|
2018-09-13
|
|
Apache Portals Pluto 3.0.0 - Remote Code Execution
|
27 |
WEB
|
Che-Chun Kuo
|
|
2018-09-12
|
|
LG Smart IP Camera 1508190 - Backup File Download
|
22 |
WEB
|
Ege Balci
|
|
2018-09-12
|
|
MyBB 1.8.17 - Cross-Site Scripting
|
27 |
WEB
|
0xB9
|
|
2018-09-12
|
|
IBM Identity Governance and Intelligence 5.2.3.2 / 5.2.4 - SQL Injection
|
22 |
WEB
|
Mohamed Sayed
|
|
2018-09-12
|
|
SynaMan 4.0 build 1488 - SMTP Credential Disclosure
|
24 |
WEB
|
bzyo
|
|
2018-09-12
|
|
SynaMan 4.0 build 1488 - (Authenticated) Cross-Site Scripting
|
27 |
WEB
|
bzyo
|
|
2018-09-12
|
|
Rubedo CMS 3.4.0 - Directory Traversal
|
23 |
WEB
|
Marouene Boubakri
|
|
2018-09-12
|
|
CirCarLife SCADA 4.3.0 - Credential Disclosure
|
22 |
WEB
|
SadFud
|
|
2018-09-11
|
|
Bayanno Hospital Management System 4.0 - Cross-Site Scripting
|
22 |
WEB
|
Gokhan Sagoglu
|
|
2018-09-04
|
|
RPi Cam Control < 6.4.25 - 'preview.php' Remote Command Execution
|
22 |
WEB
|
Reigning Shells
|
|
2018-09-10
|
|
LW-N605R 12.20.2.1486 - Remote Code Execution
|
27 |
WEB
|
Nassim Asrir
|
|
2018-09-07
|
|
QNAP Photo Station 5.7.0 - Cross-Site Scripting
|
26 |
WEB
|
Mitsuaki Shiraishi
|
|
2018-09-07
|
|
Softneta MedDream PACS Server Premium 6.7.1.1 - Directory Traversal
|
28 |
WEB
|
Carlos Avila
|
|
2018-09-07
|
|
MedDream PACS Server Premium 6.7.1.1 - 'email' SQL Injection
|
20 |
WEB
|
Carlos Avila
|
|
2018-09-06
|
|
D-Link Dir-600M N150 - Cross-Site Scripting
|
21 |
WEB
|
PUNIT DARJI
|
|
2018-09-06
|
|
WirelessHART Fieldgate SWG70 3.0 - Directory Traversal
|
25 |
WEB
|
Hamit CİBO
|
|
2018-09-06
|
|
Apache Roller 5.0.3 - XML External Entity Injection (File Disclosure)
|
21 |
WEB
|
Marko Jokic
|
|
2018-09-06
|
|
Jorani Leave Management 0.6.5 - (Authenticated) 'startdate' SQL Injection
|
28 |
WEB
|
Javier Olmedo
|
|
2018-09-06
|
|
Jorani Leave Management 0.6.5 - Cross-Site Scripting
|
24 |
WEB
|
Javier Olmedo
|
|
2018-09-06
|
|
NovaRad NovaPACS Diagnostics Viewer 8.5 - XML External Entity Injection (File Disclosure)
|
28 |
WEB
|
LiquidWorm
|
|
2018-09-05
|
|
Tenda ADSL Router D152 - Cross-Site Scripting
|
26 |
WEB
|
Sandip Dey
|
|
2018-09-04
|
|
mooSocial Store Plugin 2.6 - SQL Injection
|
26 |
WEB
|
Andrea Bocchetti
|
|
2018-09-04
|
|
Simple POS 4.0.24 - 'columns[0][search][value]' SQL Injection
|
27 |
WEB
|
Renos Nikolaou
|
|
2018-09-04
|
|
PHP File Browser Script 1 - Directory Traversal
|
25 |
WEB
|
AkkuS
|
|
2018-09-04
|
|
Logicspice FAQ Script 2.9.7 - Remote Code Execution
|
25 |
WEB
|
AkkuS
|
|
2018-09-03
|
|
Online Quiz Maker 1.0 - 'catid' SQL Injection
|
18 |
WEB
|
AkkuS
|
|
2018-09-03
|
|
Admidio 3.3.5 - Cross-Site Request Forgery (Change Permissions)
|
19 |
WEB
|
Nawaf Alkeraithe
|
|
2018-09-03
|
|
FsPro Labs Event Log Explorer v4.6.1.2115 - XML External Entity Injection
|
28 |
WEB
|
hyp3rlinx
|
|
2018-08-31
|
|
DamiCMS 6.0.0 - Cross-Site Request Forgery (Change Admin Password)
|
26 |
WEB
|
Autism_JH
|
|
2018-08-31
|
|
Vox TG790 ADSL Router - Cross-Site Scripting
|
27 |
WEB
|
cakes
|
|
2018-08-30
|
|
Cybrotech CyBroHttpServer 1.0.3 - Cross-Site Scripting
|
28 |
WEB
|
Emre ÖVÜNÇ
|
|
2018-08-30
|
|
WordPress Plugin Quizlord 2.0 - Cross-Site Scripting
|
26 |
WEB
|
Renos Nikolaou
|
|
2018-08-30
|
|
DLink DIR-601 - Credential Disclosure
|
23 |
WEB
|
Kevin Randall
|
|
2018-08-30
|
|
WordPress Plugin Jibu Pro 1.7 - Cross-Site Scripting
|
25 |
WEB
|
Renos Nikolaou
|
|
2018-08-30
|
|
Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal
|
24 |
WEB
|
Emre ÖVÜNÇ
|
|
2018-08-29
|
|
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
|
27 |
WEB
|
hyp3rlinx
|
|
2018-08-29
|
|
Episerver 7 patch 4 - XML External Entity Injection
|
29 |
WEB
|
Jonas Lejon
|
|
2018-08-29
|
|
phpMyAdmin 4.7.x - Cross-Site Request Forgery
|
26 |
WEB
|
VulnSpy
|
|
2018-08-27
|
|
WordPress Plugin Plainview Activity Monitor 20161228 - (Authenticated) Command Injection
|
26 |
WEB
|
Lydéric Lefebvre
|
|
2018-08-27
|
|
Responsive FileManager < 9.13.4 - Directory Traversal
|
23 |
WEB
|
Simon Uvarov
|
|
2018-08-27
|
|
Seagate Personal Cloud SRN21C 4.3.16.0 / 4.3.18.0 - SQL Injection
|
29 |
WEB
|
Yorick Koster
|
|
2018-08-27
|
|
LiteCart 2.1.2 - Arbitrary File Upload
|
28 |
WEB
|
Haboob Team
|
|
2018-08-27
|
|
Sentrifugo HRMS 3.2 - 'deptid' SQL Injection
|
28 |
WEB
|
Javier Olmedo
|
|
2018-08-27
|
|
RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin)
|
29 |
WEB
|
Ismail Tasdelen
|
|
2018-08-27
|
|
Gleez CMS 1.2.0 - Cross-Site Request Forgery (Add Admin)
|
23 |
WEB
|
GunEggWang
|
|
2018-08-26
|
|
ManageEngine ADManager Plus 6.5.7 - Cross-Site Scripting
|
22 |
WEB
|
Ismail Tasdelen
|
|
2018-08-26
|
|
WordPress Plugin Gift Voucher 1.0.5 - (Authenticated) 'template_id' SQL Injection
|
22 |
WEB
|
Renos Nikolaou
|
|
2018-08-25
|
|
ManageEngine ADManager Plus 6.5.7 - HTML Injection
|
21 |
WEB
|
Ismail Tasdelen
|
|
2018-08-25
|
|
UltimatePOS 2.5 - Remote Code Execution
|
26 |
WEB
|
Renos Nikolaou
|
|
2018-08-24
|
|
Vox TG790 ADSL Router - Cross-Site Request Forgery (Add Admin)
|
27 |
WEB
|
cakes
|
|
2018-08-23
|
|
PCViewer vt1000 - Directory Traversal
|
26 |
WEB
|
Berk Dusunur
|
|
2018-08-23
|
|
Twitter-Clone 1 - 'code' SQL Injection
|
29 |
WEB
|
L0RD
|
|
2018-08-22
|
|
Geutebrueck re_porter 16 - Cross-Site Scripting
|
30 |
WEB
|
Kamil Suska
|
|
2018-08-22
|
|
Geutebrueck re_porter 7.8.974.20 - Credential Disclosure
|
29 |
WEB
|
Kamil Suska
|
|
2018-08-22
|
|
KingMedia 4.1 - File Upload
|
27 |
WEB
|
Efrén Díaz
|
|
2018-08-22
|
|
ZyXEL VMG3312-B10B - Cross-Site Scripting
|
28 |
WEB
|
Samet ŞAHİN
|
|
2018-08-21
|
|
WordPress Plugin Ninja Forms 3.3.13 - CSV Injection
|
26 |
WEB
|
Mostafa Gharzi
|
|
2018-08-21
|
|
Twitter-Clone 1 - Cross-Site Request Forgery (Delete Post)
|
21 |
WEB
|
L0RD
|
|
2018-08-21
|
|
Hikvision IP Camera 5.4.0 - User Enumeration (Metasploit)
|
24 |
WEB
|
Alfie
|
|
2018-08-21
|
|
Twitter-Clone 1 - 'userid' SQL Injection
|
20 |
WEB
|
L0RD
|
|
2018-08-20
|
|
Countly - Cross-Site Scripting
|
23 |
WEB
|
Sleepy
|
|
2018-08-20
|
|
WordPress Plugin Tagregator 0.6 - Cross-Site Scripting
|
23 |
WEB
|
ManhNho
|
|
2018-08-20
|
|
MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery
|
22 |
WEB
|
0xB9
|
|
2018-08-20
|
|
WordPress Plugin Chained Quiz 1.0.8 - 'answer' SQL Injection
|
24 |
WEB
|
Çlirim Emini
|
|
2018-08-17
|
|
ADM 3.1.2RHG1 - Remote Code Execution
|
28 |
WEB
|
Matthew Fulton
|
|
2018-08-17
|
|
Mikrotik WinBox 6.42 - Credential Disclosure (golang)
|
24 |
WEB
|
Maxim Yefimenko
|
|
2018-08-16
|
|
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
|
34 |
WEB
|
SEC Consult
|
|
2018-08-16
|
|
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
|
25 |
WEB
|
SEC Consult
|
|
2018-08-16
|
|
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
|
32 |
WEB
|
SEC Consult
|
|
2018-08-16
|
|
WordPress Plugin Export Users to CSV 1.1.1 - CSV Injection
|
27 |
WEB
|
Javier Olmedo
|
|
2018-08-16
|
|
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
|
26 |
WEB
|
Joshua Fam
|
|
2018-08-15
|
|
ASUS-DSL N10 1.1.2.2_17 - Authentication Bypass
|
28 |
WEB
|
AmnBAN
|
|
2018-08-15
|
|
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
|
26 |
WEB
|
Kyle Lovett
|
|
2018-08-14
|
|
Oracle Glassfish OSE 4.1 - Path Traversal (Metasploit)
|
23 |
WEB
|
Dhiraj Mishra
|
|
2018-08-14
|
|
Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit)
|
23 |
WEB
|
Metasploit
|
|
2018-08-14
|
|
Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit)
|
21 |
WEB
|
Metasploit
|
|
2018-08-14
|
|
cgit 1.2.1 - Directory Traversal (Metasploit)
|
30 |
WEB
|
Dhiraj Mishra
|
|
2018-08-13
|
|
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
|
28 |
WEB
|
Vikas Khanna
|
|
2018-08-10
|
|
MyBB Like Plugin 3.0.0 - Cross-Site Scripting
|
32 |
WEB
|
0xB9
|
|
2018-08-10
|
|
MyBB Thank You/Like Plugin 3.0.0 - Cross-Site Scripting
|
24 |
WEB
|
0xB9
|
|
2018-08-10
|
|
Zimbra 8.6.0_GA_1153 - Cross-Site Scripting
|
23 |
WEB
|
Dino Barlattani
|
|
2018-08-09
|
|
TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Information Disclosure)
|
30 |
WEB
|
Wadeek
|
|
2018-08-09
|
|
TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Remote Reboot)
|
25 |
WEB
|
Wadeek
|
|
2018-08-08
|
|
osTicket 1.10.1 - Arbitrary File Upload
|
30 |
WEB
|
Rajwinder Singh
|
|
2018-08-08
|
|
LG-Ericsson iPECS NMS 30M - Directory Traversal
|
39 |
WEB
|
Safak Aslan
|
|
2018-08-07
|
|
Monstra-Dev 3.0.4 - Cross-Site Request Forgery (Account Hijacking)
|
29 |
WEB
|
Nainsi Gupta
|
|
2018-08-07
|
|
OpenEMR 5.0.1.3 - Remote Code Execution (Authenticated)
|
28 |
WEB
|
Cody Zacharias
|
|
2018-08-06
|
|
Open-AudIT Community 2.2.6 - Cross-Site Scripting
|
28 |
WEB
|
Ranjeet Jaiswal
|
|
2018-08-06
|
|
Wavemaker Studio 6.6 - Server-Side Request Forgery
|
29 |
WEB
|
Gionathan Reale
|
|
2018-08-06
|
|
CMS ISWEB 3.5.3 - Directory Traversal
|
26 |
WEB
|
Thiago Sena
|
|
2018-08-06
|
|
onArcade 2.4.2 - Cross-Site Request Forgery (Add Admin)
|
27 |
WEB
|
r3m0t3nu11
|
|
2018-08-06
|
|
LAMS < 3.1 - Cross-Site Scripting
|
27 |
WEB
|
Nikola Kojic
|
|
2018-08-06
|
|
Sitecore.Net 8.1 - Directory Traversal
|
30 |
WEB
|
Chris
|
|
2018-08-06
|
|
Subrion CMS 4.2.1 - Cross-Site Scripting
|
29 |
WEB
|
Zeel Chavda
|
|
2018-08-03
|
|
cgit < 1.2.1 - 'cgit_clone_objects()' Directory Traversal
|
28 |
WEB
|
Google Security Research
|
|
2018-08-03
|
|
Plex Media Server 1.13.2.5154 - SSDP Processing XML External Entity Injection
|
29 |
WEB
|
Chris Moberly
|
|
2018-08-03
|
|
Vuze Bittorrent Client 5.7.6.0 - SSDP Processing XML External Entity Injection
|
27 |
WEB
|
Chris Moberly
|
|
2018-08-03
|
|
PHP Template Store Script 3.0.6 - Cross-Site Scripting
|
29 |
WEB
|
Sarafraz Khan
|
|
2018-08-02
|
|
Seq 4.2.476 - Authentication Bypass
|
28 |
WEB
|
Daniel Chactoura
|
|
2018-08-02
|
|
ASUS DSL-N12E_C1 1.1.2.3_345 - Remote Command Execution
|
32 |
WEB
|
Fakhri Zulkifli
|
|
2018-08-02
|
|
Universal Media Server 7.1.0 - SSDP Processing XML External Entity Injection
|
28 |
WEB
|
Chris Moberly
|
|
2018-08-02
|
|
CoSoSys Endpoint Protector 4.5.0.1 - (Authenticated) Remote Root Command Injection
|
32 |
WEB
|
0x09AL
|
|
2018-08-02
|
|
PageResponse FB Inboxer Add-on 1.2 - 'search_field' SQL Injection
|
29 |
WEB
|
AkkuS
|
|
2018-08-02
|
|
TI Online Examination System v2 - Arbitrary File Download
|
26 |
WEB
|
AkkuS
|
|
2018-08-02
|
|
WityCMS 0.6.2 - Cross-Site Request Forgery (Password Change)
|
31 |
WEB
|
Porhai Eung
|
|
2018-07-31
|
|
LG NAS 3718.510.a0 - Remote Command Execution
|
27 |
WEB
|
0x616163
|
|
2018-07-31
|
|
Craft CMS SEOmatic plugin 3.1.4 - Server-Side Template Injection
|
29 |
WEB
|
0xB455
|
|
2018-07-30
|
|
H2 Database 1.4.197 - Information Disclosure
|
28 |
WEB
|
owodelta
|
|
2018-07-30
|
|
Responsive Filemanager 9.13.1 - Server-Side Request Forgery
|
28 |
WEB
|
GUIA BRAHIM FOUAD
|
|
2018-07-27
|
|
SoftNAS Cloud < 4.0.3 - OS Command Injection
|
29 |
WEB
|
Core Security
|
|
2018-07-27
|
|
Online Trade 1 - Information Disclosure
|
27 |
WEB
|
Dhamotharan
|
|
2018-07-26
|
|
Kirby CMS 2.5.12 - Cross-Site Request Forgery (Delete Page)
|
41 |
WEB
|
Zaran Shaikh
|
|
2018-07-26
|
|
Trivum Multiroom Setup Tool 8.76 - Corss-Site Request Forgery (Admin Bypass)
|
35 |
WEB
|
vulnc0d3
|
|
2018-07-24
|
|
D-link DAP-1360 - Path Traversal / Cross-Site Scripting
|
24 |
WEB
|
r3m0t3nu11
|
|
2018-07-24
|
|
D-link DAP-1360 - Path Traversal / Cross-Site Scripting
|
29 |
WEB
|
r3m0t3nu11
|
|
2018-07-24
|
|
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
|
28 |
WEB
|
Mehmet Ince
|
|
2018-07-24
|
|
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
|
27 |
WEB
|
Mehmet Ince
|
|
2018-07-23
|
|
Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
|
28 |
WEB
|
Nathu Nandwani
|
|
2018-07-23
|
|
Davolink DVW 3200 Router - Password Disclosure
|
28 |
WEB
|
Ankit Anubhav
|
|
2018-07-23
|
|
Synology DiskStation Manager 4.1 - Directory Traversal
|
28 |
WEB
|
Berk Dusunur
|
|
2018-07-23
|
|
NUUO NVRmini - 'upgrade_handle.php' Remote Command Execution
|
29 |
WEB
|
Berk Dusunur
|
|
2018-07-23
|
|
Kirby CMS 2.5.12 - Cross-Site Scripting
|
31 |
WEB
|
Zaran Shaikh
|
|
2018-07-22
|
|
GeoVision GV-SNVR0811 - Directory Traversal
|
29 |
WEB
|
Berk Dusunur
|
|
2018-07-20
|
|
Touchpad / Trivum WebTouch Setup 2.53 build 13163 - Authentication Bypass
|
27 |
WEB
|
vulnc0d3
|
|
2018-07-20
|
|
MSVOD 10 - 'cid' SQL Injection
|
25 |
WEB
|
Hzllaga
|