Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-01-01   Shopping Portal ProVersion 3.0 - Authentication Bypass 26 WEB Metin Yunus Kandemir
2019-12-31   WordPress Plugin Ultimate Addons for Beaver Builder 1.2.4.1 - Authentication Bypass 30 WEB Raphael Karger
2019-12-30   Heatmiser Netmonitor 3.03 - HTML Injection 29 WEB Ismail Tasdelen
2019-12-30   RICOH Web Image Monitor 1.09 - HTML Injection 26 WEB Ismail Tasdelen
2019-12-30   RICOH SP 4510SF Printer - HTML Injection 22 WEB Ismail Tasdelen
2019-12-30   MyDomoAtHome REST API Domoticz ISS Gateway 0.2.40 - Information Disclosure 24 WEB LiquidWorm
2019-12-30   Heatmiser Netmonitor 3.03 - Hardcoded Credentials 25 WEB Ismail Tasdelen
2019-12-30   AVE DOMINAplus 1.10.x - Authentication Bypass 24 WEB LiquidWorm
2019-12-30   AVE DOMINAplus 1.10.x - Cross-Site Request Forgery (enable/disable alarm) 25 WEB LiquidWorm
2019-12-30   AVE DOMINAplus 1.10.x - Unauthenticated Remote Reboot 20 WEB LiquidWorm
2019-12-30   AVE DOMINAplus 1.10.x - Credential Disclosure 23 WEB LiquidWorm
2019-12-30   WEMS BEMS 21.3.1 - Undocumented Backdoor Account 27 WEB LiquidWorm
2019-12-30   XEROX WorkCentre 7830 Printer - Cross-Site Request Forgery (Add Admin) 25 WEB Ismail Tasdelen
2019-12-30   XEROX WorkCentre 7855 Printer - Cross-Site Request Forgery (Add Admin) 24 WEB Ismail Tasdelen
2019-12-30   Thrive Smart Home 1.1 - Authentication Bypass 26 WEB LiquidWorm
2019-12-30   XEROX WorkCentre 6655 Printer - Cross-Site Request Forgery (Add Admin) 29 WEB Ismail Tasdelen
2019-12-30   elearning-script 1.0 - Authentication Bypass 22 WEB riamloo
2019-12-30   HomeAutomation 3.3.2 - Remote Code Execution 28 WEB LiquidWorm
2019-12-30   HomeAutomation 3.3.2 - Cross-Site Request Forgery (Add Admin) 26 WEB LiquidWorm
2019-12-30   HomeAutomation 3.3.2 - Authentication Bypass 24 WEB LiquidWorm
2019-12-30   HomeAutomation 3.3.2 - Persistent Cross-Site Scripting 27 WEB LiquidWorm
2019-12-20   phpMyChat-Plus 1.98 - 'pmc_username' Reflected Cross-Site Scripting 24 WEB Chris Inzinga
2019-12-19   Deutsche Bahn Ticket Vending Machine Local Kiosk - Privilege Escalation 26 WEB Vulnerability-Lab
2019-12-18   Telerik UI - Remote Code Execution via Insecure Deserialization 26 WEB Bishop Fox
2019-12-18   Rumpus FTP Web File Manager 8.2.9.1 - Reflected Cross-Site Scripting 25 WEB Harshit Shukla
2019-12-18   Xerox AltaLink C8035 Printer - Cross-Site Request Forgery (Add Admin) 28 WEB Ismail Tasdelen
2019-12-18   Tautulli 2.1.9 - Cross-Site Request Forgery (ShutDown) 33 WEB Ismail Tasdelen
2019-12-17   NopCommerce 4.2.0 - Privilege Escalation 31 WEB Alessandro Magnosi
2019-12-17   Netgear R6400 - Remote Code Execution 31 WEB Kevin Randall
2019-12-17   Zendesk App SweetHawk Survey 1.6 - Persistent Cross-Site Scripting 24 WEB MTK
2019-12-16   D-Link DIR-615 - Privilege Escalation 31 WEB Sanyam Chawla
2019-12-16   Roxy Fileman 1.4.5 - Directory Traversal 28 WEB Patrik Lantz
2019-12-16   D-Link DIR-615 Wireless Router  -  Persistent Cross-Site Scripting 23 WEB Sanyam Chawla
2019-12-13   NVMS 1000 - Directory Traversal 25 WEB numan türle
2019-12-12   Bullwark Momentum Series JAWS 1.0 - Directory Traversal 28 WEB numan türle
2019-12-12   OpenNetAdmin 18.1.1 - Command Injection Exploit (Metasploit) 29 WEB Onur ER
2019-12-11   Apache Olingo OData 4.0 - XML External Entity Injection 21 WEB Compass Security
2019-12-10   Inim Electronics Smartliving SmartLAN 6.x - Remote Command Execution 30 WEB LiquidWorm
2019-12-10   Inim Electronics Smartliving SmartLAN 6.x - Unauthenticated Server-Side Request Forgery 24 WEB LiquidWorm
2019-12-09   Oracle Siebel Sales 8.1 - Persistent Cross-Site Scripting 20 WEB omurugur
2019-12-09   Alcatel-Lucent Omnivista 8770 - Remote Code Execution 26 WEB 0x1911
2019-12-09   Yachtcontrol Webapplication 1.0 - Unauthenticated Remote Code Execution 19 WEB Hodorsec
2019-12-09   PRO-7070 Hazır Profesyonel Web Sitesi 1.0 - Authentication Bypass 21 WEB Ahmet Ümit BAYRAM
2019-12-09   Snipe-IT Open Source Asset Management 4.7.5 - Persistent Cross-Site Scripting 30 WEB Metin Yunus Kandemir
2019-12-06   Verot 2.0.3 - Remote Code Execution 28 WEB Jinny Ramsmark
2019-12-05   Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution 22 WEB Peter Lapp
2019-12-04   OwnCloud 8.1.8 - Username Disclosure 23 WEB Daniel Moreno
2019-12-04   Online Clinic Management System 2.2 - HTML Injection 24 WEB Cemal Cihad ÇİFTÇİ
2019-12-03   Revive Adserver 4.2 - Remote Code Execution 26 WEB crlf
2019-12-03   Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery 23 WEB Prof. Joas Antonio
2019-12-03   Online Invoicing System 2.6 - 'description' Persistent Cross-Site Scripting 23 WEB Cemal Cihad ÇİFTÇİ
2019-12-02   Dokuwiki 2018-04-22b - Username Enumeration 23 WEB Talha ŞEN
2019-12-02   SmartHouse Webapp 6.5.33 - Cross-Site Request Forgery 21 WEB LiquidWorm
2019-11-29   Online Inventory Manager 3.2 - Persistent Cross-Site Scripting 27 WEB Cemal Cihad ÇİFTÇİ
2019-11-28   Mersive Solstice 2.8.0 - Remote Code Execution 25 WEB Alexandre Teyar
2019-11-28   WordPress Core 5.3 - User Disclosure 28 WEB SajjadBnd
2019-11-21   Network Management Card 6.2.0 - Host Header Injection 21 WEB Amal E Thamban
2019-11-21   TestLink 1.9.19 - Persistent Cross-Site Scripting 24 WEB Milad Khoshdel
2019-11-20   OpenNetAdmin 18.1.1 - Remote Code Execution 26 WEB mattpascoe
2019-10-14   WordPress Core < 5.2.3 - Viewing Unauthenticated/Password/Private Posts 25 WEB Sebastian Neef
2019-10-14   Apache Httpd mod_rewrite - Open Redirects 24 WEB Sebastian Neef
2019-10-14   Apache Httpd mod_proxy - Error Page Cross-Site Scripting 28 WEB Sebastian Neef
2019-11-18   TemaTres 3.0 - 'value' Persistent Cross-site Scripting 27 WEB Pablo Santiago
2019-11-18   TemaTres 3.0 - Cross-Site Request Forgery (Add Admin) 27 WEB Pablo Santiago
2019-11-18   Centova Cast 3.2.11 - Arbitrary File Download 24 WEB DroidU
2019-11-18   Crystal Live HTTP Server 6.01 - Directory Traversal 27 WEB numan türle
2019-11-18   Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal 29 WEB Kevin Randall
2019-11-14   Xfilesharing 2.5.1 - Arbitrary File Upload 30 WEB Noman Riffat
2019-11-13   Fastweb Fastgate 0.00.81 - Remote Code Execution 34 WEB Riccardo Gasparini
2019-11-13   gSOAP 2.8 - Directory Traversal 29 WEB numan türle
2019-11-13   Technicolor TC7300.B0 - 'hostname' Persistent Cross-Site Scripting 25 WEB Luis Santana
2019-11-13   Technicolor TD5130.2 - Remote Command Execution 21 WEB João Teles
2019-11-13   FUDForum 3.0.9 - Remote Code Execution 22 WEB liquidsky
2019-11-13   Linear eMerge E3 1.00-06 - Remote Code Execution 25 WEB LiquidWorm
2019-11-12   FlexAir Access Control 2.3.35 - Authentication Bypass 22 WEB LiquidWorm
2019-11-12   Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting 20 WEB Cy83rl0gger
2019-11-12   Optergy 2.3.0a - Remote Code Execution (Backdoor) 25 WEB LiquidWorm
2019-11-12   Optergy 2.3.0a - Username Disclosure 22 WEB LiquidWorm
2019-11-12   Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin) 23 WEB LiquidWorm
2019-11-12   FlexAir Access Control 2.4.9api3 - Remote Code Execution 20 WEB LiquidWorm
2019-11-12   Optergy 2.3.0a - Remote Code Execution 25 WEB LiquidWorm
2019-11-12   Atlassian Confluence 6.15.1 - Directory Traversal (Metasploit) 21 WEB max7253
2019-11-12   Prima Access Control 2.3.35 - Arbitrary File Upload 20 WEB LiquidWorm
2019-11-12   Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting 20 WEB LiquidWorm
2019-11-12   CBAS-Web 19.0.0 - 'id' Boolean-based Blind SQL Injection 20 WEB LiquidWorm
2019-11-12   CBAS-Web 19.0.0 - Username Enumeration 18 WEB LiquidWorm
2019-11-12   CBAS-Web 19.0.0 - Cross-Site Request Forgery (Add Super Admin) 26 WEB LiquidWorm
2019-11-12   CBAS-Web 19.0.0 - Remote Code Execution 21 WEB LiquidWorm
2019-11-12   eMerge50P 5000P 4.6.07 - Remote Code Execution 23 WEB LiquidWorm
2019-11-12   eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting 17 WEB LiquidWorm
2019-11-12   eMerge E3 1.00-06 - Arbitrary File Upload 18 WEB LiquidWorm
2019-11-12   Atlassian Confluence 6.15.1 - Directory Traversal 18 WEB max7253
2019-11-12   eMerge E3 1.00-06 - Cross-Site Request Forgery 18 WEB LiquidWorm
2019-11-12   eMerge E3 1.00-06 - Remote Code Execution 19 WEB LiquidWorm
2019-11-12   eMerge E3 1.00-06 - Privilege Escalation 34 WEB LiquidWorm
2019-11-12   eMerge E3 1.00-06 - Unauthenticated Directory Traversal 22 WEB LiquidWorm
2019-11-12   Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting 22 WEB LiquidWorm
2019-11-12   Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting 24 WEB Cy83rl0gger
2019-11-12   Prima FlexAir Access Control 2.3.38 - Remote Code Execution 23 WEB LiquidWorm
2019-11-12   Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting 23 WEB Cy83rl0gger
2019-11-08   Nextcloud 17 - Cross-Site Request Forgery 27 WEB Ozer Goker
2019-11-08   Adive Framework 2.0.7 - Privilege Escalation 24 WEB Pablo Santiago
2019-11-08   Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting 22 WEB vesche
2019-11-06   Smartwares HOME easy 1.0.9 - Database Backup Information Disclosure 28 WEB LiquidWorm
2019-11-06   Smartwares HOME easy 1.0.9 - Client-Side Authentication Bypass 24 WEB LiquidWorm
2019-11-05   SD.NET RIM 4.7.3c - 'idtyp' SQL Injection 23 WEB Fabian Mosch_ Nick Theisinger
2019-11-05   html5_snmp 1.11 - 'Router_ID' SQL Injection 29 WEB cakes
2019-11-05   html5_snmp 1.11 - 'Remark' Persistent Cross-Site Scripting 21 WEB cakes
2019-11-05   rimbalinux AhadPOS 1.11 - 'alamatCustomer' SQL Injection 24 WEB cakes
2019-11-05   thrsrossi Millhouse-Project 1.414 - 'content' Persistent Cross-Site Scripting 23 WEB cakes
2019-11-05   thejshen Globitek CMS 1.4 - 'id' SQL Injection 23 WEB cakes
2019-11-01   Apache Solr 8.2.0 - Remote Code Execution 21 WEB @l3x_wong
2019-11-01   ownCloud 10.3.0 stable - Cross-Site Request Forgery 22 WEB Ozer Goker
2019-11-01   TheJshen contentManagementSystem 1.04 - 'id' SQL Injection 22 WEB cakes
2019-10-31   WordPress Plugin Google Review Slider 6.1 - 'tid' SQL Injection 26 WEB Princy Edward
2019-10-30   iSeeQ Hybrid DVR WH-H4 2.0.0.P - (get_jpeg) Stream Disclosure 24 WEB LiquidWorm
2019-10-30   Citrix StoreFront Server 7.15 - XML External Entity Injection 29 WEB Vahagn Vardanyan
2019-10-30   Ajenti 2.1.31 - Remote Code Exection (Metasploit) 26 WEB Onur ER
2019-10-29   WordPress Core 5.2.4 - Cross-Origin Resource Sharing 27 WEB Milad Khoshdel
2019-10-29   rConfig 3.9.2 - Remote Code Execution 27 WEB Askar
2019-10-28   PHP-FPM + Nginx - Remote Code Execution 21 WEB Emil Lerner
2019-10-28   delpino73 Blue-Smiley-Organizer 1.32 - 'datetime' SQL Injection 22 WEB cakes
2019-10-28   waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'description' Cross-Site Scripting 28 WEB cakes
2019-10-28   Part-DB 0.4 - Authentication Bypass 17 WEB Marvoloo
2019-10-28   waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'start' SQL Injection 21 WEB cakes