Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2019-01-23   Joomla! Component vAccount 2.0.2 - 'vid' SQL Injection 11 WEB Ihsan Sencan
2019-01-23   Joomla! Component vWishlist 1.0.1 - SQL Injection 14 WEB Ihsan Sencan
2019-01-23   Joomla! Component vBizz 1.0.7 - Remote Code Execution 10 WEB Ihsan Sencan
2019-01-23   Joomla! Component vBizz 1.0.7 - SQL Injection 14 WEB Ihsan Sencan
2019-01-23   Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation 12 WEB Chris Lyne
2019-01-22   Joomla! Component Easy Shop 1.2.3 - Local File Inclusion 13 WEB Ihsan Sencan
2019-01-21   Adianti Framework 5.5.0 - SQL Injection 13 WEB Joner de Mello Assolin
2019-01-21   PHP Uber-style GeoTracking 1.1 - SQL Injection 10 WEB Ihsan Sencan
2019-01-21   PHP Dashboards NEW 5.8 - Local File Inclusion 13 WEB Ihsan Sencan
2019-01-21   PHP Dashboards NEW 5.8 - 'dashID' SQL Injection 14 WEB Ihsan Sencan
2019-01-21   MoneyFlux 1.0 - 'id' SQL Injection 13 WEB Ihsan Sencan
2019-01-21   Reservic 1.0 - 'id' SQL Injection 12 WEB Ihsan Sencan
2019-01-21   Coman 1.0 - 'id' SQL Injection 14 WEB Ihsan Sencan
2019-01-21   Kepler Wallpaper Script 1.1 - SQL Injection 17 WEB Ihsan Sencan
2019-01-18   Pydio / AjaXplorer < 5.0.4 - (Unauthenticated) Arbitrary File Upload 24 WEB _jazz______
2019-01-18   Joomla! Core 3.9.1 - Persistent Cross-Site Scripting in Global Configuration Textfilter Settings 16 WEB Praveen Sutar
2019-01-18   phpTransformer 2016.9 - Directory Traversal 12 WEB Ihsan Sencan
2019-01-18   phpTransformer 2016.9 - SQL Injection 11 WEB Ihsan Sencan
2019-01-18   SeoToaster Ecommerce / CRM / CMS 3.0.0 - Local File Inclusion 13 WEB Ihsan Sencan
2019-01-17   Oracle Reports Developer Component 12.2.1.3 - Cross-site Scripting 12 WEB Mohamed M.Fouad
2019-01-16   Blueimp's jQuery File Upload 9.22.0 - Arbitrary File Upload Exploit 10 WEB Larry W. Cashdollar
2019-01-16   Coship Wireless Router 4.0.0.48 / 4.0.0.40 / 5.0.0.54 / 5.0.0.55 / 10.0.0.49 - Unauthenticated Admin 12 WEB Adithyan AK
2019-01-16   GL-AR300M-Lite 2.27 - (Authenticated) Command Injection / Arbitrary File Download / Directory Traver 14 WEB Pasquale Turi
2019-01-16   GL-AR300M-Lite 2.27 - (Authenticated) Command Injection / Arbitrary File Download / Directory Traver 11 WEB Pasquale Turi
2019-01-16   ShoreTel / Mitel Connect ONSITE 19.49.5200.0 - Remote Code Execution 11 WEB twosevenzero
2019-01-16   doorGets CMS 7.0 - Arbitrary File Download 11 WEB Ihsan Sencan
2019-01-16   Roxy Fileman 1.4.5 - Arbitrary File Download 10 WEB Ihsan Sencan
2019-01-16   Fortinet FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure 13 WEB Julio Ureña
2019-01-15   ownDMS 4.7 - SQL Injection 14 WEB Ihsan Sencan
2019-01-14   AudioCode 400HD - Command Injection 12 WEB Sysdream
2019-01-14   Portier Vision 4.4.4.2 / 4.4.4.6 - SQL Injection 12 WEB SySS GmbH
2019-01-14   Bigcart - Ecommerce Multivendor System 1.0 - SQL Injection 11 WEB Ihsan Sencan
2019-01-14   Umbraco CMS 7.12.4 - (Authenticated) Remote Code Execution 11 WEB Gregory Draperi
2019-01-14   Job Portal Platform 1.0 - SQL Injection 8 WEB Ihsan Sencan
2019-01-14   Real Estate Custom Script 2.0 - SQL Injection 14 WEB Ihsan Sencan
2019-01-14   ThinkPHP 5.X - Remote Command Execution 9 WEB vr_system
2019-01-14   Hucart CMS 5.7.4 - Cross-Site Request Forgery (Add Administrator Account) 10 WEB AllenChen
2019-01-14   HealthNode Hospital Management System 1.0 - SQL Injection 13 WEB Ihsan Sencan
2019-01-14   Lenovo R2105 - Cross-Site Request Forgery (Command Execution) 14 WEB Nathu Nandwani
2019-01-14   Cleanto 5.0 - SQL Injection 11 WEB Ihsan Sencan
2019-01-14   Find a Place CMS Directory 1.5 - SQL Injection 11 WEB Ihsan Sencan
2019-01-14   Craigs Classified Ads CMS Theme 1.0.2 - SQL Injection 10 WEB Ihsan Sencan
2019-01-14   Live Call Support Widget 1.5 - Remote Code Execution / SQL Injection 11 WEB Ihsan Sencan
2019-01-14   Live Call Support Widget 1.5 - Cross-Site Request Forgery (Add Admin) 11 WEB Ihsan Sencan
2019-01-14   Twilio WEB To Fax Machine System Application 1.0 - SQL Injection 14 WEB Ihsan Sencan
2019-01-14   Modern POS 1.3 - SQL Injection 11 WEB Ihsan Sencan
2019-01-14   Modern POS 1.3 - Arbitrary File Download 10 WEB Ihsan Sencan
2019-01-14   Horde Imp - 'imap_open' Remote Command Execution 8 WEB Paolo Serracino_ Pietro Minniti_ Damiano Proietti
2019-01-14   i-doit CMDB 1.12 - SQL Injection 13 WEB Ihsan Sencan
2019-01-14   i-doit CMDB 1.12 - Arbitrary File Download 10 WEB Ihsan Sencan
2019-01-14   Across DR-810 ROM-0 - Backup File Disclosure 14 WEB SajjadBnd
2019-01-11   Joomla! Component JoomCRM 1.1.1 - SQL Injection 14 WEB Ihsan Sencan
2019-01-11   Joomla! Component JoomProject 1.1.3.2 - Information Disclosure 13 WEB Ihsan Sencan
2019-01-11   Adapt Inventory Management System 1.0 - SQL Injection 12 WEB Ihsan Sencan
2019-01-10   OpenSource ERP 6.3.1. - SQL Injection 15 WEB Emre ÖVÜNÇ
2019-01-10   eBrigade ERP 4.5 - SQL Injection 12 WEB Ihsan Sencan
2019-01-10   Event Locations 1.0.1 - 'id' SQL Injection 11 WEB Ihsan Sencan
2019-01-10   Event Calendar 3.7.4 - 'id' SQL Injection 11 WEB Ihsan Sencan
2019-01-10   MLMPro 1.0 - SQL Injection 13 WEB Ihsan Sencan
2019-01-10   Architectural 1.0 - 'email' SQL Injection 13 WEB Ihsan Sencan
2019-01-10   Shield CMS 2.2 - 'email' SQL Injection 13 WEB Ihsan Sencan
2019-01-10   doitX 1.0 - 'search' SQL Injection 10 WEB Ihsan Sencan
2019-01-10   Matrix MLM Script 1.0 - Information Disclosure 10 WEB Ihsan Sencan
2019-01-10   eBrigade ERP 4.5 - Arbitrary File Download 12 WEB AkkuS
2019-01-10   PEAR Archive_Tar < 1.4.4 - PHP Object Injection 12 WEB Fariskhi Vidyan
2019-01-09   BlogEngine 3.3 - XML External Entity Injection 13 WEB Netsparker
2019-01-09   ZTE MF65 BD_HDV6MF65V1.0.0B05 - Cross-Site Scripting 19 WEB Nathu Nandwani
2019-01-09   Heatmiser Wifi Thermostat 1.7 - Cross-Site Request Forgery (Update Admin) 13 WEB SajjadBnd
2017-03-02   MDwiki < 0.6.2 - Cross-Site Scripting 11 WEB evi1m0
2019-01-08   Dolibarr ERP-CRM 8.0.4 - 'rowid' SQL Injection 12 WEB Mehmet Onder
2019-01-08   CF Image Hosting Script 1.6.5 - (Delete all Pictures) Privilege Escalation 12 WEB David Tavarez
2019-01-07   Huawei E5330 21.210.09.00.158 - Cross-Site Request Forgery (Send SMS) 13 WEB Nathu Nandwani
2019-01-07   Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 - JS/HTML Code Injection 14 WEB LiquidWorm
2019-01-07   Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 - Cross-Site Request Forgery 13 WEB LiquidWorm
2019-01-07   Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data 11 WEB Anthony Cole
2019-01-07   Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal 11 WEB Pongtorn Angsuchotmetee_ Vittawat Masaree
2019-01-07   MyT Project Management 1.5.1 - 'Charge[group_total]' SQL Injection 11 WEB Mehmet Onder
2019-01-07   WordPress Plugin UserPro < 4.9.21 - User Registration Privilege Escalation 14 WEB Noman Riffat
2019-01-07   phpMoAdmin MongoDB GUI 1.1.5 - Cross-Site Request Forgery / Cross-Site Scripting 10 WEB Ozer Goker
2019-01-07   phpMoAdmin MongoDB GUI 1.1.5 - Cross-Site Request Forgery / Cross-Site Scripting 9 WEB Ozer Goker
2019-01-07   PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Scripting 11 WEB Kumar Saurav
2019-01-07   MyBB OUGC Awards Plugin 1.8.3 - Persistent Cross-Site Scripting 11 WEB 0xB9
2019-01-07   LayerBB 1.1.1 - Persistent Cross-Site Scripting 13 WEB 0xB9
2019-01-07   All in One Video Downloader 1.2 - (Authenticated) SQL Injection 10 WEB Deyaa Muhammad
2019-01-07   Embed Video Scripts - Persistent Cross-Site Scripting 10 WEB Deyaa Muhammad
2019-01-02   Frog CMS 0.9.5 - Cross-Site Scripting 13 WEB WangDudu
2019-01-02   WordPress Plugin Adicon Server 1.2 - 'selectedPlace' SQL Injection 13 WEB Kaimi
2019-01-02   Vtiger CRM 7.1.0 - Remote Code Execution 10 WEB AkkuS
2018-12-27   WordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File Upload 13 WEB Kaimi
2018-12-27   bludit Pages Editor 3.0.0 - Arbitrary File Upload 10 WEB BouSalman
2018-12-27   WordPress Plugin Audio Record 1.0 - Arbitrary File Upload 11 WEB Kaimi
2018-12-27   Craft CMS 3.0.25 - Cross-Site Scripting 10 WEB Raif Berkay Dincel
2018-11-30   PhpSpreadsheet < 1.5.0 - XML External Entity (XXE) 11 WEB Alex Leahu
2018-12-15   phpMyAdmin 4.8.4 - 'AllowArbitraryServer' Arbitrary File Read 12 WEB VulnSpy
2018-12-24   FrontAccounting 2.4.5 - 'SubmitUser' SQL Injection 12 WEB Sainadh Jamalpur
2018-12-24   WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin) 11 WEB linfeng
2018-12-24   WSTMart 2.0.8 - Cross-Site Scripting 9 WEB linfeng
2018-12-21   ZeusCart 4.0 - Cross-Site Request Forgery (Deactivate Customer Accounts) 9 WEB mqt
2018-12-19   IBM Operational Decision Manager 8.x - XML External Entity Injection 13 WEB Mohamed M.Fouad
2018-12-19   Yeswiki Cercopitheque - 'id' SQL Injection 8 WEB Mickael BROUTY
2018-12-19   Bolt CMS < 3.6.2 - Cross-Site Scripting 9 WEB Raif Berkay Dincel
2018-12-19   Integria IMS 5.0.83 - Cross-Site Request Forgery 10 WEB Javier Olmedo
2018-12-19   Integria IMS 5.0.83 - 'search_string' Cross-Site Scripting 11 WEB Javier Olmedo
2018-12-19   Rukovoditel Project Management CRM 2.3.1 - Remote Code Execution (Metasploit) 11 WEB AkkuS
2018-12-19   Hotel Booking Script 3.4 - Cross-Site Request Forgery (Change Admin Password) 10 WEB Sainadh Jamalpur
2018-12-18   SDL Web Content Manager 8.5.0 - XML External Entity Injection 8 WEB Ahmed Elhady Mohamed
2018-12-14   Double Your Bitcoin Script Automatic - Authentication Bypass 11 WEB Veyselxan
2018-12-14   Facebook And Google Reviews System For Businesses 1.1 - Remote Code Execution 13 WEB Ihsan Sencan
2018-12-14   Facebook And Google Reviews System For Businesses 1.1 - SQL Injection 10 WEB Ihsan Sencan
2018-12-14   Facebook And Google Reviews System For Businesses - Cross-Site Request Forgery (Change Admin Passwor 10 WEB Veyselxan
2018-12-14   Huawei Router HG532e - Command Execution 12 WEB Rebellion
2018-12-14   Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2) 13 WEB alt3kx
2018-12-14   Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure 12 WEB alt3kx
2018-12-14   Responsive FileManager 9.13.4 - Multiple Vulnerabilities 12 WEB Fariskhi Vidyan
2018-12-11   Adobe ColdFusion 2018 - Arbitrary File Upload 12 WEB Vahagn Vardanyan
2018-12-11   ThinkPHP 5.0.23/5.1.31 - Remote Code Execution 10 WEB VulnSpy
2018-12-11   WordPress Plugin AutoSuggest 0.24 - 'wpas_keys' SQL Injection 8 WEB Kaimi
2018-12-11   HotelDruid 2.3.0 - 'id_utente_mod' SQL Injection 11 WEB Sainadh Jamalpur
2018-12-11   Apache OFBiz 16.11.05 - Cross-Site Scripting 10 WEB DKM
2014-02-17   IceWarp Mail Server 11.0.0.0 - Cross-Site Scripting 10 WEB Usman Saeed
2017-05-05   Sitecore CMS 8.2 - Cross-Site Scripting / Arbitrary File Disclosure 11 WEB Usman Saeed
2018-12-11   ZTE ZXHN H168N - Improper Access Restrictions 10 WEB Usman Saeed
2018-12-11   Huawei B315s-22 - Information Leak 10 WEB Usman Saeed
2018-12-11   TP-Link wireless router Archer C1200 - Cross-Site Scripting 10 WEB Usman Saeed
2018-12-11   PrinterOn Enterprise 4.1.4 - Arbitrary File Deletion 10 WEB bzyo