Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2019-03-04   Raisecom XPON ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 - Remote Code Execution 15 WEB JameelNabbo
2019-03-04   zzzphp CMS 1.6.1 - Cross-Site Request Forgery 16 WEB Yang Chenglong
2019-03-04   Splunk Enterprise 7.2.4 - Custom App Remote Command Execution (Persistent Backdoor / Custom Binary) 19 WEB Matteo Malvica
2019-03-04   Booked Scheduler 2.7.5 - Remote Command Execution (Metasploit) 12 WEB AkkuS
2019-03-04   OOP CMS BLOG 1.0 - Multiple Cross-Site Request Forgery 12 WEB Mr Winst0n
2019-03-04   OOP CMS BLOG 1.0 - Multiple SQL Injection 10 WEB Mr Winst0n
2019-03-04   elFinder 2.1.47 - 'PHP connector' Command Injection 12 WEB q3rv0
2019-03-04   CMSsite 1.0 - Multiple Cross-Site Request Forgery 9 WEB Mr Winst0n
2019-02-28   Feng Office 3.7.0.5 - Remote Command Execution (Metasploit) 16 WEB AkkuS
2019-02-28   Usermin 1.750 - Remote Command Execution (Metasploit) 13 WEB AkkuS
2019-02-28   Joomla! Component J2Store < 3.3.7 - SQL Injection 14 WEB Andrei Conache
2019-02-28   Simple Online Hotel Reservation System - Cross-Site Request Forgery (Delete Admin) 14 WEB Mr Winst0n
2019-02-28   Simple Online Hotel Reservation System - Cross-Site Request Forgery (Add Admin) 10 WEB Mr Winst0n
2019-02-28   Simple Online Hotel Reservation System - SQL Injection 8 WEB Mr Winst0n
2019-02-25   Drupal < 8.6.9 - REST Module Remote Code Execution 15 WEB leonjza
2019-02-25   Advance Gift Shop Pro Script 2.0.3 - SQL Injection 14 WEB Mr Winst0n
2019-02-25   News Website Script 2.0.5 - SQL Injection 10 WEB Mr Winst0n
2019-02-25   PHP Ecommerce Script 2.0.6 - Cross-Site Scripting / SQL Injection 10 WEB Mr Winst0n
2019-02-25   zzzphp CMS 1.6.1 - Remote Code Execution 10 WEB Yang Chenglong
2019-02-25   Jenkins Plugin Script Security 1.49/Declarative 1.3.4/Groovy 2.60 - Remote Code Execution 10 WEB wetw0rk
2019-02-23   Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution 10 WEB Charles Fol
2019-02-22   Teracue ENC-400 - Command Injection / Missing Authentication 9 WEB Stephen Shkardoon
2019-02-22   Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation 12 WEB SecureAuth
2019-02-22   Quest NetVault Backup Server < 11.4.5 - Process Manager Service SQL Injection / Remote Code Executio 16 WEB Chris Anastasio
2019-02-21   EI-Tube 3 - SQL Injection 11 WEB Meisam Monsef
2019-02-21   C4G Basic Laboratory Information System (BLIS) 3.4 - SQL Injection 13 WEB Carlos Avila
2019-02-20   HotelDruid 2.3 - Cross-Site Scripting 14 WEB Mehmet EMIROGLU
2019-02-19   Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution 12 WEB orange
2019-02-19   Ask Expert Script 3.0.5 - Cross Site Scripting / SQL Injection 12 WEB Mr Winst0n
2019-02-19   Ask Expert Script 3.0.5 - Cross Site Scripting / SQL Injection 11 WEB Mr Winst0n
2019-02-19   Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting 11 WEB Rafael Pedrero
2019-02-19   Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting 11 WEB Rafael Pedrero
2019-02-19   XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting 13 WEB Rafael Pedrero
2019-02-19   XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting 12 WEB Rafael Pedrero
2019-02-19   eDirectory - SQL Injection 12 WEB Efrén Díaz
2019-02-19   Zuz Music 2.1 - 'zuzconsole/___contact ' Persistent Cross-Site Scripting 15 WEB Deyaa Muhammad
2019-02-19   Listing Hub CMS 1.0 - 'pages.php id' SQL Injection 12 WEB Deyaa Muhammad
2019-02-19   Find a Place CMS Directory 1.5 - 'assets/external/data_2.php cate' SQL Injection 13 WEB Deyaa Muhammad
2019-02-18   WordPress Plugin WooCommerce - GloBee (cryptocurrency) Payment Gateway 1.1.1 - Payment Bypass / Unau 10 WEB GeekHack
2019-02-18   Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Upload 14 WEB Dao Duy Hung
2019-02-18   Comodo Dome Firewall 2.7.0 - Cross-Site Scripting 16 WEB Ozer Goker
2019-02-18   ArangoDB Community Edition 3.4.2-1 - Cross-Site Scripting 12 WEB Ozer Goker
2019-02-18   Apache CouchDB 2.3.0 - Cross-Site Scripting 14 WEB Ozer Goker
2019-02-18   Webiness Inventory 2.3 - 'ProductModel' Arbitrary File Upload 15 WEB Mehmet EMIROGLU
2019-02-18   M/Monit 3.7.2 - Privilege Escalation 14 WEB Dolev Farhi
2019-02-18   CMSsite 1.0 - 'post' SQL Injection 15 WEB Mr Winst0n
2019-02-18   MISP 2.4.97 - SQL Command Execution via Command Injection in STIX Module 13 WEB Tm9jdGlz
2019-02-18   Master IP CAM 01 3.3.4.2103 - Remote Command Execution 13 WEB Raffaele Sabato
2019-02-18   qdPM 9.1 - 'search[keywords]' Cross-Site Scripting 13 WEB Mehmet EMIROGLU
2019-02-18   qdPM 9.1 - 'type' Cross-Site Scripting 11 WEB Mehmet EMIROGLU
2019-02-15   UniSharp Laravel File Manager 2.0.0-alpha7 - Arbitrary File Upload 15 WEB Mohammad Danish
2019-02-15   qdPM 9.1 - 'search_by_extrafields[]' SQL Injection 15 WEB Mehmet EMIROGLU
2019-02-15   Jinja2 2.10 - 'from_string' Server Side Template Injection 15 WEB JameelNabbo
2019-02-15   MyBB Trash Bin Plugin 1.1.3 - Cross-Site Scripting / Cross-Site Request Forgery 12 WEB 0xB9
2019-02-15   MyBB Trash Bin Plugin 1.1.3 - Cross-Site Scripting / Cross-Site Request Forgery 14 WEB 0xB9
2019-02-14   LayerBB 1.1.2 - Cross-Site Request Forgery (Add Admin) 16 WEB 0xB9
2019-02-14   WordPress Plugin Booking Calendar 8.4.3 - (Authenticated) SQL Injection 14 WEB B0UG
2019-02-14   DomainMOD 4.11.01 - 'assets/edit/host.php?whid=5' Cross-Site Scripting 14 WEB Mohammed Abdul Kareem
2019-02-14   DomainMOD 4.11.01 - 'assets/add/dns.php' Cross-Site Scripting 14 WEB Mohammed Abdul Kareem
2019-02-14   DomainMOD 4.11.01 - 'category.php CatagoryName_ StakeHolder' Cross-Site Scripting 12 WEB Mohammed Abdul Raheem
2019-02-14   DomainMOD 4.11.01 - 'ssl-accounts.php username' Cross-Site Scripting 12 WEB Mohammed Abdul Raheem
2019-02-14   DomainMOD 4.11.01 - 'ssl-provider-name' Cross-Site Scripting 14 WEB Mohammed Abdul Raheem
2019-02-13   PilusCart 1.4.1 - 'send' SQL Injection 18 WEB Mehmet EMIROGLU
2019-02-13   Rukovoditel Project Management CRM 2.4.1 - Cross-Site Scripting 16 WEB Mehmet EMIROGLU
2019-02-12   LayerBB 1.1.2 - Cross-Site Scripting 17 WEB 0xB9
2019-02-12   BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution 13 WEB Dustin Cobb
2019-02-12   Jenkins 2.150.2 - Remote Command Execution (Metasploit) 13 WEB AkkuS
2019-02-12   OPNsense < 19.1.1 - Cross-Site Scripting 16 WEB Ozer Goker
2019-02-11   Webiness Inventory 2.3 - 'email' SQL Injection 13 WEB Mehmet EMIROGLU
2019-02-11   CentOS Web Panel 0.9.8.763 - Persistent Cross-Site Scripting 15 WEB DKM
2019-02-11   VA MAX 8.3.4 - (Authenticated) Remote Code Execution 13 WEB Cody Sixteen
2019-02-11   MyBB Bans List 1.0 - Cross-Site Scripting 14 WEB 0xB9
2019-02-11   IPFire 2.21 - Cross-Site Scripting 12 WEB Ozer Goker
2019-02-11   Coship Wireless Router 4.0.0.x/5.0.0.x - WiFi Password Reset 12 WEB Adithyan AK
2019-02-11   Smoothwall Express 3.1-SP4 - Cross-Site Scripting 11 WEB Ozer Goker
2019-02-06   osCommerce 2.3.4.1 - 'reviews_id' SQL Injection 13 WEB Mehmet EMIROGLU
2019-02-06   osCommerce 2.3.4.1 - 'products_id' SQL Injection 16 WEB Mehmet EMIROGLU
2019-02-06   osCommerce 2.3.4.1 - 'currency' SQL Injection 13 WEB Mehmet EMIROGLU
2019-02-05   OpenMRS Platform < 2.24.0 - Insecure Object Deserialization 17 WEB Bishop Fox
2019-02-05   Zyxel VMG3312-B10B DSL-491HNU-B1B v2 Modem - Cross-Site Request Forgery 13 WEB Yusuf Furkan
2019-02-05   devolo dLAN 550 duo+ Starter Kit - Remote Code Execution 14 WEB sm
2019-02-05   devolo dLAN 550 duo+ Starter Kit - Cross-Site Request Forgery 12 WEB sm
2019-02-05   BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure 13 WEB LiquidWorm
2019-02-05   BEWARD N100 H.264 VGA IP Camera M2.1.6 - Remote Code Execution 11 WEB LiquidWorm
2019-02-05   BEWARD N100 H.264 VGA IP Camera M2.1.6 - Cross-Site Request Forgery (Add Admin) 10 WEB LiquidWorm
2019-02-05   BEWARD N100 H.264 VGA IP Camera M2.1.6 - RTSP Stream Disclosure 10 WEB LiquidWorm
2019-02-04   pfSense 2.4.4-p1 - Cross-Site Scripting 14 WEB Ozer Goker
2019-02-04   Nessus 8.2.1 - Cross-Site Scripting 12 WEB Ozer Goker
2019-02-04   SuiteCRM 7.10.7 - 'record' SQL Injection 14 WEB Mehmet EMIROGLU
2019-02-04   SuiteCRM 7.10.7 - 'parentTab' SQL Injection 12 WEB Mehmet EMIROGLU
2019-02-04   ResourceSpace 8.6 - 'watched_searches.php' SQL Injection 11 WEB dd_
2019-02-01   SureMDM < 2018-11 Patch - Local / Remote File Inclusion 12 WEB Digital Interruption
2019-01-30   Rukovoditel Project Management CRM 2.4.1 - 'lists_id' SQL Injection 14 WEB Mehmet EMIROGLU
2019-01-29   PDF Signer 3.0 - Server-Side Template Injection leading to Remote Command Execution (via Cross-Site 13 WEB dd_
2019-01-28   ResourceSpace 8.6 - 'collection_edit.php' SQL Injection 13 WEB dd_
2019-01-28   MyBB IP History Logs Plugin 1.0.2 - Cross-Site Scripting 13 WEB 0xB9
2019-01-28   Mess Management System 1.0 - SQL Injection 10 WEB Ihsan Sencan
2019-01-28   Teameyo Project Management System 1.0 - SQL Injection 11 WEB Ihsan Sencan
2019-01-28   Care2x 2.7 (HIS) Hospital Information System - Multiple SQL Injection 12 WEB Carlos Avila
2019-01-28   Newsbull Haber Script 1.0.0 - 'search' SQL Injection 12 WEB Mehmet EMIROGLU
2019-01-28   Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting 13 WEB Bhushan B. Patil
2019-01-28   Cisco RV300 / RV320 - Information Disclosure 12 WEB Harom Ramos
2019-01-28   CMSsite 1.0 - 'search' SQL Injection 16 WEB Majid kalantari
2019-01-28   CMSsite 1.0 - 'cat_id' SQL Injection 12 WEB Majid kalantari
2019-01-28   LogonBox Limited / Hypersocket Nervepoint Access Manager - (Unauthenticated) Insecure Direct Object 11 WEB 0v3rride
2019-01-28   AirTies Air5341 Modem 1.0.0.12 - Cross-Site Request Forgery 11 WEB Ali Can Gönüllü
2019-01-28   WordPress Plugin Ad Manager WD 1.0.11 - Arbitrary File Download 14 WEB 41!kh4224rDz
2019-01-28   Rundeck Community Edition < 3.0.13 - Persistent Cross-Site Scripting 18 WEB Ishaq Mohammed
2019-01-25   WordPress Plugin Wisechat 2.6.3 - Reverse Tabnabbing 14 WEB MTK
2019-01-25   GreenCMS 2.x - Arbitrary File Download 11 WEB Ihsan Sencan
2019-01-25   GreenCMS 2.x - SQL Injection 14 WEB Ihsan Sencan
2019-01-25   Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection 12 WEB RedTeam Pentesting
2019-01-24   Zyxel NBG-418N v2 Modem 1.00(AAXM.6)C0 - Cross-Site Request Forgery 12 WEB Ali Can Gönüllü
2019-01-24   ImpressCMS 1.3.11 - 'bid' SQL Injection 14 WEB Mehmet Onder
2019-01-24   Splunk Enterprise 7.2.3 - (Authenticated) Custom App Remote Code Execution 12 WEB Lee Mazzoleni
2019-01-24   SirsiDynix e-Library 3.5.x - Cross-Site Scripting 13 WEB AkkuS
2019-01-24   SimplePress CMS 1.0.7 - SQL Injection 13 WEB Ihsan Sencan
2019-01-24   Joomla! Component JHotelReservation 6.0.7 - SQL Injection 11 WEB Ihsan Sencan
2019-01-24   Joomla! Component J-CruisePortal 6.0.4 - SQL Injection 12 WEB Ihsan Sencan
2019-01-23   Joomla! Component JMultipleHotelReservation 6.0.7 - SQL Injection 11 WEB Ihsan Sencan
2019-01-23   Joomla! Component J-ClassifiedsManager 3.0.5 - SQL Injection 10 WEB Ihsan Sencan
2019-01-23   Joomla! Component J-BusinessDirectory 4.9.7 - 'type' SQL Injection 12 WEB Ihsan Sencan
2019-01-23   Joomla! Component VMap 1.9.6 - SQL Injection 14 WEB Ihsan Sencan
2019-01-23   Joomla! Component vRestaurant 1.9.4 - SQL Injection 9 WEB Ihsan Sencan
2019-01-23   Joomla! Component vReview 1.9.11 - SQL Injection 13 WEB Ihsan Sencan