2019-03-22
|
|
Meeplace Business Review Script - 'id' SQL Injection
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-22
|
|
Matri4Web Matrimony Website Script - Multiple SQL Injection
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-21
|
|
Bootstrapy CMS - Multiple SQL Injection
|
3 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-21
|
|
Placeto CMS Alpha v4 - 'page' SQL Injection
|
1 |
WEB
|
Abdullah Çelebi
|
2019-03-21
|
|
uHotelBooking System - 'system_page' SQL Injection
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-21
|
|
The Company Business Website CMS - Multiple Vulnerabilities
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-21
|
|
Rails 5.2.1 - Arbitrary File Content Disclosure
|
2 |
WEB
|
NotoriousRebel
|
2019-03-21
|
|
Netartmedia Vlog System - 'email' SQL Injection
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-20
|
|
Netartmedia Deals Portal - 'Email' SQL Injection
|
1 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-20
|
|
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Request Forgery
|
1 |
WEB
|
Kumar Saurav
|
2019-03-20
|
|
PLC Wireless Router GPN2.4P21-C-CN - Incorrect Access Control
|
3 |
WEB
|
Kumar Saurav
|
2019-03-20
|
|
202CMS v10beta - Multiple SQL Injection
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-03-20
|
|
Netartmedia PHP Business Directory 4.2 - SQL Injection
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-20
|
|
Netartmedia PHP Dating Site - SQL Injection
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-20
|
|
Netartmedia Jobs Portal 6.1 - SQL Injection
|
4 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-20
|
|
Netartmedia PHP Real Estate Agency 4.0 - SQL Injection
|
1 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-20
|
|
Netartmedia PHP Car Dealer - SQL Injection
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-19
|
|
Netartmedia Real Estate Portal 5.0 - SQL Injection
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-19
|
|
Netartmedia PHP Mall 4.1 - SQL Injection
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-19
|
|
Netartmedia Event Portal 2.0 - 'Email' SQL Injection
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-19
|
|
eNdonesia Portal 8.7 - Multiple Vulnerabilities
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-03-19
|
|
MyBB Upcoming Events Plugin 1.32 - Cross-Site Scripting
|
2 |
WEB
|
0xB9
|
2019-03-19
|
|
Gila CMS 1.9.1 - Cross-Site Scripting
|
2 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-03-18
|
|
TheCarProject 2 - Multiple SQL Injection
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-03-15
|
|
Moodle 3.4.1 - Remote Code Execution
|
2 |
WEB
|
Darryn Ten
|
2019-03-15
|
|
Laundry CMS - Multiple Vulnerabilities
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-03-15
|
|
Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities
|
3 |
WEB
|
Gionathan Reale
|
2019-03-15
|
|
ICE HRM 23.0 - Multiple Vulnerabilities
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-03-15
|
|
CMS Made Simple Showtime2 Module 3.6.2 - (Authenticated) Arbitrary File Upload
|
2 |
WEB
|
Daniele Scanu
|
2019-03-15
|
|
NetData 1.13.0 - HTML Injection
|
3 |
WEB
|
s4vitar
|
2019-03-14
|
|
Pegasus CMS 1.0 - 'extra_fields.php' Plugin Remote Code Execution
|
4 |
WEB
|
R3zk0n
|
2019-03-14
|
|
Intel Modular Server System 10.18 - Cross-Site Request Forgery (Change Admin Password)
|
2 |
WEB
|
LiquidWorm
|
2019-03-13
|
|
pfSense 2.4.4-p1 (HAProxy Package 0.59_14) - Persistent Cross-Site Scripting
|
1 |
WEB
|
Gionathan Reale
|
2019-03-13
|
|
WordPress Plugin GraceMedia Media Player 1.0 - Local File Inclusion
|
2 |
WEB
|
Manuel García Cárdenas
|
2019-03-12
|
|
PilusCart 1.4.1 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
Gionathan Reale
|
2019-03-11
|
|
Flexpaper PHP Publish Service 2.3.6 - Remote Code Execution
|
2 |
WEB
|
redtimmysec
|
2019-03-11
|
|
PRTG Network Monitor 18.2.38 - (Authenticated) Remote Code Execution
|
2 |
WEB
|
M4LV0
|
2019-03-11
|
|
OpenKM 6.3.2 < 6.3.7 - Remote Command Execution (Metasploit)
|
2 |
WEB
|
AkkuS
|
2019-03-11
|
|
Liferay CE Portal < 7.1.2 ga3 - Remote Command Execution (Metasploit)
|
1 |
WEB
|
AkkuS
|
2019-03-08
|
|
DirectAdmin 1.55 - 'CMD_ACCOUNT_ADMIN' Cross-Site Request Forgery
|
1 |
WEB
|
ManhNho
|
2019-03-08
|
|
McAfee ePO 5.9.1 - Registered Executable Local Access Bypass
|
2 |
WEB
|
leonjza
|
2019-03-08
|
|
OrientDB 3.0.17 GA Community Edition - Cross-Site Request Forgery / Cross-Site Scripting
|
3 |
WEB
|
Ozer Goker
|
2019-03-08
|
|
OrientDB 3.0.17 GA Community Edition - Cross-Site Request Forgery / Cross-Site Scripting
|
3 |
WEB
|
Ozer Goker
|
2018-12-12
|
|
phpBB 3.2.3 - Remote Code Execution
|
2 |
WEB
|
allyshka
|
2019-03-01
|
|
WordPress Core 5.0 - Remote Code Execution
|
2 |
WEB
|
allyshka
|
2019-03-07
|
|
Kados R10 GreenBee - Multiple SQL Injection
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-03-05
|
|
OpenDocMan 1.3.4 - 'search.php where' SQL Injection
|
1 |
WEB
|
Mehmet EMIROGLU
|
2019-03-04
|
|
Fiberhome AN5506-04-F RP2669 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Tauco
|
2019-03-04
|
|
WordPress Plugin Cerber Security_ Antispam & Malware Scan 8.0 - Multiple Bypass Vulnerabilities
|
2 |
WEB
|
ed0x21son
|
2019-03-04
|
|
Craft CMS 3.1.12 Pro - Cross-Site Scripting
|
2 |
WEB
|
Ismail Tasdelen
|
2019-03-04
|
|
Bolt CMS 3.6.4 - Cross-Site Scripting
|
2 |
WEB
|
Ismail Tasdelen
|
2019-03-04
|
|
MarcomCentral FusionPro VDP Creator < 10.0 - Directory Traversal
|
2 |
WEB
|
0v3rride
|
2019-03-04
|
|
Raisecom XPON ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 - Remote Code Execution
|
1 |
WEB
|
JameelNabbo
|
2019-03-04
|
|
zzzphp CMS 1.6.1 - Cross-Site Request Forgery
|
2 |
WEB
|
Yang Chenglong
|
2019-03-04
|
|
Splunk Enterprise 7.2.4 - Custom App Remote Command Execution (Persistent Backdoor / Custom Binary)
|
2 |
WEB
|
Matteo Malvica
|
2019-03-04
|
|
Booked Scheduler 2.7.5 - Remote Command Execution (Metasploit)
|
2 |
WEB
|
AkkuS
|
2019-03-04
|
|
OOP CMS BLOG 1.0 - Multiple Cross-Site Request Forgery
|
2 |
WEB
|
Mr Winst0n
|
2019-03-04
|
|
OOP CMS BLOG 1.0 - Multiple SQL Injection
|
1 |
WEB
|
Mr Winst0n
|
2019-03-04
|
|
elFinder 2.1.47 - 'PHP connector' Command Injection
|
1 |
WEB
|
q3rv0
|
2019-03-04
|
|
CMSsite 1.0 - Multiple Cross-Site Request Forgery
|
2 |
WEB
|
Mr Winst0n
|
2019-02-28
|
|
Feng Office 3.7.0.5 - Remote Command Execution (Metasploit)
|
2 |
WEB
|
AkkuS
|
2019-02-28
|
|
Usermin 1.750 - Remote Command Execution (Metasploit)
|
2 |
WEB
|
AkkuS
|
2019-02-28
|
|
Joomla! Component J2Store < 3.3.7 - SQL Injection
|
2 |
WEB
|
Andrei Conache
|
2019-02-28
|
|
Simple Online Hotel Reservation System - Cross-Site Request Forgery (Delete Admin)
|
2 |
WEB
|
Mr Winst0n
|
2019-02-28
|
|
Simple Online Hotel Reservation System - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
Mr Winst0n
|
2019-02-28
|
|
Simple Online Hotel Reservation System - SQL Injection
|
2 |
WEB
|
Mr Winst0n
|
2019-02-25
|
|
Drupal < 8.6.9 - REST Module Remote Code Execution
|
3 |
WEB
|
leonjza
|
2019-02-25
|
|
Advance Gift Shop Pro Script 2.0.3 - SQL Injection
|
2 |
WEB
|
Mr Winst0n
|
2019-02-25
|
|
News Website Script 2.0.5 - SQL Injection
|
2 |
WEB
|
Mr Winst0n
|
2019-02-25
|
|
PHP Ecommerce Script 2.0.6 - Cross-Site Scripting / SQL Injection
|
2 |
WEB
|
Mr Winst0n
|
2019-02-25
|
|
zzzphp CMS 1.6.1 - Remote Code Execution
|
2 |
WEB
|
Yang Chenglong
|
2019-02-25
|
|
Jenkins Plugin Script Security 1.49/Declarative 1.3.4/Groovy 2.60 - Remote Code Execution
|
1 |
WEB
|
wetw0rk
|
2019-02-23
|
|
Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution
|
2 |
WEB
|
Charles Fol
|
2019-02-22
|
|
Teracue ENC-400 - Command Injection / Missing Authentication
|
2 |
WEB
|
Stephen Shkardoon
|
2019-02-22
|
|
Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation
|
2 |
WEB
|
SecureAuth
|
2019-02-22
|
|
Quest NetVault Backup Server < 11.4.5 - Process Manager Service SQL Injection / Remote Code Executio
|
2 |
WEB
|
Chris Anastasio
|
2019-02-21
|
|
EI-Tube 3 - SQL Injection
|
1 |
WEB
|
Meisam Monsef
|
2019-02-21
|
|
C4G Basic Laboratory Information System (BLIS) 3.4 - SQL Injection
|
2 |
WEB
|
Carlos Avila
|
2019-02-20
|
|
HotelDruid 2.3 - Cross-Site Scripting
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-02-19
|
|
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution
|
3 |
WEB
|
orange
|
2019-02-19
|
|
Ask Expert Script 3.0.5 - Cross Site Scripting / SQL Injection
|
2 |
WEB
|
Mr Winst0n
|
2019-02-19
|
|
Ask Expert Script 3.0.5 - Cross Site Scripting / SQL Injection
|
2 |
WEB
|
Mr Winst0n
|
2019-02-19
|
|
Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting
|
1 |
WEB
|
Rafael Pedrero
|
2019-02-19
|
|
Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting
|
2 |
WEB
|
Rafael Pedrero
|
2019-02-19
|
|
XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting
|
2 |
WEB
|
Rafael Pedrero
|
2019-02-19
|
|
XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting
|
2 |
WEB
|
Rafael Pedrero
|
2019-02-19
|
|
eDirectory - SQL Injection
|
3 |
WEB
|
Efrén Díaz
|
2019-02-19
|
|
Zuz Music 2.1 - 'zuzconsole/___contact ' Persistent Cross-Site Scripting
|
2 |
WEB
|
Deyaa Muhammad
|
2019-02-19
|
|
Listing Hub CMS 1.0 - 'pages.php id' SQL Injection
|
2 |
WEB
|
Deyaa Muhammad
|
2019-02-19
|
|
Find a Place CMS Directory 1.5 - 'assets/external/data_2.php cate' SQL Injection
|
2 |
WEB
|
Deyaa Muhammad
|
2019-02-18
|
|
WordPress Plugin WooCommerce - GloBee (cryptocurrency) Payment Gateway 1.1.1 - Payment Bypass / Unau
|
2 |
WEB
|
GeekHack
|
2019-02-18
|
|
Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Upload
|
2 |
WEB
|
Dao Duy Hung
|
2019-02-18
|
|
Comodo Dome Firewall 2.7.0 - Cross-Site Scripting
|
2 |
WEB
|
Ozer Goker
|
2019-02-18
|
|
ArangoDB Community Edition 3.4.2-1 - Cross-Site Scripting
|
3 |
WEB
|
Ozer Goker
|
2019-02-18
|
|
Apache CouchDB 2.3.0 - Cross-Site Scripting
|
2 |
WEB
|
Ozer Goker
|
2019-02-18
|
|
Webiness Inventory 2.3 - 'ProductModel' Arbitrary File Upload
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-02-18
|
|
M/Monit 3.7.2 - Privilege Escalation
|
2 |
WEB
|
Dolev Farhi
|
2019-02-18
|
|
CMSsite 1.0 - 'post' SQL Injection
|
2 |
WEB
|
Mr Winst0n
|
2019-02-18
|
|
MISP 2.4.97 - SQL Command Execution via Command Injection in STIX Module
|
3 |
WEB
|
Tm9jdGlz
|
2019-02-18
|
|
Master IP CAM 01 3.3.4.2103 - Remote Command Execution
|
2 |
WEB
|
Raffaele Sabato
|
2019-02-18
|
|
qdPM 9.1 - 'search[keywords]' Cross-Site Scripting
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-02-18
|
|
qdPM 9.1 - 'type' Cross-Site Scripting
|
3 |
WEB
|
Mehmet EMIROGLU
|
2019-02-15
|
|
UniSharp Laravel File Manager 2.0.0-alpha7 - Arbitrary File Upload
|
2 |
WEB
|
Mohammad Danish
|
2019-02-15
|
|
qdPM 9.1 - 'search_by_extrafields[]' SQL Injection
|
3 |
WEB
|
Mehmet EMIROGLU
|
2019-02-15
|
|
Jinja2 2.10 - 'from_string' Server Side Template Injection
|
2 |
WEB
|
JameelNabbo
|
2019-02-15
|
|
MyBB Trash Bin Plugin 1.1.3 - Cross-Site Scripting / Cross-Site Request Forgery
|
3 |
WEB
|
0xB9
|
2019-02-15
|
|
MyBB Trash Bin Plugin 1.1.3 - Cross-Site Scripting / Cross-Site Request Forgery
|
2 |
WEB
|
0xB9
|
2019-02-14
|
|
LayerBB 1.1.2 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
0xB9
|
2019-02-14
|
|
WordPress Plugin Booking Calendar 8.4.3 - (Authenticated) SQL Injection
|
2 |
WEB
|
B0UG
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'assets/edit/host.php?whid=5' Cross-Site Scripting
|
3 |
WEB
|
Mohammed Abdul Kareem
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'assets/add/dns.php' Cross-Site Scripting
|
2 |
WEB
|
Mohammed Abdul Kareem
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'category.php CatagoryName_ StakeHolder' Cross-Site Scripting
|
3 |
WEB
|
Mohammed Abdul Raheem
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'ssl-accounts.php username' Cross-Site Scripting
|
2 |
WEB
|
Mohammed Abdul Raheem
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'ssl-provider-name' Cross-Site Scripting
|
2 |
WEB
|
Mohammed Abdul Raheem
|
2019-02-13
|
|
PilusCart 1.4.1 - 'send' SQL Injection
|
1 |
WEB
|
Mehmet EMIROGLU
|
2019-02-13
|
|
Rukovoditel Project Management CRM 2.4.1 - Cross-Site Scripting
|
4 |
WEB
|
Mehmet EMIROGLU
|
2019-02-12
|
|
LayerBB 1.1.2 - Cross-Site Scripting
|
2 |
WEB
|
0xB9
|
2019-02-12
|
|
BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution
|
2 |
WEB
|
Dustin Cobb
|
2019-02-12
|
|
Jenkins 2.150.2 - Remote Command Execution (Metasploit)
|
2 |
WEB
|
AkkuS
|
2019-02-12
|
|
OPNsense < 19.1.1 - Cross-Site Scripting
|
3 |
WEB
|
Ozer Goker
|
2019-02-11
|
|
Webiness Inventory 2.3 - 'email' SQL Injection
|
1 |
WEB
|
Mehmet EMIROGLU
|
2019-02-11
|
|
CentOS Web Panel 0.9.8.763 - Persistent Cross-Site Scripting
|
2 |
WEB
|
DKM
|
2019-02-11
|
|
VA MAX 8.3.4 - (Authenticated) Remote Code Execution
|
3 |
WEB
|
Cody Sixteen
|
2019-02-11
|
|
MyBB Bans List 1.0 - Cross-Site Scripting
|
3 |
WEB
|
0xB9
|
2019-02-11
|
|
IPFire 2.21 - Cross-Site Scripting
|
1 |
WEB
|
Ozer Goker
|