2018-03-16
|
|
Spring Data REST < 2.6.9 (Ingalls SR9), 3.0.1 (Kay SR1) - PATCH Request Remote Code Execution
|
189 |
WEB
|
Antonio Francesco Sardella
|
2018-03-13
|
|
Advantech WebAccess < 8.3 - Directory Traversal / Remote Code Execution
|
135 |
WEB
|
Chris Lyne
|
2018-03-13
|
|
ManageEngine Applications Manager 13.5 - Remote Code Execution (Metasploit)
|
122 |
WEB
|
Mehmet Ince
|
2018-03-07
|
|
Bravo Tejari Web Portal Cross Site Scripting
|
122 |
WEB
|
Arvind V.
|
2018-02-28
|
|
Concrete5 < 8.3.0 - Username / Comments Enumeration
|
173 |
WEB
|
Chapman Schleiss
|
2018-02-26
|
|
AsusWRT LAN Unauthenticated Remote Code Execution
|
162 |
WEB
|
Pedro Ribeiro
|
2018-02-26
|
|
UserSpice 4.3 - Blind SQL Injection
|
181 |
WEB
|
Dolev Farhi
|
2018-02-07
|
|
Hava Tahmin 1.0 Database Disclosure
|
155 |
WEB
|
indoushka
|
2018-02-07
|
|
Hazir Site 2.2 Database Disclosure
|
183 |
WEB
|
indoushka
|
2018-02-07
|
|
Gateway 1.0 Database Disclosure
|
163 |
WEB
|
indoushka
|
2018-02-07
|
|
iPortalx Portal Scripti Database Disclosure
|
175 |
WEB
|
indoushka
|
2018-02-06
|
|
Online Voting System - Authentication Bypass
|
200 |
WEB
|
Giulio Comi
|
2018-02-05
|
|
Oracle Hospitality Simphony (MICROS) 2.7 < 2.9 - Directory Traversal
|
160 |
WEB
|
Dmitry Chastuhin
|
2018-01-31
|
|
BMC BladeLogic RSCD Agent 8.3.00.64 - Windows Users Disclosure
|
182 |
WEB
|
Paul Taylor
|
2018-01-30
|
|
Advantech WebAccess < 8.3 - SQL Injection
|
149 |
WEB
|
Chris Lyne
|
2018-01-29
|
|
Asus Router Cross Site Script / Authentication Bypass
|
162 |
WEB
|
4TT4CK3R
|
2018-01-29
|
|
ASUS DSL-N14U B1 Router 1.1.2.3_345 - Change Administrator Password
|
164 |
WEB
|
Víctor Calvo
|
2018-01-24
|
|
Kaltura Remote PHP Code Execution
|
152 |
WEB
|
Robin Verton
|
2018-01-24
|
|
GoAhead Web Server LD_PRELOAD Arbitrary Module Load
|
164 |
WEB
|
h00die
|
2018-01-24
|
|
Photography CMS 1.0 - Cross-Site Request Forgery (Add Admin)
|
149 |
WEB
|
Ihsan Sencan
|
2018-01-22
|
|
Simple ASC CMS 1.2 Database Disclosure
|
138 |
WEB
|
indoushka
|
2018-01-22
|
|
PHPFreeChat 1.7 - Denial of Service
|
134 |
WEB
|
A. Pakbaz
|
2018-01-19
|
|
Primefaces 5.x - Remote Code Execution (Metasploit)
|
206 |
WEB
|
Bjoern Schuette
|
2018-01-16
|
|
Adminer 4.3.1 - Server-Side Request Forgery
|
164 |
WEB
|
hyp3rlinx
|
2018-01-16
|
|
pfSense < 2.1.4 - 'status_rrd_graph_img.php' Command Injection
|
134 |
WEB
|
absolomb
|
2018-01-12
|
|
D-Link Routers 110/412/615/815 < 1.03 - 'service.cgi' Arbitrary Code Execution
|
160 |
WEB
|
Cr0n1c
|
2018-01-12
|
|
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
|
135 |
WEB
|
Vahagn Vardanyan
|
2018-01-11
|
|
Samsung SRN-1670D Web Viewer 1.0.0.193 Arbitrary File Read / Upload
|
136 |
WEB
|
Algeria
|
2018-01-11
|
|
phpCollab 2.5.1 Unauthenticated File Upload
|
140 |
WEB
|
Nick Marcoccio
|
2018-01-10
|
|
Synology Photostation 6.7.2-3429 - Remote Code Execution (Metasploit)
|
166 |
WEB
|
James Bercegay
|
2018-01-09
|
|
FiberHome LM53Q1 - Multiple Vulnerabilities
|
148 |
WEB
|
Ibad Shah
|
2018-01-05
|
|
D-Link DNS-320L 'mydlinkBRionyg' Backdoor
|
142 |
WEB
|
James Bercegay
|
2018-01-05
|
|
Western Digital WDMyCloud 'mydlinkBRionyg' Backdoor
|
133 |
WEB
|
James Bercegay
|
2018-01-04
|
|
Linksys WVBR0-25 User-Agent Command Execution
|
127 |
WEB
|
HeadlessZeke
|
2018-01-02
|
|
Huawei Router HG532 - Arbitrary Command Execution
|
166 |
WEB
|
anonymous
|
2017-12-28
|
|
DotNetNuke DreamSlider 01.01.02 - Arbitrary File Download
|
127 |
WEB
|
Glafkos Charalambous
|
2017-12-27
|
|
Sendroid < 6.5.0 - SQL Injection
|
134 |
WEB
|
Onwuka Gideon
|
2017-12-21
|
|
Ability Mail Server 3.3.2 - Cross-Site Scripting
|
91 |
WEB
|
Aloyce J. Makalanga
|
2017-12-19
|
|
Linksys WVBR0 - 'User-Agent' Remote Command Injection
|
125 |
WEB
|
nixawk
|
2017-12-18
|
|
ITGuard-Manager 0.0.0.1 - Remote Code Execution
|
120 |
WEB
|
Nassim Asrir
|
2017-12-18
|
|
Western Digital MyCloud multi_uploadify File Upload
|
112 |
WEB
|
Zenofex
|
2017-12-14
|
|
Microsoft Office DDE Payload Delivery
|
320 |
WEB
|
mumbai
|
2017-12-14
|
|
Dup Scout Enterprise 10.0.18 Buffer Overflow
|
332 |
WEB
|
Chris Higgins
|
2017-12-14
|
|
pfSense 2.4.1 CSRF Error Page Clickjacking
|
391 |
WEB
|
Yorick Koster
|
2017-12-06
|
|
WinduCMS 3.1 - Local File Disclosure
|
253 |
WEB
|
Maciek Krupa
|
2017-12-04
|
|
Artica Web Proxy 3.06 - Remote Code Execution
|
211 |
WEB
|
hyp3rlinx
|
2017-12-04
|
|
MistServer 2.12 - Cross-Site Scripting
|
203 |
WEB
|
hyp3rlinx
|
2017-12-04
|
|
WinduCMS 3.1 Local File Disclosure
|
191 |
WEB
|
Maciej Krupa
|
2017-11-30
|
|
osCommerce 2.3.4.1 - Arbitrary File Upload
|
241 |
WEB
|
Simon Scannell
|
2017-11-29
|
|
Synology StorageManager 5.2 - Remote Root Command Execution
|
236 |
WEB
|
SecuriTeam
|
2017-11-20
|
|
phpMyFAQ 2.9.9 Code Injection
|
374 |
WEB
|
tomplixsee
|
2017-11-15
|
|
Allworx Server Manager 6x / 6x12 / 48x Cross Site Scripting
|
141 |
WEB
|
LiquidWorm
|
2017-11-14
|
|
Web Viewer 1.0.0.193 (Samsung SRN-1670D) - Unrestricted File Upload
|
386 |
WEB
|
Omar Mezrag
|
2017-11-09
|
|
Geutebrueck GCore GCoreServer.exe Buffer Overflow
|
197 |
WEB
|
Luca Cappiello
|
2017-11-09
|
|
Mako Server 2.5 Command Injection
|
142 |
WEB
|
Steven Patterson
|
2017-11-06
|
|
WordPress WP Mobile Detector 3.5 Shell Upload
|
195 |
WEB
|
h00die
|
2017-11-06
|
|
Oracle PeopleSoft Enterprise PeopleTools < 8.55 - Remote Code Execution Via Blind XML External Entit
|
151 |
WEB
|
Charles Fol
|
2017-10-31
|
|
Oracle Java SE - Web Start jnlp XML External Entity Processing Information Disclosure
|
221 |
WEB
|
mr_me
|
2017-10-26
|
|
PHPMailer 5.2.21 Local File Disclosure
|
146 |
WEB
|
Maciej Krupa
|
2017-10-24
|
|
Kaltura < 13.1.0 - Remote Code Execution
|
155 |
WEB
|
Robin Verton
|
2017-10-23
|
|
TP-Link WR940N Remote Code Execution
|
171 |
WEB
|
Tim Carrington
|
2017-10-23
|
|
Check_MK 1.2.8p25 - Information Disclosure
|
153 |
WEB
|
Julien Ahrens
|
2017-10-17
|
|
Webmin 1.850 SSRF / CSRF / Cross Site Scripting
|
168 |
WEB
|
hyp3rlinx
|
2017-10-13
|
|
Tomcat JSP Upload Bypass Remote Code Execution
|
286 |
WEB
|
peewpw
|
2017-10-12
|
|
Trend Micro InterScan Messaging Security (Virtual Appliance) - Remote Code Execution (Metasploit)
|
136 |
WEB
|
Mehmet Ince
|
2017-10-10
|
|
ERS Data System 1.8.1 Java Deserialization
|
123 |
WEB
|
West Shepherd
|
2017-10-10
|
|
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execu
|
268 |
WEB
|
intx0x80
|
2017-10-10
|
|
ClipBucket 2.8.3 - Remote Code Execution
|
127 |
WEB
|
Meisam Monsef
|
2017-10-10
|
|
FileRun < 2017.09.18 - SQL Injection
|
151 |
WEB
|
SPARC
|
2017-09-28
|
|
Fibaro Home Center 2 - Remote Command Execution / Privilege Escalation
|
126 |
WEB
|
forsec
|
2017-09-26
|
|
FLIR Systems FLIR Thermal Camera F/FC/PT/D Multiple Information Disclosures
|
143 |
WEB
|
LiquidWorm
|
2017-09-26
|
|
FLIR Systems FLIR Thermal Camera PT-Series (PT-334 200562) - Root Remote Code Execution
|
122 |
WEB
|
LiquidWorm
|
2017-09-25
|
|
Cash Back Comparison Script 1.0 - SQL Injection
|
128 |
WEB
|
Ihsan Sencan
|
2017-09-25
|
|
DenyAll WAF < 6.3.0 - Remote Code Execution (Metasploit)
|
131 |
WEB
|
Mehmet Ince
|
2017-09-22
|
|
Stock Photo Selling 1.0 - SQL Injection
|
142 |
WEB
|
Ihsan Sencan
|
2017-09-21
|
|
Disk Pulse Enterprise 9.9.16 GET Buffer Overflow
|
119 |
WEB
|
Chance Johnson
|
2017-09-19
|
|
Apache - HTTP OPTIONS Memory Leak
|
172 |
WEB
|
Hanno Bock
|
2017-09-19
|
|
DigiAffiliate 1.4 - Cross-Site Request Forgery (Update Admin)
|
133 |
WEB
|
Ihsan Sencan
|
2017-09-19
|
|
Digileave 1.2 - Cross-Site Request Forgery (Update Admin)
|
136 |
WEB
|
Ihsan Sencan
|
2017-09-19
|
|
Digirez 3.4 - Cross-Site Request Forgery (Update Admin)
|
135 |
WEB
|
Ihsan Sencan
|
2017-09-18
|
|
D-Link DIR8xx Routers - Local Firmware Upload
|
232 |
WEB
|
embedi
|
2017-09-18
|
|
D-Link DIR8xx Routers - Root Remote Code Execution
|
157 |
WEB
|
embedi
|
2017-09-18
|
|
D-Link DIR8xx Routers - Leak Credentials
|
136 |
WEB
|
embedi
|
2017-09-11
|
|
Nimble Professional 1.0 - Cross-Site Request Forgery (Update Admin)
|
147 |
WEB
|
Ihsan Sencan
|
2017-09-11
|
|
Topsites Script 1.0 - Cross-Site Request Forgery / PHP Code Injection
|
127 |
WEB
|
Ihsan Sencan
|
2017-08-31
|
|
Invoice Manager 3.1 - Cross-Site Request Forgery (Add Admin)
|
251 |
WEB
|
Ali BawazeEer
|
2017-08-24
|
|
Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution
|
144 |
WEB
|
LiquidWorm
|
2017-08-11
|
|
DALIM SOFTWARE ES Core 5.0 Build 7184.1 User Enumeration
|
156 |
WEB
|
LiquidWorm
|
2017-08-09
|
|
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
|
123 |
WEB
|
Kacper Szurek
|
2017-08-02
|
|
Advantech SUSIAccess <= 3.0 - 'RecoveryMgmt' File Upload
|
137 |
WEB
|
James Fitts
|
2017-08-02
|
|
Advantech SUSIAccess <= 3.0 - Directory Traversal / Information Disclosure (Metasploit)
|
119 |
WEB
|
James Fitts
|
2017-07-31
|
|
GitHub Enterprise < 2.8.7 - Remote Code Execution
|
131 |
WEB
|
orange
|
2017-07-27
|
|
WebKit JSC - 'JSObject::putInlineSlow and JSValue::putToPrimitive' Universal Cross-Site Scripting
|
103 |
WEB
|
Google Security Research
|
2017-07-25
|
|
ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit)
|
207 |
WEB
|
Kacper Szurek
|
2017-07-21
|
|
Netscaler SD-WAN 9.1.2.26.561201 - Command Injection (Metasploit)
|
148 |
WEB
|
xort
|
2017-07-21
|
|
Sonicwall < 8.1.0.2-14sv - 'sitecustomization.cgi' Command Injection (Metasploit)
|
129 |
WEB
|
xort
|
2017-07-21
|
|
Sonicwall < 8.1.0.6-21sv - 'gencsr.cgi' Command Injection (Metasploit)
|
118 |
WEB
|
xort
|
2017-07-19
|
|
Easy File Sharing Web Server 7.2 Buffer Overflow
|
155 |
WEB
|
N_A
|
2017-07-18
|
|
Barracuda Load Balancer Firmware <= 6.0.1.006 - Remote Command Injection (Metasploit)
|
152 |
WEB
|
xort
|
2017-07-18
|
|
Sophos Web Appliance 4.3.0.2 - 'trafficType' Remote Command Injection (Metasploit)
|
130 |
WEB
|
xort
|
2017-07-17
|
|
WDTV Live SMP 2.03.20 - Remote Password Reset
|
197 |
WEB
|
Sw1tCh
|
2017-07-17
|
|
Apache Struts 2.3.x Showcase - Remote Code Execution (PoC)
|
298 |
WEB
|
Vex Woo
|
2017-07-13
|
|
RaidenHTTPD 2.0.44 User-Agent Cross Site Scripting
|
114 |
WEB
|
sultan albalawi
|
2017-07-12
|
|
NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection
|
175 |
WEB
|
Paul Taylor
|
2017-07-03
|
|
Humax HG100R 2.0.6 - Backup File Download
|
201 |
WEB
|
gambler
|
2017-06-29
|
|
Easy File Sharing Web Server 7.2 - Unrestricted File Upload
|
248 |
WEB
|
Chako
|
2017-06-26
|
|
Easy File Sharing HTTP Server 7.2 POST Buffer Overflow
|
80 |
WEB
|
Marco Rivoli
|
2017-06-26
|
|
Symantec Messaging Gateway Remote Code Execution
|
131 |
WEB
|
Mehmet Ince
|
2017-06-26
|
|
Netgear DGN2200 dnslookup.cgi Command Injection
|
105 |
WEB
|
thecarterb
|
2017-06-22
|
|
PHPMailer < 5.2.20 with Exim MTA - Remote Code Execution
|
153 |
WEB
|
phackt_ul
|
2017-06-20
|
|
D-Link ADSL DSL-2640B SEA_1.01 Unauthenticated Remote DNS Changer
|
287 |
WEB
|
Todor Donev
|
2017-06-20
|
|
D-Link DSL-2640B - Unauthenticated Remote DNS Change
|
121 |
WEB
|
Todor Donev
|
2017-06-20
|
|
D-Link DSL-2640U - Unauthenticated DNS Change
|
182 |
WEB
|
Todor Donev
|
2017-06-20
|
|
Beetel BCM96338 Router - Unauthenticated DNS Change
|
202 |
WEB
|
Todor Donev
|
2017-06-20
|
|
UTstarcom WA3002G4 - Unauthenticated DNS Change
|
139 |
WEB
|
Todor Donev
|
2017-06-20
|
|
iBall Baton iB-WRA150N - Unauthenticated DNS Change
|
182 |
WEB
|
Todor Donev
|
2017-06-16
|
|
Aerohive HiveOS 5.1r5 < 6.1r5 - Remote Code Execution
|
234 |
WEB
|
Ike-Clinton
|
2017-06-14
|
|
MyBB 1.8.12 Stored XSS / File Enumeration
|
222 |
WEB
|
MLT
|
2017-06-13
|
|
EFS Easy Chat Server 3.1 - Password Reset
|
291 |
WEB
|
Aitezaz Mohsin
|
2017-06-13
|
|
EFS Easy Chat Server 3.1 - Password Disclosure
|
107 |
WEB
|
Aitezaz Mohsin
|
2017-06-13
|
|
IPFire 2.19 - Remote Code Execution
|
135 |
WEB
|
0x09AL
|
2017-06-07
|
|
Kronos Telestaff < 2.92EU29 - SQL Injection
|
131 |
WEB
|
Goran Tuzovic
|
2017-06-06
|
|
EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 - Remote Code Execution
|
171 |
WEB
|
LiquidWorm
|
2017-06-02
|
|
Riverbed SteelHead VCX 9.6.0a - Arbitrary File Read
|
133 |
WEB
|
Gregory Draperi
|
2017-06-01
|
|
WebKit CachedFrameBase::restore Universal Cross Site Scripting
|
86 |
WEB
|
lokihardt
|