Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-07-26   ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection 45 WEB aldorm
2020-07-26   GOautodial 4.0 - Persistent Cross-Site Scripting (Authenticated) 41 WEB Balzabu
2020-07-23   UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass 44 WEB LiquidWorm
2020-07-22   Sophos VPN Web Panel 2020 - Denial of Service (Poc) 46 WEB Berk KIRAS
2020-07-22   WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection 36 WEB Vlad Vector
2020-07-22   Docsify.js 4.11.4 - Reflective Cross-Site Scripting 37 WEB Amin Sharifi
2020-07-17   CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password) 39 WEB Noth
2020-07-16   Wing FTP Server 6.3.8 - Remote Code Execution (Authenticated) 40 WEB V1n1v131r4
2020-07-15   Infor Storefront B2B 1.0 - 'usr_name' SQL Injection 38 WEB ratboy
2020-07-15   Online Farm Management System 0.1.0 - Persistent Cross-Site Scripting 41 WEB KeopssGroup0day_Inc
2020-07-15   Web Based Online Hotel Booking System 0.1.0 - Authentication Bypass 36 WEB KeopssGroup0day_Inc
2020-07-15   Online Polling System 1.0 - Authentication Bypass 34 WEB AppleBois
2020-07-15   Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection 39 WEB Mehmet Kelepçe
2020-07-15   Zyxel Armor X1 WAP6806 - Directory Traversal 39 WEB Rajivarnan R
2020-07-15   SuperMicro IPMI WebInterface 03.40 - Cross-Site Request Forgery (Add Admin) 41 WEB Metin Yunus Kandemir
2020-07-14   Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 - Remote Code Execution (Metas 39 WEB Mehmet Ince
2020-07-14   BSA Radar 1.6.7234.24750 - Local File Inclusion 40 WEB William Summerhill
2020-07-13   Park Ticketing Management System 1.0 - Authentication Bypass 41 WEB gh1mau
2020-07-13   Park Ticketing Management System 1.0 - 'viewid' SQL Injection 41 WEB gh1mau
2020-07-10   Barangay Management System 1.0 - Authentication Bypass 39 WEB BKpatron
2020-07-10   HelloWeb 2.0 - Arbitrary File Download 43 WEB bRpsd
2020-07-09   Savsoft Quiz 5 - Persistent Cross-Site Scripting 43 WEB th3d1gger
2020-07-09   Wordpress Plugin Powie's WHOIS Domain Check 0.9.31 - Persistent Cross-Site Scripting 41 WEB mqt
2020-07-07   PHP 7.4 FFI - 'disable_functions' Bypass 50 WEB hunter gregal
2020-07-07   Exhibitor Web UI 1.7.1 - Remote Code Execution 40 WEB Logan Sanderson
2020-07-08   BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password) 42 WEB William Summerhill
2020-07-08   SuperMicro IPMI 03.40 - Cross-Site Request Forgery (Add Admin) 46 WEB Metin Yunus Kandemir
2020-07-07   BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation 47 WEB William Summerhill
2020-07-07   Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection 43 WEB Mehmet Kelepçe
2020-07-07   Online Shopping Portal 3.1 - 'email' SQL Injection 49 WEB gh1mau
2020-07-07   Sickbeard 0.1 - Remote Command Injection 44 WEB bdrake
2020-07-05   BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6 46 WEB Budi Khoirudin
2020-07-06   BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6 44 WEB Critical Start
2020-07-06   Nagios XI 5.6.12 - 'export-rrd.php' Remote Code Execution 51 WEB Basim Alabdullah
2020-07-06   RSA IG&L Aveksa 7.1.1 - Remote Code Execution 52 WEB Jakub Palaczynski
2020-07-06   RiteCMS 2.2.1 - Authenticated Remote Code Execution 47 WEB Enes Özeser
2020-07-06   File Management System 1.1 - Persistent Cross-Site Scripting 44 WEB KeopssGroup0day_Inc
2020-07-02   OCS Inventory NG 2.7 - Remote Code Execution 47 WEB Askar
2020-07-02   ZenTao Pro 8.8.2 - Command Injection 45 WEB Daniel Monzón
2020-07-01   Online Shopping Portal 3.1 - Authentication Bypass 43 WEB Ümit Yalçın
2020-07-01   PHP-Fusion 9.03.60 - PHP Object Injection 47 WEB coiffeur
2020-07-01   e-learning Php Script 0.1.0 - 'search' SQL Injection 44 WEB KeopssGroup0day_Inc
2020-06-30   Reside Property Management 3.0 - 'profile' SQL Injection 41 WEB Behzad Khalifeh
2020-06-30   Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scripting 40 WEB Anushree Priyadarshini
2020-06-26   OpenEMR 5.0.1 - 'controller' Remote Code Execution 45 WEB Emre ÖVÜNÇ
2020-06-25   FHEM 6.0 - Local File Inclusion 51 WEB Emre ÖVÜNÇ
2020-06-24   BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting 44 WEB William Summerhill
2020-06-23   Online Student Enrollment System 1.0 - Cross-Site Request Forgery (Add Student) 47 WEB BKpatron
2020-06-23   Responsive Online Blog 1.0 - 'id' SQL Injection 49 WEB Eren Şimşek
2020-06-22   Eaton Intelligent Power Manager 1.6 - Directory Traversal 49 WEB Emre ÖVÜNÇ
2020-06-22   WebPort 1.19.1 - 'setup' Reflected Cross-Site Scripting 50 WEB Emre ÖVÜNÇ
2020-06-22   WebPort 1.19.1 - Reflected Cross-Site Scripting 52 WEB Emre ÖVÜNÇ
2020-06-22   Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload 53 WEB BKpatron
2020-06-22   Odoo 12.0 - Local File Inclusion 52 WEB Emre ÖVÜNÇ
2020-06-22   Student Enrollment 1.0 - Unauthenticated Remote Code Execution 53 WEB Enesdex
2020-06-22   FileRun 2019.05.21 - Reflected Cross-Site Scripting 49 WEB Emre ÖVÜNÇ
2020-06-18   Beauty Parlour Management System 1.0 - Authentication Bypass 54 WEB Prof. Kailas PATIL
2020-06-17   OpenCTI 3.3.1 - Directory Traversal 47 WEB Raif Berkay Dincel
2020-06-17   College-Management-System-Php 1.0 - Authentication Bypass 51 WEB BLAY ABU SAFIAN
2020-06-16   Gila CMS 1.11.8 - 'query' SQL Injection 48 WEB BillyV4
2020-06-15   Netgear R7000 Router - Remote Code Execution 68 WEB grimm-co
2020-06-12   Sysax MultiServer 6.90 - Reflected Cross Site Scripting 52 WEB Luca Epifanio
2020-06-12   Avaya IP Office 11 - Password Disclosure 47 WEB hyp3rlinx
2020-06-12   SmarterMail 16 - Arbitrary File Upload 52 WEB vvhack.org
2020-06-10   Virtual Airlines Manager 2.6.2 - 'id' SQL Injection 43 WEB Mosaaed
2020-06-10   Joomla! J2 Store 3.3.11 - 'filter_order_Dir' Authenticated SQL Injection 39 WEB Mehmet Kelepçe
2020-06-10   Sistem Informasi Pengumuman Kelulusan Online 1.0 - Cross-Site Request Forgery (Add Admin) 43 WEB Extinction
2020-06-09   Bludit 3.9.12 - Directory Traversal 52 WEB Luis Vacacas
2020-06-09   Virtual Airlines Manager 2.6.2 - 'airport' SQL Injection 47 WEB Kostadin Tonev
2020-06-08   Virtual Airlines Manager 2.6.2 - 'notam' SQL Injection 41 WEB Pankaj Kumar Thakur
2020-06-08   Kyocera Printer d-COPIA253MF - Directory Traversal (PoC) 40 WEB Hakan Eren ŞAN
2020-06-05   Online-Exam-System 2015 - 'feedback' SQL Injection 44 WEB Gus Ralph
2020-06-05   Online Course Registration 1.0 - Authentication Bypass 40 WEB BKpatron
2020-06-04   Cayin Digital Signage System xPost 2.5 - Remote Command Injection 41 WEB LiquidWorm
2020-06-04   Cayin Signage Media Player 3.0 - Remote Command Injection (root) 38 WEB LiquidWorm
2020-06-04   Secure Computing SnapGear Management Console SG560 3.1.5 - Arbitrary File Read 43 WEB LiquidWorm
2020-06-04   SnapGear Management Console SG560 3.1.5 - Cross-Site Request Forgery (Add Super User) 41 WEB LiquidWorm
2020-06-04   Cayin Content Management Server 11.0 - Remote Command Injection (root) 41 WEB LiquidWorm
2020-06-04   Online Marriage Registration System 1.0 - Remote Code Execution (1) 41 WEB Enesdex
2020-06-04   D-Link DIR-615 T1 20.10 - CAPTCHA Bypass 40 WEB huzaifa hussain
2020-06-04   Navigate CMS 2.8.7 - Authenticated Directory Traversal 42 WEB Gus Ralph
2020-06-04   VMWAre vCloud Director 9.7.0.15498291 - Remote Code Execution 39 WEB Tomas Melicher
2020-06-04   Navigate CMS 2.8.7 - Cross-Site Request Forgery (Add Admin) 42 WEB Gus Ralph
2020-06-04   Clinic Management System 1.0 - Authenticated Arbitrary File Upload 41 WEB BKpatron
2020-06-04   Oriol Espinal CMS 1.0 - 'id' SQL Injection 37 WEB TSAR
2020-06-04   Navigate CMS 2.8.7 - ''sidx' SQL Injection (Authenticated) 45 WEB Gus Ralph
2020-06-04   Clinic Management System 1.0 - Unauthenticated Remote Code Execution 42 WEB BKpatron
2020-06-04   Hostel Management System 2.0 - 'id' SQL Injection (Unauthenticated) 42 WEB Enesdex
2020-06-04   AirControl 1.4.2 - PreAuth Remote Code Execution 46 WEB 0xd0ff9
2020-06-02   OpenCart 3.0.3.2 - Stored Cross Site Scripting (Authenticated) 40 WEB Kailash Bohara
2020-06-02   Clinic Management System 1.0 - Authentication Bypass 63 WEB BKpatron
2020-06-01   QuickBox Pro 2.1.8 - Authenticated Remote Code Execution 44 WEB s1gh
2020-06-01   VMware vCenter Server 6.7 - Authentication Bypass 44 WEB Photubias
2020-06-01   WordPress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation 46 WEB Raphael Karger
2020-05-29   Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass 41 WEB Halis Duraki
2020-05-29   WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete User) 45 WEB UnD3sc0n0c1d0
2020-05-28   QNAP QTS and Photo Station 6.0.3 - Remote Command Execution 45 WEB Th3GundY
2020-05-28   EyouCMS 1.4.6 - Persistent Cross-Site Scripting 54 WEB China Banking and Insurance Information Technology
2020-05-28   Online-Exam-System 2015 - 'fid' SQL Injection 46 WEB Berk Dusunur
2020-05-28   NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection 44 WEB Berk Dusunur
2020-05-27   OXID eShop 6.3.4 - 'sorting' SQL Injection 54 WEB VulnSpy
2020-05-27   Kuicms PHP EE 2.0 - Persistent Cross-Site Scripting 44 WEB China Banking and Insurance Information Technology
2020-05-27   osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting 50 WEB Matthew Aberegg
2020-05-27   osTicket 1.14.1 - 'Ticket Queue' Persistent Cross-Site Scripting 49 WEB Matthew Aberegg
2020-05-27   LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting 42 WEB Matthew Aberegg
2020-05-27   Online Marriage Registration System 1.0 - Persistent Cross-Site Scripting 48 WEB that faceless coder
2020-05-26   WordPress Plugin Drag and Drop File Upload Contact Form 1.3.3.2 - Remote Code Execution 55 WEB Austin Martin
2020-05-26   Pi-hole 4.4.0 - Remote Code Execution (Authenticated) 41 WEB Photubias
2020-05-26   Joomla! Plugin XCloner Backup 3.5.3 - Local File Inclusion (Authenticated) 45 WEB Mehmet Kelepçe
2020-05-26   Open-AudIT 3.3.0 - Reflective Cross-Site Scripting (Authenticated) 59 WEB Kamaljeet Kumar
2020-05-26   OpenEMR 5.0.1 - Remote Code Execution (1) 60 WEB Musyoka Ian
2020-05-25   Online Discussion Forum Site 1.0 - Remote Code Execution 45 WEB Enesdex
2020-05-25   Victor CMS 1.0 - 'add_user' Persistent Cross-Site Scripting 36 WEB Nitya Nand
2020-05-25   WordPress Plugin Form Maker 5.4.1 - 's' SQL Injection (Authenticated) 50 WEB SunCSR
2020-05-22   Gym Management System 1.0 - Unauthenticated Remote Code Execution 50 WEB boku
2020-05-22   Dolibarr 11.0.3 - Persistent Cross-Site Scripting 46 WEB Mehmet Kelepçe
2020-05-21   OpenEDX platform Ironwood 2.5 - Remote Code Execution 47 WEB Daniel Monzón
2020-05-21   PHPFusion 9.03.50 - Persistent Cross-Site Scripting 48 WEB coiffeur
2020-05-21   Composr CMS 10.0.30 - Persistent Cross-Site Scripting 46 WEB Manuel García Cárdenas
2020-05-21   forma.lms 5.6.40 - Cross-Site Request Forgery (Change Admin Email) 54 WEB Daniel Ortiz
2020-05-20   CraftCMS 3 vCard Plugin 1.0.0 - Remote Code Execution 49 WEB Wade Guest
2020-05-19   Victor CMS 1.0 - Authenticated Arbitrary File Upload 50 WEB Kishan Lal Choudhary
2020-05-19   NukeViet VMS 4.4.00 - Cross-Site Request Forgery (Change Admin Password) 43 WEB JEBARAJ
2020-05-19   Submitty 20.04.01 - Persistent Cross-Site Scripting 44 WEB humblelad
2020-05-19   php-fusion 9.03.50 - 'ctype' SQL Injection 39 WEB SunCSR