Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2019-01-14   Live Call Support Widget 1.5 - Cross-Site Request Forgery (Add Admin) 30 WEB Ihsan Sencan
2019-01-14   Twilio WEB To Fax Machine System Application 1.0 - SQL Injection 39 WEB Ihsan Sencan
2019-01-14   Modern POS 1.3 - SQL Injection 29 WEB Ihsan Sencan
2019-01-14   Modern POS 1.3 - Arbitrary File Download 27 WEB Ihsan Sencan
2019-01-14   Horde Imp - 'imap_open' Remote Command Execution 28 WEB Paolo Serracino_ Pietro Minniti_ Damiano Proietti
2019-01-14   i-doit CMDB 1.12 - SQL Injection 30 WEB Ihsan Sencan
2019-01-14   i-doit CMDB 1.12 - Arbitrary File Download 27 WEB Ihsan Sencan
2019-01-14   Across DR-810 ROM-0 - Backup File Disclosure 32 WEB SajjadBnd
2019-01-11   Joomla! Component JoomCRM 1.1.1 - SQL Injection 33 WEB Ihsan Sencan
2019-01-11   Joomla! Component JoomProject 1.1.3.2 - Information Disclosure 30 WEB Ihsan Sencan
2019-01-11   Adapt Inventory Management System 1.0 - SQL Injection 29 WEB Ihsan Sencan
2019-01-10   OpenSource ERP 6.3.1. - SQL Injection 35 WEB Emre ÖVÜNÇ
2019-01-10   eBrigade ERP 4.5 - SQL Injection 30 WEB Ihsan Sencan
2019-01-10   Event Locations 1.0.1 - 'id' SQL Injection 35 WEB Ihsan Sencan
2019-01-10   Event Calendar 3.7.4 - 'id' SQL Injection 29 WEB Ihsan Sencan
2019-01-10   MLMPro 1.0 - SQL Injection 34 WEB Ihsan Sencan
2019-01-10   Architectural 1.0 - 'email' SQL Injection 32 WEB Ihsan Sencan
2019-01-10   Shield CMS 2.2 - 'email' SQL Injection 30 WEB Ihsan Sencan
2019-01-10   doitX 1.0 - 'search' SQL Injection 28 WEB Ihsan Sencan
2019-01-10   Matrix MLM Script 1.0 - Information Disclosure 28 WEB Ihsan Sencan
2019-01-10   eBrigade ERP 4.5 - Arbitrary File Download 36 WEB AkkuS
2019-01-10   PEAR Archive_Tar < 1.4.4 - PHP Object Injection 33 WEB Fariskhi Vidyan
2019-01-09   BlogEngine 3.3 - XML External Entity Injection 33 WEB Netsparker
2019-01-09   ZTE MF65 BD_HDV6MF65V1.0.0B05 - Cross-Site Scripting 37 WEB Nathu Nandwani
2019-01-09   Heatmiser Wifi Thermostat 1.7 - Cross-Site Request Forgery (Update Admin) 29 WEB SajjadBnd
2017-03-02   MDwiki < 0.6.2 - Cross-Site Scripting 29 WEB evi1m0
2019-01-08   Dolibarr ERP-CRM 8.0.4 - 'rowid' SQL Injection 29 WEB Mehmet Onder
2019-01-08   CF Image Hosting Script 1.6.5 - (Delete all Pictures) Privilege Escalation 31 WEB David Tavarez
2019-01-07   Huawei E5330 21.210.09.00.158 - Cross-Site Request Forgery (Send SMS) 32 WEB Nathu Nandwani
2019-01-07   Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 - JS/HTML Code Injection 35 WEB LiquidWorm
2019-01-07   Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 - Cross-Site Request Forgery 30 WEB LiquidWorm
2019-01-07   Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data 31 WEB Anthony Cole
2019-01-07   Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal 28 WEB Pongtorn Angsuchotmetee_ Vittawat Masaree
2019-01-07   MyT Project Management 1.5.1 - 'Charge[group_total]' SQL Injection 29 WEB Mehmet Onder
2019-01-07   WordPress Plugin UserPro < 4.9.21 - User Registration Privilege Escalation 28 WEB Noman Riffat
2019-01-07   phpMoAdmin MongoDB GUI 1.1.5 - Cross-Site Request Forgery / Cross-Site Scripting 28 WEB Ozer Goker
2019-01-07   phpMoAdmin MongoDB GUI 1.1.5 - Cross-Site Request Forgery / Cross-Site Scripting 27 WEB Ozer Goker
2019-01-07   PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Scripting 28 WEB Kumar Saurav
2019-01-07   MyBB OUGC Awards Plugin 1.8.3 - Persistent Cross-Site Scripting 27 WEB 0xB9
2019-01-07   LayerBB 1.1.1 - Persistent Cross-Site Scripting 35 WEB 0xB9
2019-01-07   All in One Video Downloader 1.2 - (Authenticated) SQL Injection 31 WEB Deyaa Muhammad
2019-01-07   Embed Video Scripts - Persistent Cross-Site Scripting 29 WEB Deyaa Muhammad
2019-01-02   Frog CMS 0.9.5 - Cross-Site Scripting 33 WEB WangDudu
2019-01-02   WordPress Plugin Adicon Server 1.2 - 'selectedPlace' SQL Injection 37 WEB Kaimi
2019-01-02   Vtiger CRM 7.1.0 - Remote Code Execution 32 WEB AkkuS
2018-12-27   WordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File Upload 34 WEB Kaimi
2018-12-27   bludit Pages Editor 3.0.0 - Arbitrary File Upload 32 WEB BouSalman
2018-12-27   WordPress Plugin Audio Record 1.0 - Arbitrary File Upload 26 WEB Kaimi
2018-12-27   Craft CMS 3.0.25 - Cross-Site Scripting 26 WEB Raif Berkay Dincel
2018-11-30   PhpSpreadsheet < 1.5.0 - XML External Entity (XXE) 30 WEB Alex Leahu
2018-12-15   phpMyAdmin 4.8.4 - 'AllowArbitraryServer' Arbitrary File Read 33 WEB VulnSpy
2018-12-24   FrontAccounting 2.4.5 - 'SubmitUser' SQL Injection 36 WEB Sainadh Jamalpur
2018-12-24   WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin) 32 WEB linfeng
2018-12-24   WSTMart 2.0.8 - Cross-Site Scripting 29 WEB linfeng
2018-12-21   ZeusCart 4.0 - Cross-Site Request Forgery (Deactivate Customer Accounts) 32 WEB mqt
2018-12-19   IBM Operational Decision Manager 8.x - XML External Entity Injection 29 WEB Mohamed M.Fouad
2018-12-19   Yeswiki Cercopitheque - 'id' SQL Injection 25 WEB Mickael BROUTY
2018-12-19   Bolt CMS < 3.6.2 - Cross-Site Scripting 27 WEB Raif Berkay Dincel
2018-12-19   Integria IMS 5.0.83 - Cross-Site Request Forgery 25 WEB Javier Olmedo
2018-12-19   Integria IMS 5.0.83 - 'search_string' Cross-Site Scripting 29 WEB Javier Olmedo
2018-12-19   Rukovoditel Project Management CRM 2.3.1 - Remote Code Execution (Metasploit) 27 WEB AkkuS
2018-12-19   Hotel Booking Script 3.4 - Cross-Site Request Forgery (Change Admin Password) 29 WEB Sainadh Jamalpur
2018-12-18   SDL Web Content Manager 8.5.0 - XML External Entity Injection 29 WEB Ahmed Elhady Mohamed
2018-12-14   Double Your Bitcoin Script Automatic - Authentication Bypass 30 WEB Veyselxan
2018-12-14   Facebook And Google Reviews System For Businesses 1.1 - Remote Code Execution 33 WEB Ihsan Sencan
2018-12-14   Facebook And Google Reviews System For Businesses 1.1 - SQL Injection 32 WEB Ihsan Sencan
2018-12-14   Facebook And Google Reviews System For Businesses - Cross-Site Request Forgery (Change Admin Passwor 29 WEB Veyselxan
2018-12-14   Huawei Router HG532e - Command Execution 32 WEB Rebellion
2018-12-14   Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2) 31 WEB alt3kx
2018-12-14   Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure 32 WEB alt3kx
2018-12-14   Responsive FileManager 9.13.4 - Multiple Vulnerabilities 30 WEB Fariskhi Vidyan
2018-12-11   Adobe ColdFusion 2018 - Arbitrary File Upload 30 WEB Vahagn Vardanyan
2018-12-11   ThinkPHP 5.0.23/5.1.31 - Remote Code Execution 34 WEB VulnSpy
2018-12-11   WordPress Plugin AutoSuggest 0.24 - 'wpas_keys' SQL Injection 28 WEB Kaimi
2018-12-11   HotelDruid 2.3.0 - 'id_utente_mod' SQL Injection 28 WEB Sainadh Jamalpur
2018-12-11   Apache OFBiz 16.11.05 - Cross-Site Scripting 27 WEB DKM
2014-02-17   IceWarp Mail Server 11.0.0.0 - Cross-Site Scripting 31 WEB Usman Saeed
2017-05-05   Sitecore CMS 8.2 - Cross-Site Scripting / Arbitrary File Disclosure 30 WEB Usman Saeed
2018-12-11   ZTE ZXHN H168N - Improper Access Restrictions 27 WEB Usman Saeed
2018-12-11   Huawei B315s-22 - Information Leak 30 WEB Usman Saeed
2018-12-11   TP-Link wireless router Archer C1200 - Cross-Site Scripting 29 WEB Usman Saeed
2018-12-11   PrinterOn Enterprise 4.1.4 - Arbitrary File Deletion 26 WEB bzyo
2018-12-11   DomainMOD 4.11.01 - Cross-Site Scripting 30 WEB Mohammed Abdul Raheem
2018-12-11   PrestaShop 1.6.x/1.7.x - Remote Code Execution 26 WEB Fariskhi Vidyan
2018-12-11   Alumni Tracer SMS Notification - SQL Injection / Cross-Site Request Forgery 27 WEB Ihsan Sencan
2018-12-11   Alumni Tracer SMS Notification - SQL Injection / Cross-Site Request Forgery 29 WEB Ihsan Sencan
2018-12-11   Tourism Website Blog - Remote Code Execution / SQL Injection 34 WEB Ihsan Sencan
2018-12-09   DomainMOD 4.11.01 - 'DisplayName' Cross-Site Scripting 33 WEB Mohammed Abdul Raheem
2018-12-09   Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting 27 WEB Gustavo Sorondo
2018-12-09   i-doit CMDB 1.11.2 - Remote Code Execution 30 WEB AkkuS
2018-12-05   HasanMWB 1.0 - SQL Injection 30 WEB Ihsan Sencan
2018-12-04   FreshRSS 1.11.1 - Cross-Site Scripting 28 WEB Netsparker
2018-12-04   DomainMOD 4.11.01 - Registrar Cross-Site Scripting 28 WEB Mohammed Abdul Raheem
2018-12-04   NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection 30 WEB Artem Metla
2018-12-04   DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting 30 WEB Mohammed Abdul Raheem
2018-12-04   DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting 27 WEB Mohammed Abdul Raheem
2018-12-04   Dolibarr ERP/CRM 8.0.3 - Cross-Site Scripting 28 WEB AkkuS
2018-12-04   KeyBase Botnet 1.5 - SQL Injection 29 WEB n4pst3r
2018-12-04   NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage 35 WEB hyp3rlinx
2018-12-04   DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting 28 WEB Mohammed Abdul Raheem
2018-12-04   Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass 28 WEB Luca.Chiou
2018-12-03   WordPress Plugin Advanced-Custom-Fields 5.7.7 - Cross-Site Scripting 24 WEB Loading Kura Kura
2018-12-03   Apache Superset < 0.23 - Remote Code Execution 25 WEB David May
2018-12-03   PHP Server Monitor 3.3.1 - Cross-Site Request Forgery 27 WEB Javier Olmedo
2018-12-03   Joomla! Component JE Photo Gallery 1.1 - 'categoryid' SQL Injection 25 WEB Ihsan Sencan
2018-12-03   PaloAlto Networks Expedition Migration Tool 1.0.106 - Information Disclosure 28 WEB ParagonSec
2018-12-03   Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting 30 WEB Luca.Chiou
2018-12-03   Fleetco Fleet Maintenance Management 1.2 - Remote Code Execution 28 WEB AkkuS
2018-11-30   Synaccess netBooter NP-02x/NP-08x 6.8 - Authentication Bypass 32 WEB LiquidWorm
2018-11-30   Schneider Electric PLC - Session Calculation Authentication Bypass 29 WEB Photubias
2018-11-26   Zyxel VMG1312-B10D 5.13AAXA.8 - Directory Traversal 30 WEB numan türle
2018-11-26   No-Cms 1.0 - 'order_by' SQL Injection 27 WEB Loading Kura Kura
2018-11-26   Ticketly 1.0 - 'kind_id' SQL Injection 25 WEB Javier Olmedo
2018-11-26   WordPress Plugin Easy Testimonials 3.2 - Cross-Site Scripting 27 WEB En_dust
2018-11-26   Ricoh myPrint 2.9.2.4 - Hard-Coded Credentials 30 WEB Hodorsec
2018-11-21   WebOfisi E-Ticaret V4 - 'urun' SQL Injection 33 WEB AkkuS
2018-11-21   WordPress Theme CherryFramework 3.1.4 - Backup File Download 29 WEB b1p0l4r
2018-11-21   Ticketly 1.0 - 'name' SQL Injection 33 WEB Javier Olmedo
2018-11-21   Synaccess netBooter NP-0801DU 7.4 - Cross-Site Request Forgery (Add Admin) 29 WEB LiquidWorm
2018-11-20   Ticketly 1.0 - Cross-Site Request Forgery (Add Admin) 28 WEB Javier Olmedo
2018-11-16   DomainMOD 4.11.01 - 'raid' Cross-Site Scripting 30 WEB Dawood Ansar
2018-11-16   Helpdezk 1.1.1 - Arbitrary File Upload 26 WEB Ihsan Sencan
2018-11-16   Warranty Tracking System 11.06.3 - 'txtCustomerCode' SQL Injection 26 WEB Ihsan Sencan
2018-11-15   WordPress Plugin Ninja Forms 3.3.17 - Cross-Site Scripting 29 WEB MTK
2018-11-15   PHP Mass Mail 1.0 - Arbitrary File Upload 25 WEB Ihsan Sencan