|
2019-10-03
|
|
mintinstall 7.9.9 - Code Execution
|
23 |
WEB
|
İbrahim Hakan Şeker
|
|
2019-10-02
|
|
Detrix EDMS 1.2.3.1505 - SQL Injection
|
21 |
WEB
|
Burov Konstantin
|
|
2019-10-01
|
|
DotNetNuke 9.3.2 - Cross-Site Scripting
|
29 |
WEB
|
Semen Alexandrovich Lyhin
|
|
2019-10-01
|
|
DotNetNuke < 9.4.0 - Cross-Site Scripting
|
30 |
WEB
|
MaYaSeVeN
|
|
2019-09-23
|
|
vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution
|
24 |
WEB
|
anonymous
|
|
2019-09-28
|
|
PHP 7.1 < 7.3 - 'json serializer' disable_functions Bypass
|
25 |
WEB
|
mm0r1
|
|
2019-09-30
|
|
WordPress Plugin ARforms 3.7.1 - Arbitrary File Deletion
|
21 |
WEB
|
Ahmad Almorabea
|
|
2019-09-30
|
|
TheSystem 1.0 - Command Injection
|
24 |
WEB
|
Sadik Cetin
|
|
2019-09-30
|
|
thesystem 1.0 - Cross-Site Scripting
|
21 |
WEB
|
Anıl Baran Yelken
|
|
2019-09-30
|
|
phpIPAM 1.4 - SQL Injection
|
22 |
WEB
|
Kevin Kirsche
|
|
2019-09-30
|
|
vBulletin 5.x - Remote Command Execution (Metasploit)
|
22 |
WEB
|
r00tpgp
|
|
2019-09-27
|
|
WordPress Theme Zoner Real Estate - 4.1.1 Persistent Cross-Site Scripting
|
17 |
WEB
|
m0ze
|
|
2019-09-27
|
|
V-SOL GPON/EPON OLT Platform 2.03 - Remote Privilege Escalation
|
21 |
WEB
|
LiquidWorm
|
|
2019-09-27
|
|
V-SOL GPON/EPON OLT Platform 2.03 - Cross-Site Request Forgery
|
26 |
WEB
|
LiquidWorm
|
|
2019-09-27
|
|
V-SOL GPON/EPON OLT Platform 2.03 - Unauthenticated Configuration Download
|
18 |
WEB
|
LiquidWorm
|
|
2019-09-27
|
|
thesystem App 1.0 - 'username' SQL Injection
|
21 |
WEB
|
Anıl Baran Yelken
|
|
2019-09-27
|
|
thesystem App 1.0 - Persistent Cross-Site Scripting
|
21 |
WEB
|
İsmail Güngör
|
|
2019-09-27
|
|
thesystem App 1.0 - 'server_name' SQL Injection
|
27 |
WEB
|
Sadik Cetin
|
|
2019-09-27
|
|
InoERP 0.7.2 - Persistent Cross-Site Scripting
|
26 |
WEB
|
strider
|
|
2019-09-26
|
|
citecodecrashers Pic-A-Point 1.1 - 'Consignment' SQL Injection
|
24 |
WEB
|
cakes
|
|
2019-09-26
|
|
inoERP 4.15 - 'download' SQL Injection
|
32 |
WEB
|
Semen Alexandrovich Lyhin
|
|
2019-09-26
|
|
all-in-one-seo-pack 3.2.7 - Persistent Cross-Site Scripting
|
24 |
WEB
|
Unk9vvN
|
|
2019-09-26
|
|
Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting
|
24 |
WEB
|
Unk9vvN
|
|
2019-09-26
|
|
Chamillo LMS 1.11.8 - Arbitrary File Upload
|
32 |
WEB
|
Sohel Yousef
|
|
2019-09-25
|
|
YzmCMS 5.3 - 'Host' Header Injection
|
27 |
WEB
|
Debashis Pal
|
|
2019-09-25
|
|
NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution
|
20 |
WEB
|
Semen Alexandrovich Lyhin
|
|
2019-09-25
|
|
WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting
|
28 |
WEB
|
strider
|
|
2019-09-25
|
|
Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting
|
24 |
WEB
|
Davide Cioccia
|
|
2019-09-24
|
|
Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
|
28 |
WEB
|
Nassim Asrir
|
|
2019-09-23
|
|
Gila CMS < 1.11.1 - Local File Inclusion
|
27 |
WEB
|
Sainadh Jamalpur
|
|
2019-09-20
|
|
LayerBB < 1.1.4 - Cross-Site Request Forgery
|
22 |
WEB
|
0xB9
|
|
2019-09-19
|
|
GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting
|
26 |
WEB
|
cakes
|
|
2019-09-19
|
|
DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection
|
26 |
WEB
|
n1x_
|
|
2019-09-19
|
|
Western Digital My Book World II NAS 1.02.12 - Authentication Bypass / Command Execution
|
21 |
WEB
|
Noman Riffat
|
|
2019-09-18
|
|
Hospital-Management 1.26 - 'fname' SQL Injection
|
26 |
WEB
|
cakes
|
|
2019-09-16
|
|
CollegeManagementSystem-CMS 1.3 - 'batch' SQL Injection
|
29 |
WEB
|
cakes
|
|
2019-09-16
|
|
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
|
28 |
WEB
|
Pankaj Kumar Thakur
|
|
2019-09-16
|
|
NetGain EM Plus 10.1.68 - Remote Command Execution
|
30 |
WEB
|
azams
|
|
2019-09-14
|
|
College-Management-System 1.2 - Authentication Bypass
|
22 |
WEB
|
cakes
|
|
2019-09-14
|
|
Ticket-Booking 1.4 - Authentication Bypass
|
30 |
WEB
|
cakes
|
|
2019-09-13
|
|
LimeSurvey 3.17.13 - Cross-Site Scripting
|
22 |
WEB
|
SEC Consult
|
|
2019-09-13
|
|
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
|
27 |
WEB
|
Manuel García Cárdenas
|
|
2019-09-13
|
|
Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
|
25 |
WEB
|
Metin Yunus Kandemir
|
|
2019-09-11
|
|
eWON Flexy - Authentication Bypass
|
26 |
WEB
|
Photubias
|
|
2019-09-11
|
|
AVCON6 systems management platform - OGNL Remote Command Execution
|
33 |
WEB
|
Nassim Asrir
|
|
2019-09-10
|
|
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2)
|
26 |
WEB
|
MTK
|
|
2019-09-10
|
|
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting
|
23 |
WEB
|
MTK
|
|
2019-09-10
|
|
WordPress Plugin Photo Gallery 1.5.34 - SQL Injection
|
20 |
WEB
|
MTK
|
|
2019-09-09
|
|
Dolibarr ERP-CRM 10.0.1 - SQL Injection
|
20 |
WEB
|
Metin Yunus Kandemir
|
|
2019-09-09
|
|
WordPress Plugin Sell Downloads 1.0.86 - Cross-Site Scripting
|
24 |
WEB
|
Mr Winst0n
|
|
2019-09-09
|
|
Rifatron Intelligent Digital Security System - 'animate.cgi' Stream Disclosure
|
21 |
WEB
|
LiquidWorm
|
|
2019-09-09
|
|
Online Appointment - SQL Injection
|
27 |
WEB
|
mohammad zaheri
|
|
2019-09-09
|
|
Enigma NMS 65.0.0 - SQL Injection
|
24 |
WEB
|
xerubus
|
|
2019-09-09
|
|
Enigma NMS 65.0.0 - OS Command Injection
|
21 |
WEB
|
xerubus
|
|
2019-09-09
|
|
Enigma NMS 65.0.0 - Cross-Site Request Forgery
|
22 |
WEB
|
xerubus
|
|
2019-09-09
|
|
Dolibarr ERP-CRM 10.0.1 - 'elemid' SQL Injection
|
22 |
WEB
|
Metin Yunus Kandemir
|
|
2019-09-09
|
|
WordPress Core 5.2.3 - Cross-Site Host Modification
|
26 |
WEB
|
Todor Donev
|
|
2019-09-06
|
|
Publisure Hybrid - Multiple Vulnerabilities
|
26 |
WEB
|
Jean-Marie Bourbon
|
|
2019-09-06
|
|
Inventory Webapp - 'itemquery' SQL injection
|
28 |
WEB
|
mohammad zaheri
|
|
2019-09-04
|
|
DASAN Zhone ZNID GPON 2426A EU - Multiple Cross-Site Scripting
|
27 |
WEB
|
Adam Ziaja
|
|
2019-09-04
|
|
WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting
|
28 |
WEB
|
MgThuraMoeMyint
|
|
2019-09-03
|
|
FileThingie 2.5.7 - Arbitrary File Upload
|
47 |
WEB
|
cakes
|
|
2019-09-02
|
|
Craft CMS 2.7.9/3.2.5 - Information Disclosure
|
25 |
WEB
|
Mohammed Abdul Raheem
|
|
2019-09-02
|
|
Wolters Kluwer TeamMate 3.1 - Cross-Site Request Forgery
|
29 |
WEB
|
Bhadresh Patel
|
|
2019-09-02
|
|
Alkacon OpenCMS 10.5.x - Local File inclusion
|
35 |
WEB
|
Aetsu
|
|
2019-09-02
|
|
Alkacon OpenCMS 10.5.x - Cross-Site Scripting (2)
|
26 |
WEB
|
Aetsu
|
|
2019-09-02
|
|
Alkacon OpenCMS 10.5.x - Cross-Site Scripting
|
25 |
WEB
|
Aetsu
|
|
2019-09-02
|
|
WordPress Plugin Event Tickets 4.10.7.1 - CSV Injection
|
31 |
WEB
|
MTK
|
|
2019-09-02
|
|
Opencart 3.x - Cross-Site Scripting
|
26 |
WEB
|
Nipun Somani
|
|
2019-09-02
|
|
Webmin < 1.920 - 'rpc.cgi' Remote Code Execution (Metasploit)
|
27 |
WEB
|
James Bercegay
|
|
2019-08-30
|
|
WordPress Plugin WooCommerce Product Feed 2.2.18 - Cross-Site Scripting
|
25 |
WEB
|
Damian Ebelties
|
|
2019-08-30
|
|
YouPHPTube 7.4 - Remote Code Execution
|
32 |
WEB
|
Damian Ebelties
|
|
2019-08-30
|
|
DomainMod 4.13 - Cross-Site Scripting
|
29 |
WEB
|
Damian Ebelties
|
|
2019-08-30
|
|
Sentrifugo 3.2 - Persistent Cross-Site Scripting
|
33 |
WEB
|
creosote
|
|
2019-08-30
|
|
Sentrifugo 3.2 - File Upload Restriction Bypass
|
34 |
WEB
|
creosote
|
|
2019-08-29
|
|
PilusCart 1.4.1 - Local File Disclosure
|
28 |
WEB
|
Damian Ebelties
|
|
2019-08-29
|
|
Jobberbase 2.0 - 'subscribe' SQL Injection
|
30 |
WEB
|
Damian Ebelties
|
|
2018-10-31
|
|
WordPress Plugin GoURL.io < 1.4.14 - File Upload
|
36 |
WEB
|
Pouya Darabi
|
|
2019-08-28
|
|
Jobberbase 2.0 CMS - 'jobs-in' SQL Injection
|
27 |
WEB
|
Suvadip Kar
|
|
2019-08-28
|
|
SQLiteManager 1.2.0 / 1.2.4 - Blind SQL Injection
|
28 |
WEB
|
Rafael Pedrero
|
|
2019-08-27
|
|
Tableau - XML External Entity
|
26 |
WEB
|
Jarad Kopf
|
|
2019-08-26
|
|
openITCOCKPIT 3.6.1-2 - Cross-Site Request Forgery
|
27 |
WEB
|
Julian Rittweger
|
|
2019-08-26
|
|
WordPress Plugin UserPro 4.9.32 - Cross-Site Scripting
|
24 |
WEB
|
Damian Ebelties
|
|
2019-08-26
|
|
WordPress Plugin Import Export WordPress Users 1.3.1 - CSV Injection
|
22 |
WEB
|
Javier Olmedo
|
|
2019-08-26
|
|
LSoft ListServ < 16.5-2018a - Cross-Site Scripting
|
24 |
WEB
|
MTK
|
|
2019-08-23
|
|
Nimble Streamer 3.0.2-2 < 3.5.4-9 - Directory Traversal
|
23 |
WEB
|
MaYaSeVeN
|
|
2019-08-21
|
|
Nagios XI 5.6.5 - Remote Code Execution / Root Privilege Escalation
|
26 |
WEB
|
Jak Gibb
|
|
2019-08-21
|
|
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure (Metasploit)
|
23 |
WEB
|
Alyssa Herrera
|
|
2019-08-20
|
|
WordPress Plugin Add Mime Types 2.2.1 - Cross-Site Request Forgery
|
30 |
WEB
|
Princy Edward
|
|
2019-08-19
|
|
YouPHPTube 7.2 - 'userCreate.json.php' SQL Injection
|
30 |
WEB
|
Fabian Mosch
|
|
2019-08-19
|
|
Webmin 1.920 - Remote Code Execution
|
24 |
WEB
|
Fernando A. Lagos B
|
|
2019-08-19
|
|
Neo Billing 3.5 - Persistent Cross-Site Scripting
|
33 |
WEB
|
n1x_
|
|
2019-08-19
|
|
Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure
|
29 |
WEB
|
Carlos E. Vieira
|
|
2019-08-19
|
|
Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Metasploit)
|
29 |
WEB
|
Carlos E. Vieira
|
|
2019-08-19
|
|
Kimai 2 - Persistent Cross-Site Scripting
|
24 |
WEB
|
osamaalaa
|
|
2019-08-16
|
|
Web Wiz Forums 12.01 - 'PF' SQL Injection
|
31 |
WEB
|
n1x_
|
|
2019-08-16
|
|
Integria IMS 5.0.86 - Arbitrary File Upload
|
27 |
WEB
|
Greg.Priest
|
|
2019-08-16
|
|
Joomla! component com_jsjobs 1.2.6 - Arbitrary File Deletion
|
33 |
WEB
|
qw3rTyTy
|
|
2019-08-16
|
|
EyesOfNetwork 5.1 - Authenticated Remote Command Execution
|
21 |
WEB
|
Nassim Asrir
|
|
2019-08-14
|
|
ManageEngine opManager 12.3.150 - Authenticated Code Execution
|
29 |
WEB
|
kindredsec
|
|
2019-08-14
|
|
TortoiseSVN 1.12.1 - Remote Code Execution
|
23 |
WEB
|
Vulnerability-Lab
|
|
2019-08-14
|
|
WordPress Plugin Download Manager 2.5 - Cross-Site Request Forgery
|
27 |
WEB
|
Princy Edward
|
|
2019-08-14
|
|
D-Link DIR-600M - Authentication Bypass (Metasploit)
|
18 |
WEB
|
Devendra Singh Solanki
|
|
2019-08-14
|
|
D-Link DIR-600M - Authentication Bypass (Metasploit)
|
19 |
WEB
|
Devendra Singh Solanki
|
|
2019-08-14
|
|
Joomla! Component JS Jobs (com_jsjobs) 1.2.5 - 'customfields.php' SQL Injection
|
25 |
WEB
|
qw3rTyTy
|
|
2019-08-14
|
|
SugarCRM Enterprise 9.0.0 - Cross-Site Scripting
|
31 |
WEB
|
Ilca Lucian Florin
|
|
2019-08-12
|
|
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated OS Command Injection Bind Shell
|
30 |
WEB
|
xerubus
|
|
2019-08-12
|
|
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated Configuration Download
|
26 |
WEB
|
xerubus
|
|
2019-08-12
|
|
Joomla! Component JS Jobs (com_jsjobs) 1.2.5 - 'cities.php' SQL Injection
|
27 |
WEB
|
qw3rTyTy
|
|
2019-08-12
|
|
osTicket 1.12 - Persistent Cross-Site Scripting
|
27 |
WEB
|
Aishwarya Iyer
|
|
2019-08-12
|
|
osTicket 1.12 - Formula Injection
|
27 |
WEB
|
Aishwarya Iyer
|
|
2019-08-12
|
|
osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
|
24 |
WEB
|
Aishwarya Iyer
|
|
2019-08-12
|
|
Joomla! Component JS Support Ticket (com_jssupportticket) 1.1.6 - 'ticket.php' Arbitrary File Deleti
|
20 |
WEB
|
qw3rTyTy
|
|
2019-08-12
|
|
Joomla! Component JS Support Ticket (com_jssupportticket) 1.1.6 - 'ticketreply.php' SQL Injection
|
18 |
WEB
|
qw3rTyTy
|
|
2019-08-12
|
|
UNA 10.0.0 RC1 - 'polyglot.php' Persistent Cross-Site Scripting
|
17 |
WEB
|
Greg.Priest
|
|
2019-08-12
|
|
Cisco Adaptive Security Appliance - Path Traversal (Metasploit)
|
16 |
WEB
|
Angelo Ruwantha
|
|
2019-08-12
|
|
BSI Advance Hotel Booking System 2.0 - 'booking_details.php Persistent Cross-Site Scripting
|
21 |
WEB
|
Angelo Ruwantha
|
|
2019-08-08
|
|
Joomla! Component JS Support Ticket (component com_jssupportticket) 1.1.5 - SQL Injection
|
24 |
WEB
|
qw3rTyTy
|
|
2019-08-08
|
|
Adive Framework 2.0.7 - Cross-Site Request Forgery
|
25 |
WEB
|
Pablo Santiago
|
|
2019-08-08
|
|
Joomla! Component JS Support Ticket (component com_jssupportticket) 1.1.5 - Arbitrary File Download
|
25 |
WEB
|
qw3rTyTy
|
|
2019-08-08
|
|
Aptana Jaxer 1.0.3.4547 - Local File inclusion
|
27 |
WEB
|
Steph Jensen
|
|
2019-08-08
|
|
Daily Expense Manager 1.0 - Cross-Site Request Forgery (Delete Income)
|
27 |
WEB
|
Mr Winst0n
|
|
2019-08-08
|
|
Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting
|
25 |
WEB
|
Greg.Priest
|
|
2019-08-07
|
|
WordPress Plugin JoomSport 3.3 - SQL Injection
|
25 |
WEB
|
Pablo Santiago
|
|
2019-08-02
|
|
1CRM On-Premise Software 8.5.7 - Persistent Cross-Site Scripting
|
27 |
WEB
|
Kusol Watchara-Apanukorn
|