98 |
WEB
|
RedTeam Pentesting
|
2018-04-04
|
|
ProcessMaker Plugin Code Execution
|
118 |
WEB
|
Brendan Coles
|
2018-04-04
|
|
DuckDuckGo 4.2.0 WebRTC Private IP Leakage
|
143 |
WEB
|
Brendan Coles
|
2018-04-02
|
|
Vtiger CRM 6.3.0 - Authenticated Arbitrary File Upload (Metasploit)
|
145 |
WEB
|
Touhid M.Shaikh
|
2018-04-02
|
|
osCommerce 2.3.4.1 - Remote Code Execution
|
149 |
WEB
|
Simon Scannell
|
2018-04-02
|
|
Homematic CCU2 2.29.23 - Remote Command Execution
|
150 |
WEB
|
Gregor Kopf
|
2018-04-02
|
|
Homematic CCU2 2.29.23 - Arbitrary File Write
|
164 |
WEB
|
Gregor Kopf
|
2018-03-30
|
|
Joomla Component Fields - SQLi Remote Code Execution (Metasploit)
|
183 |
WEB
|
luisco100
|
2018-03-30
|
|
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session)
|
139 |
WEB
|
Stefan Horst
|
2018-03-30
|
|
Square 9 GlobalForms 6.2.x Blind SQL Injection
|
135 |
WEB
|
Darrell Damstedt
|
2018-03-29
|
|
TwonkyMedia Server 7.0.11-8.5 - Directory Traversal
|
138 |
WEB
|
Sven Fassbender
|
2018-03-27
|
|
ClipBucket beats_uploader Unauthenticated Arbitrary File Upload
|
108 |
WEB
|
Touhid M.Shaikh
|
2018-03-26
|
|
XenForo 2 - CSS Loader Denial of Service
|
137 |
WEB
|
LockedByte
|
2018-03-26
|
|
TL-WR720N 150Mbps Wireless N Router - Cross-Site Request Forgery
|
150 |
WEB
|
Mans van Someren
|
2018-03-26
|
|
Hikvision IP Camera versions 5.2.0 - 5.3.9 (Builds 140721 - 170109) - Access Control Bypass
|
312 |
WEB
|
Matamorphosis
|
2018-03-22
|
|
Cisco node-jos < 0.11.0 - Re-sign Tokens
|
161 |
WEB
|
zioBlack
|
2018-03-21
|
|
Intelbras Telefone IP TIP200 LITE - Local File Disclosure
|
127 |
WEB
|
anhax0r
|