Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2018-08-30   Cybrotech CyBroHttpServer 1.0.3 - Cross-Site Scripting 25 WEB Emre ÖVÜNÇ
2018-08-30   WordPress Plugin Quizlord 2.0 - Cross-Site Scripting 26 WEB Renos Nikolaou
2018-08-30   DLink DIR-601 - Credential Disclosure 23 WEB Kevin Randall
2018-08-30   WordPress Plugin Jibu Pro 1.7 - Cross-Site Scripting 23 WEB Renos Nikolaou
2018-08-30   Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal 23 WEB Emre ÖVÜNÇ
2018-08-29   Argus Surveillance DVR 4.0.0.0 - Directory Traversal 23 WEB hyp3rlinx
2018-08-29   Episerver 7 patch 4 - XML External Entity Injection 29 WEB Jonas Lejon
2018-08-29   phpMyAdmin 4.7.x - Cross-Site Request Forgery 25 WEB VulnSpy
2018-08-27   WordPress Plugin Plainview Activity Monitor 20161228 - (Authenticated) Command Injection 23 WEB Lydéric Lefebvre
2018-08-27   Responsive FileManager < 9.13.4 - Directory Traversal 21 WEB Simon Uvarov
2018-08-27   Seagate Personal Cloud SRN21C 4.3.16.0 / 4.3.18.0 - SQL Injection 24 WEB Yorick Koster
2018-08-27   LiteCart 2.1.2 - Arbitrary File Upload 27 WEB Haboob Team
2018-08-27   Sentrifugo HRMS 3.2 - 'deptid' SQL Injection 26 WEB Javier Olmedo
2018-08-27   RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin) 26 WEB Ismail Tasdelen
2018-08-27   Gleez CMS 1.2.0 - Cross-Site Request Forgery (Add Admin) 23 WEB GunEggWang
2018-08-26   ManageEngine ADManager Plus 6.5.7 - Cross-Site Scripting 22 WEB Ismail Tasdelen
2018-08-26   WordPress Plugin Gift Voucher 1.0.5 - (Authenticated) 'template_id' SQL Injection 20 WEB Renos Nikolaou
2018-08-25   ManageEngine ADManager Plus 6.5.7 - HTML Injection 21 WEB Ismail Tasdelen
2018-08-25   UltimatePOS 2.5 - Remote Code Execution 26 WEB Renos Nikolaou
2018-08-24   Vox TG790 ADSL Router - Cross-Site Request Forgery (Add Admin) 25 WEB cakes
2018-08-23   PCViewer vt1000 - Directory Traversal 24 WEB Berk Dusunur
2018-08-23   Twitter-Clone 1 - 'code' SQL Injection 28 WEB L0RD
2018-08-22   Geutebrueck re_porter 16 - Cross-Site Scripting 30 WEB Kamil Suska
2018-08-22   Geutebrueck re_porter 7.8.974.20 - Credential Disclosure 26 WEB Kamil Suska
2018-08-22   KingMedia 4.1 - File Upload 26 WEB Efrén Díaz
2018-08-22   ZyXEL VMG3312-B10B - Cross-Site Scripting 26 WEB Samet ŞAHİN
2018-08-21   WordPress Plugin Ninja Forms 3.3.13 - CSV Injection 24 WEB Mostafa Gharzi
2018-08-21   Twitter-Clone 1 - Cross-Site Request Forgery (Delete Post) 19 WEB L0RD
2018-08-21   Hikvision IP Camera 5.4.0 - User Enumeration (Metasploit) 23 WEB Alfie
2018-08-21   Twitter-Clone 1 - 'userid' SQL Injection 20 WEB L0RD
2018-08-20   Countly - Cross-Site Scripting 22 WEB Sleepy
2018-08-20   WordPress Plugin Tagregator 0.6 - Cross-Site Scripting 23 WEB ManhNho
2018-08-20   MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery 20 WEB 0xB9
2018-08-20   WordPress Plugin Chained Quiz 1.0.8 - 'answer' SQL Injection 24 WEB Çlirim Emini
2018-08-17   ADM 3.1.2RHG1 - Remote Code Execution 26 WEB Matthew Fulton
2018-08-17   Mikrotik WinBox 6.42 - Credential Disclosure (golang) 24 WEB Maxim Yefimenko
2018-08-16   Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery 30 WEB SEC Consult
2018-08-16   Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery 25 WEB SEC Consult
2018-08-16   Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery 30 WEB SEC Consult
2018-08-16   WordPress Plugin Export Users to CSV 1.1.1 - CSV Injection 26 WEB Javier Olmedo
2018-08-16   OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions 24 WEB Joshua Fam
2018-08-15   ASUS-DSL N10 1.1.2.2_17 - Authentication Bypass 25 WEB AmnBAN
2018-08-15   ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection 25 WEB Kyle Lovett
2018-08-14   Oracle Glassfish OSE 4.1 - Path Traversal (Metasploit) 23 WEB Dhiraj Mishra
2018-08-14   Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit) 23 WEB Metasploit
2018-08-14   Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit) 20 WEB Metasploit
2018-08-14   cgit 1.2.1 - Directory Traversal (Metasploit) 28 WEB Dhiraj Mishra
2018-08-13   IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting 26 WEB Vikas Khanna
2018-08-10   MyBB Like Plugin 3.0.0 - Cross-Site Scripting 29 WEB 0xB9
2018-08-10   MyBB Thank You/Like Plugin 3.0.0 - Cross-Site Scripting 23 WEB 0xB9
2018-08-10   Zimbra 8.6.0_GA_1153 - Cross-Site Scripting 23 WEB Dino Barlattani
2018-08-09   TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Information Disclosure) 30 WEB Wadeek
2018-08-09   TP-Link C50 Wireless Router 3 - Cross-Site Request Forgery (Remote Reboot) 24 WEB Wadeek
2018-08-08   osTicket 1.10.1 - Arbitrary File Upload 25 WEB Rajwinder Singh
2018-08-08   LG-Ericsson iPECS NMS 30M - Directory Traversal 37 WEB Safak Aslan
2018-08-07   Monstra-Dev 3.0.4 - Cross-Site Request Forgery (Account Hijacking) 28 WEB Nainsi Gupta
2018-08-07   OpenEMR 5.0.1.3 - Remote Code Execution (Authenticated) 25 WEB Cody Zacharias
2018-08-06   Open-AudIT Community 2.2.6 - Cross-Site Scripting 23 WEB Ranjeet Jaiswal
2018-08-06   Wavemaker Studio 6.6 - Server-Side Request Forgery 23 WEB Gionathan Reale
2018-08-06   CMS ISWEB 3.5.3 - Directory Traversal 24 WEB Thiago Sena
2018-08-06   onArcade 2.4.2 - Cross-Site Request Forgery (Add Admin) 26 WEB r3m0t3nu11
2018-08-06   LAMS < 3.1 - Cross-Site Scripting 27 WEB Nikola Kojic
2018-08-06   Sitecore.Net 8.1 - Directory Traversal 28 WEB Chris
2018-08-06   Subrion CMS 4.2.1 - Cross-Site Scripting 27 WEB Zeel Chavda
2018-08-03   cgit < 1.2.1 - 'cgit_clone_objects()' Directory Traversal 27 WEB Google Security Research
2018-08-03   Plex Media Server 1.13.2.5154 - SSDP Processing XML External Entity Injection 29 WEB Chris Moberly
2018-08-03   Vuze Bittorrent Client 5.7.6.0 - SSDP Processing XML External Entity Injection 27 WEB Chris Moberly
2018-08-03   PHP Template Store Script 3.0.6 - Cross-Site Scripting 29 WEB Sarafraz Khan
2018-08-02   Seq 4.2.476 - Authentication Bypass 26 WEB Daniel Chactoura
2018-08-02   ASUS DSL-N12E_C1 1.1.2.3_345 - Remote Command Execution 30 WEB Fakhri Zulkifli
2018-08-02   Universal Media Server 7.1.0 - SSDP Processing XML External Entity Injection 26 WEB Chris Moberly
2018-08-02   CoSoSys Endpoint Protector 4.5.0.1 - (Authenticated) Remote Root Command Injection 30 WEB 0x09AL
2018-08-02   PageResponse FB Inboxer Add-on 1.2 - 'search_field' SQL Injection 28 WEB AkkuS
2018-08-02   TI Online Examination System v2 - Arbitrary File Download 26 WEB AkkuS
2018-08-02   WityCMS 0.6.2 - Cross-Site Request Forgery (Password Change) 28 WEB Porhai Eung
2018-07-31   LG NAS 3718.510.a0 - Remote Command Execution 25 WEB 0x616163
2018-07-31   Craft CMS SEOmatic plugin 3.1.4 - Server-Side Template Injection 27 WEB 0xB455
2018-07-30   H2 Database 1.4.197 - Information Disclosure 28 WEB owodelta
2018-07-30   Responsive Filemanager 9.13.1 - Server-Side Request Forgery 28 WEB GUIA BRAHIM FOUAD
2018-07-27   SoftNAS Cloud < 4.0.3 - OS Command Injection 29 WEB Core Security
2018-07-27   Online Trade 1 - Information Disclosure 24 WEB Dhamotharan
2018-07-26   Kirby CMS 2.5.12 - Cross-Site Request Forgery (Delete Page) 29 WEB Zaran Shaikh
2018-07-26   Trivum Multiroom Setup Tool 8.76 - Corss-Site Request Forgery (Admin Bypass) 33 WEB vulnc0d3
2018-07-24   D-link DAP-1360 - Path Traversal / Cross-Site Scripting 24 WEB r3m0t3nu11
2018-07-24   D-link DAP-1360 - Path Traversal / Cross-Site Scripting 28 WEB r3m0t3nu11
2018-07-24   Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit) 28 WEB Mehmet Ince
2018-07-24   Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit) 27 WEB Mehmet Ince
2018-07-23   Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router) 28 WEB Nathu Nandwani
2018-07-23   Davolink DVW 3200 Router - Password Disclosure 24 WEB Ankit Anubhav
2018-07-23   Synology DiskStation Manager 4.1 - Directory Traversal 27 WEB Berk Dusunur
2018-07-23   NUUO NVRmini - 'upgrade_handle.php' Remote Command Execution 27 WEB Berk Dusunur
2018-07-23   Kirby CMS 2.5.12 - Cross-Site Scripting 29 WEB Zaran Shaikh
2018-07-22   GeoVision GV-SNVR0811 - Directory Traversal 26 WEB Berk Dusunur
2018-07-20   Touchpad / Trivum WebTouch Setup 2.53 build 13163 - Authentication Bypass 25 WEB vulnc0d3
2018-07-20   MSVOD 10 - 'cid' SQL Injection 24 WEB Hzllaga
2018-07-19   MyBB New Threads Plugin 1.1 - Cross-Site Scripting 23 WEB 0xB9
2018-07-19   WordPress Plugin All In One Favicon 4.6 - (Authenticated) Cross-Site Scripting 21 WEB Javier Olmedo
2018-07-18   Modx Revolution < 2.6.4 - Remote Code Execution 20 WEB Vitalii Rudnykh
2018-07-18   FTP2FTP 1.0 - Arbitrary File Download 24 WEB AkkuS
2018-07-18   Open-AudIT Community 2.1.1 - Cross-Site Scripting 28 WEB Ranjeet Jaiswal
2018-07-18   Smart SMS & Email Manager 3.3 - 'contact_type_id' SQL Injection 24 WEB AkkuS
2018-07-16   PrestaShop < 1.6.1.19 - 'BlowFish ECD' Privilege Escalation 23 WEB Charles Fol
2018-07-16   PrestaShop < 1.6.1.19 - 'AES CBC' Privilege Escalation 22 WEB Charles Fol
2018-07-17   Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway - Remote Root 24 WEB LiquidWorm
2018-07-17   Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway - File Manipulation 21 WEB LiquidWorm
2018-07-17   Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway - Configuration Download 18 WEB LiquidWorm
2018-07-17   Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway - Cross-Site Request Forgery 22 WEB LiquidWorm
2018-07-16   WordPress Plugin Job Manager 4.1.0 - Cross-Site Scripting 25 WEB Berk Dusunur
2018-07-16   VelotiSmart WiFi B-380 Camera - Directory Traversal 24 WEB Miguel Mendez Z
2018-07-16   Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection 34 WEB alt3kx
2018-07-13   Grundig Smart Inter@ctive 3.0 - Cross-Site Request Forgery 26 WEB t4rkd3vilz
2018-07-13   Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload 25 WEB Safak Aslan
2018-07-13   Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure 23 WEB SEC Consult
2018-07-13   QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities 28 WEB Core Security
2018-07-13   WAGO e!DISPLAY 7300T - Multiple Vulnerabilities 30 WEB SEC Consult
2018-07-11   Dicoogle PACS 2.5.0 - Directory Traversal 26 WEB Carlos Avila
2018-07-11   Instagram-Clone Script 2.0 - Cross-Site Scripting 24 WEB L0RD
2018-07-10   D-Link DIR601 2.02 - Credential Disclosure 23 WEB Thomas Zuk
2018-07-10   Elektronischer Leitz-Ordner 10 - SQL Injection 23 WEB Jens Regel
2018-07-07   Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code Execution 25 WEB bobsecq
2018-07-10   WolfSight CMS 3.2 - SQL Injection 20 WEB Berk Dusunur
2018-07-04   Gitea 1.4.0 - Remote Code Execution 22 WEB Kacper Szurek
2018-07-09   Umbraco CMS SeoChecker Plugin 1.9.2 - Cross-Site Scripting 27 WEB Ahmed Elhady Mohamed
2018-07-06   Airties AIR5444TT - Cross-Site Scripting 28 WEB Raif Berkay Dincel
2018-07-05   ADB Broadband Gateways / Routers - Authorization Bypass 22 WEB SEC Consult