|
2017-09-07
|
|
Huawei HG255s - Directory Traversal
|
6 |
WEB
|
Ahmet Mersin
|
|
2017-09-07
|
|
Roteador Wireless Intelbras WRN150 - Cross-Site Scripting
|
6 |
WEB
|
Elber Tavares
|
|
2017-09-07
|
|
EzInvoice 6.02 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-09-07
|
|
EzBan 5.3 - 'id' SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-09-07
|
|
Online Invoice System 3.0 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-09-05
|
|
Ultimate HR System < 1.2 - Directory Traversal / Cross-Site Scripting
|
8 |
WEB
|
8bitsec
|
|
2017-09-06
|
|
Pay Banner Text Link Ad 1.0.6.1 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-09-06
|
|
Pay Banner Text Link Ad 1.0.6.1 - Cross-Site Request Forgery (Update Admin)
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-09-06
|
|
Advertiz PHP Script 0.2 - Cross-Site Request Forgery (Update Admin)
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-09-06
|
|
Cory Support - 'pr' SQL Injection
|
7 |
WEB
|
v3n0m
|
|
2017-09-05
|
|
The Car Project 1.0 - SQL Injection
|
10 |
WEB
|
Ihsan Sencan
|
|
2017-09-01
|
|
WordPress Plugin Participants Database < 1.7.5.10 - Cross-Site Scripting
|
7 |
WEB
|
Benjamin Lim
|
|
2017-09-04
|
|
iGreeting Cards 1.0 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-09-04
|
|
A2billing 2.x - Backup File Download / Remote Code Execution
|
6 |
WEB
|
0x4148
|
|
2017-09-05
|
|
A2billing 2.x - SQL Injection
|
8 |
WEB
|
0x4148
|
|
2017-08-09
|
|
Symantec Messaging Gateway < 10.6.3-267 - Cross-Site Request Forgery
|
7 |
WEB
|
Dhiraj Mishra
|
|
2017-09-04
|
|
CodeMeter 6.50 - Cross-Site Scripting
|
8 |
WEB
|
Vulnerability-Lab
|
|
2017-09-04
|
|
Wireless Repeater BE126 - Remote Code Execution
|
8 |
WEB
|
Hay Mizrachi
|
|
2017-09-03
|
|
Joomla! Component CheckList 1.1.0 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-09-03
|
|
Joomla! Component Survey Force Deluxe 3.2.4 - 'invite' SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-29
|
|
FineCMS 1.0 - Multiple Vulnerabilities
|
8 |
WEB
|
sohaip-hackerDZ
|
|
2017-08-31
|
|
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.7 - SQL Injection
|
10 |
WEB
|
Larry W. Cashdollar
|
|
2017-08-31
|
|
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.6 - SQL Injection
|
9 |
WEB
|
Larry W. Cashdollar
|
|
2017-08-31
|
|
Joomla! Component Huge-IT Video Gallery 1.0.9 - SQL Injection
|
9 |
WEB
|
Larry W. Cashdollar
|
|
2017-08-30
|
|
PHP-SecureArea < 2.7 - Multiple Vulnerabilities
|
10 |
WEB
|
Cryo
|
|
2017-08-30
|
|
Invoice Manager 3.1 - Cross-Site Request Forgery (Add Admin)
|
11 |
WEB
|
Ali BawazeEer
|
|
2017-03-07
|
|
iBall Baton 150M Wireless Router - Authentication Bypass
|
8 |
WEB
|
Indrajith.A.N
|
|
2017-08-30
|
|
Joomla! Component Joomanager 2.0.0 - 'com_Joomanager' Arbitrary File Download (PoC)
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-30
|
|
Joomla! Component Quiz Deluxe 3.7.4 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-29
|
|
Brickcom IP Camera - Credentials Disclosure
|
7 |
WEB
|
Emiliano Ipar
|
|
2017-08-28
|
|
PHP Video Battle Script 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-29
|
|
User Login and Management - Multiple Vulnerabilities
|
7 |
WEB
|
Ali BawazeEer
|
|
2017-08-28
|
|
PHP Appointment Booking Script - Authentication Bypass
|
7 |
WEB
|
Ali BawazeEer
|
|
2017-08-28
|
|
Car or Cab Booking Script - Authentication Bypass
|
7 |
WEB
|
Ali BawazeEer
|
|
2017-08-29
|
|
D-Link DIR-600 - Authentication Bypass
|
6 |
WEB
|
Jithin D Kurup
|
|
2017-08-28
|
|
NethServer 7.3.1611 - Cross-Site Request Forgery (Create User / Enable SSH Access)
|
6 |
WEB
|
LiquidWorm
|
|
2017-08-28
|
|
NethServer 7.3.1611 - Cross-Site Request Forgery / Cross-Site Scripting
|
6 |
WEB
|
LiquidWorm
|
|
2017-08-28
|
|
Schools Alert Management Script - Authentication Bypass
|
6 |
WEB
|
Ali BawazeEer
|
|
2017-06-01
|
|
CMS Web-Gooroo < 1.141 - Multiple Vulnerabilities
|
6 |
WEB
|
Kaimi
|
|
2017-08-28
|
|
Login-Reg Members Management PHP 1.0 - Arbitrary File Upload
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-28
|
|
Flash Poker 2.0 - 'game' SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-28
|
|
PHP Search Engine 1.0 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-28
|
|
Easy Web Search 4.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-28
|
|
WYSIWYG HTML Editor PRO 1.0 - Arbitrary File Download
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-28
|
|
FTP Made Easy PRO 1.2 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-28
|
|
Smart Chat 1.0.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-27
|
|
Matrimonial Script 2.7 - Authentication Bypass
|
8 |
WEB
|
Ali BawazeEer
|
|
2017-08-25
|
|
Joomla! Component Responsive Portfolio 1.6.1 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-25
|
|
Joomla! Component Photo Contest 1.0.2 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-25
|
|
AutoCar 1.1 - 'category' SQL Injection
|
6 |
WEB
|
Bora Bozdogan
|
|
2017-08-25
|
|
Joomla! Component OSDownloads 1.7.4 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-24
|
|
Joomla! Component Price Alert 3.0.2 - 'product_id' SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-24
|
|
Joomla! Component Bargain Product VM3 1.0 - 'product_id' SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-23
|
|
Wireless Repeater BE126 - Local File Inclusion
|
8 |
WEB
|
Hay Mizrachi
|
|
2017-08-22
|
|
Matrimonial Script - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-22
|
|
Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution
|
11 |
WEB
|
LiquidWorm
|
|
2017-08-22
|
|
Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write
|
9 |
WEB
|
LiquidWorm
|
|
2017-08-21
|
|
PHPMyWind 5.3 - Cross-Site Scripting
|
9 |
WEB
|
小雨
|
|
2017-08-21
|
|
PHP Jokesite 2.0 - 'joke_id' SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
PHP-Lance 1.52 - 'subcat' SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
Joomla! Component Ajax Quiz 1.8 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
(Bitcoin / Dogecoin) PHP Cloud Mining Script - Authentication Bypass
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
Joomla! Component FocalPoint 1.2.3 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
iTech Social Networking Script 3.08 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
PHP Coupon Script 6.0 - 'cid' SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
Affiliate Niche Script 3.4.0 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
PHP Classifieds Script 5.6.2 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
Joomla! Component Sponsor Wall 8.0 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
Joomla! Component Flip Wall 8.0 - 'wallid' SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-21
|
|
Apache2Triad 1.5.4 - Multiple Vulnerabilities
|
9 |
WEB
|
hyp3rlinx
|
|
2017-08-18
|
|
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
|
8 |
WEB
|
Philip Pettersson
|
|
2017-08-18
|
|
QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities
|
8 |
WEB
|
VVVSecurity
|
|
2017-08-18
|
|
iTech Movie Script 7.51 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
iTech Job Script 9.27 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
iTech Dating Script 3.40 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
iTech Multi Vendor Script 6.63 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
iTech Travel Script 9.49 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
iTech Freelancer Script 5.27 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
iTech Image Sharing Script 4.13 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
iTech Classifieds Script 7.41 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
iTech Caregiver Script 2.71 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
iTech Business Networking Script 8.26 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
iTech B2B Script 4.42 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
DeWorkshop 1.0 - Arbitrary File Upload
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
Joomla! Component SP Movie Database 1.3 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
Joomla! Component Calendar Planner 1.0.1 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
Joomla! Component Zap Calendar Lite 4.3.4 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
SOA School Management 3.0 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
eCardMAX 10.5 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
Matrimony Script 2.7 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
Joomla! Component KissGallery 1.0.0 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
Joomla! Component Twitch Tv 1.1 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
Joomla! Component Appointment 1.1 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
LiveProjects 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
LiveSales 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
LiveInvoices 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
LiveSupport 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-18
|
|
LiveCRM 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-17
|
|
Food Ordering Script 1.0 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-08-17
|
|
Doctor Patient Project 1.0 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-17
|
|
Photogallery Project 1.0 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-17
|
|
Online Quiz Project 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-15
|
|
AdvanDate iCupid Dating Software 12.2 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-15
|
|
ClipBucket 2.8.3 - Multiple Vulnerabilities
|
7 |
WEB
|
bRpsd
|
|
2017-08-14
|
|
Quali CloudShell 7.1.0.6508 (Patch 6) - Persistent Cross-Site Scripting
|
7 |
WEB
|
Benjamin Lee
|
|
2017-08-14
|
|
RPi Cam Control < 6.3.14 - Remote Command Execution
|
7 |
WEB
|
Alexander Korznikov
|
|
2017-08-12
|
|
AirMaster 3000M - Multiple Vulnerabilities
|
8 |
WEB
|
Mr.8Th BiT
|
|
2017-08-12
|
|
RealTime RWR-3G-100 Router - Cross-Site Request Forgery (Change Admin Password)
|
7 |
WEB
|
Touhid M.Shaikh
|
|
2017-08-11
|
|
De-Tutor 1.0 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
|
2017-08-11
|
|
De-Journal 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-11
|
|
DeWorkshop 1.0 - SQL Injection
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-10
|
|
Red-Gate SQL Monitor < 3.10 / 4.2 - Authentication Bypass
|
8 |
WEB
|
Paul Taylor
|
|
2017-08-10
|
|
Piwigo Plugin User Tag 0.9.0 - Cross-Site Scripting
|
7 |
WEB
|
Touhid M.Shaikh
|
|
2017-08-10
|
|
GIF Collection 2.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-10
|
|
ImageBay 1.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-09
|
|
WebFile Explorer 1.0 - Arbitrary File Download
|
8 |
WEB
|
Ihsan Sencan
|
|
2017-08-09
|
|
DALIM SOFTWARE ES Core 5.0 build 7184.1 - Server-Side Request Forgery
|
7 |
WEB
|
LiquidWorm
|
|
2017-08-09
|
|
DALIM SOFTWARE ES Core 5.0 build 7184.1 - Directory Traversal
|
9 |
WEB
|
LiquidWorm
|
|
2017-08-09
|
|
DALIM SOFTWARE ES Core 5.0 build 7184.1 - Cross-Site Scripting / Cross-Site Request Forgery
|
6 |
WEB
|
LiquidWorm
|
|
2017-08-09
|
|
DALIM SOFTWARE ES Core 5.0 build 7184.1 - User Enumeration
|
7 |
WEB
|
LiquidWorm
|
|
2017-08-08
|
|
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
|
9 |
WEB
|
Kacper Szurek
|
|
2017-08-07
|
|
WordPress Plugin Easy Modal 2.0.17 - SQL Injection
|
9 |
WEB
|
defensecode
|
|
2017-08-03
|
|
Technicolor TC7337 - 'SSID' Persistent Cross-Site Scripting
|
11 |
WEB
|
Geolado giolado
|
|
2017-08-03
|
|
Joomla! Component StreetGuessr Game 1.1.8 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-02
|
|
Muviko 1.0 - 'q' SQL Injection
|
9 |
WEB
|
Kaan KAMIS
|