2020-05-05
|
|
Fishing Reservation System 7.5 - 'uid' SQL Injection
|
3 |
WEB
|
Vulnerability-Lab
|
2020-05-04
|
|
addressbook 9.0.0.1 - 'id' SQL Injection
|
3 |
WEB
|
David Velazquez
|
2020-05-04
|
|
osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting
|
3 |
WEB
|
Mehmet Kelepçe
|
2020-05-04
|
|
BoltWire 6.03 - Local File Inclusion
|
6 |
WEB
|
Andrey Stoykov
|
2020-05-01
|
|
Online Scheduling System 1.0 - Authentication Bypass
|
5 |
WEB
|
boku
|
2020-05-01
|
|
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
|
4 |
WEB
|
Faiz Ahmed Zaidi
|
2020-05-01
|
|
HardDrive 2.1 for iOS - Arbitrary File Upload
|
4 |
WEB
|
Vulnerability-Lab
|
2020-05-01
|
|
Super Backup 2.0.5 for iOS - Directory Traversal
|
4 |
WEB
|
Vulnerability-Lab
|
2020-05-01
|
|
php-fusion 9.03.50 - Persistent Cross-Site Scripting
|
4 |
WEB
|
SunCSR
|
2020-05-01
|
|
Online Scheduling System 1.0 - Persistent Cross-Site Scripting
|
5 |
WEB
|
boku
|
2020-05-01
|
|
ChemInv 1.0 - Authenticated Persistent Cross-Site Scripting
|
4 |
WEB
|
boku
|
2020-04-29
|
|
hits script 1.0 - 'item_name' SQL Injection
|
4 |
WEB
|
SajjadBnd
|
2020-04-29
|
|
Easy Transfer 1.7 for iOS - Directory Traversal
|
4 |
WEB
|
Vulnerability-Lab
|
2020-04-29
|
|
School ERP Pro 1.0 - Arbitrary File Read
|
5 |
WEB
|
Besim
|
2020-04-29
|
|
Open-AudIT Professional 3.3.1 - Remote Code Execution
|
6 |
WEB
|
Askar
|
2020-04-28
|
|
School ERP Pro 1.0 - Remote Code Execution
|
5 |
WEB
|
Besim
|
2020-04-28
|
|
School ERP Pro 1.0 - 'es_messagesid' SQL Injection
|
7 |
WEB
|
Besim
|
2020-04-27
|
|
Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
Besim
|
2020-04-27
|
|
Online Course Registration 2.0 - Authentication Bypass
|
5 |
WEB
|
Daniel Monzón
|
2020-04-27
|
|
Netis E1+ V1.2.32533 - Unauthenticated WiFi Password Leak
|
6 |
WEB
|
Besim
|
2020-04-27
|
|
Online shopping system advanced 1.0 - 'p' SQL Injection
|
5 |
WEB
|
Majid kalantari
|
2020-04-27
|
|
Netis E1+ 1.2.32533 - Backdoor Account (root)
|
6 |
WEB
|
Besim
|
2020-04-27
|
|
PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
|
5 |
WEB
|
Besim
|
2020-04-24
|
|
Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
|
4 |
WEB
|
LiquidWorm
|
2020-04-24
|
|
Edimax EW-7438RPn 1.13 - Remote Code Execution
|
5 |
WEB
|
Besim
|
2020-04-24
|
|
EspoCRM 5.8.5 - Privilege Escalation
|
5 |
WEB
|
Besim
|
2020-04-23
|
|
Sky File 2.1.0 iOS - Directory Traversal
|
6 |
WEB
|
Vulnerability-Lab
|
2020-04-23
|
|
Library CMS Powerful Book Management System 2.2.0 - Session Fixation
|
5 |
WEB
|
Ismail Tasdelen
|
2020-04-23
|
|
Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)
|
7 |
WEB
|
Dhiraj Mishra
|
2020-04-23
|
|
Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
|
4 |
WEB
|
Besim
|
2020-04-23
|
|
Complaint Management System 4.2 - Authentication Bypass
|
5 |
WEB
|
Besim
|
2020-04-23
|
|
Complaint Management System 4.2 - Persistent Cross-Site Scripting
|
5 |
WEB
|
Besim
|
2020-04-23
|
|
User Management System 2.0 - Authentication Bypass
|
9 |
WEB
|
Besim
|
2020-04-23
|
|
User Management System 2.0 - Persistent Cross-Site Scripting
|
5 |
WEB
|
Besim
|
2020-04-22
|
|
Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
|
5 |
WEB
|
Vulnerability-Lab
|
2020-04-22
|
|
Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)
|
5 |
WEB
|
Besim
|
2020-04-22
|
|
Edimax EW-7438RPn - Information Disclosure (WiFi Password)
|
5 |
WEB
|
Besim
|
2020-04-21
|
|
P5 FNIP-8x16A FNIP-4xSH 1.0.20 - Cross-Site Request Forgery (Add Admin)
|
5 |
WEB
|
LiquidWorm
|
2020-04-21
|
|
jizhi CMS 1.6.7 - Arbitrary File Download
|
5 |
WEB
|
jizhicms
|
2020-04-21
|
|
NSClient++ 0.5.2.35 - Authenticated Remote Code Execution
|
4 |
WEB
|
kindredsec
|
2020-04-21
|
|
IQrouter 3.3.1 Firmware - Remote Code Execution
|
5 |
WEB
|
drakylar
|
2020-04-21
|
|
CSZ CMS 1.2.7 - 'title' HTML Injection
|
6 |
WEB
|
Metin Yunus Kandemir
|
2020-04-21
|
|
PMB 5.6 - 'logid' SQL Injection
|
4 |
WEB
|
41-trk
|
2020-04-21
|
|
CSZ CMS 1.2.7 - Persistent Cross-Site Scripting
|
5 |
WEB
|
Metin Yunus Kandemir
|
2020-04-20
|
|
Fork CMS 5.8.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Vulnerability-Lab
|
2020-04-20
|
|
Prestashop 1.7.6.4 - Cross-Site Request Forgery
|
5 |
WEB
|
Sivanesh Ashok
|
2020-04-20
|
|
Centreon 19.10.5 - 'id' SQL Injection
|
5 |
WEB
|
Basim Alabdullah
|
2020-04-17
|
|
TAO Open Source Assessment Platform 3.3.0 RC02 - HTML Injection
|
5 |
WEB
|
Vulnerability-Lab
|
2020-04-17
|
|
Playable 9.18 iOS - Persistent Cross-Site Scripting
|
4 |
WEB
|
Vulnerability-Lab
|
2020-04-15
|
|
Xeroneit Library Management System 3.0 - 'category' SQL Injection
|
4 |
WEB
|
Sohel Yousef
|
2020-04-15
|
|
File Transfer iFamily 2.1 - Directory Traversal
|
6 |
WEB
|
Vulnerability-Lab
|
2020-04-15
|
|
DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting
|
5 |
WEB
|
Vulnerability Research Laboratory
|
2020-04-15
|
|
Macs Framework 1.14f CMS - Persistent Cross-Site Scripting
|
5 |
WEB
|
Vulnerability-Lab
|
2020-04-15
|
|
SeedDMS 5.1.18 - Persistent Cross-Site Scripting
|
6 |
WEB
|
Vulnerability-Lab
|
2020-04-15
|
|
Pinger 1.0 - Remote Code Execution
|
4 |
WEB
|
Milad karimi
|
2020-04-15
|
|
SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2020-04-15
|
|
AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting
|
4 |
WEB
|
Vulnerability-Lab
|
2020-04-14
|
|
Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
|
4 |
WEB
|
nu11secur1ty
|
2020-04-14
|
|
WSO2 3.1.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Raki Ben Hamouda
|
2020-04-14
|
|
Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
|
3 |
WEB
|
Wadeek
|
2020-04-13
|
|
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
|
2 |
WEB
|
Aviv Beniash
|
2020-04-13
|
|
WordPress Plugin Media Library Assistant 2.81 - Local File Inclusion
|
4 |
WEB
|
Daniel Monzón
|
2020-04-13
|
|
WSO2 3.1.0 - Arbitrary File Delete
|
4 |
WEB
|
Raki Ben Hamouda
|
2020-04-13
|
|
Webtateas 2.0 - Arbitrary File Read
|
4 |
WEB
|
China Banking and Insurance Information Technology
|
2020-04-13
|
|
TVT NVMS 1000 - Directory Traversal
|
4 |
WEB
|
Mohin Paramasivam
|
2020-04-13
|
|
Huawei HG630 2 Router - Authentication Bypass
|
3 |
WEB
|
Eslam Medhat
|
2020-04-10
|
|
Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal
|
4 |
WEB
|
Basim Alabdullah
|
2020-04-10
|
|
WordPress Plugin Helpful 2.4.11 - SQL Injection
|
3 |
WEB
|
numan türle
|
2020-04-08
|
|
Django 3.0 - Cross-Site Request Forgery Token Bypass
|
6 |
WEB
|
Spad Security Group
|
2020-04-06
|
|
pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
|
4 |
WEB
|
Matthew Aberegg
|
2020-04-06
|
|
LimeSurvey 4.1.11 - 'File Manager' Path Traversal
|
5 |
WEB
|
Matthew Aberegg
|
2020-04-06
|
|
Bolt CMS 3.7.0 - Authenticated Remote Code Execution
|
4 |
WEB
|
r3m0t3nu11
|
2020-04-06
|
|
WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Gal Weizman
|
2020-04-06
|
|
Vesta Control Panel 0.9.8-26 - Authenticated Remote Code Execution (Metasploit)
|
3 |
WEB
|
Mehmet Ince
|
2020-04-06
|
|
LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
|
4 |
WEB
|
Matthew Aberegg
|
2020-04-03
|
|
Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution
|
3 |
WEB
|
Basim Alabdullah
|
2020-04-02
|
|
PHP-Fusion 9.03.50 - 'panels.php' Remote Code Execution
|
3 |
WEB
|
Unkn0wn
|
2020-03-31
|
|
Grandstream UCM6200 Series WebSocket 1.0.20.20 - 'user_password' SQL Injection
|
4 |
WEB
|
Jacob Baines
|
2020-03-31
|
|
Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection
|
4 |
WEB
|
Jacob Baines
|
2020-03-30
|
|
Zen Load Balancer 3.10.1 - Remote Code Execution
|
2 |
WEB
|
Cody Sixteen
|
2020-03-30
|
|
Joomla! com_fabrik 3.9.11 - Directory Traversal
|
4 |
WEB
|
qw3rTyTy
|
2020-03-27
|
|
rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
|
4 |
WEB
|
vikingfr
|
2020-03-27
|
|
Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal
|
3 |
WEB
|
hongphukt
|
2020-03-27
|
|
ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
Mustafa Emre Gül
|
2020-03-26
|
|
Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
|
5 |
WEB
|
Engin Demirbilek
|
2020-03-25
|
|
LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
|
3 |
WEB
|
SunCSR
|
2020-03-25
|
|
Joomla! Component GMapFP 3.30 - Arbitrary File Upload
|
3 |
WEB
|
ThelastVvV
|
2020-03-24
|
|
UCM6202 1.0.18.13 - Remote Command Injection
|
3 |
WEB
|
Jacob Baines
|
2020-03-24
|
|
WordPress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Jinson Varghese Behanan
|
2020-03-24
|
|
UliCMS 2020.1 - Persistent Cross-Site Scripting
|
4 |
WEB
|
SunCSR
|
2020-03-23
|
|
Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
|
3 |
WEB
|
qw3rTyTy
|
2020-03-23
|
|
rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
|
3 |
WEB
|
Matthew Aberegg
|
2020-03-23
|
|
FIBARO System Home Center 5.021 - Remote File Include
|
4 |
WEB
|
LiquidWorm
|
2020-03-23
|
|
Wordpress Plugin PicUploader 1.0 - Remote File Upload
|
4 |
WEB
|
Milad karimi
|
2020-03-20
|
|
Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
Metin Yunus Kandemir
|
2020-03-18
|
|
Joomla! Component ACYMAILING 3.9.0 - Unauthenticated Arbitrary File Upload
|
4 |
WEB
|
qw3rTyTy
|
2020-03-18
|
|
Netlink GPON Router 1.0.11 - Remote Code Execution
|
4 |
WEB
|
shellord
|
2020-03-17
|
|
UADMIN Botnet 1.0 - 'link' SQL Injection
|
5 |
WEB
|
n4pst3r
|
2020-03-16
|
|
PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution
|
4 |
WEB
|
Antonio Cannito
|
2020-03-16
|
|
PHPKB Multi-Language 9 - Authenticated Directory Traversal
|
4 |
WEB
|
Antonio Cannito
|
2020-03-16
|
|
PHPKB Multi-Language 9 - Authenticated Remote Code Execution
|
4 |
WEB
|
Antonio Cannito
|
2020-03-16
|
|
MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
|
4 |
WEB
|
AYADI Mohamed
|
2020-03-16
|
|
Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
Miguel Mendez Z
|
2020-03-10
|
|
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
|
5 |
WEB
|
Andrea Cardaci
|
2020-03-13
|
|
WordPress Plugin Custom Searchable Data System - Unauthenticated Data M]odification
|
5 |
WEB
|
Nawaf Alkeraithe
|
2020-03-13
|
|
Centos WebPanel 7 - 'term' SQL Injection
|
3 |
WEB
|
Berke YILMAZ
|
2020-03-11
|
|
Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
|
3 |
WEB
|
Andrea Cardaci
|
2020-03-11
|
|
Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
|
4 |
WEB
|
Andrea Cardaci
|
2020-03-12
|
|
rConfig 3.9 - 'searchColumn' SQL Injection
|
4 |
WEB
|
vikingfr
|
2020-03-12
|
|
rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
|
3 |
WEB
|
Engin Demirbilek
|
2020-03-12
|
|
HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
Ismail Akıcı
|
2020-03-12
|
|
WordPress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
|
4 |
WEB
|
Daniel Monzón
|
2020-03-12
|
|
WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
|
6 |
WEB
|
RedTeam Pentesting GmbH
|
2020-03-12
|
|
Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
|
4 |
WEB
|
Milad karimi
|
2020-03-11
|
|
TeamCity Agent XML-RPC 10.0 - Remote Code Execution
|
4 |
WEB
|
1F98D
|
2020-03-11
|
|
Wing FTP Server - Authenticated CSRF (Delete Admin)
|
4 |
WEB
|
Dhiraj Mishra
|
2020-03-11
|
|
PlaySMS 1.4.3 - Template Injection / Remote Code Execution
|
4 |
WEB
|
Touhid M.Shaikh
|
2020-03-11
|
|
Joomla! 3.9.0 < 3.9.7 - CSV Injection
|
4 |
WEB
|
i4bdullah
|
2020-03-11
|
|
WordPress Plugin Search Meter 2.13.2 - CSV injection
|
5 |
WEB
|
Daniel Monzón
|
2020-03-10
|
|
Persian VIP Download Script 1.0 - 'active' SQL Injection
|
4 |
WEB
|
Amir Hossein Vafifar
|
2020-03-10
|
|
YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
|
5 |
WEB
|
En_dust
|
2020-03-10
|
|
Sysaid 20.1.11 b26 - Remote Command Execution
|
3 |
WEB
|
Ahmed Sherif
|
2020-03-09
|
|
Sentrifugo HRMS 3.2 - 'id' SQL Injection
|
2 |
WEB
|
minhnb
|
2020-03-09
|
|
60CycleCMS - 'news.php' SQL Injection
|
3 |
WEB
|
Unkn0wn
|
2019-12-12
|
|
ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization / Unauthenticated Remote
|
4 |
WEB
|
mr_me
|