Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2018-12-14   Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure 17 WEB alt3kx
2018-12-14   Responsive FileManager 9.13.4 - Multiple Vulnerabilities 18 WEB Fariskhi Vidyan
2018-12-11   Adobe ColdFusion 2018 - Arbitrary File Upload 16 WEB Vahagn Vardanyan
2018-12-11   ThinkPHP 5.0.23/5.1.31 - Remote Code Execution 15 WEB VulnSpy
2018-12-11   WordPress Plugin AutoSuggest 0.24 - 'wpas_keys' SQL Injection 15 WEB Kaimi
2018-12-11   HotelDruid 2.3.0 - 'id_utente_mod' SQL Injection 16 WEB Sainadh Jamalpur
2018-12-11   Apache OFBiz 16.11.05 - Cross-Site Scripting 16 WEB DKM
2014-02-17   IceWarp Mail Server 11.0.0.0 - Cross-Site Scripting 15 WEB Usman Saeed
2017-05-05   Sitecore CMS 8.2 - Cross-Site Scripting / Arbitrary File Disclosure 17 WEB Usman Saeed
2018-12-11   ZTE ZXHN H168N - Improper Access Restrictions 15 WEB Usman Saeed
2018-12-11   Huawei B315s-22 - Information Leak 14 WEB Usman Saeed
2018-12-11   TP-Link wireless router Archer C1200 - Cross-Site Scripting 14 WEB Usman Saeed
2018-12-11   PrinterOn Enterprise 4.1.4 - Arbitrary File Deletion 14 WEB bzyo
2018-12-11   DomainMOD 4.11.01 - Cross-Site Scripting 13 WEB Mohammed Abdul Raheem
2018-12-11   PrestaShop 1.6.x/1.7.x - Remote Code Execution 12 WEB Fariskhi Vidyan
2018-12-11   Alumni Tracer SMS Notification - SQL Injection / Cross-Site Request Forgery 15 WEB Ihsan Sencan
2018-12-11   Alumni Tracer SMS Notification - SQL Injection / Cross-Site Request Forgery 15 WEB Ihsan Sencan
2018-12-11   Tourism Website Blog - Remote Code Execution / SQL Injection 21 WEB Ihsan Sencan
2018-12-09   DomainMOD 4.11.01 - 'DisplayName' Cross-Site Scripting 19 WEB Mohammed Abdul Raheem
2018-12-09   Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting 14 WEB Gustavo Sorondo
2018-12-09   i-doit CMDB 1.11.2 - Remote Code Execution 17 WEB AkkuS
2018-12-05   HasanMWB 1.0 - SQL Injection 16 WEB Ihsan Sencan
2018-12-04   FreshRSS 1.11.1 - Cross-Site Scripting 13 WEB Netsparker
2018-12-04   DomainMOD 4.11.01 - Registrar Cross-Site Scripting 18 WEB Mohammed Abdul Raheem
2018-12-04   NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection 16 WEB Artem Metla
2018-12-04   DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting 17 WEB Mohammed Abdul Raheem
2018-12-04   DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting 15 WEB Mohammed Abdul Raheem
2018-12-04   Dolibarr ERP/CRM 8.0.3 - Cross-Site Scripting 18 WEB AkkuS
2018-12-04   KeyBase Botnet 1.5 - SQL Injection 18 WEB n4pst3r
2018-12-04   NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage 18 WEB hyp3rlinx
2018-12-04   DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting 16 WEB Mohammed Abdul Raheem
2018-12-04   Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass 15 WEB Luca.Chiou
2018-12-03   WordPress Plugin Advanced-Custom-Fields 5.7.7 - Cross-Site Scripting 11 WEB Loading Kura Kura
2018-12-03   Apache Superset < 0.23 - Remote Code Execution 14 WEB David May
2018-12-03   PHP Server Monitor 3.3.1 - Cross-Site Request Forgery 10 WEB Javier Olmedo
2018-12-03   Joomla! Component JE Photo Gallery 1.1 - 'categoryid' SQL Injection 14 WEB Ihsan Sencan
2018-12-03   PaloAlto Networks Expedition Migration Tool 1.0.106 - Information Disclosure 15 WEB ParagonSec
2018-12-03   Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting 18 WEB Luca.Chiou
2018-12-03   Fleetco Fleet Maintenance Management 1.2 - Remote Code Execution 15 WEB AkkuS
2018-11-30   Synaccess netBooter NP-02x/NP-08x 6.8 - Authentication Bypass 14 WEB LiquidWorm
2018-11-30   Schneider Electric PLC - Session Calculation Authentication Bypass 12 WEB Photubias
2018-11-26   Zyxel VMG1312-B10D 5.13AAXA.8 - Directory Traversal 14 WEB numan türle
2018-11-26   No-Cms 1.0 - 'order_by' SQL Injection 14 WEB Loading Kura Kura
2018-11-26   Ticketly 1.0 - 'kind_id' SQL Injection 13 WEB Javier Olmedo
2018-11-26   WordPress Plugin Easy Testimonials 3.2 - Cross-Site Scripting 13 WEB En_dust
2018-11-26   Ricoh myPrint 2.9.2.4 - Hard-Coded Credentials 13 WEB Hodorsec
2018-11-21   WebOfisi E-Ticaret V4 - 'urun' SQL Injection 15 WEB AkkuS
2018-11-21   WordPress Theme CherryFramework 3.1.4 - Backup File Download 16 WEB b1p0l4r
2018-11-21   Ticketly 1.0 - 'name' SQL Injection 18 WEB Javier Olmedo
2018-11-21   Synaccess netBooter NP-0801DU 7.4 - Cross-Site Request Forgery (Add Admin) 18 WEB LiquidWorm
2018-11-20   Ticketly 1.0 - Cross-Site Request Forgery (Add Admin) 11 WEB Javier Olmedo
2018-11-16   DomainMOD 4.11.01 - 'raid' Cross-Site Scripting 15 WEB Dawood Ansar
2018-11-16   Helpdezk 1.1.1 - Arbitrary File Upload 11 WEB Ihsan Sencan
2018-11-16   Warranty Tracking System 11.06.3 - 'txtCustomerCode' SQL Injection 14 WEB Ihsan Sencan
2018-11-15   WordPress Plugin Ninja Forms 3.3.17 - Cross-Site Scripting 14 WEB MTK
2018-11-15   PHP Mass Mail 1.0 - Arbitrary File Upload 13 WEB Ihsan Sencan
2018-11-15   2-Plan Team 1.0.4 - Arbitrary File Upload 14 WEB Ihsan Sencan
2018-11-15   Simple E-Document 1.31 - 'username' SQL Injection 14 WEB Ihsan Sencan
2018-11-15   Kordil EDMS 2.2.60rc3 - Arbitrary File Upload 13 WEB Ihsan Sencan
2018-11-15   Meneame English Pligg 5.8 - 'search' SQL Injection 13 WEB Ihsan Sencan
2018-11-15   EverSync 0.5 - Arbitrary File Download 13 WEB Ihsan Sencan
2018-11-15   Galaxy Forces MMORPG 0.5.8 - 'type' SQL Injection 14 WEB Ihsan Sencan
2018-11-15   Net-Billetterie 2.9 - 'login' SQL Injection 14 WEB Ihsan Sencan
2018-11-15   BitZoom 1.0 - 'rollno' SQL Injection 16 WEB Ihsan Sencan
2018-11-15   PHP-Proxy 5.1.0 - Local File Inclusion 17 WEB Ameer Pornillos
2018-11-15   Precurio Intranet Portal 2.0 - Cross-Site Request Forgery (Add Admin) 14 WEB Ihsan Sencan
2018-11-14   DoceboLMS 1.2 - SQL Injection / Arbitrary File Upload 13 WEB Ihsan Sencan
2018-11-14   Electricks eCommerce 1.0 - Persistent Cross-Site Scripting 10 WEB Nawaf Alkeraithe
2018-11-14   Pedidos 1.0 - SQL Injection 14 WEB Ihsan Sencan
2018-11-14   Rmedia SMS 1.0 - SQL Injection 15 WEB Ihsan Sencan
2018-11-14   Advanced Comment System 1.0 - SQL Injection 14 WEB Rafael Pedrero
2018-11-14   Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities 15 WEB KoreLogic
2018-11-14   EdTv 2 - 'id' SQL Injection 16 WEB Ihsan Sencan
2018-11-14   Electricks eCommerce 1.0 - Cross-Site Request Forgery (Change Admin Password) 14 WEB Nawaf Alkeraithe
2018-11-14   Helpdezk 1.1.1 - 'query' SQL Injection 14 WEB Ihsan Sencan
2018-11-14   iServiceOnline 1.0 - 'r' SQL Injection 14 WEB Ihsan Sencan
2018-11-13   SIPve 0.0.2-R19 - SQL Injection 17 WEB Ihsan Sencan
2018-11-13   Webiness Inventory 2.3 - 'order' SQL Injection 12 WEB Ihsan Sencan
2018-11-13   Webiness Inventory 2.3 - Arbitrary File Upload / Cross-Site Request Forgery (Add Admin) 13 WEB Ihsan Sencan
2018-11-13   Maitra Mail Tracking System 1.7.2 - SQL Injection / Database File Download 14 WEB Ihsan Sencan
2018-11-13   Alive Parish 2.0.4 - SQL Injection / Arbitrary File Upload 12 WEB Ihsan Sencan
2018-11-13   ClipperCMS 1.3.3 - Cross-Site Request Forgery (File Upload) 14 WEB Ameer Pornillos
2018-11-13   Silurus Classifieds Script 2.0 - 'wcategory' SQL Injection 13 WEB Ihsan Sencan
2018-11-13   Gumbo CMS 0.99 - SQL Injection 14 WEB Ihsan Sencan
2018-11-13   ABC ERP 0.6.4 - Cross-Site Request Forgery (Update Admin) 12 WEB Ihsan Sencan
2018-11-13   Easyndexer 1.0 - Arbitrary File Download 12 WEB Ihsan Sencan
2018-11-13   Tina4 Stack 1.0.3 - Cross-Site Request Forgery (Update Admin) 14 WEB Ihsan Sencan
2018-11-13   Tina4 Stack 1.0.3 - SQL Injection / Database File Download 14 WEB Ihsan Sencan
2018-11-13   Data Center Audit 2.6.2 - Cross-Site Request Forgery (Update Admin) 16 WEB Ihsan Sencan
2018-11-13   Musicco 2.0.0 - Arbitrary Directory Download 14 WEB Ihsan Sencan
2018-11-13   Alienor Web Libre 2.0 - SQL Injection 13 WEB Ihsan Sencan
2018-11-13   Surreal ToDo 0.6.1.2 - Local File Inclusion 16 WEB Ihsan Sencan
2018-11-13   Surreal ToDo 0.6.1.2 - SQL Injection 13 WEB Ihsan Sencan
2018-11-13   CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting 15 WEB InfinitumIT
2018-11-13   CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting 17 WEB InfinitumIT
2018-11-12   Nominas 0.27 - 'username' SQL Injection 19 WEB Ihsan Sencan
2018-11-12   D-LINK Central WifiManager CWM-100 - Server-Side Request Forgery 13 WEB hyp3rlinx
2018-11-12   ServerZilla 1.0 - 'email' SQL Injection 16 WEB Ihsan Sencan
2018-11-12   GPS Tracking System 2.12 - 'username' SQL Injection 12 WEB Ihsan Sencan
2018-11-12   Easyndexer 1.0 - Cross-Site Request Forgery (Add Admin) 13 WEB Ihsan Sencan
2018-11-12   Facturation System 1.0 - 'modid' SQL Injection 14 WEB Ihsan Sencan
2018-11-12   The Don 1.0.1 - 'login' SQL Injection 17 WEB Ihsan Sencan
2018-11-12   TP-Link Archer C50 Wireless Router 171227 - Cross-Site Request Forgery (Configuration File Disclosur 17 WEB Wadeek
2018-11-12   Paroiciel 11.20 - 'tRecIdListe' SQL Injection 14 WEB Ihsan Sencan
2018-11-12   WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting 17 WEB Pasquale Turi
2018-11-12   WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting 16 WEB Pasquale Turi
2018-11-12   TufinOS 2.17 Build 1193 - XML External Entity Injection 12 WEB Konstantinos Alexiou
2018-11-12   Data Center Audit 2.6.2 - 'username' SQL Injection 16 WEB Ihsan Sencan
2018-11-07   PlayJoom 0.10.1 - 'catid' SQL Injection 16 WEB Ihsan Sencan
2018-11-06   LibreHealth 2.0.0 - (Authenticated) Arbitrary File Actions 22 WEB Carlos Avila
2018-11-06   OpenBiz Cubi Lite 3.0.8 - 'username' SQL Injection 13 WEB AkkuS
2018-11-06   OOP CMS BLOG 1.0 - 'search' SQL Injection 15 WEB Ihsan Sencan
2018-11-06   Grocery crud 1.6.1 - 'search_field' SQL Injection 13 WEB Loading Kura Kura
2018-11-06   OOP CMS BLOG 1.0 - Cross-Site Request Forgery (Add Admin) 15 WEB Ihsan Sencan
2018-11-06   CMS Made Simple 2.2.7 - (Authenticated) Remote Code Execution 17 WEB Lucian Ioan Nitescu
2018-11-05   Voovi Social Networking Script 1.0 - 'user' SQL Injection 17 WEB Ihsan Sencan
2018-11-05   Royal TS/X - Information Disclosure 16 WEB Jakub Palaczynski
2018-11-05   PHP Proxy 3.0.3 - Local File Inclusion 14 WEB AkkuS
2018-11-05   Mongo Web Admin 6.0 - Information Disclosure 14 WEB Ihsan Sencan
2018-11-05   Poppy Web Interface Generator 0.8 - Arbitrary File Upload 17 WEB Ihsan Sencan
2018-11-05   WebVet 0.1a - 'id' SQL Injection 13 WEB Ihsan Sencan
2018-11-05   Advantech WebAccess SCADA 8.3.2 - Remote Code Execution 14 WEB Chris Lyne
2018-11-05   SiAdmin 1.1 - 'id' SQL Injection 14 WEB Ihsan Sencan
2018-11-02   Yot CMS 3.3.1 - 'aid' SQL Injection 15 WEB Ihsan Sencan
2018-11-02   qdPM 9.1 - 'filter_by' SQL Injection 12 WEB AkkuS