Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2019-11-05   thrsrossi Millhouse-Project 1.414 - 'content' Persistent Cross-Site Scripting 27 WEB cakes
2019-11-05   thejshen Globitek CMS 1.4 - 'id' SQL Injection 27 WEB cakes
2019-11-01   Apache Solr 8.2.0 - Remote Code Execution 25 WEB @l3x_wong
2019-11-01   ownCloud 10.3.0 stable - Cross-Site Request Forgery 27 WEB Ozer Goker
2019-11-01   TheJshen contentManagementSystem 1.04 - 'id' SQL Injection 25 WEB cakes
2019-10-31   WordPress Plugin Google Review Slider 6.1 - 'tid' SQL Injection 29 WEB Princy Edward
2019-10-30   iSeeQ Hybrid DVR WH-H4 2.0.0.P - (get_jpeg) Stream Disclosure 27 WEB LiquidWorm
2019-10-30   Citrix StoreFront Server 7.15 - XML External Entity Injection 32 WEB Vahagn Vardanyan
2019-10-30   Ajenti 2.1.31 - Remote Code Exection (Metasploit) 31 WEB Onur ER
2019-10-29   WordPress Core 5.2.4 - Cross-Origin Resource Sharing 30 WEB Milad Khoshdel
2019-10-29   rConfig 3.9.2 - Remote Code Execution 31 WEB Askar
2019-10-28   PHP-FPM + Nginx - Remote Code Execution 26 WEB Emil Lerner
2019-10-28   delpino73 Blue-Smiley-Organizer 1.32 - 'datetime' SQL Injection 26 WEB cakes
2019-10-28   waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'description' Cross-Site Scripting 31 WEB cakes
2019-10-28   Part-DB 0.4 - Authentication Bypass 22 WEB Marvoloo
2019-10-28   waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'start' SQL Injection 26 WEB cakes
2019-10-28   Intelbras Router WRN150 1.0.18 - Cross-Site Request Forgery 23 WEB Prof. Joas Antonio
2019-10-25   ClonOs WEB UI 19.09 - Improper Access Control 27 WEB İbrahim Hakan Şeker
2019-10-24   AUO SunVeillance Monitoring System 1.1.9e - 'MailAdd' SQL Injection 24 WEB Luca.Chiou
2019-10-24   AUO SunVeillance Monitoring System 1.1.9e - Incorrect Access Control 25 WEB Luca.Chiou
2019-10-24   WordPress Plugin Sliced Invoices 3.8.2 - 'post' SQL Injection 23 WEB Lucian Ioan Nitescu
2019-10-23   Joomla! 3.4.6 - Remote Code Execution (Metasploit) 23 WEB Alessandro Groppo
2019-10-23   Rocket.Chat 2.1.0 - Cross-Site Scripting 25 WEB 3H34N
2019-10-18   Joomla! 3.4.6 - Remote Code Execution 25 WEB Alessandro Groppo
2019-10-17   Restaurant Management System 1.0 - Remote Code Execution 23 WEB Ibad Shah
2019-10-17   WordPress Plugin Popup Builder 3.49 - Persistent Cross-Site Scripting 29 WEB Unk9vvN
2019-10-17   WordPress Plugin Soliloquy Lite 2.5.6 - Persistent Cross-Site Scripting 28 WEB Unk9vvN
2019-10-17   WordPress Plugin FooGallery 1.8.12 - Persistent Cross-Site Scripting 28 WEB Unk9vvN
2019-10-16   Accounts Accounting 7.02 - Persistent Cross-Site Scripting 30 WEB Debashis Pal
2019-10-15   Bolt CMS 3.6.10 - Cross-Site Request Forgery 28 WEB r3m0t3nu11
2019-10-14   Kirona-DRS 5.5.3.5 - Information Disclosure 32 WEB Ramikan
2019-10-14   Ajenti 2.1.31 - Remote Code Execution 27 WEB Jeremy Brown
2019-10-14   Express Invoice 7.12 - 'Customer' Persistent Cross-Site Scripting 26 WEB Debashis Pal
2019-10-11   WordPress Plugin Arforms 3.7.1 - Directory Traversal 31 WEB Ahmad Almorabea
2019-10-11   Intelbras Router WRN150 1.0.18 - Persistent Cross-Site Scripting 30 WEB Prof. Joas Antonio
2019-10-10   TP-Link TL-WR1043ND 2 - Authentication Bypass 29 WEB Uriel Kosayev
2019-10-10   SMA Solar Technology AG Sunny WebBox device - 1.6 - Cross-Site Request Forgery 32 WEB Borja Merino
2019-10-07   vBulletin 5.0 < 5.5.4 - 'updateAvatar' Authenticated Remote Code Execution 30 WEB EgiX
2019-10-08   Zabbix 4.4 - Authentication Bypass 31 WEB Todor Donev
2019-10-07   IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload 32 WEB Jakub Palaczynski
2019-10-07   Subrion 4.2.1 - 'Email' Persistant Cross-Site Scripting 25 WEB Creatigon
2019-10-07   Zabbix 4.2 - Authentication Bypass 27 WEB Milad Khoshdel
2019-10-07   Joomla! 3.4.6 - 'configuration.php' Remote Code Execution 29 WEB Alessandro Groppo
2019-10-03   PHP 7.0 < 7.3 (Unix) - 'gc' disable_functions Bypass 36 WEB mm0r1
2019-10-04   LabCollector 5.423 - SQL Injection 29 WEB Carlos Avila
2019-10-03   AnchorCMS < 0.12.3a - Information Disclosure 27 WEB Tijme Gommers
2019-10-03   mintinstall 7.9.9 - Code Execution 28 WEB İbrahim Hakan Şeker
2019-10-02   Detrix EDMS 1.2.3.1505 - SQL Injection 25 WEB Burov Konstantin
2019-10-01   DotNetNuke 9.3.2 - Cross-Site Scripting 34 WEB Semen Alexandrovich Lyhin
2019-10-01   DotNetNuke < 9.4.0 - Cross-Site Scripting 34 WEB MaYaSeVeN
2019-09-23   vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution 28 WEB anonymous
2019-09-28   PHP 7.1 < 7.3 - 'json serializer' disable_functions Bypass 28 WEB mm0r1
2019-09-30   WordPress Plugin ARforms 3.7.1 - Arbitrary File Deletion 26 WEB Ahmad Almorabea
2019-09-30   TheSystem 1.0 - Command Injection 30 WEB Sadik Cetin
2019-09-30   thesystem 1.0 - Cross-Site Scripting 26 WEB Anıl Baran Yelken
2019-09-30   phpIPAM 1.4 - SQL Injection 26 WEB Kevin Kirsche
2019-09-30   vBulletin 5.x - Remote Command Execution (Metasploit) 27 WEB r00tpgp
2019-09-27   WordPress Theme Zoner Real Estate - 4.1.1 Persistent Cross-Site Scripting 23 WEB m0ze
2019-09-27   V-SOL GPON/EPON OLT Platform 2.03 - Remote Privilege Escalation 25 WEB LiquidWorm
2019-09-27   V-SOL GPON/EPON OLT Platform 2.03 - Cross-Site Request Forgery 30 WEB LiquidWorm
2019-09-27   V-SOL GPON/EPON OLT Platform 2.03 - Unauthenticated Configuration Download 25 WEB LiquidWorm
2019-09-27   thesystem App 1.0 - 'username' SQL Injection 25 WEB Anıl Baran Yelken
2019-09-27   thesystem App 1.0 - Persistent Cross-Site Scripting 26 WEB İsmail Güngör
2019-09-27   thesystem App 1.0 - 'server_name' SQL Injection 32 WEB Sadik Cetin
2019-09-27   InoERP 0.7.2 - Persistent Cross-Site Scripting 32 WEB strider
2019-09-26   citecodecrashers Pic-A-Point 1.1 - 'Consignment' SQL Injection 30 WEB cakes
2019-09-26   inoERP 4.15 - 'download' SQL Injection 41 WEB Semen Alexandrovich Lyhin
2019-09-26   all-in-one-seo-pack 3.2.7 - Persistent Cross-Site Scripting 28 WEB Unk9vvN
2019-09-26   Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting 28 WEB Unk9vvN
2019-09-26   Chamillo LMS 1.11.8 - Arbitrary File Upload 37 WEB Sohel Yousef
2019-09-25   YzmCMS 5.3 - 'Host' Header Injection 35 WEB Debashis Pal
2019-09-25   NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution 27 WEB Semen Alexandrovich Lyhin
2019-09-25   WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting 31 WEB strider
2019-09-25   Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting 28 WEB Davide Cioccia
2019-09-24   Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection 32 WEB Nassim Asrir
2019-09-23   Gila CMS < 1.11.1 - Local File Inclusion 30 WEB Sainadh Jamalpur
2019-09-20   LayerBB < 1.1.4 - Cross-Site Request Forgery 29 WEB 0xB9
2019-09-19   GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting 32 WEB cakes
2019-09-19   DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection 30 WEB n1x_
2019-09-19   Western Digital My Book World II NAS 1.02.12 - Authentication Bypass / Command Execution 27 WEB Noman Riffat
2019-09-18   Hospital-Management 1.26 - 'fname' SQL Injection 30 WEB cakes
2019-09-16   CollegeManagementSystem-CMS 1.3 - 'batch' SQL Injection 33 WEB cakes
2019-09-16   Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload 33 WEB Pankaj Kumar Thakur
2019-09-16   NetGain EM Plus 10.1.68 - Remote Command Execution 35 WEB azams
2019-09-14   College-Management-System 1.2 - Authentication Bypass 27 WEB cakes
2019-09-14   Ticket-Booking 1.4 - Authentication Bypass 38 WEB cakes
2019-09-13   LimeSurvey 3.17.13 - Cross-Site Scripting 25 WEB SEC Consult
2019-09-13   phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery 31 WEB Manuel García Cárdenas
2019-09-13   Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting 28 WEB Metin Yunus Kandemir
2019-09-11   eWON Flexy - Authentication Bypass 31 WEB Photubias
2019-09-11   AVCON6 systems management platform - OGNL Remote Command Execution 36 WEB Nassim Asrir
2019-09-10   WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2) 30 WEB MTK
2019-09-10   WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting 27 WEB MTK
2019-09-10   WordPress Plugin Photo Gallery 1.5.34 - SQL Injection 25 WEB MTK
2019-09-09   Dolibarr ERP-CRM 10.0.1 - SQL Injection 26 WEB Metin Yunus Kandemir
2019-09-09   WordPress Plugin Sell Downloads 1.0.86 - Cross-Site Scripting 30 WEB Mr Winst0n
2019-09-09   Rifatron Intelligent Digital Security System - 'animate.cgi' Stream Disclosure 27 WEB LiquidWorm
2019-09-09   Online Appointment - SQL Injection 36 WEB mohammad zaheri
2019-09-09   Enigma NMS 65.0.0 - SQL Injection 28 WEB xerubus
2019-09-09   Enigma NMS 65.0.0 - OS Command Injection 26 WEB xerubus
2019-09-09   Enigma NMS 65.0.0 - Cross-Site Request Forgery 28 WEB xerubus
2019-09-09   Dolibarr ERP-CRM 10.0.1 - 'elemid' SQL Injection 27 WEB Metin Yunus Kandemir
2019-09-09   WordPress Core 5.2.3 - Cross-Site Host Modification 30 WEB Todor Donev
2019-09-06   Publisure Hybrid - Multiple Vulnerabilities 30 WEB Jean-Marie Bourbon
2019-09-06   Inventory Webapp - 'itemquery' SQL injection 35 WEB mohammad zaheri
2019-09-04   DASAN Zhone ZNID GPON 2426A EU - Multiple Cross-Site Scripting 31 WEB Adam Ziaja
2019-09-04   WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting 32 WEB MgThuraMoeMyint
2019-09-03   FileThingie 2.5.7 - Arbitrary File Upload 52 WEB cakes
2019-09-02   Craft CMS 2.7.9/3.2.5 - Information Disclosure 30 WEB Mohammed Abdul Raheem
2019-09-02   Wolters Kluwer TeamMate 3.1 - Cross-Site Request Forgery 34 WEB Bhadresh Patel
2019-09-02   Alkacon OpenCMS 10.5.x - Local File inclusion 39 WEB Aetsu
2019-09-02   Alkacon OpenCMS 10.5.x - Cross-Site Scripting (2) 32 WEB Aetsu
2019-09-02   Alkacon OpenCMS 10.5.x - Cross-Site Scripting 30 WEB Aetsu
2019-09-02   WordPress Plugin Event Tickets 4.10.7.1 - CSV Injection 37 WEB MTK
2019-09-02   Opencart 3.x - Cross-Site Scripting 30 WEB Nipun Somani
2019-09-02   Webmin < 1.920 - 'rpc.cgi' Remote Code Execution (Metasploit) 31 WEB James Bercegay
2019-08-30   WordPress Plugin WooCommerce Product Feed 2.2.18 - Cross-Site Scripting 32 WEB Damian Ebelties
2019-08-30   YouPHPTube 7.4 - Remote Code Execution 35 WEB Damian Ebelties
2019-08-30   DomainMod 4.13 - Cross-Site Scripting 34 WEB Damian Ebelties
2019-08-30   Sentrifugo 3.2 - Persistent Cross-Site Scripting 36 WEB creosote
2019-08-30   Sentrifugo 3.2 - File Upload Restriction Bypass 37 WEB creosote
2019-08-29   PilusCart 1.4.1 - Local File Disclosure 33 WEB Damian Ebelties
2019-08-29   Jobberbase 2.0 - 'subscribe' SQL Injection 36 WEB Damian Ebelties
2018-10-31   WordPress Plugin GoURL.io < 1.4.14 - File Upload 40 WEB Pouya Darabi
2019-08-28   Jobberbase 2.0 CMS - 'jobs-in' SQL Injection 30 WEB Suvadip Kar