|
2017-10-04
|
|
ClipBucket 2.8.3 - Remote Code Execution
|
12 |
WEB
|
Meisam Monsef
|
|
2017-09-20
|
|
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execu
|
10 |
WEB
|
xxlegend
|
|
2017-10-03
|
|
EPESI 1.8.2 rev20170830 - Cross-Site Scripting
|
9 |
WEB
|
Zeeshan Shaikh
|
|
2017-10-03
|
|
Fiberhome AN5506-04-F - Command Injection
|
11 |
WEB
|
Tauco
|
|
2017-10-02
|
|
OpenText Document Sciences xPression 4.5SP1 Patch 13 - 'documentId' SQL Injection
|
11 |
WEB
|
Marcin Woloszyn
|
|
2017-10-02
|
|
OpenText Document Sciences xPression 4.5SP1 Patch 13 - 'jobRunId' SQL Injection
|
9 |
WEB
|
Marcin Woloszyn
|
|
2017-10-02
|
|
phpCollab 2.5.1 - SQL Injection
|
10 |
WEB
|
Sysdream
|
|
2017-10-02
|
|
phpCollab 2.5.1 - Arbitrary File Upload
|
8 |
WEB
|
Sysdream
|
|
2017-10-02
|
|
NPM-V (Network Power Manager) 2.4.1 - Password Reset
|
12 |
WEB
|
Saeed reza Zamanian
|
|
2017-09-24
|
|
HBGK DVR 3.0.0 build20161206 - Authentication Bypass
|
10 |
WEB
|
RAT - ThiefKing
|
|
2017-09-29
|
|
ConverTo Video Downloader & Converter 1.4.1 - Arbitrary File Download
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-28
|
|
Real Estate MLM plan script 1.0 - 'srch' SQL Injection
|
9 |
WEB
|
8bitsec
|
|
2017-09-28
|
|
PHP Multi Vendor Script 1.02 - 'sid' SQL Injection
|
11 |
WEB
|
8bitsec
|
|
2017-09-29
|
|
WordPress Plugin WPHRM - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-27
|
|
SmarterStats 11.3.6347 - Cross-Site Scripting
|
9 |
WEB
|
sqlhacker
|
|
2017-09-29
|
|
FileRun < 2017.09.18 - SQL Injection
|
10 |
WEB
|
SPARC
|
|
2017-09-28
|
|
Easy Blog PHP Script 1.3a - 'id' SQL Injection
|
12 |
WEB
|
8bitsec
|
|
2017-09-28
|
|
Roteador Wireless Intelbras WRN150 - Autentication Bypass
|
11 |
WEB
|
Elber Tavares
|
|
2017-09-28
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - 'Host' Header Injection
|
11 |
WEB
|
hyp3rlinx
|
|
2017-09-28
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - Server Side Request Forgery
|
9 |
WEB
|
hyp3rlinx
|
|
2017-09-28
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - Information Disclosure
|
10 |
WEB
|
hyp3rlinx
|
|
2017-09-28
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - Code Execution / Memory Corruption
|
11 |
WEB
|
hyp3rlinx
|
|
2017-09-28
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - Private Key Disclosure
|
8 |
WEB
|
hyp3rlinx
|
|
2017-02-22
|
|
Fibaro Home Center 2 - Remote Command Execution / Privilege Escalation
|
9 |
WEB
|
forsec
|
|
2017-09-26
|
|
WordPress Plugin WPAMS - SQL Injection
|
12 |
WEB
|
Ihsan Sencan
|
|
2017-09-26
|
|
WordPress Plugin School Management System - SQL Injection
|
17 |
WEB
|
Ihsan Sencan
|
|
2017-09-26
|
|
WordPress Plugin Hospital Management System - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-26
|
|
WordPress Plugin WPGYM - SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2017-09-26
|
|
WordPress Plugin WPCHURCH - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-26
|
|
AMC Master - Arbitrary File Upload
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-09-26
|
|
SMSmaster - SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-26
|
|
Photo Fusion - Arbitrary File Upload
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-26
|
|
TicketPlus - Arbitrary File Upload
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-26
|
|
Job Links - Arbitrary File Upload
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-09-16
|
|
WordPress Plugin Content Timeline - SQL Injection
|
9 |
WEB
|
Jeroen - IT Nerdbox
|
|
2017-08-31
|
|
Sitefinity CMS 9.2 - Cross-Site Scripting
|
11 |
WEB
|
Pralhad Chaskar
|
|
2017-09-25
|
|
FLIR Thermal Camera F/FC/PT/D - Stream Disclosure
|
10 |
WEB
|
LiquidWorm
|
|
2017-09-25
|
|
FLIR Thermal Camera FC-S/PT - Command Injection
|
10 |
WEB
|
LiquidWorm
|
|
2017-09-25
|
|
FLIR Thermal Camera F/FC/PT/D - Information Disclosure
|
10 |
WEB
|
LiquidWorm
|
|
2017-09-25
|
|
FLIR Thermal Camera PT-Series (PT-334 200562) - Root Remote Code Execution
|
12 |
WEB
|
LiquidWorm
|
|
2017-09-22
|
|
JitBit HelpDesk < 9.0.2 - Authentication Bypass
|
11 |
WEB
|
Kc57
|
|
2017-09-22
|
|
PHP Auction Ecommerce Script 1.6 - SQL Injection
|
8 |
WEB
|
8bitsec
|
|
2017-09-22
|
|
Secure E-commerce Script 1.02 - 'sid' SQL Injection
|
7 |
WEB
|
8bitsec
|
|
2017-09-22
|
|
Claydip Airbnb Clone 1.0 - Arbitrary File Upload
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-22
|
|
Cash Back Comparison Script 1.0 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-09-22
|
|
Multi Level Marketing - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-09-22
|
|
Lending And Borrowing - 'pid' SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-19
|
|
DenyAll WAF < 6.3.0 - Remote Code Execution (Metasploit)
|
10 |
WEB
|
Mehmet Ince
|
|
2017-09-22
|
|
Stock Photo Selling 1.0 - SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-21
|
|
PHPMyFAQ 2.9.8 - Cross-Site Scripting (1)
|
11 |
WEB
|
Ishaq Mohammed
|
|
2017-05-19
|
|
Tecnovision DLX Spot - Arbitrary File Upload
|
8 |
WEB
|
Simon Brannstrom
|
|
2017-05-19
|
|
Tecnovision DLX Spot - Authentication Bypass
|
11 |
WEB
|
Simon Brannstrom
|
|
2017-09-15
|
|
iTech Gigs Script 1.20 - 'cat' SQL Injection
|
9 |
WEB
|
8bitsec
|
|
2017-09-13
|
|
Foodspotting Clone 1.0 - SQL Injection
|
10 |
WEB
|
8bitsec
|
|
2017-09-18
|
|
Apache < 2.2.34 / < 2.4.27 - OPTIONS Memory Leak
|
9 |
WEB
|
Hanno Bock
|
|
2017-09-18
|
|
iBall ADSL2+ Home Router - Authentication Bypass
|
10 |
WEB
|
Gem George
|
|
2017-09-15
|
|
UTStar WA3002G4 ADSL Broadband Modem - Authentication Bypass
|
10 |
WEB
|
Gem George
|
|
2017-09-18
|
|
DigiAffiliate 1.4 - Cross-Site Request Forgery (Update Admin)
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-09-18
|
|
Digileave 1.2 - Cross-Site Request Forgery (Update Admin)
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-09-18
|
|
Digirez 3.4 - Cross-Site Request Forgery (Update Admin)
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-15
|
|
Contact Manager 1.0 - 'femail' SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-15
|
|
PTCEvolution 5.50 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-14
|
|
Humax Wi-Fi Router HG100R 2.0.6 - Authentication Bypass
|
9 |
WEB
|
Kivson
|
|
2017-09-12
|
|
D-Link DIR-8xx Routers - Local Firmware Upload
|
9 |
WEB
|
embedi
|
|
2017-09-12
|
|
D-Link DIR-8xx Routers - Root Remote Code Execution
|
8 |
WEB
|
embedi
|
|
2017-09-12
|
|
D-Link DIR-8xx Routers - Leak Credentials
|
10 |
WEB
|
embedi
|
|
2017-09-12
|
|
Consumer Review Script 1.0 - SQL Injection
|
7 |
WEB
|
8bitsec
|
|
2017-09-12
|
|
XYZ Auto Classifieds 1.0 - SQL Injection
|
7 |
WEB
|
8bitsec
|
|
2017-09-14
|
|
Justdial Clone Script - 'fid' SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-14
|
|
Theater Management Script - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-14
|
|
PTC KSV1 Script 1.7 - 'type' SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-09-14
|
|
Adserver Script 5.6 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-14
|
|
Enterprise Edition Payment Processor Script 3.7 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2011-09-13
|
|
Carel PlantVisor 2.4.4 - Directory Traversal
|
10 |
WEB
|
Luigi Auriemma
|
|
2017-09-13
|
|
Carel PlantVisor 2.4.4 - Directory Traversal Information Disclosure (Metasploit)
|
10 |
WEB
|
James Fitts
|
|
2017-09-13
|
|
Carlo Gavazzi Powersoft 2.1.1.1 - Directory Traversal File Disclosure (Metasploit)
|
8 |
WEB
|
James Fitts
|
|
2017-09-13
|
|
Indusoft Web Studio - Directory Traversal Information Disclosure (Metasploit)
|
8 |
WEB
|
James Fitts
|
|
2017-09-13
|
|
ICAffiliateTracking 1.1 - Authentication Bypass
|
11 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICSiteBuilder 1.1 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICHelpDesk 1.1 - 'pk' SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICEstate 1.1 - 'id' SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICDental Clinic 1.2 - 'key' SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICProjectBidding 1.1 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICCallLimousine 1.1 - 'key' SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICGrocery 1.1 - 'key' SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICProductConfigurator 1.1 - 'key' SQL Injection
|
12 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
IC-T-Shirt 1.2 - 'key' SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICJewelry 1.1 - 'key' SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICSurvey 1.1 - SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICStudents 1.2 - 'key' SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICClassifieds 1.1 - SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICTraveling 2.2 - Authentication Bypass
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICAutosales 2.2 - SQL Injection
|
15 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICDutchAuction 1.2 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICRestaurant software 1.4 - 'key' SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICDoctor Appointment 1.3 - 'key' SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICAuction 2.2 - 'id' SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICHotelReservation 3.3 - 'key' SQL Injection
|
12 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICMLM 2.1 - 'key' SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-13
|
|
ICLowBidAuction 3.3 - SQL Injection
|
12 |
WEB
|
Ihsan Sencan
|
|
2017-09-12
|
|
inClick Cloud Server 5.0 - SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-12
|
|
Gr8 Multiple Search Engine Script 1.0 - SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2017-09-12
|
|
FoodStar 1.0 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-12
|
|
osTicket 1.10 - SQL Injection (PoC)
|
11 |
WEB
|
Mehmet Ince
|
|
2017-09-11
|
|
AirStar Airbnb Clone Script 1.0 - SQL Injection
|
11 |
WEB
|
8bitsec
|
|
2017-09-11
|
|
EduStar Udemy Clone Script 1.0 - SQL Injection
|
11 |
WEB
|
8bitsec
|
|
2017-09-11
|
|
iTech StockPhoto Script 2.02 - SQL Injection
|
9 |
WEB
|
8bitsec
|
|
2017-09-11
|
|
iTech Book Store Script 2.02 - SQL Injection
|
12 |
WEB
|
8bitsec
|
|
2017-09-11
|
|
JobStar Monster Clone Script 1.0 - SQL Injection
|
9 |
WEB
|
8bitsec
|
|
2017-09-11
|
|
PHP Dashboards NEW 4.4 - SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-11
|
|
PHP Dashboards NEW 4.4 - Arbitrary File Read
|
11 |
WEB
|
Ihsan Sencan
|
|
2017-09-11
|
|
WiseGiga NAS - Multiple Vulnerabilities
|
11 |
WEB
|
Pierre Kim
|
|
2017-09-05
|
|
FiberHome ADSL AN1020-25 - Improper Access Restrictions
|
9 |
WEB
|
Ibad Shah
|
|
2017-09-11
|
|
Nimble Professional 1.0 - Cross-Site Request Forgery (Update Admin)
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-09
|
|
My Builder Marketplace 1.0 - SQL Injection
|
11 |
WEB
|
Ihsan Sencan
|
|
2017-09-09
|
|
Topsites Script 1.0 - Cross-Site Request Forgery / PHP Code Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-09
|
|
Law Firm 1.0 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-09-09
|
|
Restaurant Website Script 1.0 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-09-09
|
|
Professional Service Booking 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-09-09
|
|
Online Print Business 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-09-09
|
|
Just Dial Marketplace 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-16
|
|
RPi Cam Control < 6.3.14 - Multiple Vulnerabilities
|
6 |
WEB
|
Alexander Korznikov
|
|
2017-09-09
|
|
Job Board Software 1.0 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-09-09
|
|
Babysitter Website Script 1.0 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-09-09
|
|
Escort Marketplace 1.0 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|