Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2018-05-23   MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection / Cross-Site Scripting 11 WEB AkkuS
2018-05-23   MySQL Blob Uploader 1.7 - 'home-file-edit.php' SQL Injection / Cross-Site Scripting 10 WEB AkkuS
2018-05-23   MySQL Blob Uploader 1.7 - 'download.php' SQL Injection / Cross-Site Scripting 11 WEB AkkuS
2018-05-23   MySQL Smart Reports 1.0 - 'id' SQL Injection / Cross-Site Scripting 10 WEB AkkuS
2018-05-23   EasyService Billing 1.0 - 'p1' SQL Injection 10 WEB AkkuS
2018-05-23   EasyService Billing 1.0 - SQL Injection / Cross-Site Scripting 10 WEB AkkuS
2018-05-22   Easy File Uploader 1.7 - SQL Injection / Cross-Site Scripting 10 WEB AkkuS
2018-05-22   NewsBee CMS 1.4 - 'download.php' SQL Injection 10 WEB AkkuS
2018-05-22   Feedy RSS News Ticker 2.0 - 'cat' SQL Injection 14 WEB AkkuS
2018-05-22   NewsBee CMS 1.4 - 'home-text-edit.php' SQL Injection 11 WEB AkkuS
2018-05-22   Auto Car 1.2 - 'car_title' SQL Injection / Cross-Site Scripting 10 WEB L0RD
2018-05-22   NewsBee CMS 1.4 - 'home-text-edit.php' SQL Injection 14 WEB AkkuS
2018-05-22   iSocial 1.2.0 - Cross-Site Scripting / Cross-Site Request Forgery 13 WEB L0RD
2018-05-22   ERPnext 11 - Cross-Site Scripting 14 WEB Veerababu Penugonda
2018-05-22   PaulPrinting CMS Printing 1.0 - SQL Injection 13 WEB Mehmet Onder
2018-05-22   Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting 13 WEB t4rkd3vilz
2018-05-22   WebSocket Live Chat - Cross-Site Scripting 10 WEB Alireza Norkazemi
2018-05-22   Zechat 1.5 - SQL Injection / Cross-Site Request Forgery 11 WEB L0RD
2018-05-22   Nordex N149/4.0-4.5 - SQL Injection 10 WEB t4rkd3vilz
2018-05-21   Wchat PHP AJAX Chat Script 1.5 - Cross-Site Scripting 12 WEB L0RD
2018-05-21   Model Agency Media House & Model Gallery 1.0 - Multiple Vulnerabilities 11 WEB L0RD
2018-05-21   Merge PACS 7.0 - Cross-Site Request Forgery 14 WEB Safak Aslan
2018-05-21   Auto Dealership & Vehicle Showroom WebSys 1.0 - Multiple Vulnerabilities 16 WEB L0RD
2018-05-21   Schneider Electric PLCs - Cross-Site Request Forgery 15 WEB t4rkd3vilz
2018-05-21   Teradek Slice 7.3.15 - Cross-Site Request Forgery 16 WEB LiquidWorm
2018-05-21   Teradek Cube 7.3.6 - Cross-Site Request Forgery 11 WEB LiquidWorm
2018-05-21   Teradek VidiU Pro 3.0.3 - Server-Side Request Forgery 13 WEB LiquidWorm
2018-05-21   Teradek VidiU Pro 3.0.3 - Cross-Site Request Forgery 11 WEB LiquidWorm
2018-05-21   GitBucket 4.23.1 - Remote Code Execution 12 WEB Kacper Szurek
2018-05-21   Siemens SIMATIC S7-1200 CPU - Cross-Site Request Forgery 11 WEB t4rkd3vilz
2018-05-21   ManageEngine Recovery Manager Plus 5.3 - Cross-Site Scripting 12 WEB Ahmet Gurel
2018-05-21   Zenar Content Management System - Cross-Site Scripting 13 WEB Berk Dusunur
2018-05-21   Flippy DamnFacts - Viral Fun Facts Sharing Script 1.1.0 - Cross-Site Scripting / Cross-Site Request 12 WEB L0RD
2018-05-21   Flippy DamnFacts - Viral Fun Facts Sharing Script 1.1.0 - Cross-Site Scripting / Cross-Site Request 11 WEB L0RD
2018-05-21   Private Message PHP Script 2.0 - Cross-Site Scripting 12 WEB L0RD
2018-05-21   Superfood 1.0 - Multiple Vulnerabilities 11 WEB L0RD
2018-05-20   Joomla! Component EkRishta 2.10 - Cross-Site Scripting / SQL Injection 11 WEB Sina Kheirkhah
2018-05-20   D-Link DSL-3782 - Authentication Bypass 14 WEB Giulio Comi
2018-05-18   SAP B2B / B2C CRM 2.x < 4.x - Local File Inclusion 13 WEB Richard Alviarez
2018-05-18   Infinity Market Classified Ads Script 1.6.2 - Cross-Site Request Forgery 12 WEB L0RD
2018-05-18   Cisco SA520W Security Appliance - Path Traversal 16 WEB Nassim Asrir
2018-05-18   SAP NetWeaver Web Dynpro 6.4 < 7.5 - Information Disclosure 17 WEB Richard Alviarez
2018-05-18   Monstra CMS < 3.0.4 - Cross-Site Scripting (2) 12 WEB Berk Dusunur
2018-05-18   Healwire Online Pharmacy 3.0 - Cross-Site Scripting / Cross-Site Request Forgery 16 WEB L0RD
2018-05-17   Powerlogic/Schneider Electric IONXXXX Series - Cross-Site Request Forgery 17 WEB t4rkd3vilz
2018-05-17   SuperCom Online Shopping Ecommerce Cart 1 - Persistent Cross-Site scripting / Cross site request for 12 WEB L0RD
2018-05-17   SuperCom Online Shopping Ecommerce Cart 1 - Persistent Cross-Site scripting / Cross site request for 14 WEB L0RD
2018-05-17   Intelbras NCLOUD 300 1.0 - Authentication bypass 13 WEB Pedro Aguiar
2018-05-17   NodAPS 4.0 - SQL injection / Cross-Site Request Forgery 14 WEB L0RD
2018-05-17   NodAPS 4.0 - SQL injection / Cross-Site Request Forgery 14 WEB L0RD
2018-05-16   RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross 16 WEB SEC Consult
2018-05-16   RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross 15 WEB SEC Consult
2018-05-16   WordPress Plugin Metronet Tag Manager 1.2.7 - Cross-Site Request Forgery 16 WEB dxw
2018-05-16   totemomail Encryption Gateway 6.0.0 Build 371 - Cross-Site Request Forgery 14 WEB Compass Security
2018-05-16   Horse Market Sell & Rent Portal Script 1.5.7 - Cross-Site Request Forgery 14 WEB L0RD
2018-05-16   Multiplayer BlackJack Online Casino Game 2.5 - Cross-Site Scripting 15 WEB L0RD
2018-05-16   Rockwell Scada System 27.011 - Cross-Site Scripting 12 WEB t4rkd3vilz
2018-05-16   VirtueMart 3.1.14 - Persistent Cross-Site Scripting 15 WEB Mattia Furlani
2018-05-16   MyBB Admin Notes Plugin 1.1 - Cross-Site Request Forgery 13 WEB 0xB9
2018-05-03   JasperReports - (Authenticated) File Read 18 WEB Hector Monsegur
2018-05-14   XATABoost 1.0.0 - SQL Injection 13 WEB MgThuraMoeMyint
2018-05-13   WUZHI CMS 4.1.0 - 'tag[pinyin]' Cross-Site Scripting 15 WEB jiguang
2018-05-13   WUZHI CMS 4.1.0 - 'form[qq_10]' Cross-Site Scripting 16 WEB jiguang
2018-05-11   Open-AudIT Community 2.2.0 - Cross-Site Scripting 15 WEB Tejesh Kolisetty
2018-05-11   Open-AudIT Professional - 2.1.1 - Cross-Site Scripting 16 WEB Tejesh Kolisetty
2018-05-10   MyBB Latest Posts on Profile Plugin 1.1 - Cross-Site Scripting 19 WEB 0xB9
2018-05-10   ModbusPal 1.6b - XML External Entity Injection 16 WEB Trent Gordon
2018-05-10   Fastweb FASTGate 0.00.47 - Cross-Site Request Forgery 16 WEB Raffaele Sabato
2018-05-06   WordPress Plugin User Role Editor < 4.25 - Privilege Escalation 18 WEB Tomislav Paskalev
2018-05-06   CSP MySQL User Manager 2.3.1 - Authentication Bypass 23 WEB Youssef Mami
2018-05-04   IceWarp Mail Server < 11.1.1 - Directory Traversal 15 WEB Trustwave's SpiderLabs
2018-05-04   WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting 17 WEB B0UG
2014-01-14   Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection 19 WEB Takeshi Terada
2018-03-27   DLINK DCS-5020L - Remote Code Execution (PoC) 17 WEB Fidus InfoSecurity
2018-05-02   Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery 22 WEB Qian Wu_ Bo Wang_ Jiawang Zhang
2018-05-01   WordPress Plugin Responsive Cookie Consent 1.7 / 1.6 / 1.5 - (Authenticated) Persistent Cross-Site S 15 WEB B0UG
2018-04-30   Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root 13 WEB Jared Arave
2018-04-30   Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root 13 WEB Jared Arave
2018-04-30   WordPress Plugin Form Maker 1.12.20 - CSV Injection 15 WEB Sairam Jetty
2018-04-30   Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit) 13 WEB SixP4ck3r
2018-04-30   Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit) 15 WEB SixP4ck3r
2018-04-26   Frog CMS 0.9.5 - Persistent Cross-Site Scripting 15 WEB Wenming Jiang
2018-04-26   TP-Link Technologies TL-WA850RE Wi-Fi Range Extender - Remote Reboot 17 WEB Wadeek
2018-04-26   GitList 0.6 - Remote Code Execution 18 WEB Kacper Szurek
2018-04-26   MyBB Threads to Link Plugin 1.3 - Cross-Site Scripting 15 WEB 0xB9
2018-04-26   October CMS User Plugin 1.4.5 - Persistent Cross-Site Scripting 14 WEB 0xB9
2018-04-26   SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response 11 WEB Sven Fassbender
2018-04-26   WordPress Plugin WP with Spritz 1.0 - Remote File Inclusion 9 WEB Wadeek
2018-04-26   Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution 14 WEB Alessio Sergi
2018-04-25   Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC) 12 WEB Blaklis
2018-04-25   HRSALE The Ultimate HRM 1.0.2 - Local File Inclusion 11 WEB 8bitsec
2018-04-25   HRSALE The Ultimate HRM 1.0.2 - (Authenticated) Cross-Site Scripting 12 WEB 8bitsec
2018-04-25   HRSALE The Ultimate HRM 1.0.2 - 'award_id' SQL Injection 11 WEB 8bitsec
2018-04-25   HRSALE The Ultimate HRM 1.0.2 - CSV Injection 12 WEB 8bitsec
2018-04-25   Blog Master Pro 1.0 - CSV Injection 16 WEB 8bitsec
2018-04-25   Shopy Point of Sale 1.0 - CSV Injection 15 WEB 8bitsec
2018-04-24   WSO2 Carbon / WSO2 Dashboard Server 5.3.0 - Persistent Cross-Site Scripting 17 WEB SEC Consult
2018-04-24   WordPress Plugin Woo Import Export 1.0 - Arbitrary File Deletion 16 WEB Lenon Leite
2018-04-24   Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure 15 WEB Berk Cem Göksel
2018-04-24   Interspire Email Marketer < 6.1.6 - Remote Admin Authentication Bypass 13 WEB devcoinfet
2018-04-24   Monstra CMS 3.0.4 - Arbitrary Folder Deletion 15 WEB Wenming Jiang
2018-04-24   Open-AudIT 2.1 - CSV Macro Injection 15 WEB Sureshbabu Narvaneni
2018-04-24   WUZHI CMS 4.1.0 - Cross-Site Request Forgery 17 WEB jiguang
2018-04-24   UK Cookie Consent - Persistent Cross-Site Scripting 15 WEB B0UG
2018-04-23   Monstra cms 3.0.4 - Persitent Cross-Site Scripting 12 WEB Wenming Jiang
2018-04-23   Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure 17 WEB Larry W. Cashdollar
2018-04-23   Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation 16 WEB r4wd3r
2018-04-23   Ncomputing vSpace Pro 10/11 - Directory Traversal 13 WEB Javier Bernardo
2018-04-23   phpMyAdmin 4.8.0 < 4.8.0-1 - Cross-Site Request Forgery 17 WEB revengsh
2018-04-20   Cobub Razor 0.8.0 - Physical Path Leakage 14 WEB Kyhvedn
2018-04-18   Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities 15 WEB bzyo
2018-04-18   Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities 12 WEB bzyo
2018-04-18   Joomla! Component JS Jobs 1.2.0 - Cross-Site Request Forgery 13 WEB Sureshbabu Narvaneni
2018-04-18   WordPress Plugin Caldera Forms 1.5.9.1 - Cross-Site Scripting 11 WEB Federico Scalco
2018-04-18   Lutron Quantum 2.0 - 3.2.243 - Information Disclosure 14 WEB SadFud
2018-04-18   Kodi 17.6 - Persistent Cross-Site Scripting 15 WEB Manuel García Cárdenas
2018-04-18   Match Clone Script 1.0.4 - Cross-Site Scripting 18 WEB ManhNho
2018-04-18   Rvsitebuilder CMS - Database Backup Download 15 WEB Hesam Bazvand
2018-04-18   MySQL Squid Access Report 2.1.4 - SQL Injection / Cross-Site Scripting 14 WEB Keerati T.
2018-04-18   MySQL Squid Access Report 2.1.4 - SQL Injection / Cross-Site Scripting 19 WEB Keerati T.
2018-04-17   Joomla! Component jDownloads 3.2.58 - Cross Site Scripting 14 WEB Sureshbabu Narvaneni
2018-04-16   Sophos Cyberoam UTM CR25iNG - 10.6.3 MR-5 - Direct Object Reference 14 WEB Frogy
2018-04-16   Cobub Razor 0.8.0 - SQL injection 19 WEB Kyhvedn
2018-04-13   Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution 16 WEB Hans Topo & g0tmi1k
2018-04-13   Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC) 15 WEB Vitalii Rudnykh