|
2019-07-17
|
|
Oracle Siebel CRM 19.0 - Persistent Cross-Site Scripting
|
13 |
WEB
|
Sarath Nair
|
|
2019-07-16
|
|
CentOS Control Web Panel 0.9.8.838 - User Enumeration
|
12 |
WEB
|
Pongtorn Angsuchotmetee_ Nissana Sirijirakal_ Nari
|
|
2019-07-16
|
|
CentOS Control Web Panel 0.9.8.836 - Privilege Escalation
|
11 |
WEB
|
Pongtorn Angsuchotmetee_ Nissana Sirijirakal_ Nari
|
|
2019-07-16
|
|
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
|
9 |
WEB
|
Pongtorn Angsuchotmetee
|
|
2019-07-15
|
|
FlightPath < 4.8.2 / < 5.0-rc2 - Local File Inclusion
|
9 |
WEB
|
Mohammed Althibyani
|
|
2019-07-15
|
|
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities
|
10 |
WEB
|
Ramikan
|
|
2019-07-15
|
|
Netgear WiFi Router JWNR2010v5 / R6080 - Authentication Bypass
|
14 |
WEB
|
Wadeek
|
|
2019-07-12
|
|
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
|
13 |
WEB
|
Chris Lyne
|
|
2019-07-12
|
|
Jenkins Dependency Graph View Plugin 0.13 - Persistent Cross-Site Scripting
|
13 |
WEB
|
Ishaq Mohammed
|
|
2019-07-12
|
|
Sahi Pro 8.0.0 - Remote Command Execution
|
15 |
WEB
|
AkkuS
|
|
2019-07-12
|
|
MyT Project Management 1.5.1 - User[username] Persistent Cross-Site Scripting
|
13 |
WEB
|
Metin Yunus Kandemir
|
|
2019-07-12
|
|
Tenda D301 v2 Modem Router - Persistent Cross-Site Scripting
|
13 |
WEB
|
ABDO10
|
|
2019-07-11
|
|
Sitecore 9.0 rev 171002 - Persistent Cross-Site Scripting
|
13 |
WEB
|
Owais Mehtab
|
|
2019-07-08
|
|
WordPress Plugin Like Button 1.6.0 - Authentication Bypass
|
16 |
WEB
|
Benjamin Lim
|
|
2019-07-08
|
|
Karenderia Multiple Restaurant System 5.3 - SQL Injection
|
12 |
WEB
|
Mehmet EMIROGLU
|
|
2019-07-05
|
|
Karenderia Multiple Restaurant System 5.3 - Local File Inclusion
|
11 |
WEB
|
Mehmet EMIROGLU
|
|
2019-07-03
|
|
Symantec DLP 15.5 MP1 - Cross-Site Scripting
|
13 |
WEB
|
Chapman Schleiss
|
|
2019-07-02
|
|
Centreon 19.04 - Remote Code Execution
|
13 |
WEB
|
Askar
|
|
2019-07-01
|
|
FaceSentry Access Control System 6.4.8 - Remote Root Exploit
|
13 |
WEB
|
LiquidWorm
|
|
2019-07-01
|
|
FaceSentry Access Control System 6.4.8 - Cross-Site Request Forgery
|
11 |
WEB
|
LiquidWorm
|
|
2019-07-01
|
|
FaceSentry Access Control System 6.4.8 - Remote Command Injection
|
10 |
WEB
|
LiquidWorm
|
|
2019-07-01
|
|
CyberPanel 1.8.4 - Cross-Site Request Forgery
|
10 |
WEB
|
Bilgi Birikim Sistemleri
|
|
2019-07-01
|
|
Sahi pro 8.x - Directory Traversal
|
9 |
WEB
|
Operat0r
|
|
2019-07-01
|
|
SAP Crystal Reports - Information Disclosure
|
9 |
WEB
|
Mohamed M.Fouad
|
|
2019-07-01
|
|
ZoneMinder 1.32.3 - Cross-Site Scripting
|
11 |
WEB
|
Joey Lane
|
|
2019-07-01
|
|
PowerPanel Business Edition - Cross-Site Scripting
|
11 |
WEB
|
Joey Lane
|
|
2019-07-01
|
|
Varient 1.6.1 - SQL Injection
|
11 |
WEB
|
Mehmet EMIROGLU
|
|
2019-07-01
|
|
CiuisCRM 1.6 - 'eventType' SQL Injection
|
15 |
WEB
|
Mehmet EMIROGLU
|
|
2019-07-01
|
|
WorkSuite PRM 2.4 - 'password' SQL Injection
|
14 |
WEB
|
Mehmet EMIROGLU
|
|
2019-06-28
|
|
LibreNMS 1.46 - 'addhost' Remote Code Execution
|
12 |
WEB
|
Askar
|
|
2019-06-25
|
|
WordPress Plugin Live Chat Unlimited 2.8.3 - Cross-Site Scripting
|
11 |
WEB
|
m0ze
|
|
2019-06-25
|
|
WordPress Plugin iLive 1.0.4 - Cross-Site Scripting
|
12 |
WEB
|
m0ze
|
|
2019-06-25
|
|
BlogEngine.NET 3.3.6/3.3.7 - 'path' Directory Traversal
|
13 |
WEB
|
Aaron Bishop
|
|
2019-06-25
|
|
AZADMIN CMS 1.0 - SQL Injection
|
12 |
WEB
|
felipe andrian
|
|
2019-06-25
|
|
Fortinet FCM-MB40 - Cross-Site Request Forgery / Remote Command Execution
|
11 |
WEB
|
XORcat
|
|
2019-06-24
|
|
GrandNode 4.40 - Path Traversal / Arbitrary File Download
|
11 |
WEB
|
Corey Robinson
|
|
2019-06-24
|
|
SeedDMS < 5.1.11 - 'out.GroupMgr.php' Cross-Site Scripting
|
15 |
WEB
|
Nimit Jain
|
|
2019-06-24
|
|
SeedDMS < 5.1.11 - 'out.UsrMgr.php' Cross-Site Scripting
|
12 |
WEB
|
Nimit Jain
|
|
2019-06-24
|
|
SeedDMS versions < 5.1.11 - Remote Command Execution
|
13 |
WEB
|
Nimit Jain
|
|
2019-06-24
|
|
dotProject 2.1.9 - SQL Injection
|
12 |
WEB
|
Metin Yunus Kandemir
|
|
2019-06-20
|
|
BlogEngine.NET 3.3.6/3.3.7 - XML External Entity Injection
|
12 |
WEB
|
Aaron Bishop
|
|
2019-06-20
|
|
WebERP 4.15 - SQL injection
|
12 |
WEB
|
Semen Alexandrovich Lyhin
|
|
2019-06-19
|
|
BlogEngine.NET 3.3.6/3.3.7 - 'theme Cookie' Directory Traversal / Remote Code Execution
|
12 |
WEB
|
Aaron Bishop
|
|
2019-06-19
|
|
BlogEngine.NET 3.3.6/3.3.7 - 'dirPath' Directory Traversal / Remote Code Execution
|
12 |
WEB
|
Aaron Bishop
|
|
2019-06-18
|
|
Sahi pro 8.x - Cross-Site Scripting
|
13 |
WEB
|
Goutham Madhwaraj
|
|
2019-06-18
|
|
Sahi pro 8.x - SQL Injection
|
13 |
WEB
|
Goutham Madhwaraj
|
|
2019-06-18
|
|
Sahi pro 7.x/8.x - Directory Traversal
|
11 |
WEB
|
Goutham Madhwaraj
|
|
2019-06-17
|
|
Spring Security OAuth - Open Redirector
|
15 |
WEB
|
Riemann
|
|
2019-06-17
|
|
CleverDog Smart Camera DOG-2W / DOG-2W-V4 - Multiple Vulnerabilities
|
12 |
WEB
|
Alex Akinbi
|
|
2019-06-17
|
|
RedwoodHQ 2.5.5 - Authentication Bypass
|
14 |
WEB
|
EthicalHCOP
|
|
2019-06-13
|
|
Sitecore 8.x - Deserialization Remote Code Execution
|
11 |
WEB
|
Jarad Kopf
|
|
2019-06-12
|
|
FusionPBX 4.4.3 - Remote Command Execution
|
11 |
WEB
|
Dustin Cobb
|
|
2019-06-11
|
|
Liferay Portal 7.1 CE GA=3 / SimpleCaptcha API - Cross-Site Scripting
|
12 |
WEB
|
Valerio Brussani
|
|
2019-06-11
|
|
phpMyAdmin 4.8 - Cross-Site Request Forgery
|
13 |
WEB
|
Riemann
|
|
2019-06-11
|
|
WordPress Plugin Insert or Embed Articulate Content into WordPress - Remote Code Execution
|
14 |
WEB
|
xulchibalraa
|
|
2019-06-10
|
|
UliCMS 2019.1 'Spitting Lama' - Persistent Cross-Site Scripting
|
13 |
WEB
|
Unk9vvN
|
|
2019-06-06
|
|
Supra Smart Cloud TV - 'openLiveURL()' Remote File Inclusion
|
15 |
WEB
|
Dhiraj Mishra
|
|
2019-06-05
|
|
Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery
|
10 |
WEB
|
k8gege
|
|
2019-06-05
|
|
Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery
|
9 |
WEB
|
k8gege
|
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'PurchaseRequest.do' Cross-Site Scripting
|
8 |
WEB
|
Vingroup
|
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SearchN.do' Cross-Site Scripting
|
10 |
WEB
|
Vingroup
|
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SolutionSearch.do' Cross-Site Scripting
|
9 |
WEB
|
Vingroup
|
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SiteLookup.do' Cross-Site Scripting
|
8 |
WEB
|
Vingroup
|
|
2019-06-04
|
|
IceWarp 10.4.4 - Local File Inclusion
|
16 |
WEB
|
JameelNabbo
|
|
2019-06-03
|
|
WordPress Plugin Form Maker 1.13.3 - SQL Injection
|
10 |
WEB
|
Daniele Scanu
|
|
2019-06-03
|
|
AUO Solar Data Recorder < 1.3.0 - Incorrect Access Control
|
11 |
WEB
|
Luca.Chiou
|
|
2019-06-03
|
|
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
|
9 |
WEB
|
SlidingWindow
|
|
2019-05-29
|
|
pfSense 2.4.4-p3 (ACME Package 0.59_14) - Persistent Cross-Site Scripting
|
11 |
WEB
|
Chi Tran
|
|
2019-05-28
|
|
Phraseanet < 4.0.7 - Cross-Site Scripting
|
12 |
WEB
|
Krzysztof Szulski
|
|
2019-05-27
|
|
Deltek Maconomy 2.2.5 - Local File Inclusion
|
12 |
WEB
|
JameelNabbo
|
|
2019-05-23
|
|
Nagios XI 5.6.1 - SQL injection
|
13 |
WEB
|
JameelNabbo
|
|
2019-05-22
|
|
Horde Webmail 5.2.22 - Multiple Vulnerabilities
|
11 |
WEB
|
InfinitumIT
|
|
2019-05-22
|
|
Carel pCOWeb < B1.2.1 - Credentials Disclosure
|
9 |
WEB
|
Luca.Chiou
|
|
2019-05-22
|
|
Carel pCOWeb < B1.2.1 - Cross-Site Scripting
|
8 |
WEB
|
Luca.Chiou
|
|
2019-05-22
|
|
AUO Solar Data Recorder < 1.3.0 - 'addr' Cross-Site Scripting
|
9 |
WEB
|
Luca.Chiou
|
|
2019-05-22
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - Cross-Site Scripting
|
6 |
WEB
|
Vingroup
|
|
2019-05-22
|
|
Zoho ManageEngine ServiceDesk Plus < 10.5 - Improper Access Restrictions
|
9 |
WEB
|
Vingroup
|
|
2019-05-21
|
|
Brocade Network Advisor 14.4.1 - Unauthenticated Remote Code Execution
|
9 |
WEB
|
Jakub Palaczynski
|
|
2019-05-21
|
|
WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities
|
9 |
WEB
|
Simone Quatrini
|
|
2019-05-21
|
|
Oracle CTI Web Service - 'EBS_ASSET_HISTORY_OPERATIONS' XML Entity Injection
|
7 |
WEB
|
omurugur
|
|
2019-05-21
|
|
TP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting
|
9 |
WEB
|
purnendu ghosh
|
|
2019-05-21
|
|
Moodle Jmol Filter 6.1 - Directory Traversal / Cross-Site Scripting
|
12 |
WEB
|
Dionach Ltd
|
|
2019-05-21
|
|
Moodle Jmol Filter 6.1 - Directory Traversal / Cross-Site Scripting
|
12 |
WEB
|
Dionach Ltd
|
|
2019-05-20
|
|
eLabFTW 1.8.5 - Arbitrary File Upload / Remote Code Execution
|
11 |
WEB
|
liquidsky
|
|
2019-05-17
|
|
Interspire Email Marketer 6.20 - 'surveys_submit.php' Remote Code Execution
|
11 |
WEB
|
numan türle
|
|
2019-05-16
|
|
DeepSound 1.0.4 - SQL Injection
|
12 |
WEB
|
Mehmet EMIROGLU
|
|
2019-05-15
|
|
Legrand BTicino Driver Manager F454 1.0.51 - Cross-Site Request Forgery / Cross-Site Scripting
|
11 |
WEB
|
LiquidWorm
|
|
2019-05-15
|
|
Legrand BTicino Driver Manager F454 1.0.51 - Cross-Site Request Forgery / Cross-Site Scripting
|
12 |
WEB
|
LiquidWorm
|
|
2019-05-15
|
|
CommSy 8.6.5 - SQL injection
|
11 |
WEB
|
Jens Regel
|
|
2019-05-14
|
|
PasteShr 1.6 - Multiple SQL Injection
|
10 |
WEB
|
Mehmet EMIROGLU
|
|
2019-05-14
|
|
Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Comm
|
9 |
WEB
|
Julien Ahrens
|
|
2019-05-14
|
|
D-Link DWL-2600AP - Multiple OS Command Injection
|
12 |
WEB
|
Raki Ben Hamouda
|
|
2019-05-14
|
|
Sales ERP 8.1 - Multiple SQL Injection
|
12 |
WEB
|
Mehmet EMIROGLU
|
|
2019-05-13
|
|
OpenProject 5.0.0 - 8.3.1 - SQL Injection
|
12 |
WEB
|
SEC Consult
|
|
2019-05-13
|
|
XOOPS 2.5.9 - SQL Injection
|
11 |
WEB
|
felipe andrian
|
|
2019-05-13
|
|
SOCA Access Control System 180612 - Cross-Site Request Forgery (Add Admin)
|
12 |
WEB
|
LiquidWorm
|
|
2019-05-13
|
|
SOCA Access Control System 180612 - SQL Injection
|
11 |
WEB
|
LiquidWorm
|
|
2019-05-13
|
|
SOCA Access Control System 180612 - Information Disclosure
|
14 |
WEB
|
LiquidWorm
|
|
2019-05-10
|
|
CyberArk Enterprise Password Vault 10.7 - XML External Entity Injection
|
12 |
WEB
|
Marcelo Toran
|
|
2019-05-10
|
|
RICOH SP 4520DN Printer - HTML Injection
|
12 |
WEB
|
Ismail Tasdelen
|
|
2019-05-10
|
|
RICOH SP 4510DN Printer - HTML Injection
|
11 |
WEB
|
Ismail Tasdelen
|
|
2019-05-10
|
|
dotCMS 5.1.1 - HTML Injection
|
10 |
WEB
|
Ismail Tasdelen
|
|
2019-05-10
|
|
Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
|
18 |
WEB
|
Alexandre Basquin
|
|
2019-05-09
|
|
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting
|
11 |
WEB
|
Ibrahim Raafat
|
|
2019-05-08
|
|
NetNumber Titan ENUM/DNS/NP 7.9.1 - Path Traversal / Authorization Bypass
|
12 |
WEB
|
MobileNetworkSecurity
|
|
2019-05-07
|
|
Prinect Archive System 2015 Release 2.6 - Cross-Site Scripting
|
13 |
WEB
|
alt3kx
|
|
2019-05-06
|
|
microASP (Portal+) CMS - 'pagina.phtml?explode_tree' SQL Injection
|
14 |
WEB
|
felipe andrian
|
|
2019-05-06
|
|
PHPads 2.0 - 'click.php3?bannerID' SQL Injection
|
14 |
WEB
|
felipe andrian
|
|
2019-05-06
|
|
ReadyAPI 2.5.0 / 2.6.0 - Remote Code Execution
|
16 |
WEB
|
Gilson Camelo
|
|
2019-05-03
|
|
WordPress Plugin Social Warfare < 3.5.3 - Remote Code Execution
|
15 |
WEB
|
hash3liZer
|
|
2019-05-03
|
|
Zotonic < 0.47.0 mod_admin - Cross-Site Scripting
|
11 |
WEB
|
Ramòn Janssen
|
|
2019-05-03
|
|
Instagram Auto Follow - Authentication Bypass
|
13 |
WEB
|
Veyselxan
|
|
2019-05-03
|
|
Crestron AM/Barco wePresent WiPG/Extron ShareLink/Teq AV IT/SHARP PN-L703WA/Optoma WPS-Pro/Blackbox
|
14 |
WEB
|
Jacob Baines
|
|
2019-05-01
|
|
CentOS Web Panel 0.9.8.793 (Free) / v0.9.8.753 (Pro) / 0.9.8.807 (Pro) - Domain Field (Add DNS Zone)
|
11 |
WEB
|
DKM
|
|
2019-04-30
|
|
Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 - Remote Code Execution
|
13 |
WEB
|
Avinash Kumar Thapa
|
|
2019-04-30
|
|
Agent Tesla Botnet - Information Disclosure
|
8 |
WEB
|
n4pst3r
|
|
2019-04-30
|
|
Hyvikk Fleet Manager - Shell Upload
|
8 |
WEB
|
saxgy1331
|
|
2019-04-30
|
|
Joomla! Component JiFile 2.3.1 - Arbitrary File Download
|
9 |
WEB
|
Mr Winst0n
|
|
2019-04-30
|
|
Domoticz 4.10577 - Unauthenticated Remote Command Execution
|
7 |
WEB
|
Fabio Carretto
|
|
2019-04-30
|
|
Spring Cloud Config 2.1.x - Path Traversal (Metasploit)
|
6 |
WEB
|
Dhiraj Mishra
|
|
2019-04-30
|
|
Spring Cloud Config 2.1.x - Path Traversal (Metasploit)
|
7 |
WEB
|
Dhiraj Mishra
|
|
2019-04-30
|
|
HumHub 1.3.12 - Cross-Site Scripting
|
9 |
WEB
|
Kağan EĞLENCE
|
|
2019-04-30
|
|
Intelbras IWR 3000N 1.5.0 - Cross-Site Request Forgery
|
7 |
WEB
|
Social Engineering Neo
|
|
2019-04-30
|
|
Joomla! Component ARI Quiz 3.7.4 - SQL Injection
|
6 |
WEB
|
Mr Winst0n
|
|
2019-04-30
|
|
Veeam ONE Reporter 9.5.0.3201 - Persistent Cross-site Scripting (Add/Edit Widget)
|
7 |
WEB
|
Seyed Sadegh Khatami
|