|
2019-04-30
|
|
Veeam ONE Reporter 9.5.0.3201 - Persistent Cross-Site Scripting
|
9 |
WEB
|
Seyed Sadegh Khatami
|
|
2019-04-30
|
|
Veeam ONE Reporter 9.5.0.3201 - Multiple Cross-Site Request Forgery
|
12 |
WEB
|
Seyed Sadegh Khatami
|
|
2019-04-30
|
|
Netgear DGN2200 / DGND3700 - Admin Password Disclosure
|
10 |
WEB
|
Social Engineering Neo
|
|
2019-04-26
|
|
Apache Pluto 3.0.0 / 3.0.1 - Persistent Cross-Site Scripting
|
11 |
WEB
|
Dhiraj Mishra
|
|
2019-04-25
|
|
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
|
7 |
WEB
|
AkkuS
|
|
2019-04-25
|
|
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
|
9 |
WEB
|
AkkuS
|
|
2019-04-25
|
|
JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting
|
12 |
WEB
|
Vikas Chaudhary
|
|
2019-04-22
|
|
UliCMS 2019.2 / 2019.1 - Multiple Cross-Site Scripting
|
12 |
WEB
|
Kağan EĞLENCE
|
|
2019-04-22
|
|
Msvod 10 - Cross-Site Request Forgery (Change User Information)
|
12 |
WEB
|
ax8
|
|
2019-04-22
|
|
74CMS 5.0.1 - Cross-Site Request Forgery (Add New Admin User)
|
12 |
WEB
|
ax8
|
|
2019-04-22
|
|
WordPress Plugin Contact Form Builder 1.0.67 - Cross-Site Request Forgery / Local File Inclusion
|
10 |
WEB
|
Panagiotis Vagenas
|
|
2019-04-22
|
|
WordPress Plugin Contact Form Builder 1.0.67 - Cross-Site Request Forgery / Local File Inclusion
|
12 |
WEB
|
Panagiotis Vagenas
|
|
2019-04-19
|
|
Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Ent
|
10 |
WEB
|
Vahagn Vardanyan
|
|
2019-04-19
|
|
Oracle Business Intelligence 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - Directory Traversal
|
10 |
WEB
|
Vahagn Vardanyan
|
|
2019-04-16
|
|
Joomla! Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion
|
12 |
WEB
|
Haboob Team
|
|
2019-04-16
|
|
Zyxel ZyWall 310 / ZyWall 110 / USG1900 / ATP500 / USG40 - Login Page Cross-Site Scripting
|
12 |
WEB
|
Aaron Bishop
|
|
2019-04-15
|
|
DirectAdmin 1.561 - Multiple Vulnerabilities
|
12 |
WEB
|
InfinitumIT
|
|
2019-04-12
|
|
ATutor < 2.2.4 - 'file_manager' Remote Code Execution (Metasploit)
|
11 |
WEB
|
AkkuS
|
|
2019-04-10
|
|
D-Link DI-524 V2.06RU - Multiple Cross-Site Scripting
|
12 |
WEB
|
Semen Alexandrovich Lyhin
|
|
2019-04-10
|
|
Dell KACE Systems Management Appliance (K1000) 6.4.120756 - Unauthenticated Remote Code Execution
|
10 |
WEB
|
Julien Ahrens
|
|
2019-04-09
|
|
Ashop Shopping Cart Software - 'bannedcustomers.php?blacklistitemid' SQL Injection
|
12 |
WEB
|
Doğukan Karaciğer
|
|
2019-04-08
|
|
ManageEngine ServiceDesk Plus 9.3 - User Enumeration
|
11 |
WEB
|
Operat0r
|
|
2019-04-08
|
|
WordPress Plugin Limit Login Attempts Reloaded 2.7.4 - Login Limit Bypass
|
11 |
WEB
|
isdampe
|
|
2019-04-08
|
|
Tradebox CryptoCurrency - 'symbol' SQL Injection
|
10 |
WEB
|
Abdullah Çelebi
|
|
2019-04-08
|
|
CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) - Cross-Site Scripting
|
13 |
WEB
|
DKM
|
|
2019-04-08
|
|
SaLICru -SLC-20-cube3(5) - HTML Injection
|
13 |
WEB
|
Ramikan
|
|
2019-04-08
|
|
ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities
|
12 |
WEB
|
Ramikan
|
|
2019-04-08
|
|
Bolt CMS 3.6.6 - Cross-Site Request Forgery / Remote Code Execution
|
10 |
WEB
|
FelipeGaspar
|
|
2019-04-08
|
|
Jobgator - 'experience' SQL Injection
|
12 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-04-05
|
|
WordPress Plugin Contact Form Maker 1.13.1 - Cross-Site Request Forgery
|
14 |
WEB
|
Peyman Forouzan
|
|
2019-04-05
|
|
Manage Engine ServiceDesk Plus 10.0 - Privilege Escalation
|
13 |
WEB
|
Ata Hakçıl_ Melih Kaan Yıldız
|
|
2019-04-04
|
|
FreeSMS 2.1.2 - SQL Injection (Authentication Bypass)
|
10 |
WEB
|
Yilmaz Degirmenci
|
|
2019-04-03
|
|
PhreeBooks ERP 5.2.3 - Arbitrary File Upload
|
13 |
WEB
|
Abdullah Çelebi
|
|
2019-04-03
|
|
Ashop Shopping Cart Software - SQL Injection
|
12 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-04-03
|
|
Clinic Pro v4 - 'month' SQL Injection
|
10 |
WEB
|
Abdullah Çelebi
|
|
2019-04-03
|
|
iScripts ReserveLogic - SQL Injection
|
12 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-04-02
|
|
phpFileManager 1.7.8 - Local File Inclusion
|
11 |
WEB
|
Murat Kalafatoglu
|
|
2019-04-02
|
|
Fiverr Clone Script 1.2.2 - SQL Injection / Cross-Site Scripting
|
8 |
WEB
|
Mr Winst0n
|
|
2019-04-02
|
|
CMS Made Simple < 2.2.10 - SQL Injection
|
10 |
WEB
|
Daniele Scanu
|
|
2019-04-02
|
|
LimeSurvey < 3.16 - Remote Code Execution
|
9 |
WEB
|
q3rv0
|
|
2019-04-02
|
|
JioFi 4G M2S 1.0.2 - Cross-Site Request Forgery
|
11 |
WEB
|
Vikas Chaudhary
|
|
2019-04-02
|
|
WordPress Plugin PayPal Checkout Payment Gateway 1.6.8 - Parameter Tampering
|
10 |
WEB
|
Vikas Chaudhary
|
|
2019-04-02
|
|
Inout RealEstate - 'city' SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-04-02
|
|
Inout EasyRooms - SQL Injection
|
14 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-29
|
|
CentOS Web Panel 0.9.8.789 - NameServer Field Persistent Cross-Site Scripting
|
13 |
WEB
|
DKM
|
|
2019-03-28
|
|
Jettweb PHP Hazır Rent A Car Sitesi Scripti V2 - 'arac_kategori_id' SQL Injection
|
9 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-28
|
|
BigTree 4.3.4 CMS - Multiple SQL Injection
|
11 |
WEB
|
Mehmet EMIROGLU
|
|
2019-03-28
|
|
Job Portal 3.1 - 'job_submit' SQL Injection
|
12 |
WEB
|
Mehmet EMIROGLU
|
|
2019-03-28
|
|
i-doit 1.12 - 'qr.php' Cross-Site Scripting
|
11 |
WEB
|
BlackFog Team
|
|
2019-03-28
|
|
WordPress Plugin Loco Translate 2.2.1 - Local File Inclusion
|
10 |
WEB
|
Ali S. Ahmad
|
|
2019-03-28
|
|
WordPress Plugin Anti-Malware Security and Brute-Force Firewall 4.18.63 - Local File Inclusion (PoC)
|
11 |
WEB
|
Ali S. Ahmad
|
|
2019-03-28
|
|
Fat Free CRM 0.19.0 - HTML Injection
|
12 |
WEB
|
Ismail Tasdelen
|
|
2019-03-28
|
|
Airbnb Clone Script - Multiple SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-28
|
|
Thomson Reuters Concourse & Firm Central < 2.13.0097 - Directory Traversal / Local File Inclusion
|
11 |
WEB
|
0v3rride
|
|
2019-03-28
|
|
Thomson Reuters Concourse & Firm Central < 2.13.0097 - Directory Traversal / Local File Inclusion
|
9 |
WEB
|
0v3rride
|
|
2019-03-27
|
|
Jettweb Hazır Rent A Car Scripti V4 - SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-26
|
|
SJS Simple Job Script - SQL Injection / Cross-Site Scripting
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-26
|
|
SJS Simple Job Script - SQL Injection / Cross-Site Scripting
|
13 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-26
|
|
Titan FTP Server Version 2019 Build 3505 - Directory Traversal / Local File Inclusion
|
9 |
WEB
|
Kevin Randall
|
|
2019-03-26
|
|
Titan FTP Server Version 2019 Build 3505 - Directory Traversal / Local File Inclusion
|
10 |
WEB
|
Kevin Randall
|
|
2019-03-26
|
|
XooDigital - 'p' SQL Injection
|
10 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-26
|
|
XooGallery - Multiple SQL Injection
|
9 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-26
|
|
Rukovoditel ERP & CRM 2.4.1 - 'path' Cross-Site Scripting
|
11 |
WEB
|
Javier Olmedo
|
|
2019-03-26
|
|
Jettweb Php Hazır İlan Sitesi Scripti V2 - SQL Injection
|
12 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-25
|
|
Zeeways Matrimony CMS - SQL Injection
|
10 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-25
|
|
Zeeways Jobsite CMS - 'id' SQL Injection
|
12 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-25
|
|
Jettweb PHP Hazır Haber Sitesi Scripti V3 - SQL Injection
|
7 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-25
|
|
Jettweb PHP Hazır Haber Sitesi Scripti V2 - SQL Injection (Authentication Bypass)
|
8 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-25
|
|
Jettweb PHP Hazır Haber Sitesi Scripti V2 - SQL Injection (Authentication Bypass)
|
9 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-25
|
|
Jettweb PHP Hazır Haber Sitesi Scripti V1 - SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-25
|
|
Apache CouchDB 2.3.1 - Cross-Site Request Forgery / Cross-Site Scripting
|
11 |
WEB
|
Ozer Goker
|
|
2019-03-25
|
|
Apache CouchDB 2.3.1 - Cross-Site Request Forgery / Cross-Site Scripting
|
13 |
WEB
|
Ozer Goker
|
|
2019-03-22
|
|
Inout Article Base CMS - SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-22
|
|
Meeplace Business Review Script - 'id' SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-22
|
|
Matri4Web Matrimony Website Script - Multiple SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-21
|
|
Bootstrapy CMS - Multiple SQL Injection
|
16 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-21
|
|
Placeto CMS Alpha v4 - 'page' SQL Injection
|
9 |
WEB
|
Abdullah Çelebi
|
|
2019-03-21
|
|
uHotelBooking System - 'system_page' SQL Injection
|
9 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-21
|
|
The Company Business Website CMS - Multiple Vulnerabilities
|
9 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-21
|
|
Rails 5.2.1 - Arbitrary File Content Disclosure
|
10 |
WEB
|
NotoriousRebel
|
|
2019-03-21
|
|
Netartmedia Vlog System - 'email' SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-20
|
|
Netartmedia Deals Portal - 'Email' SQL Injection
|
9 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-20
|
|
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Request Forgery
|
9 |
WEB
|
Kumar Saurav
|
|
2019-03-20
|
|
PLC Wireless Router GPN2.4P21-C-CN - Incorrect Access Control
|
10 |
WEB
|
Kumar Saurav
|
|
2019-03-20
|
|
202CMS v10beta - Multiple SQL Injection
|
10 |
WEB
|
Mehmet EMIROGLU
|
|
2019-03-20
|
|
Netartmedia PHP Business Directory 4.2 - SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-20
|
|
Netartmedia PHP Dating Site - SQL Injection
|
14 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-20
|
|
Netartmedia Jobs Portal 6.1 - SQL Injection
|
13 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-20
|
|
Netartmedia PHP Real Estate Agency 4.0 - SQL Injection
|
13 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-20
|
|
Netartmedia PHP Car Dealer - SQL Injection
|
17 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-19
|
|
Netartmedia Real Estate Portal 5.0 - SQL Injection
|
12 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-19
|
|
Netartmedia PHP Mall 4.1 - SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-19
|
|
Netartmedia Event Portal 2.0 - 'Email' SQL Injection
|
11 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-19
|
|
eNdonesia Portal 8.7 - Multiple Vulnerabilities
|
11 |
WEB
|
Mehmet EMIROGLU
|
|
2019-03-19
|
|
MyBB Upcoming Events Plugin 1.32 - Cross-Site Scripting
|
14 |
WEB
|
0xB9
|
|
2019-03-19
|
|
Gila CMS 1.9.1 - Cross-Site Scripting
|
13 |
WEB
|
Ahmet Ümit BAYRAM
|
|
2019-03-18
|
|
TheCarProject 2 - Multiple SQL Injection
|
16 |
WEB
|
Mehmet EMIROGLU
|
|
2019-03-15
|
|
Moodle 3.4.1 - Remote Code Execution
|
12 |
WEB
|
Darryn Ten
|
|
2019-03-15
|
|
Laundry CMS - Multiple Vulnerabilities
|
10 |
WEB
|
Mehmet EMIROGLU
|
|
2019-03-15
|
|
Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities
|
12 |
WEB
|
Gionathan Reale
|
|
2019-03-15
|
|
ICE HRM 23.0 - Multiple Vulnerabilities
|
11 |
WEB
|
Mehmet EMIROGLU
|
|
2019-03-15
|
|
CMS Made Simple Showtime2 Module 3.6.2 - (Authenticated) Arbitrary File Upload
|
17 |
WEB
|
Daniele Scanu
|
|
2019-03-15
|
|
NetData 1.13.0 - HTML Injection
|
13 |
WEB
|
s4vitar
|
|
2019-03-14
|
|
Pegasus CMS 1.0 - 'extra_fields.php' Plugin Remote Code Execution
|
16 |
WEB
|
R3zk0n
|
|
2019-03-14
|
|
Intel Modular Server System 10.18 - Cross-Site Request Forgery (Change Admin Password)
|
15 |
WEB
|
LiquidWorm
|
|
2019-03-13
|
|
pfSense 2.4.4-p1 (HAProxy Package 0.59_14) - Persistent Cross-Site Scripting
|
15 |
WEB
|
Gionathan Reale
|
|
2019-03-13
|
|
WordPress Plugin GraceMedia Media Player 1.0 - Local File Inclusion
|
11 |
WEB
|
Manuel García Cárdenas
|
|
2019-03-12
|
|
PilusCart 1.4.1 - Cross-Site Request Forgery (Add Admin)
|
16 |
WEB
|
Gionathan Reale
|
|
2019-03-11
|
|
Flexpaper PHP Publish Service 2.3.6 - Remote Code Execution
|
13 |
WEB
|
redtimmysec
|
|
2019-03-11
|
|
PRTG Network Monitor 18.2.38 - (Authenticated) Remote Code Execution
|
13 |
WEB
|
M4LV0
|
|
2019-03-11
|
|
OpenKM 6.3.2 < 6.3.7 - Remote Command Execution (Metasploit)
|
12 |
WEB
|
AkkuS
|
|
2019-03-11
|
|
Liferay CE Portal < 7.1.2 ga3 - Remote Command Execution (Metasploit)
|
12 |
WEB
|
AkkuS
|
|
2019-03-08
|
|
DirectAdmin 1.55 - 'CMD_ACCOUNT_ADMIN' Cross-Site Request Forgery
|
14 |
WEB
|
ManhNho
|
|
2019-03-08
|
|
McAfee ePO 5.9.1 - Registered Executable Local Access Bypass
|
13 |
WEB
|
leonjza
|
|
2019-03-08
|
|
OrientDB 3.0.17 GA Community Edition - Cross-Site Request Forgery / Cross-Site Scripting
|
15 |
WEB
|
Ozer Goker
|
|
2019-03-08
|
|
OrientDB 3.0.17 GA Community Edition - Cross-Site Request Forgery / Cross-Site Scripting
|
15 |
WEB
|
Ozer Goker
|
|
2018-12-12
|
|
phpBB 3.2.3 - Remote Code Execution
|
16 |
WEB
|
allyshka
|
|
2019-03-01
|
|
WordPress Core 5.0 - Remote Code Execution
|
17 |
WEB
|
allyshka
|
|
2019-03-07
|
|
Kados R10 GreenBee - Multiple SQL Injection
|
17 |
WEB
|
Mehmet EMIROGLU
|
|
2019-03-05
|
|
OpenDocMan 1.3.4 - 'search.php where' SQL Injection
|
11 |
WEB
|
Mehmet EMIROGLU
|
|
2019-03-04
|
|
Fiberhome AN5506-04-F RP2669 - Persistent Cross-Site Scripting
|
12 |
WEB
|
Tauco
|
|
2019-03-04
|
|
WordPress Plugin Cerber Security_ Antispam & Malware Scan 8.0 - Multiple Bypass Vulnerabilities
|
13 |
WEB
|
ed0x21son
|
|
2019-03-04
|
|
Craft CMS 3.1.12 Pro - Cross-Site Scripting
|
15 |
WEB
|
Ismail Tasdelen
|
|
2019-03-04
|
|
Bolt CMS 3.6.4 - Cross-Site Scripting
|
12 |
WEB
|
Ismail Tasdelen
|
|
2019-03-04
|
|
MarcomCentral FusionPro VDP Creator < 10.0 - Directory Traversal
|
11 |
WEB
|
0v3rride
|