|
2019-08-16
|
|
Web Wiz Forums 12.01 - 'PF' SQL Injection
|
31 |
WEB
|
n1x_
|
|
2019-08-16
|
|
Integria IMS 5.0.86 - Arbitrary File Upload
|
27 |
WEB
|
Greg.Priest
|
|
2019-08-16
|
|
Joomla! component com_jsjobs 1.2.6 - Arbitrary File Deletion
|
34 |
WEB
|
qw3rTyTy
|
|
2019-08-16
|
|
EyesOfNetwork 5.1 - Authenticated Remote Command Execution
|
23 |
WEB
|
Nassim Asrir
|
|
2019-08-14
|
|
ManageEngine opManager 12.3.150 - Authenticated Code Execution
|
29 |
WEB
|
kindredsec
|
|
2019-08-14
|
|
TortoiseSVN 1.12.1 - Remote Code Execution
|
25 |
WEB
|
Vulnerability-Lab
|
|
2019-08-14
|
|
WordPress Plugin Download Manager 2.5 - Cross-Site Request Forgery
|
27 |
WEB
|
Princy Edward
|
|
2019-08-14
|
|
D-Link DIR-600M - Authentication Bypass (Metasploit)
|
20 |
WEB
|
Devendra Singh Solanki
|
|
2019-08-14
|
|
D-Link DIR-600M - Authentication Bypass (Metasploit)
|
20 |
WEB
|
Devendra Singh Solanki
|
|
2019-08-14
|
|
Joomla! Component JS Jobs (com_jsjobs) 1.2.5 - 'customfields.php' SQL Injection
|
26 |
WEB
|
qw3rTyTy
|
|
2019-08-14
|
|
SugarCRM Enterprise 9.0.0 - Cross-Site Scripting
|
33 |
WEB
|
Ilca Lucian Florin
|
|
2019-08-12
|
|
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated OS Command Injection Bind Shell
|
31 |
WEB
|
xerubus
|
|
2019-08-12
|
|
Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated Configuration Download
|
32 |
WEB
|
xerubus
|
|
2019-08-12
|
|
Joomla! Component JS Jobs (com_jsjobs) 1.2.5 - 'cities.php' SQL Injection
|
27 |
WEB
|
qw3rTyTy
|
|
2019-08-12
|
|
osTicket 1.12 - Persistent Cross-Site Scripting
|
28 |
WEB
|
Aishwarya Iyer
|
|
2019-08-12
|
|
osTicket 1.12 - Formula Injection
|
29 |
WEB
|
Aishwarya Iyer
|
|
2019-08-12
|
|
osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
|
24 |
WEB
|
Aishwarya Iyer
|
|
2019-08-12
|
|
Joomla! Component JS Support Ticket (com_jssupportticket) 1.1.6 - 'ticket.php' Arbitrary File Deleti
|
22 |
WEB
|
qw3rTyTy
|
|
2019-08-12
|
|
Joomla! Component JS Support Ticket (com_jssupportticket) 1.1.6 - 'ticketreply.php' SQL Injection
|
21 |
WEB
|
qw3rTyTy
|
|
2019-08-12
|
|
UNA 10.0.0 RC1 - 'polyglot.php' Persistent Cross-Site Scripting
|
20 |
WEB
|
Greg.Priest
|
|
2019-08-12
|
|
Cisco Adaptive Security Appliance - Path Traversal (Metasploit)
|
18 |
WEB
|
Angelo Ruwantha
|
|
2019-08-12
|
|
BSI Advance Hotel Booking System 2.0 - 'booking_details.php Persistent Cross-Site Scripting
|
24 |
WEB
|
Angelo Ruwantha
|
|
2019-08-08
|
|
Joomla! Component JS Support Ticket (component com_jssupportticket) 1.1.5 - SQL Injection
|
25 |
WEB
|
qw3rTyTy
|
|
2019-08-08
|
|
Adive Framework 2.0.7 - Cross-Site Request Forgery
|
28 |
WEB
|
Pablo Santiago
|
|
2019-08-08
|
|
Joomla! Component JS Support Ticket (component com_jssupportticket) 1.1.5 - Arbitrary File Download
|
25 |
WEB
|
qw3rTyTy
|
|
2019-08-08
|
|
Aptana Jaxer 1.0.3.4547 - Local File inclusion
|
29 |
WEB
|
Steph Jensen
|
|
2019-08-08
|
|
Daily Expense Manager 1.0 - Cross-Site Request Forgery (Delete Income)
|
29 |
WEB
|
Mr Winst0n
|
|
2019-08-08
|
|
Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting
|
28 |
WEB
|
Greg.Priest
|
|
2019-08-07
|
|
WordPress Plugin JoomSport 3.3 - SQL Injection
|
26 |
WEB
|
Pablo Santiago
|
|
2019-08-02
|
|
1CRM On-Premise Software 8.5.7 - Persistent Cross-Site Scripting
|
29 |
WEB
|
Kusol Watchara-Apanukorn
|
|
2019-08-02
|
|
Rest - Cafe and Restaurant Website CMS - 'slug' SQL Injection
|
23 |
WEB
|
n1x_
|
|
2019-08-02
|
|
Sar2HTML 3.2.1 - Remote Command Execution
|
25 |
WEB
|
Cemal Cihad ÇİFTÇİ
|
|
2019-08-01
|
|
Cisco Catalyst 3850 Series Device Manager - Cross-Site Request Forgery
|
31 |
WEB
|
Alperen Soydan
|
|
2019-08-01
|
|
WebIncorp ERP - SQL injection
|
24 |
WEB
|
n1x_
|
|
2019-08-01
|
|
Ultimate Loan Manager 2.0 - Cross-Site Scripting
|
28 |
WEB
|
Metin Yunus Kandemir
|
|
2019-07-31
|
|
Oracle Hyperion Planning 11.1.2.3 - XML External Entity
|
28 |
WEB
|
Lucas Dinucci
|
|
2019-07-30
|
|
Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
|
28 |
WEB
|
Jacob Baines
|
|
2019-07-29
|
|
GigToDo 1.3 - Cross-Site Scripting
|
29 |
WEB
|
m0ze
|
|
2019-07-29
|
|
WordPress Theme Real Estate 2.8.9 - Cross-Site Scripting
|
27 |
WEB
|
m0ze
|
|
2019-07-29
|
|
WordPress Plugin Simple Membership 3.8.4 - Cross-Site Request Forgery
|
28 |
WEB
|
rubyman
|
|
2019-07-26
|
|
Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection
|
29 |
WEB
|
Wietse Boonstra
|
|
2019-07-26
|
|
Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote Code Execution (Metasploi
|
26 |
WEB
|
Wietse Boonstra
|
|
2019-07-26
|
|
Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
|
30 |
WEB
|
Wietse Boonstra
|
|
2019-07-26
|
|
Moodle Filepicker 3.5.2 - Server Side Request Forgery
|
26 |
WEB
|
Fabian Mosch_ Nick Theisinger
|
|
2019-07-25
|
|
MyBB < 1.8.21 - Remote Code Execution
|
28 |
WEB
|
Giovanni Chhatta
|
|
2019-07-25
|
|
Ovidentia 8.4.3 - SQL Injection
|
25 |
WEB
|
UserX
|
|
2019-07-25
|
|
Ovidentia 8.4.3 - Cross-Site Scripting
|
30 |
WEB
|
n3k00n3
|
|
2019-07-24
|
|
WordPress Plugin Hybrid Composer 1.4.6 - Improper Access Restrictions
|
27 |
WEB
|
yasin
|
|
2019-07-24
|
|
Cisco Wireless Controller 3.6.10E - Cross-Site Request Forgery
|
27 |
WEB
|
Mehmet Onder
|
|
2019-07-24
|
|
NoviSmart CMS - SQL injection
|
30 |
WEB
|
n1x_
|
|
2019-07-22
|
|
Axway SecureTransport 5 - Unauthenticated XML Injection
|
35 |
WEB
|
Dominik Penner
|
|
2019-07-19
|
|
REDCap < 9.1.2 - Cross-Site Scripting
|
27 |
WEB
|
Alexandre ZANNI
|
|
2019-07-19
|
|
Web Ofisi Firma 13 - 'oz' SQL Injection
|
24 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-07-19
|
|
Web Ofisi Rent a Car 3 - 'klima' SQL Injection
|
23 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-07-19
|
|
Web Ofisi Firma Rehberi 1 - 'il' SQL Injection
|
20 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-07-19
|
|
Web Ofisi Emlak 3 - 'emlak_durumu' SQL Injection
|
18 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-07-19
|
|
Web Ofisi Emlak 2 - 'ara' SQL Injection
|
23 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-07-19
|
|
Web Ofisi Platinum E-Ticaret 5 - 'q' SQL Injection
|
25 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-07-19
|
|
Web Ofisi E-Ticaret 3 - 'a' SQL Injection
|
26 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-07-19
|
|
fuel CMS 1.4.1 - Remote Code Execution (1)
|
37 |
WEB
|
0xd0ff9
|
|
2019-07-18
|
|
WordPress Plugin OneSignal 1.17.5 - 'subdomain' Persistent Cross-Site Scripting
|
29 |
WEB
|
LiquidWorm
|
|
2019-07-17
|
|
Oracle Siebel CRM 19.0 - Persistent Cross-Site Scripting
|
33 |
WEB
|
Sarath Nair
|
|
2019-07-16
|
|
CentOS Control Web Panel 0.9.8.838 - User Enumeration
|
33 |
WEB
|
Pongtorn Angsuchotmetee_ Nissana Sirijirakal_ Nari
|
|
2019-07-16
|
|
CentOS Control Web Panel 0.9.8.836 - Privilege Escalation
|
26 |
WEB
|
Pongtorn Angsuchotmetee_ Nissana Sirijirakal_ Nari
|
|
2019-07-16
|
|
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
|
20 |
WEB
|
Pongtorn Angsuchotmetee
|
|
2019-07-15
|
|
FlightPath < 4.8.2 / < 5.0-rc2 - Local File Inclusion
|
24 |
WEB
|
Mohammed Althibyani
|
|
2019-07-15
|
|
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities
|
24 |
WEB
|
Ramikan
|
|
2019-07-15
|
|
Netgear WiFi Router JWNR2010v5 / R6080 - Authentication Bypass
|
29 |
WEB
|
Wadeek
|
|
2019-07-12
|
|
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
|
26 |
WEB
|
Chris Lyne
|
|
2019-07-12
|
|
Jenkins Dependency Graph View Plugin 0.13 - Persistent Cross-Site Scripting
|
29 |
WEB
|
Ishaq Mohammed
|
|
2019-07-12
|
|
Sahi Pro 8.0.0 - Remote Command Execution
|
30 |
WEB
|
AkkuS
|
|
2019-07-12
|
|
MyT Project Management 1.5.1 - User[username] Persistent Cross-Site Scripting
|
31 |
WEB
|
Metin Yunus Kandemir
|
|
2019-07-12
|
|
Tenda D301 v2 Modem Router - Persistent Cross-Site Scripting
|
26 |
WEB
|
ABDO10
|
|
2019-07-11
|
|
Sitecore 9.0 rev 171002 - Persistent Cross-Site Scripting
|
25 |
WEB
|
Owais Mehtab
|
|
2019-07-08
|
|
WordPress Plugin Like Button 1.6.0 - Authentication Bypass
|
32 |
WEB
|
Benjamin Lim
|
|
2019-07-08
|
|
Karenderia Multiple Restaurant System 5.3 - SQL Injection
|
30 |
WEB
|
Mehmet EMIROGLU
|
|
2019-07-05
|
|
Karenderia Multiple Restaurant System 5.3 - Local File Inclusion
|
28 |
WEB
|
Mehmet EMIROGLU
|
|
2019-07-03
|
|
Symantec DLP 15.5 MP1 - Cross-Site Scripting
|
24 |
WEB
|
Chapman Schleiss
|
|
2019-07-02
|
|
Centreon 19.04 - Remote Code Execution
|
26 |
WEB
|
Askar
|
|
2019-07-01
|
|
FaceSentry Access Control System 6.4.8 - Remote Root Exploit
|
27 |
WEB
|
LiquidWorm
|
|
2019-07-01
|
|
FaceSentry Access Control System 6.4.8 - Cross-Site Request Forgery
|
24 |
WEB
|
LiquidWorm
|
|
2019-07-01
|
|
FaceSentry Access Control System 6.4.8 - Remote Command Injection
|
27 |
WEB
|
LiquidWorm
|
|
2019-07-01
|
|
CyberPanel 1.8.4 - Cross-Site Request Forgery
|
24 |
WEB
|
Bilgi Birikim Sistemleri
|
|
2019-07-01
|
|
Sahi pro 8.x - Directory Traversal
|
22 |
WEB
|
Operat0r
|
|
2019-07-01
|
|
SAP Crystal Reports - Information Disclosure
|
22 |
WEB
|
Mohamed M.Fouad
|
|
2019-07-01
|
|
ZoneMinder 1.32.3 - Cross-Site Scripting
|
24 |
WEB
|
Joey Lane
|
|
2019-07-01
|
|
PowerPanel Business Edition - Cross-Site Scripting
|
26 |
WEB
|
Joey Lane
|
|
2019-07-01
|
|
Varient 1.6.1 - SQL Injection
|
25 |
WEB
|
Mehmet EMIROGLU
|
|
2019-07-01
|
|
CiuisCRM 1.6 - 'eventType' SQL Injection
|
31 |
WEB
|
Mehmet EMIROGLU
|
|
2019-07-01
|
|
WorkSuite PRM 2.4 - 'password' SQL Injection
|
27 |
WEB
|
Mehmet EMIROGLU
|
|
2019-06-28
|
|
LibreNMS 1.46 - 'addhost' Remote Code Execution
|
33 |
WEB
|
Askar
|
|
2019-06-25
|
|
WordPress Plugin Live Chat Unlimited 2.8.3 - Cross-Site Scripting
|
25 |
WEB
|
m0ze
|
|
2019-06-25
|
|
WordPress Plugin iLive 1.0.4 - Cross-Site Scripting
|
29 |
WEB
|
m0ze
|
|
2019-06-25
|
|
BlogEngine.NET 3.3.6/3.3.7 - 'path' Directory Traversal
|
28 |
WEB
|
Aaron Bishop
|
|
2019-06-25
|
|
AZADMIN CMS 1.0 - SQL Injection
|
32 |
WEB
|
felipe andrian
|
|
2019-06-25
|
|
Fortinet FCM-MB40 - Cross-Site Request Forgery / Remote Command Execution
|
28 |
WEB
|
XORcat
|
|
2019-06-24
|
|
GrandNode 4.40 - Path Traversal / Arbitrary File Download
|
29 |
WEB
|
Corey Robinson
|
|
2019-06-24
|
|
SeedDMS < 5.1.11 - 'out.GroupMgr.php' Cross-Site Scripting
|
31 |
WEB
|
Nimit Jain
|
|
2019-06-24
|
|
SeedDMS < 5.1.11 - 'out.UsrMgr.php' Cross-Site Scripting
|
25 |
WEB
|
Nimit Jain
|
|
2019-06-24
|
|
SeedDMS versions < 5.1.11 - Remote Command Execution
|
27 |
WEB
|
Nimit Jain
|
|
2019-06-24
|
|
dotProject 2.1.9 - SQL Injection
|
23 |
WEB
|
Metin Yunus Kandemir
|
|
2019-06-20
|
|
BlogEngine.NET 3.3.6/3.3.7 - XML External Entity Injection
|
29 |
WEB
|
Aaron Bishop
|
|
2019-06-20
|
|
WebERP 4.15 - SQL injection
|
23 |
WEB
|
Semen Alexandrovich Lyhin
|
|
2019-06-19
|
|
BlogEngine.NET 3.3.6/3.3.7 - 'theme Cookie' Directory Traversal / Remote Code Execution
|
27 |
WEB
|
Aaron Bishop
|
|
2019-06-19
|
|
BlogEngine.NET 3.3.6/3.3.7 - 'dirPath' Directory Traversal / Remote Code Execution
|
32 |
WEB
|
Aaron Bishop
|
|
2019-06-18
|
|
Sahi pro 8.x - Cross-Site Scripting
|
32 |
WEB
|
Goutham Madhwaraj
|
|
2019-06-18
|
|
Sahi pro 8.x - SQL Injection
|
31 |
WEB
|
Goutham Madhwaraj
|
|
2019-06-18
|
|
Sahi pro 7.x/8.x - Directory Traversal
|
29 |
WEB
|
Goutham Madhwaraj
|
|
2019-06-17
|
|
Spring Security OAuth - Open Redirector
|
31 |
WEB
|
Riemann
|
|
2019-06-17
|
|
CleverDog Smart Camera DOG-2W / DOG-2W-V4 - Multiple Vulnerabilities
|
25 |
WEB
|
Alex Akinbi
|
|
2019-06-17
|
|
RedwoodHQ 2.5.5 - Authentication Bypass
|
26 |
WEB
|
EthicalHCOP
|
|
2019-06-13
|
|
Sitecore 8.x - Deserialization Remote Code Execution
|
29 |
WEB
|
Jarad Kopf
|
|
2019-06-12
|
|
FusionPBX 4.4.3 - Remote Command Execution
|
31 |
WEB
|
Dustin Cobb
|
|
2019-06-11
|
|
Liferay Portal 7.1 CE GA=3 / SimpleCaptcha API - Cross-Site Scripting
|
23 |
WEB
|
Valerio Brussani
|
|
2019-06-11
|
|
phpMyAdmin 4.8 - Cross-Site Request Forgery
|
25 |
WEB
|
Riemann
|
|
2019-06-11
|
|
WordPress Plugin Insert or Embed Articulate Content into WordPress - Remote Code Execution
|
27 |
WEB
|
xulchibalraa
|
|
2019-06-10
|
|
UliCMS 2019.1 'Spitting Lama' - Persistent Cross-Site Scripting
|
26 |
WEB
|
Unk9vvN
|
|
2019-06-06
|
|
Supra Smart Cloud TV - 'openLiveURL()' Remote File Inclusion
|
31 |
WEB
|
Dhiraj Mishra
|
|
2019-06-05
|
|
Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery
|
30 |
WEB
|
k8gege
|
|
2019-06-05
|
|
Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery
|
23 |
WEB
|
k8gege
|
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'PurchaseRequest.do' Cross-Site Scripting
|
25 |
WEB
|
Vingroup
|
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SearchN.do' Cross-Site Scripting
|
26 |
WEB
|
Vingroup
|
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SolutionSearch.do' Cross-Site Scripting
|
24 |
WEB
|
Vingroup
|
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SiteLookup.do' Cross-Site Scripting
|
24 |
WEB
|
Vingroup
|
|
2019-06-04
|
|
IceWarp 10.4.4 - Local File Inclusion
|
29 |
WEB
|
JameelNabbo
|