|
2019-03-04
|
|
Raisecom XPON ISCOMHT803G-U_2.0.0_140521_R4.1.47.002 - Remote Code Execution
|
15 |
WEB
|
JameelNabbo
|
|
2019-03-04
|
|
zzzphp CMS 1.6.1 - Cross-Site Request Forgery
|
16 |
WEB
|
Yang Chenglong
|
|
2019-03-04
|
|
Splunk Enterprise 7.2.4 - Custom App Remote Command Execution (Persistent Backdoor / Custom Binary)
|
19 |
WEB
|
Matteo Malvica
|
|
2019-03-04
|
|
Booked Scheduler 2.7.5 - Remote Command Execution (Metasploit)
|
12 |
WEB
|
AkkuS
|
|
2019-03-04
|
|
OOP CMS BLOG 1.0 - Multiple Cross-Site Request Forgery
|
12 |
WEB
|
Mr Winst0n
|
|
2019-03-04
|
|
OOP CMS BLOG 1.0 - Multiple SQL Injection
|
10 |
WEB
|
Mr Winst0n
|
|
2019-03-04
|
|
elFinder 2.1.47 - 'PHP connector' Command Injection
|
12 |
WEB
|
q3rv0
|
|
2019-03-04
|
|
CMSsite 1.0 - Multiple Cross-Site Request Forgery
|
9 |
WEB
|
Mr Winst0n
|
|
2019-02-28
|
|
Feng Office 3.7.0.5 - Remote Command Execution (Metasploit)
|
16 |
WEB
|
AkkuS
|
|
2019-02-28
|
|
Usermin 1.750 - Remote Command Execution (Metasploit)
|
13 |
WEB
|
AkkuS
|
|
2019-02-28
|
|
Joomla! Component J2Store < 3.3.7 - SQL Injection
|
14 |
WEB
|
Andrei Conache
|
|
2019-02-28
|
|
Simple Online Hotel Reservation System - Cross-Site Request Forgery (Delete Admin)
|
14 |
WEB
|
Mr Winst0n
|
|
2019-02-28
|
|
Simple Online Hotel Reservation System - Cross-Site Request Forgery (Add Admin)
|
10 |
WEB
|
Mr Winst0n
|
|
2019-02-28
|
|
Simple Online Hotel Reservation System - SQL Injection
|
8 |
WEB
|
Mr Winst0n
|
|
2019-02-25
|
|
Drupal < 8.6.9 - REST Module Remote Code Execution
|
15 |
WEB
|
leonjza
|
|
2019-02-25
|
|
Advance Gift Shop Pro Script 2.0.3 - SQL Injection
|
14 |
WEB
|
Mr Winst0n
|
|
2019-02-25
|
|
News Website Script 2.0.5 - SQL Injection
|
10 |
WEB
|
Mr Winst0n
|
|
2019-02-25
|
|
PHP Ecommerce Script 2.0.6 - Cross-Site Scripting / SQL Injection
|
10 |
WEB
|
Mr Winst0n
|
|
2019-02-25
|
|
zzzphp CMS 1.6.1 - Remote Code Execution
|
10 |
WEB
|
Yang Chenglong
|
|
2019-02-25
|
|
Jenkins Plugin Script Security 1.49/Declarative 1.3.4/Groovy 2.60 - Remote Code Execution
|
10 |
WEB
|
wetw0rk
|
|
2019-02-23
|
|
Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution
|
10 |
WEB
|
Charles Fol
|
|
2019-02-22
|
|
Teracue ENC-400 - Command Injection / Missing Authentication
|
9 |
WEB
|
Stephen Shkardoon
|
|
2019-02-22
|
|
Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation
|
12 |
WEB
|
SecureAuth
|
|
2019-02-22
|
|
Quest NetVault Backup Server < 11.4.5 - Process Manager Service SQL Injection / Remote Code Executio
|
16 |
WEB
|
Chris Anastasio
|
|
2019-02-21
|
|
EI-Tube 3 - SQL Injection
|
11 |
WEB
|
Meisam Monsef
|
|
2019-02-21
|
|
C4G Basic Laboratory Information System (BLIS) 3.4 - SQL Injection
|
13 |
WEB
|
Carlos Avila
|
|
2019-02-20
|
|
HotelDruid 2.3 - Cross-Site Scripting
|
14 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-19
|
|
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution
|
12 |
WEB
|
orange
|
|
2019-02-19
|
|
Ask Expert Script 3.0.5 - Cross Site Scripting / SQL Injection
|
12 |
WEB
|
Mr Winst0n
|
|
2019-02-19
|
|
Ask Expert Script 3.0.5 - Cross Site Scripting / SQL Injection
|
11 |
WEB
|
Mr Winst0n
|
|
2019-02-19
|
|
Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting
|
11 |
WEB
|
Rafael Pedrero
|
|
2019-02-19
|
|
Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting
|
11 |
WEB
|
Rafael Pedrero
|
|
2019-02-19
|
|
XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting
|
13 |
WEB
|
Rafael Pedrero
|
|
2019-02-19
|
|
XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting
|
12 |
WEB
|
Rafael Pedrero
|
|
2019-02-19
|
|
eDirectory - SQL Injection
|
12 |
WEB
|
Efrén Díaz
|
|
2019-02-19
|
|
Zuz Music 2.1 - 'zuzconsole/___contact ' Persistent Cross-Site Scripting
|
15 |
WEB
|
Deyaa Muhammad
|
|
2019-02-19
|
|
Listing Hub CMS 1.0 - 'pages.php id' SQL Injection
|
12 |
WEB
|
Deyaa Muhammad
|
|
2019-02-19
|
|
Find a Place CMS Directory 1.5 - 'assets/external/data_2.php cate' SQL Injection
|
13 |
WEB
|
Deyaa Muhammad
|
|
2019-02-18
|
|
WordPress Plugin WooCommerce - GloBee (cryptocurrency) Payment Gateway 1.1.1 - Payment Bypass / Unau
|
10 |
WEB
|
GeekHack
|
|
2019-02-18
|
|
Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Upload
|
14 |
WEB
|
Dao Duy Hung
|
|
2019-02-18
|
|
Comodo Dome Firewall 2.7.0 - Cross-Site Scripting
|
16 |
WEB
|
Ozer Goker
|
|
2019-02-18
|
|
ArangoDB Community Edition 3.4.2-1 - Cross-Site Scripting
|
12 |
WEB
|
Ozer Goker
|
|
2019-02-18
|
|
Apache CouchDB 2.3.0 - Cross-Site Scripting
|
14 |
WEB
|
Ozer Goker
|
|
2019-02-18
|
|
Webiness Inventory 2.3 - 'ProductModel' Arbitrary File Upload
|
15 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-18
|
|
M/Monit 3.7.2 - Privilege Escalation
|
14 |
WEB
|
Dolev Farhi
|
|
2019-02-18
|
|
CMSsite 1.0 - 'post' SQL Injection
|
15 |
WEB
|
Mr Winst0n
|
|
2019-02-18
|
|
MISP 2.4.97 - SQL Command Execution via Command Injection in STIX Module
|
13 |
WEB
|
Tm9jdGlz
|
|
2019-02-18
|
|
Master IP CAM 01 3.3.4.2103 - Remote Command Execution
|
13 |
WEB
|
Raffaele Sabato
|
|
2019-02-18
|
|
qdPM 9.1 - 'search[keywords]' Cross-Site Scripting
|
13 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-18
|
|
qdPM 9.1 - 'type' Cross-Site Scripting
|
11 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-15
|
|
UniSharp Laravel File Manager 2.0.0-alpha7 - Arbitrary File Upload
|
15 |
WEB
|
Mohammad Danish
|
|
2019-02-15
|
|
qdPM 9.1 - 'search_by_extrafields[]' SQL Injection
|
15 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-15
|
|
Jinja2 2.10 - 'from_string' Server Side Template Injection
|
15 |
WEB
|
JameelNabbo
|
|
2019-02-15
|
|
MyBB Trash Bin Plugin 1.1.3 - Cross-Site Scripting / Cross-Site Request Forgery
|
12 |
WEB
|
0xB9
|
|
2019-02-15
|
|
MyBB Trash Bin Plugin 1.1.3 - Cross-Site Scripting / Cross-Site Request Forgery
|
14 |
WEB
|
0xB9
|
|
2019-02-14
|
|
LayerBB 1.1.2 - Cross-Site Request Forgery (Add Admin)
|
16 |
WEB
|
0xB9
|
|
2019-02-14
|
|
WordPress Plugin Booking Calendar 8.4.3 - (Authenticated) SQL Injection
|
14 |
WEB
|
B0UG
|
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'assets/edit/host.php?whid=5' Cross-Site Scripting
|
14 |
WEB
|
Mohammed Abdul Kareem
|
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'assets/add/dns.php' Cross-Site Scripting
|
14 |
WEB
|
Mohammed Abdul Kareem
|
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'category.php CatagoryName_ StakeHolder' Cross-Site Scripting
|
12 |
WEB
|
Mohammed Abdul Raheem
|
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'ssl-accounts.php username' Cross-Site Scripting
|
12 |
WEB
|
Mohammed Abdul Raheem
|
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'ssl-provider-name' Cross-Site Scripting
|
14 |
WEB
|
Mohammed Abdul Raheem
|
|
2019-02-13
|
|
PilusCart 1.4.1 - 'send' SQL Injection
|
18 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-13
|
|
Rukovoditel Project Management CRM 2.4.1 - Cross-Site Scripting
|
16 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-12
|
|
LayerBB 1.1.2 - Cross-Site Scripting
|
17 |
WEB
|
0xB9
|
|
2019-02-12
|
|
BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution
|
13 |
WEB
|
Dustin Cobb
|
|
2019-02-12
|
|
Jenkins 2.150.2 - Remote Command Execution (Metasploit)
|
13 |
WEB
|
AkkuS
|
|
2019-02-12
|
|
OPNsense < 19.1.1 - Cross-Site Scripting
|
16 |
WEB
|
Ozer Goker
|
|
2019-02-11
|
|
Webiness Inventory 2.3 - 'email' SQL Injection
|
13 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-11
|
|
CentOS Web Panel 0.9.8.763 - Persistent Cross-Site Scripting
|
15 |
WEB
|
DKM
|
|
2019-02-11
|
|
VA MAX 8.3.4 - (Authenticated) Remote Code Execution
|
13 |
WEB
|
Cody Sixteen
|
|
2019-02-11
|
|
MyBB Bans List 1.0 - Cross-Site Scripting
|
14 |
WEB
|
0xB9
|
|
2019-02-11
|
|
IPFire 2.21 - Cross-Site Scripting
|
12 |
WEB
|
Ozer Goker
|
|
2019-02-11
|
|
Coship Wireless Router 4.0.0.x/5.0.0.x - WiFi Password Reset
|
12 |
WEB
|
Adithyan AK
|
|
2019-02-11
|
|
Smoothwall Express 3.1-SP4 - Cross-Site Scripting
|
11 |
WEB
|
Ozer Goker
|
|
2019-02-06
|
|
osCommerce 2.3.4.1 - 'reviews_id' SQL Injection
|
13 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-06
|
|
osCommerce 2.3.4.1 - 'products_id' SQL Injection
|
16 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-06
|
|
osCommerce 2.3.4.1 - 'currency' SQL Injection
|
13 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-05
|
|
OpenMRS Platform < 2.24.0 - Insecure Object Deserialization
|
17 |
WEB
|
Bishop Fox
|
|
2019-02-05
|
|
Zyxel VMG3312-B10B DSL-491HNU-B1B v2 Modem - Cross-Site Request Forgery
|
13 |
WEB
|
Yusuf Furkan
|
|
2019-02-05
|
|
devolo dLAN 550 duo+ Starter Kit - Remote Code Execution
|
14 |
WEB
|
sm
|
|
2019-02-05
|
|
devolo dLAN 550 duo+ Starter Kit - Cross-Site Request Forgery
|
12 |
WEB
|
sm
|
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure
|
13 |
WEB
|
LiquidWorm
|
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - Remote Code Execution
|
11 |
WEB
|
LiquidWorm
|
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - Cross-Site Request Forgery (Add Admin)
|
10 |
WEB
|
LiquidWorm
|
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - RTSP Stream Disclosure
|
10 |
WEB
|
LiquidWorm
|
|
2019-02-04
|
|
pfSense 2.4.4-p1 - Cross-Site Scripting
|
14 |
WEB
|
Ozer Goker
|
|
2019-02-04
|
|
Nessus 8.2.1 - Cross-Site Scripting
|
12 |
WEB
|
Ozer Goker
|
|
2019-02-04
|
|
SuiteCRM 7.10.7 - 'record' SQL Injection
|
14 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-04
|
|
SuiteCRM 7.10.7 - 'parentTab' SQL Injection
|
12 |
WEB
|
Mehmet EMIROGLU
|
|
2019-02-04
|
|
ResourceSpace 8.6 - 'watched_searches.php' SQL Injection
|
11 |
WEB
|
dd_
|
|
2019-02-01
|
|
SureMDM < 2018-11 Patch - Local / Remote File Inclusion
|
12 |
WEB
|
Digital Interruption
|
|
2019-01-30
|
|
Rukovoditel Project Management CRM 2.4.1 - 'lists_id' SQL Injection
|
14 |
WEB
|
Mehmet EMIROGLU
|
|
2019-01-29
|
|
PDF Signer 3.0 - Server-Side Template Injection leading to Remote Command Execution (via Cross-Site
|
13 |
WEB
|
dd_
|
|
2019-01-28
|
|
ResourceSpace 8.6 - 'collection_edit.php' SQL Injection
|
13 |
WEB
|
dd_
|
|
2019-01-28
|
|
MyBB IP History Logs Plugin 1.0.2 - Cross-Site Scripting
|
13 |
WEB
|
0xB9
|
|
2019-01-28
|
|
Mess Management System 1.0 - SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2019-01-28
|
|
Teameyo Project Management System 1.0 - SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2019-01-28
|
|
Care2x 2.7 (HIS) Hospital Information System - Multiple SQL Injection
|
12 |
WEB
|
Carlos Avila
|
|
2019-01-28
|
|
Newsbull Haber Script 1.0.0 - 'search' SQL Injection
|
12 |
WEB
|
Mehmet EMIROGLU
|
|
2019-01-28
|
|
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
|
13 |
WEB
|
Bhushan B. Patil
|
|
2019-01-28
|
|
Cisco RV300 / RV320 - Information Disclosure
|
12 |
WEB
|
Harom Ramos
|
|
2019-01-28
|
|
CMSsite 1.0 - 'search' SQL Injection
|
16 |
WEB
|
Majid kalantari
|
|
2019-01-28
|
|
CMSsite 1.0 - 'cat_id' SQL Injection
|
12 |
WEB
|
Majid kalantari
|
|
2019-01-28
|
|
LogonBox Limited / Hypersocket Nervepoint Access Manager - (Unauthenticated) Insecure Direct Object
|
11 |
WEB
|
0v3rride
|
|
2019-01-28
|
|
AirTies Air5341 Modem 1.0.0.12 - Cross-Site Request Forgery
|
11 |
WEB
|
Ali Can Gönüllü
|
|
2019-01-28
|
|
WordPress Plugin Ad Manager WD 1.0.11 - Arbitrary File Download
|
14 |
WEB
|
41!kh4224rDz
|
|
2019-01-28
|
|
Rundeck Community Edition < 3.0.13 - Persistent Cross-Site Scripting
|
18 |
WEB
|
Ishaq Mohammed
|
|
2019-01-25
|
|
WordPress Plugin Wisechat 2.6.3 - Reverse Tabnabbing
|
14 |
WEB
|
MTK
|
|
2019-01-25
|
|
GreenCMS 2.x - Arbitrary File Download
|
11 |
WEB
|
Ihsan Sencan
|
|
2019-01-25
|
|
GreenCMS 2.x - SQL Injection
|
14 |
WEB
|
Ihsan Sencan
|
|
2019-01-25
|
|
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
|
12 |
WEB
|
RedTeam Pentesting
|
|
2019-01-24
|
|
Zyxel NBG-418N v2 Modem 1.00(AAXM.6)C0 - Cross-Site Request Forgery
|
12 |
WEB
|
Ali Can Gönüllü
|
|
2019-01-24
|
|
ImpressCMS 1.3.11 - 'bid' SQL Injection
|
14 |
WEB
|
Mehmet Onder
|
|
2019-01-24
|
|
Splunk Enterprise 7.2.3 - (Authenticated) Custom App Remote Code Execution
|
12 |
WEB
|
Lee Mazzoleni
|
|
2019-01-24
|
|
SirsiDynix e-Library 3.5.x - Cross-Site Scripting
|
13 |
WEB
|
AkkuS
|
|
2019-01-24
|
|
SimplePress CMS 1.0.7 - SQL Injection
|
13 |
WEB
|
Ihsan Sencan
|
|
2019-01-24
|
|
Joomla! Component JHotelReservation 6.0.7 - SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2019-01-24
|
|
Joomla! Component J-CruisePortal 6.0.4 - SQL Injection
|
12 |
WEB
|
Ihsan Sencan
|
|
2019-01-23
|
|
Joomla! Component JMultipleHotelReservation 6.0.7 - SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2019-01-23
|
|
Joomla! Component J-ClassifiedsManager 3.0.5 - SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2019-01-23
|
|
Joomla! Component J-BusinessDirectory 4.9.7 - 'type' SQL Injection
|
12 |
WEB
|
Ihsan Sencan
|
|
2019-01-23
|
|
Joomla! Component VMap 1.9.6 - SQL Injection
|
14 |
WEB
|
Ihsan Sencan
|
|
2019-01-23
|
|
Joomla! Component vRestaurant 1.9.4 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2019-01-23
|
|
Joomla! Component vReview 1.9.11 - SQL Injection
|
13 |
WEB
|
Ihsan Sencan
|