Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-02-10   Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting 24 WEB Prasenjit Kanti Paul
2020-02-07   Google Invisible RECAPTCHA 3 - Spoof Bypass 27 WEB Matamorphosis
2020-02-07   ExpertGPS 6.38 - XML External Entity Injection 24 WEB Trent Gordon
2020-02-07   EyesOfNetwork 5.3 - Remote Code Execution 20 WEB Clément Billac
2020-02-07   PackWeb Formap E-learning 1.0 - 'NumCours' SQL Injection 24 WEB Amel BOUZIANE-LEBLOND
2020-02-07   VehicleWorkshop 1.0 - 'bookingid' SQL Injection 23 WEB Mehran Feizi
2020-02-07   QuickDate 1.3.2 - SQL Injection 28 WEB Ihsan Sencan
2020-02-06   Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection 22 WEB mr_me
2020-02-06   Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection 18 WEB mr_me
2020-02-06   Cisco Data Center Network Manager 11.2 - Remote Code Execution 16 WEB mr_me
2020-02-06   Ecommerce Systempay 1.0 - Production KEY Brute Force 20 WEB live3
2020-02-06   Online Job Portal 1.0 - Cross Site Request Forgery (Add User) 24 WEB Ihsan Sencan
2020-02-06   Online Job Portal 1.0 - Remote Code Execution 24 WEB Ihsan Sencan
2020-02-06   Online Job Portal 1.0 - 'user_email' SQL Injection 27 WEB Ihsan Sencan
2020-02-05   AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset) 22 WEB Ihsan Sencan
2020-02-05   Verodin Director Web Console 3.5.4.0 - Remote Authenticated Password Disclosure (PoC) 22 WEB nxkennedy
2020-02-05   Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation 26 WEB nxkennedy
2020-02-05   Wago PFC200 - Authenticated Remote Code Execution (Metasploit) 17 WEB 0x483d
2020-02-05   AVideo Platform 8.1 - Information Disclosure (User Enumeration) 21 WEB Ihsan Sencan
2020-02-04   F-Secure Internet Gatekeeper 5.40 - Heap Overflow (PoC) 25 WEB Kevin Joensen
2020-02-04   Centreon 19.10.5 - 'Pollers' Remote Command Execution (Metasploit) 26 WEB mekhalleh
2020-02-03   School ERP System 1.0 - Cross Site Request Forgery (Add Admin) 22 WEB J3rryBl4nks
2020-02-03   Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection 21 WEB Cosmin Craciun
2020-02-03   Jira 8.3.4 - Information Disclosure (Username Enumeration) 17 WEB Mufeed VH
2020-02-03   phpList 3.5.0 - Authentication Bypass 27 WEB Suvadip Kar
2020-02-03   IceWarp WebMail 11.4.4.1 - Reflective Cross-Site Scripting 24 WEB Lutfu Mert Ceylan
2020-01-31   FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin) 20 WEB Ismail Tasdelen
2020-01-31   Lotus Core CMS 1.0.1 - Local File Inclusion 24 WEB Daniel Monzón
2020-01-30   rConfig 3.9.3 - Authenticated Remote Code Execution 21 WEB vikingfr
2020-01-29   Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting 23 WEB LiquidWorm
2020-01-29   Centreon 19.10.5 - 'centreontrapd' Remote Command Execution 24 WEB Fabien AUNAY
2020-01-29   Centreon 19.10.5 - 'Pollers' Remote Command Execution 29 WEB Omri Baso
2020-01-29   Satellian 1.12 - Remote Code Execution 26 WEB Xh4H
2020-01-29   Cups Easy 1.0 - Cross Site Request Forgery (Password Reset) 24 WEB J3rryBl4nks
2020-01-29   Liferay CE Portal 6.0.2 - Remote Command Execution 30 WEB Berk Dusunur
2020-01-29   Kibana 6.6.1 - CSV Injection 26 WEB Aamir Rehman
2020-01-28   Centreon 19.10.5 - Remote Command Execution 32 WEB Fabien AUNAY
2020-01-28   Centreon 19.10.5 - Database Credentials Disclosure 29 WEB Fabien AUNAY
2020-01-28   Octeth Oempro 4.8 - 'CampaignID' SQL Injection 27 WEB Bruno de Barros Bulle
2020-01-28   Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password) 27 WEB Sarthak Saini
2020-01-24   Genexis Platinum-4410 2.1 - Authentication Bypass 25 WEB Husinul Sanub
2020-01-24   OLK Web Store 2020 - Cross-Site Request Forgery 27 WEB Joel Aviad Ossi
2020-01-24   Webtareas 2.0 - 'id' SQL Injection 22 WEB Greg.Priest
2020-01-24   TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot 20 WEB PCEumel
2020-01-23   qdPM 9.1 - Remote Code Execution 21 WEB Rishal Dwivedi
2020-01-22   Citrix XenMobile Server 10.8 - XML External Entity Injection 24 WEB Jonas Lejon
2020-01-21   ManageEngine Network Configuration Manager 12.2 - 'apiKey' SQL Injection 21 WEB Ertebat Gostar Co
2020-01-20   Centreon 19.04 - Authenticated Remote Code Execution (Metasploit) 22 WEB TheCyberGeek
2020-01-20   Adive Framework 2.0.8 - Persistent Cross-Site Scripting 23 WEB Sarthak Saini
2020-01-17   WordPress Plugin Time Capsule 1.21.16 - Authentication Bypass 28 WEB B. Canavate
2020-01-17   WordPress Plugin InfiniteWP Client 1.9.4.5 - Authentication Bypass 23 WEB Raphael Karger
2020-01-16   Rukovoditel Project Management CRM 2.5.2 - 'filters' SQL Injection 24 WEB Fatih Çelik
2020-01-16   Rukovoditel Project Management CRM 2.5.2 - 'entities_id' SQL Injection 27 WEB Fatih Çelik
2020-01-16   Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal 23 WEB Dhiraj Mishra
2020-01-16   Online Book Store 1.0 - Arbitrary File Upload 27 WEB Or4nG.M4N
2020-01-16   Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting 21 WEB Ai Ho
2020-01-16   Rukovoditel Project Management CRM 2.5.2 - 'reports_id' SQL Injection 23 WEB Fatih Çelik
2020-01-16   WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting 27 WEB V1n1v131r4
2020-01-15   Huawei HG255 - Directory Traversal (Metasploit) 26 WEB Ismail Tasdelen
2020-01-15   Online Book Store 1.0 - 'bookisbn' SQL Injection 30 WEB Ertebat Gostar Co
2020-01-14   IBM RICOH 6400 Printer - HTML Injection 26 WEB Ismail Tasdelen
2020-01-14   IBM RICOH InfoPrint 6500 Printer - HTML Injection 22 WEB Ismail Tasdelen
2020-01-13   Digi AnywhereUSB 14 - Reflective Cross-Site Scripting 32 WEB Raspina Net Pars Group
2020-01-13   Citrix Application Delivery Controller and Gateway 10.5 - Remote Code Execution (Metasploit) 26 WEB mekhalleh
2020-01-13   Chevereto 3.13.4 Core - Remote Code Execution 23 WEB Jinny Ramsmark
2020-01-11   Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution 26 WEB TrustedSec
2020-01-11   Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution (PoC) 25 WEB Project Zero India
2020-01-10   ASTPP 4.0.1 VoIP Billing - Database Backup Download 24 WEB Fabien AUNAY
2020-01-10   PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution 28 WEB .:UND3R:.
2020-01-10   Pandora 7.0NG - Remote Code Execution 22 WEB Askar
2020-01-09   Oracle Weblogic 10.3.6.0.0 - Remote Command Execution 23 WEB james
2019-12-31   Sony Playstation 4 (PS4) < 6.72 - WebKit Code Execution (PoC) 29 WEB TJ Corley
2020-01-08   Tomcat proprietaryEvaluate 9.0.0.M1 - Sandbox Escape 26 WEB hantwister
2020-01-08   Online Book Store 1.0 - Unauthenticated Remote Code Execution 29 WEB Tib3rius
2020-01-08   Codoforum 4.8.3 - 'input_txt' Persistent Cross-Site Scripting 29 WEB Vyshnav nk
2020-01-07   Complaint Management System 4.0 - Remote Code Execution 26 WEB Metin Yunus Kandemir
2020-01-07   piSignage 2.6.4 - Directory Traversal 26 WEB JunYeong Ko
2020-01-07   Job Portal 1.0 - Remote Code Execution 27 WEB Tib3rius
2019-12-24   Django < 3.0 < 2.2 < 1.11 - Account Hijack 26 WEB Ryuji Tsutsui
2020-01-06   Codoforum 4.8.3 - Persistent Cross-Site Scripting 31 WEB Prasanth
2020-01-06   Voyager 1.3.0 - Directory Traversal 29 WEB NgoAnhDuc
2020-01-06   Small CRM 2.0 - Authentication Bypass 25 WEB FULLSHADE
2020-01-06   elaniin CMS 1.0 - Authentication Bypass 27 WEB riamloo
2020-01-06   Hostel Management System 2.0 - 'id' SQL Injection 22 WEB FULLSHADE
2020-01-06   Subrion CMS 4.0.5 - Cross-Site Request Forgery (Add Admin) 24 WEB Ismail Tasdelen
2020-01-06   IBM RICOH Infoprint 1532 Printer - Persistent Cross-Site Scripting 27 WEB Ismail Tasdelen
2020-01-06   Complaint Management System 4.0 - 'cid' SQL injection 29 WEB FULLSHADE
2020-01-06   Dairy Farm Shop Management System 1.0 - 'username' SQL Injection 29 WEB Chris Inzinga
2020-01-03   Karakuzu ERP Management Web 5.7.0 - 'k_adi_duz' SQL Injection 26 WEB Hakan TAŞKÖPRÜ
2020-01-03   Online Course Registration 2.0 - Remote Code Execution 28 WEB Metin Yunus Kandemir
2020-01-02   BloodX 1.0 - Authentication Bypass 27 WEB riamloo
2020-01-02   Hospital Management System 4.0 - Persistent Cross-Site Scripting 26 WEB FULLSHADE
2020-01-02   Hospital Management System 4.0 - 'searchdata' SQL Injection 26 WEB FULLSHADE
2020-01-01   Hospital Management System 4.0 - Authentication Bypass 23 WEB Metin Yunus Kandemir
2020-01-01   IBM InfoPrint 4247-Z03 Impact Matrix Printer - Directory Traversal 23 WEB Raif Berkay Dincel
2020-01-01   Shopping Portal ProVersion 3.0 - Authentication Bypass 25 WEB Metin Yunus Kandemir
2019-12-31   WordPress Plugin Ultimate Addons for Beaver Builder 1.2.4.1 - Authentication Bypass 27 WEB Raphael Karger
2019-12-30   Heatmiser Netmonitor 3.03 - HTML Injection 29 WEB Ismail Tasdelen
2019-12-30   RICOH Web Image Monitor 1.09 - HTML Injection 23 WEB Ismail Tasdelen
2019-12-30   RICOH SP 4510SF Printer - HTML Injection 22 WEB Ismail Tasdelen
2019-12-30   MyDomoAtHome REST API Domoticz ISS Gateway 0.2.40 - Information Disclosure 24 WEB LiquidWorm
2019-12-30   Heatmiser Netmonitor 3.03 - Hardcoded Credentials 22 WEB Ismail Tasdelen
2019-12-30   AVE DOMINAplus 1.10.x - Authentication Bypass 21 WEB LiquidWorm
2019-12-30   AVE DOMINAplus 1.10.x - Cross-Site Request Forgery (enable/disable alarm) 24 WEB LiquidWorm
2019-12-30   AVE DOMINAplus 1.10.x - Unauthenticated Remote Reboot 19 WEB LiquidWorm
2019-12-30   AVE DOMINAplus 1.10.x - Credential Disclosure 21 WEB LiquidWorm
2019-12-30   WEMS BEMS 21.3.1 - Undocumented Backdoor Account 27 WEB LiquidWorm
2019-12-30   XEROX WorkCentre 7830 Printer - Cross-Site Request Forgery (Add Admin) 25 WEB Ismail Tasdelen
2019-12-30   XEROX WorkCentre 7855 Printer - Cross-Site Request Forgery (Add Admin) 22 WEB Ismail Tasdelen
2019-12-30   Thrive Smart Home 1.1 - Authentication Bypass 25 WEB LiquidWorm
2019-12-30   XEROX WorkCentre 6655 Printer - Cross-Site Request Forgery (Add Admin) 25 WEB Ismail Tasdelen
2019-12-30   elearning-script 1.0 - Authentication Bypass 21 WEB riamloo
2019-12-30   HomeAutomation 3.3.2 - Remote Code Execution 27 WEB LiquidWorm
2019-12-30   HomeAutomation 3.3.2 - Cross-Site Request Forgery (Add Admin) 25 WEB LiquidWorm
2019-12-30   HomeAutomation 3.3.2 - Authentication Bypass 23 WEB LiquidWorm
2019-12-30   HomeAutomation 3.3.2 - Persistent Cross-Site Scripting 24 WEB LiquidWorm
2019-12-20   phpMyChat-Plus 1.98 - 'pmc_username' Reflected Cross-Site Scripting 22 WEB Chris Inzinga
2019-12-19   Deutsche Bahn Ticket Vending Machine Local Kiosk - Privilege Escalation 25 WEB Vulnerability-Lab
2019-12-18   Telerik UI - Remote Code Execution via Insecure Deserialization 22 WEB Bishop Fox
2019-12-18   Rumpus FTP Web File Manager 8.2.9.1 - Reflected Cross-Site Scripting 23 WEB Harshit Shukla
2019-12-18   Xerox AltaLink C8035 Printer - Cross-Site Request Forgery (Add Admin) 26 WEB Ismail Tasdelen
2019-12-18   Tautulli 2.1.9 - Cross-Site Request Forgery (ShutDown) 33 WEB Ismail Tasdelen
2019-12-17   NopCommerce 4.2.0 - Privilege Escalation 30 WEB Alessandro Magnosi
2019-12-17   Netgear R6400 - Remote Code Execution 30 WEB Kevin Randall
2019-12-17   Zendesk App SweetHawk Survey 1.6 - Persistent Cross-Site Scripting 23 WEB MTK