Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2019-10-14   Apache Httpd mod_proxy - Error Page Cross-Site Scripting 12 WEB Sebastian Neef
2019-11-18   TemaTres 3.0 - 'value' Persistent Cross-site Scripting 12 WEB Pablo Santiago
2019-11-18   TemaTres 3.0 - Cross-Site Request Forgery (Add Admin) 11 WEB Pablo Santiago
2019-11-18   Centova Cast 3.2.11 - Arbitrary File Download 10 WEB DroidU
2019-11-18   Crystal Live HTTP Server 6.01 - Directory Traversal 13 WEB numan türle
2019-11-18   Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal 10 WEB Kevin Randall
2019-11-14   Xfilesharing 2.5.1 - Arbitrary File Upload 14 WEB Noman Riffat
2019-11-13   Fastweb Fastgate 0.00.81 - Remote Code Execution 11 WEB Riccardo Gasparini
2019-11-13   gSOAP 2.8 - Directory Traversal 10 WEB numan türle
2019-11-13   Technicolor TC7300.B0 - 'hostname' Persistent Cross-Site Scripting 8 WEB Luis Santana
2019-11-13   Technicolor TD5130.2 - Remote Command Execution 9 WEB João Teles
2019-11-13   FUDForum 3.0.9 - Remote Code Execution 8 WEB liquidsky
2019-11-13   Linear eMerge E3 1.00-06 - Remote Code Execution 10 WEB LiquidWorm
2019-11-12   FlexAir Access Control 2.3.35 - Authentication Bypass 10 WEB LiquidWorm
2019-11-12   Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting 9 WEB Cy83rl0gger
2019-11-12   Optergy 2.3.0a - Remote Code Execution (Backdoor) 10 WEB LiquidWorm
2019-11-12   Optergy 2.3.0a - Username Disclosure 8 WEB LiquidWorm
2019-11-12   Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin) 9 WEB LiquidWorm
2019-11-12   FlexAir Access Control 2.4.9api3 - Remote Code Execution 9 WEB LiquidWorm
2019-11-12   Optergy 2.3.0a - Remote Code Execution 11 WEB LiquidWorm
2019-11-12   Atlassian Confluence 6.15.1 - Directory Traversal (Metasploit) 10 WEB max7253
2019-11-12   Prima Access Control 2.3.35 - Arbitrary File Upload 10 WEB LiquidWorm
2019-11-12   Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting 9 WEB LiquidWorm
2019-11-12   CBAS-Web 19.0.0 - 'id' Boolean-based Blind SQL Injection 10 WEB LiquidWorm
2019-11-12   CBAS-Web 19.0.0 - Username Enumeration 9 WEB LiquidWorm
2019-11-12   CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin) 9 WEB LiquidWorm
2019-11-12   CBAS-Web 19.0.0 - Remote Code Execution 8 WEB LiquidWorm
2019-11-12   eMerge50P 5000P 4.6.07 - Remote Code Execution 9 WEB LiquidWorm
2019-11-12   eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting 8 WEB LiquidWorm
2019-11-12   eMerge E3 1.00-06 - Arbitrary File Upload 8 WEB LiquidWorm
2019-11-12   Atlassian Confluence 6.15.1 - Directory Traversal 8 WEB max7253
2019-11-12   eMerge E3 1.00-06 - Cross-Site Request Forgery 7 WEB LiquidWorm
2019-11-12   eMerge E3 1.00-06 - Remote Code Execution 10 WEB LiquidWorm
2019-11-12   eMerge E3 1.00-06 - Privilege Escalation 24 WEB LiquidWorm
2019-11-12   eMerge E3 1.00-06 - Unauthenticated Directory Traversal 10 WEB LiquidWorm
2019-11-12   Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting 11 WEB LiquidWorm
2019-11-12   Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting 11 WEB Cy83rl0gger
2019-11-12   Prima FlexAir Access Control 2.3.38 - Remote Code Execution 11 WEB LiquidWorm
2019-11-12   Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting 12 WEB Cy83rl0gger
2019-11-08   Nextcloud 17 - Cross-Site Request Forgery 10 WEB Ozer Goker
2019-11-08   Adive Framework 2.0.7 - Privilege Escalation 9 WEB Pablo Santiago
2019-11-08   Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting 8 WEB vesche
2019-11-06   Smartwares HOME easy 1.0.9 - Database Backup Information Disclosure 10 WEB LiquidWorm
2019-11-06   Smartwares HOME easy 1.0.9 - Client-Side Authentication Bypass 10 WEB LiquidWorm
2019-11-05   SD.NET RIM 4.7.3c - 'idtyp' SQL Injection 11 WEB Fabian Mosch_ Nick Theisinger
2019-11-05   html5_snmp 1.11 - 'Router_ID' SQL Injection 14 WEB cakes
2019-11-05   html5_snmp 1.11 - 'Remark' Persistent Cross-Site Scripting 9 WEB cakes
2019-11-05   rimbalinux AhadPOS 1.11 - 'alamatCustomer' SQL Injection 10 WEB cakes
2019-11-05   thrsrossi Millhouse-Project 1.414 - 'content' Persistent Cross-Site Scripting 11 WEB cakes
2019-11-05   thejshen Globitek CMS 1.4 - 'id' SQL Injection 10 WEB cakes
2019-11-01   Apache Solr 8.2.0 - Remote Code Execution 8 WEB @l3x_wong
2019-11-01   ownCloud 10.3.0 stable - Cross-Site Request Forgery 9 WEB Ozer Goker
2019-11-01   TheJshen contentManagementSystem 1.04 - 'id' SQL Injection 8 WEB cakes
2019-10-31   WordPress Plugin Google Review Slider 6.1 - 'tid' SQL Injection 13 WEB Princy Edward
2019-10-30   iSeeQ Hybrid DVR WH-H4 2.0.0.P - (get_jpeg) Stream Disclosure 12 WEB LiquidWorm
2019-10-30   Citrix StoreFront Server 7.15 - XML External Entity Injection 12 WEB Vahagn Vardanyan
2019-10-30   Ajenti 2.1.31 - Remote Code Exection (Metasploit) 13 WEB Onur ER
2019-10-29   WordPress Core 5.2.4 - Cross-Origin Resource Sharing 13 WEB Milad Khoshdel
2019-10-29   rConfig 3.9.2 - Remote Code Execution 12 WEB Askar
2019-10-28   PHP-FPM + Nginx - Remote Code Execution 10 WEB Emil Lerner
2019-10-28   delpino73 Blue-Smiley-Organizer 1.32 - 'datetime' SQL Injection 10 WEB cakes
2019-10-28   waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'description' Cross-Site Scripting 12 WEB cakes
2019-10-28   Part-DB 0.4 - Authentication Bypass 6 WEB Marvoloo
2019-10-28   waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'start' SQL Injection 7 WEB cakes
2019-10-28   Intelbras Router WRN150 1.0.18 - Cross-Site Request Forgery 7 WEB Prof. Joas Antonio
2019-10-25   ClonOs WEB UI 19.09 - Improper Access Control 9 WEB İbrahim Hakan Şeker
2019-10-24   AUO SunVeillance Monitoring System 1.1.9e - 'MailAdd' SQL Injection 8 WEB Luca.Chiou
2019-10-24   AUO SunVeillance Monitoring System 1.1.9e - Incorrect Access Control 9 WEB Luca.Chiou
2019-10-24   WordPress Plugin Sliced Invoices 3.8.2 - 'post' SQL Injection 9 WEB Lucian Ioan Nitescu
2019-10-23   Joomla! 3.4.6 - Remote Code Execution (Metasploit) 12 WEB Alessandro Groppo
2019-10-23   Rocket.Chat 2.1.0 - Cross-Site Scripting 11 WEB 3H34N
2019-10-18   Joomla! 3.4.6 - Remote Code Execution 11 WEB Alessandro Groppo
2019-10-17   Restaurant Management System 1.0 - Remote Code Execution 12 WEB Ibad Shah
2019-10-17   WordPress Plugin Popup Builder 3.49 - Persistent Cross-Site Scripting 13 WEB Unk9vvN
2019-10-17   WordPress Plugin Soliloquy Lite 2.5.6 - Persistent Cross-Site Scripting 13 WEB Unk9vvN
2019-10-17   WordPress Plugin FooGallery 1.8.12 - Persistent Cross-Site Scripting 14 WEB Unk9vvN
2019-10-16   Accounts Accounting 7.02 - Persistent Cross-Site Scripting 13 WEB Debashis Pal
2019-10-15   Bolt CMS 3.6.10 - Cross-Site Request Forgery 13 WEB r3m0t3nu11
2019-10-14   Kirona-DRS 5.5.3.5 - Information Disclosure 13 WEB Ramikan
2019-10-14   Ajenti 2.1.31 - Remote Code Execution 13 WEB Jeremy Brown
2019-10-14   Express Invoice 7.12 - 'Customer' Persistent Cross-Site Scripting 11 WEB Debashis Pal
2019-10-11   WordPress Plugin Arforms 3.7.1 - Directory Traversal 15 WEB Ahmad Almorabea
2019-10-11   Intelbras Router WRN150 1.0.18 - Persistent Cross-Site Scripting 13 WEB Prof. Joas Antonio
2019-10-10   TP-Link TL-WR1043ND 2 - Authentication Bypass 13 WEB Uriel Kosayev
2019-10-10   SMA Solar Technology AG Sunny WebBox device - 1.6 - Cross-Site Request Forgery 15 WEB Borja Merino
2019-10-07   vBulletin 5.0 < 5.5.4 - 'updateAvatar' Authenticated Remote Code Execution 13 WEB EgiX
2019-10-08   Zabbix 4.4 - Authentication Bypass 12 WEB Todor Donev
2019-10-07   IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload 15 WEB Jakub Palaczynski
2019-10-07   Subrion 4.2.1 - 'Email' Persistant Cross-Site Scripting 11 WEB Creatigon
2019-10-07   Zabbix 4.2 - Authentication Bypass 11 WEB Milad Khoshdel
2019-10-07   Joomla! 3.4.6 - 'configuration.php' Remote Code Execution 13 WEB Alessandro Groppo
2019-10-03   PHP 7.0 < 7.3 (Unix) - 'gc' disable_functions Bypass 13 WEB mm0r1
2019-10-04   LabCollector 5.423 - SQL Injection 15 WEB Carlos Avila
2019-10-03   AnchorCMS < 0.12.3a - Information Disclosure 13 WEB Tijme Gommers
2019-10-03   mintinstall 7.9.9 - Code Execution 14 WEB İbrahim Hakan Şeker
2019-10-02   Detrix EDMS 1.2.3.1505 - SQL Injection 10 WEB Burov Konstantin
2019-10-01   DotNetNuke 9.3.2 - Cross-Site Scripting 13 WEB Semen Alexandrovich Lyhin
2019-10-01   DotNetNuke < 9.4.0 - Cross-Site Scripting 12 WEB MaYaSeVeN
2019-09-23   vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution 15 WEB anonymous
2019-09-28   PHP 7.1 < 7.3 - 'json serializer' disable_functions Bypass 12 WEB mm0r1
2019-09-30   WordPress Plugin ARforms 3.7.1 - Arbitrary File Deletion 10 WEB Ahmad Almorabea
2019-09-30   TheSystem 1.0 - Command Injection 12 WEB Sadik Cetin
2019-09-30   thesystem 1.0 - Cross-Site Scripting 12 WEB Anıl Baran Yelken
2019-09-30   phpIPAM 1.4 - SQL Injection 11 WEB Kevin Kirsche
2019-09-30   vBulletin 5.x - Remote Command Execution (Metasploit) 9 WEB r00tpgp
2019-09-27   WordPress Theme Zoner Real Estate - 4.1.1 Persistent Cross-Site Scripting 8 WEB m0ze
2019-09-27   V-SOL GPON/EPON OLT Platform 2.03 - Remote Privilege Escalation 11 WEB LiquidWorm
2019-09-27   V-SOL GPON/EPON OLT Platform 2.03 - Cross-Site Request Forgery 12 WEB LiquidWorm
2019-09-27   V-SOL GPON/EPON OLT Platform 2.03 - Unauthenticated Configuration Download 10 WEB LiquidWorm
2019-09-27   thesystem App 1.0 - 'username' SQL Injection 11 WEB Anıl Baran Yelken
2019-09-27   thesystem App 1.0 - Persistent Cross-Site Scripting 10 WEB İsmail Güngör
2019-09-27   thesystem App 1.0 - 'server_name' SQL Injection 12 WEB Sadik Cetin
2019-09-27   InoERP 0.7.2 - Persistent Cross-Site Scripting 10 WEB strider
2019-09-26   citecodecrashers Pic-A-Point 1.1 - 'Consignment' SQL Injection 13 WEB cakes
2019-09-26   inoERP 4.15 - 'download' SQL Injection 13 WEB Semen Alexandrovich Lyhin
2019-09-26   all-in-one-seo-pack 3.2.7 - Persistent Cross-Site Scripting 10 WEB Unk9vvN
2019-09-26   Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting 13 WEB Unk9vvN
2019-09-26   Chamillo LMS 1.11.8 - Arbitrary File Upload 18 WEB Sohel Yousef
2019-09-25   YzmCMS 5.3 - 'Host' Header Injection 14 WEB Debashis Pal
2019-09-25   NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution 12 WEB Semen Alexandrovich Lyhin
2019-09-25   WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting 15 WEB strider
2019-09-25   Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting 13 WEB Davide Cioccia
2019-09-24   Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection 15 WEB Nassim Asrir
2019-09-23   Gila CMS < 1.11.1 - Local File Inclusion 12 WEB Sainadh Jamalpur
2019-09-20   LayerBB < 1.1.4 - Cross-Site Request Forgery 12 WEB 0xB9