Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2015-03-25   WordPress Plugin InBoundio Marketing 1.0 - Shell Upload Vulnerability 176 WEB KedAns-Dz
2015-03-24   Powershell Remoting Remote Command Execution 75 WEB Ben Campbell
2015-03-24   Belkin Play N750 login.cgi Buffer Overflow 55 WEB Michael Messner
2015-03-23   Wordpress WP Marketplace 2.4.0 Arbitrary File Download Vulnerability 60 WEB Kacper Szurek
2015-03-20   Chamilo LMS 1.9.10 Cross Site Request Forgery / Cross Site Scripting 105 WEB Rehan Ahmed
2015-03-20   Metasploit Project < 4.11.1 - Initial User Creation CSRF Vulnerability 110 WEB Mohamed Abdelbaset Elnoby
2015-03-20   GoAutoDial CE 2.0 - Shell Upload Vulnerability 141 WEB R-73eN
2015-03-20   EMC M&R (Watch4net) - Credential Disclosure 59 WEB Han Sahin
2015-03-17   WordPress Reflex Gallery 3.1.3 Shell Upload 98 WEB Cleiton Pinheiro
2015-03-09   Betster 1.0.4 SQL Injection / Authentication Bypass 72 WEB ZeQ3uL
2015-03-06   PHPMoAdmin 1.1.2 Remote Code Execution 104 WEB Ricardo Jorge Borges de Almeida
2015-03-06   Wordpress Theme DesignFolio+ Arbitrary File Upload Vulnerability 95 WEB CrashBandicot
2015-03-05   PHPMoAdmin Remote Code Execution 152 WEB Pichaya Morimoto
2015-03-05   Generic Web Application DLL Injection 54 WEB Matthew Hall
2015-03-03   Symantec Web Gateway 5 restore.php Command Injection 73 WEB sinn3r
2015-03-02   Seagate Business NAS <= 2014.00319 - Pre-Authentication Remote Code Execution (0day) 109 WEB OJ Reeves
2015-02-25   WordPress Holding Pattern Theme Arbitrary File Upload 92 WEB Alexander Borg
2015-02-25   WordPress Admin Shell Upload 77 WEB Rob Carr
2015-02-25   WeBid 1.1.1 Unrestricted File Upload 71 WEB CWH Underground
2015-02-25   WordPress Webdorado Spider Event Calendar 1.4.9 - SQL Injection 81 WEB Mateusz Lach
2015-02-11   Achat 0.150 beta7 Buffer Overflow 72 WEB Balazs Bucsay
2015-02-11   LG DVR LE6016D - Unauthenticated Remote Users/Passwords Disclosure Exploit 171 WEB Todor Donev
2015-02-10   WordPress WP EasyCart Unrestricted File Upload 90 WEB Kacper Szurek
2015-02-10   Redaxscript CMS 2.2.0 - SQL Injection Vulnerability 108 WEB ITAS Team
2015-02-05   ManageEngine Desktop Central 9 Build 90087 - CSRF Vulnerability 79 WEB Mohamed Idris
2015-02-04   WordPress Pixabay Images PHP Code Upload 92 WEB h0ng10
2015-02-04   WordPress Platform Theme Remote Code Execution 90 WEB Christian Mehlmauer
2015-02-03   Sefrengo CMS 1.6.1 SQL Injection 100 WEB Nguyen Hung Tuan
2015-01-27   SWFupload 2.5.0 Cross Frame Scripting 102 WEB MindCracker
2015-01-27   Symantec Data Center Security - Multiple Vulnerabilities 159 WEB SEC Consult
2015-01-27   PHP Webquest 2.6 - SQL Injection 86 WEB jordan root
2015-01-23   Arris VAP2500 tools_command.php Command Execution 144 WEB HeadlessZeke
2015-01-21   WordPress Pixarbay Images 2.3 XSS / Bypass / Upload / Traversal 71 WEB Hans-Martin Muench
2015-01-21   N-Central Remote Support Manager 14.2.7.171 File Read / Code Execution 60 WEB Thomas Hibbert
2015-01-21   D-Link DSL-2730B Modem - XSS Injection Stored Exploit Lancfg2get.cgi 95 WEB Mauricio Correa
2015-01-21   D-Link DSL-2730B Modem - XSS Injection Stored Exploit DnsProxy.cmd 101 WEB Mauricio Correa
2015-01-15   Congstar Internet-Manager SEH Buffer Overflow 83 WEB metacom
2015-01-15   T-Mobile Internet Manager SEH Buffer Overflow 74 WEB metacom
2015-01-14   Wordpress Photo Gallery Unauthenticated SQL Injection User Enumeration 61 WEB Brandon Perry
2015-01-14   Dell iDRAC IPMI 1.5 - Insufficient Session ID Randomness 70 WEB Yong Chuan, Koh
2015-01-13   WordPress WP Symposium 14.11 Shell Upload 81 WEB Claudio Viviani
2015-01-06   AdaptCMS 3.0.3 HTTP Referer Header Open Redirect 144 WEB LiquidWorm
2015-01-06   WordPress Banner Effect Header 1.2.6 XSS / CSRF 147 WEB Mahdi.Hidden
2015-01-06   Wordpress Infocus3 Theme Arbitrary File Download Vulnerability 162 WEB killer~x
2015-01-06   Wordpress Infocus2 Theme Arbitrary File Download Vulnerability 184 WEB killer~x
2015-01-06   Wordpress WP-EMail 2.64 Cross Site Scripting Vulnerability 60 WEB Ashiyane
2015-01-06   Wordpress Email 1.1 Cross Site Scripting Vulnerability 72 WEB Ashiyane
2015-01-06   Wordpress Email newsletter 20.9 Cross Site Scripting Vulnerability 76 WEB Ashiyane
2015-01-06   Wordpress sumome 1.6 Cross Site Scripting Vulnerability 56 WEB Ashiyane
2015-01-06   AdaptCMS 3.0.3 XSS / Remote Code Execute Vulnerabilities 54 WEB LiquidWorm
2015-01-06   HikaShop 2.3.3 Local File Inclusion Vulnerability 90 WEB HauntIT Blog
2015-01-04   WordPress RevSlider Local File Disclosure 78 WEB FarbodEZRaeL
2015-01-04   PHPads <= 213607 - Authentication Bypass / Password Change Exploit 106 WEB Shaker msallm
2014-12-30   ProjectSend Arbitrary File Upload 109 WEB Fady Mohammed Osman
2014-12-30   WordPress Dmsguestbook Unauthenticated Data Injection 73 WEB Evex
2014-12-25   WordPress Themes download.php File Disclosure 189 WEB Cleiton Pinheiro
2014-12-25   AMSI 3.20.47 Build 37 File Disclosure 192 WEB KnocKout
2014-12-24   Phase botnet blind SQL injection vulnerability 66 WEB Xylitol
2014-12-22   Cacti Superlinks Plugin 1.4-2 RCE(LFI) via SQL Injection Exploit 79 WEB Wireghoul
2014-12-17   ProjectSend r-561 - Arbitrary File Upload 84 WEB Fady Mohammed Osman
2014-12-16   Wordpress Download Manager 2.7.4 - Remote Code Execution Vulnerability 82 WEB Claudio Viviani
2014-12-15   Tuleap PHP Unserialize Code Execution 155 WEB EgiX
2014-12-15   WordPress WP Symposium 14.11 Shell Upload 79 WEB Claudio Viviani
2014-12-09   Flat Calendar 1.1 HTML Injection 122 WEB ZoRLu
2014-11-27   Device42 Embedded Credentials 93 WEB Brandon Perry
2014-11-27   Slider Revolution/Showbiz Pro Shell Upload Exploit 78 WEB Simo Ben Youssef
2014-11-27   Device42 WAN Emulator 2.3 Ping Command Injection 56 WEB Brandon Perry
2014-11-27   Device42 WAN Emulator 2.3 Traceroute Command Injection 72 WEB Brandon Perry
2014-11-26   All-in-One WP Migration 2.0.2 Remote Code Execution Vulnerability 81 WEB Kacper Szurek
2014-11-26   Arris VAP2500 Authentication Bypass 96 WEB HeadlessZeke
2014-11-26   phpMyRecipes 1.2.2 (dosearch.php, words_exact param) - SQL Injection 141 WEB bard
2014-11-25   WordPress WP-DB-Backup 2.2.4 Backup Theft 108 WEB Larry W. Cashdollar
2014-11-25   FluxBB 1.5.6 SQL Injection 84 WEB secthrowaway
2014-11-25   Atrax Botnet Shell Upload Vulnerability 83 WEB Xylitol
2014-11-24   Wordpress wpDataTables 1.5.3 shell Upload Exploit 71 WEB Claudio Viviani
2014-11-18   MantisBT XmlImportExport Plugin PHP Code Injection 57 WEB EgiX
2014-11-18   Joomla HD FLV 2.1.0.1 Arbitrary File Download 96 WEB Claudio Viviani
2014-11-18   PHP 5.x - Bypass Disable Functions Vulnerability 150 WEB Ryan King
2014-11-18   Proticaret E-Commerce Script 3.0 - SQL Injection Vulnerability 67 WEB Onur Alanbel
2014-11-18   ZTE ZXHN H108L - Authentication Bypass 204 WEB Project Zero Labs
2014-11-18   ZTE ZXHN H108L - Authentication Bypass 53 WEB Project Zero Labs
2014-11-14   Who's Who Script Cross Site Request Forgery 82 WEB ZoRLu
2014-11-14   Joomla HD FLV 2.1.0.1 SQL Injection 89 WEB Claudio Viviani
2014-11-11   IP.Board 3.4.7 SQL Injection 84 WEB secthrowaway
2014-11-05   Drupal < 7.32 Pre Auth SQL Injection 149 WEB Stefan Horst
2014-10-31   Joomla RD Download SQL Injection 123 WEB Claudio Viviani
2014-10-30   MAARCH 1.4 - Arbitrary File Upload 70 WEB Adrien Thierry
2014-10-29   vBulletin Tapatalk - Blind SQL Injection 182 WEB tintinweb
2014-10-28   vBulletin 4.x Tapatalk Blind SQL Injection 100 WEB tintinweb
2014-10-28   Incredible PBX 2.0.6.5.0 - Remote Command Execution Exploit 79 WEB Simo Ben Youssef
2014-10-28   HP Operations Agent Remote XSS iFrame Injection 94 WEB Matt Schmidt
2014-10-28   Creative Contact Form (Wordpress 0.9.7 and Joomla 2.0.0) - Shell Upload Vulnerability 85 WEB Claudio Viviani
2014-10-24   Centreon SQL / Command Injection 91 WEB MaZ
2014-10-24   WordPress / Joomla Creative Contact Form 0.9.7 Shell Upload 92 WEB Claudio Viviani
2014-10-24   Feng Office 1.7.4 - Arbitrary File Upload 65 WEB AutoSec Tools
2014-10-23   DotNetNuke DNNspot Store 3.0.0 Arbitary File Upload 160 WEB Glafkos Charalambous
2014-10-21   ZTE ZXDSL-931VII - Unauthenticated Configuration Dump 243 WEB L0ukanik0-s S0kniaku0l
2014-10-20   Fonality Trixbox CE 2.8.0.4 Command Execution Vulnerability 84 WEB Simo Ben
2014-10-20   NETIS DL4322D Multiple Vulnerabilities 78 WEB AkaStep
2014-10-20   Wordpress Theme Dazzling Shell Upload Vulnerability 96 WEB king_cobra
2014-10-20   Drupal Core <= 7.32 - SQL Injection (PHP) 89 WEB Dustin Dörr
2014-10-20   Drupal Core <= 7.32 - SQL Injection 72 WEB fyukyuk
2014-10-17   Drupal 7.X SQL Injection 188 WEB Claudio Viviani
2014-10-15   SEO Control Panel 3.6.0 - Authenticated SQL Injection 78 WEB Tiago Carvalho
2014-10-14   Croogo 2.0.0 Arbitrary PHP Code Execution / Cross Site Scripting Vulnerabilities 82 WEB LiquidWorm
2014-10-09   Nessus Web UI 2.3.3 Cross Site Scripting Vulnerability 62 WEB Frank Lycops
2014-10-09   Wordpress InfusionSoft Upload 118 WEB us3r777
2014-10-08   Toast Forums Database Disclosure 94 WEB indoushka
2014-10-08   Snitz Forums 2000 3.4.07 Database Disclosure 85 WEB indoushka
2014-10-08   AutoWeb 3.0 SQL Injection 254 WEB ZoRLu
2014-10-08   Wordpress Slideshow Gallery 1.4.6 - Shell Upload (Python Exploit) 67 WEB Claudio Viviani
2014-10-08   IPFire Cgi Web Interface Authenticated Bash Environment Variable Code Injection exploit 90 WEB Claudio Viviani
2014-09-30   Microsoft Exchange IIS HTTP Internal IP Address Disclosure 73 WEB Nate Power
2014-09-30   OpenFiler 2.99.1 - CSRF Vulnerability 84 WEB Dolev Farhi
2014-09-28   Comersus Sophisticated Cart Database Disclosure 82 WEB indoushka
2014-09-26   Nucom ADSL ADSLR5000UN ISP Credentials Disclosure 66 WEB Sebastián Magof
2014-09-25   ZyXEL Prestig P-660HNU-T1 ISP Credentials Disclosure Exploit 84 WEB Sebastián Magof
2014-09-23   Joomla Face Gallery 1.0 Multiple Vulnerabilities 90 WEB Claudio Viviani
2014-09-23   Joomla Mac Gallery <= 1.5 Arbitrary File Download Exploit 80 WEB Claudio Viviani
2014-09-22   GetSimpleCMS PHP File Upload 69 WEB Ahmed Elhady Mohamed
2014-09-19   Briefcase 4.0 iOS - Code Execution & File Include Vulnerability 92 WEB Vulnerability-Lab
2014-09-18   ZTE ZXDSL-931VII Unauthenticated Configuration Dump 339 WEB L0ukanik0s
2014-09-17   WordPress Slideshow Gallery 1.4.6 Shell Upload 74 WEB Claudio Viviani
2014-09-16   ALCASAR <= 2.8.1 - Remote Root Code Execution Vulnerability 126 WEB eF
2014-09-15   EGYWEB (Mantrac) <= Remote File Disclosure Exploit 104 WEB KnocKout