Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2018-09-24   Joomla! Component Auction Factory 4.5.5 - 'filter_order' SQL Injection 35 WEB Ihsan Sencan
2018-09-24   RICOH Aficio MP 301 Printer - Cross-Site Scripting 31 WEB Ismail Tasdelen
2018-09-24   Joomla! Component Micro Deal Factory 2.4.0 - 'id' SQL Injection 31 WEB Ihsan Sencan
2018-09-24   Joomla! Component AMGallery 1.2.3 - 'filter_category_id' SQL Injection 26 WEB Ihsan Sencan
2018-09-24   MyBB Visual Editor 1.8.18 - Cross-Site Scripting 31 WEB Numan OZDEMIR
2018-09-24   LG SuperSign EZ CMS 2.5 - Remote Code Execution 29 WEB Alejandro Fanjul
2018-09-24   Joomla! Component CW Article Attachments 1.0.6 - 'id' SQL Injection 36 WEB Haboob Team
2018-09-21   Collectric CMU 1.0 - 'lang' Hard-Coded Credentials / SQL injection 32 WEB Simon Brannstrom
2018-09-24   Navigate CMS 2.8 - Cross-Site Scripting 37 WEB Renzi
2018-09-19   LG SuperSign EZ CMS 2.5 - Local File Inclusion 37 WEB Alejandro Fanjul
2018-09-19   WordPress Plugin Localize My Post 1.0 - Local File Inclusion 37 WEB Manuel García Cárdenas
2018-09-19   WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion 31 WEB Manuel García Cárdenas
2018-09-19   Roundcube rcfilters plugin 2.1.6 - Cross-Site Scripting 28 WEB Fahimeh Rezaei
2018-09-18   WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Si 31 WEB Larry W. Cashdollar
2018-09-18   WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Si 31 WEB Larry W. Cashdollar
2018-09-17   Joomla! Component JCK Editor 6.4.4 - 'parent' SQL Injection 32 WEB Hamza Megahed
2018-09-17   Netis ADSL Router DL4322D RTK 2.1.1 - Cross-Site Scripting 33 WEB cakes
2018-09-14   WordPress Plugin Survey & Poll 1.5.7.3 - 'sss_params' SQL Injection 35 WEB Ceylan BOZOĞULLARINDAN
2018-09-14   Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit) 28 WEB Stephen Shkardoon
2018-09-14   Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit) 31 WEB Stephen Shkardoon
2018-09-13   Apache Syncope 2.0.7 - Remote Code Execution 34 WEB Che-Chun Kuo
2018-09-13   Apache Portals Pluto 3.0.0 - Remote Code Execution 32 WEB Che-Chun Kuo
2018-09-12   LG Smart IP Camera 1508190 - Backup File Download 28 WEB Ege Balci
2018-09-12   MyBB 1.8.17 - Cross-Site Scripting 30 WEB 0xB9
2018-09-12   IBM Identity Governance and Intelligence 5.2.3.2 / 5.2.4 - SQL Injection 27 WEB Mohamed Sayed
2018-09-12   SynaMan 4.0 build 1488 - SMTP Credential Disclosure 29 WEB bzyo
2018-09-12   SynaMan 4.0 build 1488 - (Authenticated) Cross-Site Scripting 33 WEB bzyo
2018-09-12   Rubedo CMS 3.4.0 - Directory Traversal 28 WEB Marouene Boubakri
2018-09-12   CirCarLife SCADA 4.3.0 - Credential Disclosure 26 WEB SadFud
2018-09-11   Bayanno Hospital Management System 4.0 - Cross-Site Scripting 29 WEB Gokhan Sagoglu
2018-09-04   RPi Cam Control < 6.4.25 - 'preview.php' Remote Command Execution 28 WEB Reigning Shells
2018-09-10   LW-N605R 12.20.2.1486 - Remote Code Execution 32 WEB Nassim Asrir
2018-09-07   QNAP Photo Station 5.7.0 - Cross-Site Scripting 31 WEB Mitsuaki Shiraishi
2018-09-07   Softneta MedDream PACS Server Premium 6.7.1.1 - Directory Traversal 33 WEB Carlos Avila
2018-09-07   MedDream PACS Server Premium 6.7.1.1 - 'email' SQL Injection 27 WEB Carlos Avila
2018-09-06   D-Link Dir-600M N150 - Cross-Site Scripting 27 WEB PUNIT DARJI
2018-09-06   WirelessHART Fieldgate SWG70 3.0 - Directory Traversal 29 WEB Hamit CİBO
2018-09-06   Apache Roller 5.0.3 - XML External Entity Injection (File Disclosure) 25 WEB Marko Jokic
2018-09-06   Jorani Leave Management 0.6.5 - (Authenticated) 'startdate' SQL Injection 33 WEB Javier Olmedo
2018-09-06   Jorani Leave Management 0.6.5 - Cross-Site Scripting 28 WEB Javier Olmedo
2018-09-06   NovaRad NovaPACS Diagnostics Viewer 8.5 - XML External Entity Injection (File Disclosure) 34 WEB LiquidWorm
2018-09-05   Tenda ADSL Router D152 - Cross-Site Scripting 32 WEB Sandip Dey
2018-09-04   mooSocial Store Plugin 2.6 - SQL Injection 30 WEB Andrea Bocchetti
2018-09-04   Simple POS 4.0.24 - 'columns[0][search][value]' SQL Injection 31 WEB Renos Nikolaou
2018-09-04   PHP File Browser Script 1 - Directory Traversal 30 WEB AkkuS
2018-09-04   Logicspice FAQ Script 2.9.7 - Remote Code Execution 29 WEB AkkuS
2018-09-03   Online Quiz Maker 1.0 - 'catid' SQL Injection 23 WEB AkkuS
2018-09-03   Admidio 3.3.5 - Cross-Site Request Forgery (Change Permissions) 24 WEB Nawaf Alkeraithe
2018-09-03   FsPro Labs Event Log Explorer v4.6.1.2115 - XML External Entity Injection 33 WEB hyp3rlinx
2018-08-31   DamiCMS 6.0.0 - Cross-Site Request Forgery (Change Admin Password) 30 WEB Autism_JH
2018-08-31   Vox TG790 ADSL Router - Cross-Site Scripting 32 WEB cakes
2018-08-30   Cybrotech CyBroHttpServer 1.0.3 - Cross-Site Scripting 34 WEB Emre ÖVÜNÇ
2018-08-30   WordPress Plugin Quizlord 2.0 - Cross-Site Scripting 30 WEB Renos Nikolaou
2018-08-30   DLink DIR-601 - Credential Disclosure 27 WEB Kevin Randall
2018-08-30   WordPress Plugin Jibu Pro 1.7 - Cross-Site Scripting 30 WEB Renos Nikolaou
2018-08-30   Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal 30 WEB Emre ÖVÜNÇ
2018-08-29   Argus Surveillance DVR 4.0.0.0 - Directory Traversal 30 WEB hyp3rlinx
2018-08-29   Episerver 7 patch 4 - XML External Entity Injection 33 WEB Jonas Lejon
2018-08-29   phpMyAdmin 4.7.x - Cross-Site Request Forgery 32 WEB VulnSpy
2018-08-27   WordPress Plugin Plainview Activity Monitor 20161228 - (Authenticated) Command Injection 30 WEB Lydéric Lefebvre
2018-08-27   Responsive FileManager < 9.13.4 - Directory Traversal 28 WEB Simon Uvarov
2018-08-27   Seagate Personal Cloud SRN21C 4.3.16.0 / 4.3.18.0 - SQL Injection 33 WEB Yorick Koster
2018-08-27   LiteCart 2.1.2 - Arbitrary File Upload 33 WEB Haboob Team
2018-08-27   Sentrifugo HRMS 3.2 - 'deptid' SQL Injection 34 WEB Javier Olmedo
2018-08-27   RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin) 33 WEB Ismail Tasdelen
2018-08-27   Gleez CMS 1.2.0 - Cross-Site Request Forgery (Add Admin) 28 WEB GunEggWang
2018-08-26   ManageEngine ADManager Plus 6.5.7 - Cross-Site Scripting 27 WEB Ismail Tasdelen
2018-08-26   WordPress Plugin Gift Voucher 1.0.5 - (Authenticated) 'template_id' SQL Injection 26 WEB Renos Nikolaou
2018-08-25   ManageEngine ADManager Plus 6.5.7 - HTML Injection 26 WEB Ismail Tasdelen
2018-08-25   UltimatePOS 2.5 - Remote Code Execution 33 WEB Renos Nikolaou
2018-08-24   Vox TG790 ADSL Router - Cross-Site Request Forgery (Add Admin) 31 WEB cakes
2018-08-23   PCViewer vt1000 - Directory Traversal 30 WEB Berk Dusunur
2018-08-23   Twitter-Clone 1 - 'code' SQL Injection 32 WEB L0RD
2018-08-22   Geutebrueck re_porter 16 - Cross-Site Scripting 34 WEB Kamil Suska
2018-08-22   Geutebrueck re_porter 7.8.974.20 - Credential Disclosure 33 WEB Kamil Suska
2018-08-22   KingMedia 4.1 - File Upload 31 WEB Efrén Díaz
2018-08-22   ZyXEL VMG3312-B10B - Cross-Site Scripting 32 WEB Samet ŞAHİN
2018-08-21   WordPress Plugin Ninja Forms 3.3.13 - CSV Injection 30 WEB Mostafa Gharzi
2018-08-21   Twitter-Clone 1 - Cross-Site Request Forgery (Delete Post) 25 WEB L0RD
2018-08-21   Hikvision IP Camera 5.4.0 - User Enumeration (Metasploit) 29 WEB Alfie
2018-08-21   Twitter-Clone 1 - 'userid' SQL Injection 24 WEB L0RD
2018-08-20   Countly - Cross-Site Scripting 29 WEB Sleepy
2018-08-20   WordPress Plugin Tagregator 0.6 - Cross-Site Scripting 27 WEB ManhNho
2018-08-20   MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery 27 WEB 0xB9
2018-08-20   WordPress Plugin Chained Quiz 1.0.8 - 'answer' SQL Injection 29 WEB Çlirim Emini
2018-08-17   ADM 3.1.2RHG1 - Remote Code Execution 32 WEB Matthew Fulton
2018-08-17   Mikrotik WinBox 6.42 - Credential Disclosure (golang) 29 WEB Maxim Yefimenko
2018-08-16   Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery 39 WEB SEC Consult
2018-08-16   Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery 30 WEB SEC Consult
2018-08-16   Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery 37 WEB SEC Consult
2018-08-16   WordPress Plugin Export Users to CSV 1.1.1 - CSV Injection 32 WEB Javier Olmedo
2018-08-16   OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions 29 WEB Joshua Fam
2018-08-15   ASUS-DSL N10 1.1.2.2_17 - Authentication Bypass 31 WEB AmnBAN
2018-08-15   ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection 30 WEB Kyle Lovett
2018-08-14   Oracle Glassfish OSE 4.1 - Path Traversal (Metasploit) 28 WEB Dhiraj Mishra
2018-08-14   Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit) 27 WEB Metasploit
2018-08-14   Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit) 25 WEB Metasploit
2018-08-14   cgit 1.2.1 - Directory Traversal (Metasploit) 36 WEB Dhiraj Mishra
2018-08-13   IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting 31 WEB Vikas Khanna
2018-08-10   MyBB Like Plugin 3.0.0 - Cross-Site Scripting 37 WEB 0xB9
2018-08-10   MyBB Thank You/Like Plugin 3.0.0 - Cross-Site Scripting 28 WEB 0xB9
2018-08-10   Zimbra 8.6.0_GA_1153 - Cross-Site Scripting 29 WEB Dino Barlattani
2018-08-09   TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Information Disclosure) 34 WEB Wadeek
2018-08-09   TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Remote Reboot) 29 WEB Wadeek
2018-08-08   osTicket 1.10.1 - Arbitrary File Upload 34 WEB Rajwinder Singh
2018-08-08   LG-Ericsson iPECS NMS 30M - Directory Traversal 43 WEB Safak Aslan
2018-08-07   Monstra-Dev 3.0.4 - Cross-Site Request Forgery (Account Hijacking) 33 WEB Nainsi Gupta
2018-08-07   OpenEMR 5.0.1.3 - Remote Code Execution (Authenticated) 31 WEB Cody Zacharias
2018-08-06   Open-AudIT Community 2.2.6 - Cross-Site Scripting 31 WEB Ranjeet Jaiswal
2018-08-06   Wavemaker Studio 6.6 - Server-Side Request Forgery 32 WEB Gionathan Reale
2018-08-06   CMS ISWEB 3.5.3 - Directory Traversal 30 WEB Thiago Sena
2018-08-06   onArcade 2.4.2 - Cross-Site Request Forgery (Add Admin) 30 WEB r3m0t3nu11
2018-08-06   LAMS < 3.1 - Cross-Site Scripting 31 WEB Nikola Kojic
2018-08-06   Sitecore.Net 8.1 - Directory Traversal 34 WEB Chris
2018-08-06   Subrion CMS 4.2.1 - Cross-Site Scripting 33 WEB Zeel Chavda
2018-08-03   cgit < 1.2.1 - 'cgit_clone_objects()' Directory Traversal 32 WEB Google Security Research
2018-08-03   Plex Media Server 1.13.2.5154 - SSDP Processing XML External Entity Injection 35 WEB Chris Moberly
2018-08-03   Vuze Bittorrent Client 5.7.6.0 - SSDP Processing XML External Entity Injection 30 WEB Chris Moberly
2018-08-03   PHP Template Store Script 3.0.6 - Cross-Site Scripting 32 WEB Sarafraz Khan
2018-08-02   Seq 4.2.476 - Authentication Bypass 32 WEB Daniel Chactoura
2018-08-02   ASUS DSL-N12E_C1 1.1.2.3_345 - Remote Command Execution 36 WEB Fakhri Zulkifli
2018-08-02   Universal Media Server 7.1.0 - SSDP Processing XML External Entity Injection 32 WEB Chris Moberly
2018-08-02   CoSoSys Endpoint Protector 4.5.0.1 - (Authenticated) Remote Root Command Injection 36 WEB 0x09AL
2018-08-02   PageResponse FB Inboxer Add-on 1.2 - 'search_field' SQL Injection 33 WEB AkkuS
2018-08-02   TI Online Examination System v2 - Arbitrary File Download 30 WEB AkkuS