Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2018-06-25   WordPress Plugin iThemes Security < 7.0.3 - SQL Injection 17 WEB Çlirim Emini
2018-06-25   WordPress Plugin Comments Import & Export < 2.0.4 - CSV Injection 23 WEB Bhushan B. Patil
2018-06-25   Intex Router N-150 - Arbitrary File Upload 15 WEB Samrat Das
2018-06-25   Ecessa ShieldLink SL175EHQ < 10.7.4 - Cross-Site Request Forgery (Add Superuser) 18 WEB LiquidWorm
2018-06-25   AsusWRT RT-AC750GF - Cross-Site Request Forgery (Change Admin Password) 16 WEB Wadeek
2018-06-25   Ecessa WANWorx WVR-30 < 10.7.4 - Cross-Site Request Forgery (Add Superuser) 16 WEB LiquidWorm
2018-06-25   DIGISOL DG-BR4000NG - Cross-Site Scripting 17 WEB Adipta Basu
2018-06-25   Intex Router N-150 - Cross-Site Request Forgery (Add Admin) 16 WEB Samrat Das
2018-06-25   Ecessa Edge EV150 10.7.4 - Cross-Site Request Forgery (Add Superuser) 15 WEB LiquidWorm
2018-06-25   WordPress Plugin Advanced Order Export For WooCommerce < 1.5.4 - CSV Injection 17 WEB Bhushan B. Patil
2018-06-22   phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (2) 22 WEB VulnSpy
2018-06-22   phpLDAPadmin 1.2.2 - 'server_id' LDAP Injection (Username) 20 WEB Berk Dusunur
2018-06-21   phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (1) 18 WEB ChaMd5
2018-06-22   GreenCMS 2.3.0603 - Information Disclosure 20 WEB vr_system
2018-06-21   LFCMS 3.7.0 - Cross-Site Request Forgery (Add Admin) 18 WEB bay0net
2018-06-21   LFCMS 3.7.0 - Cross-Site Request Forgery (Add User) 16 WEB bay0net
2018-06-20   VideoInsight WebClient 5 - SQL Injection 16 WEB vosec
2018-06-20   IPConfigure Orchid VMS 2.0.5 - Directory Traversal / Information Disclosure (Metasploit) 17 WEB Nettitude
2018-06-20   IPConfigure Orchid VMS 2.0.5 - Directory Traversal / Information Disclosure (Metasploit) 17 WEB Nettitude
2018-06-20   Apache CouchDB < 2.1.0 - Remote Code Execution 16 WEB Cody Zacharias
2018-06-20   TP-Link TL-WA850RE - Remote Command Execution 16 WEB yoresongo
2018-06-20   NewMark CMS 2.1 - 'sec_id' SQL Injection 16 WEB Berk Dusunur
2018-06-20   MaDDash 2.0.2 - Directory Listing 16 WEB ManhNho
2018-06-20   Mirasys DVMS Workstation 5.12.6 - Path Traversal 19 WEB Onvio
2018-06-18   Redatam Web Server < 7 - Directory Traversal 17 WEB Berk Dusunur
2018-06-18   RabbitMQ Web Management < 3.7.6 - Cross-Site Request Forgery (Add Admin) 21 WEB Dolev Farhi
2018-06-18   Joomla! Component Jomres 9.11.2 - Cross-Site Request Forgery (Add User) 20 WEB L0RD
2018-06-15   Dimofinf CMS 3.0.0 - Cross-Site Scripting 22 WEB Renzi
2018-06-15   OEcms 3.1 - Cross-Site Scripting 17 WEB Renzi
2018-06-14   Joomla! Component Ek Rishta 2.10 - SQL Injection 17 WEB Guilherme Assmann
2018-06-13   Redaxo CMS Mediapool Addon < 5.5.1 - Arbitrary File Upload 24 WEB h0n1gsp3cht
2018-06-13   MACCMS 10 - Cross-Site Request Forgery (Add User) 19 WEB bay0net
2018-06-12   WordPress Plugin Ultimate Form Builder Lite < 1.3.7 - SQL Injection 13 WEB defensecode
2018-06-12   WordPress Plugin Google Map < 4.0.4 - SQL Injection 17 WEB defensecode
2018-06-12   Canon PrintMe EFI - Cross-Site Scripting 14 WEB Huy Kha
2018-06-12   OX App Suite 7.8.4 - Multiple Vulnerabilities 12 WEB Open-Xchange
2018-06-12   OX App Suite 7.8.4 - Multiple Vulnerabilities 14 WEB Open-Xchange
2018-06-11   Siaberry 1.2.2 - Command Injection 12 WEB Space Duck
2018-06-12   Joomla! Component EkRishta 2.10 - 'username' SQL Injection 14 WEB L0RD
2018-06-11   Schools Alert Management Script - Arbitrary File Read 14 WEB M3@Pandas
2018-06-11   Schools Alert Management Script - 'get_sec.php' SQL Injection 13 WEB M3@Pandas
2018-06-11   userSpice 4.3.24 - Username Enumeration 14 WEB Dolev Farhi
2018-06-11   userSpice 4.3.24 - 'X-Forwarded-For' Cross-Site Scripting 12 WEB Dolev Farhi
2018-06-11   Schools Alert Management Script - Arbitrary File Deletion 12 WEB M3@Pandas
2018-06-11   Joomla! Component EkRishta 2.10 - 'cid' SQL Injection 15 WEB 41!kh4224rDz
2018-06-11   Event Manager Admin panel - 'events_new.php' SQL injection 11 WEB telahdihapus
2018-06-11   WordPress Plugin Pie Register < 3.0.9 - Blind SQL Injection 15 WEB Manuel García Cárdenas
2018-06-11   Schools Alert Management Script - SQL Injection 17 WEB M3@Pandas
2018-06-08   Splunk < 7.0.1 - Information Disclosure 20 WEB KoF2002
2018-06-08   XiongMai uc-httpd 1.0.0 - Buffer Overflow 18 WEB Andrew Watson
2018-06-07   Monstra CMS < 3.0.4 - Cross-Site Scripting (1) 16 WEB DEEPIN2
2018-06-07   WordPress Plugin Contact Form Maker 1.12.20 - SQL Injection 19 WEB defensecode
2018-06-07   WordPress Plugin Form Maker 1.12.24 - SQL Injection 17 WEB defensecode
2018-06-07   WampServer 3.0.6 - Cross-Site Request Forgery 21 WEB L0RD
2018-06-05   Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email) 18 WEB Kl3_GMjq6
2018-06-04   Brother HL Series Printers 1.15 - Cross-Site Scripting 16 WEB Huy Kha
2018-06-05   Pagekit < 1.0.13 - Cross-Site Scripting Code Generator 24 WEB DEEPIN2
2018-06-05   MyBB Recent Threads Plugin 1.0 - Cross-Site Scripting 20 WEB 0xB9
2018-06-04   EMS Master Calendar < 8.0.0.20180520 - Cross-Site Scripting 19 WEB Chris Barretto
2018-06-04   SearchBlox 8.6.7 - XML External Entity Injection 15 WEB Ahmet Gurel
2018-06-03   GreenCMS 2.3.0603 - Cross-Site Request Forgery (Add Admin) 16 WEB xichao
2018-06-03   GreenCMS 2.3.0603 - Cross-Site Request Forgery / Remote Code Execution 18 WEB xichao
2018-06-03   Smartshop 1 - Cross-Site Request Forgery 15 WEB L0RD
2018-06-03   Smartshop 1 - 'id' SQL Injection 16 WEB L0RD
2018-05-31   Grid Pro Big Data 1.0 - SQL Injection 18 WEB Kağan Çapar
2018-05-31   CSV Import & Export 1.1.0 - SQL Injection / Cross-Site Scripting 20 WEB Kağan Çapar
2018-05-31   PHP Dashboards NEW 5.5 - 'email' SQL Injection 23 WEB Kağan Çapar
2018-05-31   New STAR 2.1 - SQL Injection / Cross-Site Scripting 20 WEB Kağan Çapar
2018-05-31   TAC Xenta 511/911 - Directory Traversal 20 WEB Marek Cybul
2018-05-30   Dolibarr ERP/CRM 7.0.0 - (Authenticated) SQL Injection 14 WEB Sysdream
2018-05-30   MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass 17 WEB Amine Taouirsa
2018-05-30   Yosoro 1.0.4 - Remote Code Execution 15 WEB Carlo Pelliccioni
2018-05-30   SearchBlox 8.6.6 - Cross-Site Request Forgery 16 WEB Ahmet Gurel
2018-05-29   Facebook Clone Script 1.0.5 - Cross-Site Request Forgery 16 WEB L0RD
2018-05-29   Facebook Clone Script 1.0.5 - 'search' SQL Injection 18 WEB L0RD
2018-05-29   MyBB ChangUonDyU Plugin 1.0.2 - Cross-Site Scripting 18 WEB 0xB9
2018-05-29   NUUO NVRmini2 / NVRsolo - Arbitrary File Upload 18 WEB M3@Pandas
2018-05-29   Sitemakin SLAC 1.0 - 'my_item_search' SQL Injection 17 WEB Divya Jain
2018-05-29   IssueTrak 7.0 - SQL Injection 17 WEB Chris Anastasio
2018-05-28   wityCMS 0.6.1 - Cross-Site Scripting 19 WEB Nathu Nandwani
2018-05-28   Joomla! Component JoomOCShop 1.0 - Cross-Site Request Forgery 20 WEB L0RD
2018-05-28   Joomla! Component jCart for OpenCart 2.3.0.2 - Cross-Site Request Forgery 19 WEB L0RD
2018-05-28   Joomla! Component Full Social 1.1.0 - 'search_query' SQL Injection 17 WEB L0RD
2018-05-28   WordPress Plugin Events Calendar - SQL Injection 22 WEB AkkuS
2018-05-28   DomainMod 4.09.03 - 'sslpaid' Cross-Site Scripting 23 WEB longer
2018-05-28   DomainMod 4.09.03 - 'oid' Cross-Site Scripting 16 WEB longer
2018-05-28   TP-Link TL-WR840N/TL-WR841N - Authenticaton Bypass 21 WEB BlackFog Team
2018-05-27   Baby Names Search Engine 1.0 - 'a' SQL Injection 23 WEB AkkuS
2018-05-27   My Directory 2.0 - SQL Injection / Cross-Site Scripting 21 WEB AkkuS
2018-05-27   ClipperCMS 1.3.3 - Cross-Site Scripting 17 WEB Nathu Nandwani
2018-05-27   Listing Hub CMS 1.0 - SQL Injection 17 WEB AkkuS
2018-05-27   BookingWizz Booking System 5.5 - 'id' SQL Injection 14 WEB AkkuS
2018-05-27   Lyrist - 'id' SQL Injection 14 WEB Meisam Monsef
2018-05-27   Sharetronix CMS 3.6.2 - Cross-Site Request Forgery / Cross-Site Scripting 11 WEB Hesam Bazvand
2018-05-27   Ingenious School Management System - 'id' SQL Injection 13 WEB Meisam Monsef
2018-05-27   WordPress Plugin Booking Calendar 3.0.0 - SQL Injection / Cross-Site Scripting 13 WEB AkkuS
2018-05-26   easyLetters 1.0 - 'id' SQL Injection 15 WEB AkkuS
2018-05-26   mySurvey 1.0 - 'id' SQL Injection 14 WEB AkkuS
2018-05-26   EasyService Billing 1.0 - 'q' SQL Injection 10 WEB Divya Jain
2018-05-26   EasyService Billing 1.0 - Cross-Site Scripting 10 WEB Divya Jain
2018-05-26   EasyService Billing 1.0 - Cross-Site Request Forgery 13 WEB Divya Jain
2018-05-26   Ajax Full Featured Calendar 2.0 - 'search' SQL Injection 16 WEB AkkuS
2018-05-26   Employee Work Schedule 5.9 - 'cal_id' SQL Injection 16 WEB AkkuS
2018-05-25   Oracle WebCenter FatWire Content Server < 7 - Improper Access Control 15 WEB Sebastian Cornejo
2018-05-25   SAP Internet Transaction Server 6200.x - Session Fixation / Cross-Site Scripting 13 WEB J. Carrillo Lencina
2018-05-25   MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Scripting 13 WEB 0xB9
2018-05-25   KomSeo Cart 1.3 - 'my_item_search' SQL Injection 11 WEB AkkuS
2018-05-25   Oracle WebCenter Sites 11.1.1.8.0/12.2.1.x - Cross-Site Scripting 12 WEB Richard Alviarez
2018-05-24   EU MRV Regulatory Complete Solution 1 - Authentication Bypass 11 WEB Veyselxan
2018-05-24   Honeywell XL Web Controller - Cross-Site Scripting 12 WEB t4rkd3vilz
2018-05-24   Timber 1.1 - Cross-Site Request Forgery 12 WEB L0RD
2018-05-24   PaulNews 1.0 - 'keyword' SQL Injection / Cross-Site Scripting 16 WEB AkkuS
2018-05-24   ASP.NET jVideo Kit - 'query' SQL Injection 16 WEB AkkuS
2018-05-23   WordPress Plugin Peugeot Music - Arbitrary File Upload 16 WEB Mr.7z
2018-05-23   SKT LTE Wi-Fi SDT-CW3B1 - Unauthorized Admin Credential Change 14 WEB Safak Aslan
2018-05-23   Honeywell Scada System - Information Disclosure 15 WEB t4rkd3vilz
2018-05-23   Mcard Mobile Card Selling Platform 1 - SQL Injection 14 WEB L0RD
2018-05-23   eWallet Online Payment Gateway 2 - Cross-Site Request Forgery 16 WEB L0RD
2018-05-23   Wecodex Restaurant CMS 1.0 - 'Login' SQL Injection 12 WEB AkkuS
2018-05-23   Wecodex Hotel CMS 1.0 - 'Admin Login' SQL Injection 14 WEB AkkuS
2018-05-23   Library CMS 1.0 - SQL Injection 10 WEB AkkuS
2018-05-23   School Management System CMS 1.0 - 'username' SQL Injection 12 WEB AkkuS
2018-05-23   SAT CFDI 3.3 - SQL Injection 12 WEB AkkuS
2018-05-23   Wecodex Store Paypal 1.0 - SQL Injection 14 WEB AkkuS
2018-05-23   Shipping System CMS 1.0 - SQL Injection 16 WEB AkkuS