|
2017-08-02
|
|
EDUMOD Pro 1.3 - SQL Injection
|
9 |
WEB
|
Kaan KAMIS
|
|
2017-08-02
|
|
Premium Servers List Tracker 1.0 - SQL Injection
|
7 |
WEB
|
Kaan KAMIS
|
|
2017-08-02
|
|
Joomla! Component Ultimate Property Listing 1.0.2 - SQL Injection
|
9 |
WEB
|
Ihsan Sencan
|
|
2017-08-02
|
|
Joomla! Component Event Registration Pro Calendar 4.1.3 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-02
|
|
Joomla! Component LMS King Professional 3.2.4.0 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-02
|
|
Joomla! Component PHP-Bridge 1.2.3 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-02
|
|
Joomla! Component SIMGenealogy 2.1.5 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-08-02
|
|
Entrepreneur B2B Script - 'pid' SQL Injection
|
8 |
WEB
|
Meisam Monsef
|
|
2017-08-01
|
|
JoySale 2.2.1 - Arbitrary File Upload
|
8 |
WEB
|
Mutlu Benmutlu
|
|
2017-08-01
|
|
SOL.Connect ISET-mpp meter 1.2.4.2 - SQL Injection
|
8 |
WEB
|
Andy Tan
|
|
2017-08-01
|
|
VehicleWorkshop - Arbitrary File Upload
|
7 |
WEB
|
Touhid M.Shaikh
|
|
2017-08-01
|
|
VehicleWorkshop - Authentication Bypass
|
7 |
WEB
|
Touhid M.Shaikh
|
|
2017-08-01
|
|
Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload
|
7 |
WEB
|
James Fitts
|
|
2017-08-01
|
|
Advantech SUSIAccess < 3.0 - Directory Traversal / Information Disclosure (Metasploit)
|
8 |
WEB
|
James Fitts
|
|
2017-07-28
|
|
VehicleWorkshop - SQL Injection
|
8 |
WEB
|
Shahab Shamsi
|
|
2017-03-15
|
|
GitHub Enterprise < 2.8.7 - Remote Code Execution
|
8 |
WEB
|
orange
|
|
2017-07-28
|
|
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
|
8 |
WEB
|
patryk_bogdan
|
|
2017-07-27
|
|
Joomla! Component CCNewsLetter 2.1.9 - 'sbid' SQL Injection
|
7 |
WEB
|
Shahab Shamsi
|
|
2017-07-26
|
|
Friends in War Make or Break 1.7 - Cross-Site Request Forgery (Change Admin Password)
|
7 |
WEB
|
shinnai
|
|
2017-07-26
|
|
Friends in War Make or Break 1.7 - SQL Injection
|
7 |
WEB
|
Ihsan Sencan
|
|
2017-07-25
|
|
WordPress Plugin Ads Pro < 3.4 - Cross-Site Scripting / SQL Injection
|
6 |
WEB
|
8bitsec
|
|
2017-07-25
|
|
Friends in War Make or Break 1.7 - Authentication Bypass
|
7 |
WEB
|
Adam
|
|
2017-07-25
|
|
WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting
|
8 |
WEB
|
Google Security Research
|
|
2017-07-24
|
|
REDDOXX Appliance Build 2032 / 2.0.625 - Arbitrary File Disclosure
|
10 |
WEB
|
RedTeam Pentesting
|
|
2017-07-24
|
|
REDDOXX Appliance Build 2032 / 2.0.625 - Remote Command Execution
|
9 |
WEB
|
RedTeam Pentesting
|
|
2017-07-24
|
|
PaulShop - SQL Injection / Cross-Site Scripting
|
7 |
WEB
|
BTIS Team
|
|
2017-07-24
|
|
ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit)
|
9 |
WEB
|
Kacper Szurek
|
|
2017-07-21
|
|
NEC UNIVERGE UM4730 < 11.8 - SQL Injection
|
10 |
WEB
|
b0x41s
|
|
2017-07-20
|
|
VACRON VIG-US731VE 1.0.18-09-B727 IP Camera - Authentication Bypass
|
10 |
WEB
|
Viktoras
|
|
2017-07-20
|
|
WordPress Plugin IBPS Online Exam 1.0 - SQL Injection / Cross-Site Scripting
|
10 |
WEB
|
8bitsec
|
|
2017-07-20
|
|
Tilde CMS 1.01 - Multiple Vulnerabilities
|
10 |
WEB
|
Raffaele Forte
|
|
2017-07-20
|
|
Joomla! Component JoomRecipe 1.0.4 - 'search_author' SQL Injection
|
10 |
WEB
|
Teng
|
|
2017-07-19
|
|
Citrix CloudBridge - 'CAKEPHP' Cookie Command Injection
|
9 |
WEB
|
xort
|
|
2017-07-19
|
|
Netscaler SD-WAN 9.1.2.26.561201 - Command Injection (Metasploit)
|
7 |
WEB
|
xort
|
|
2017-07-19
|
|
Sonicwall < 8.1.0.2-14sv - 'sitecustomization.cgi' Command Injection (Metasploit)
|
8 |
WEB
|
xort
|
|
2017-07-19
|
|
Sonicwall < 8.1.0.6-21sv - 'gencsr.cgi' Command Injection (Metasploit)
|
8 |
WEB
|
xort
|
|
2017-07-19
|
|
Sonicwall Secure Remote Access 8.1.0.2-14sv - Command Injection
|
11 |
WEB
|
xort
|
|
2017-07-19
|
|
Oracle E-Business Suite 12.x - Server-Side Request Forgery
|
11 |
WEB
|
Sarath Nair
|
|
2017-07-18
|
|
PEGA Platform <= 7.2 ML0 - Missing Access Control / Cross-Site Scripting
|
10 |
WEB
|
Daniel Correa
|
|
2017-07-18
|
|
Barracuda Load Balancer Firmware < 6.0.1.006 - Remote Command Injection (Metasploit)
|
10 |
WEB
|
xort
|
|
2017-07-18
|
|
Sophos Web Appliance 4.3.0.2 - 'trafficType' Remote Command Injection (Metasploit)
|
12 |
WEB
|
xort
|
|
2017-07-16
|
|
Orangescrum 1.6.1 - Multiple Vulnerabilities
|
10 |
WEB
|
tomplixsee
|
|
2017-07-14
|
|
WDTV Live SMP 2.03.20 - Remote Password Reset
|
11 |
WEB
|
Sw1tCh
|
|
2017-07-07
|
|
Apache Struts 2.3.x Showcase - Remote Code Execution
|
10 |
WEB
|
Vex Woo
|
|
2017-07-13
|
|
Dasan Networks GPON ONT WiFi Router H64X Series - Configuration Download
|
9 |
WEB
|
LiquidWorm
|
|
2017-07-13
|
|
Dasan Networks GPON ONT WiFi Router H64X Series - Privilege Escalation
|
9 |
WEB
|
LiquidWorm
|
|
2017-07-13
|
|
Dasan Networks GPON ONT WiFi Router H64X Series - Cross-Site Request Forgery
|
11 |
WEB
|
LiquidWorm
|
|
2017-07-13
|
|
Dasan Networks GPON ONT WiFi Router H64X Series - Authentication Bypass
|
10 |
WEB
|
LiquidWorm
|
|
2017-07-12
|
|
WordPress Plugin Sabai Discuss - Cross-Site Scripting
|
10 |
WEB
|
Hesam Bazvand
|
|
2017-07-11
|
|
NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection
|
10 |
WEB
|
Paul Taylor
|
|
2017-07-11
|
|
DataTaker DT80 dEX 1.50.012 - Information Disclosure
|
10 |
WEB
|
Nassim Asrir
|
|
2017-07-10
|
|
Pelco VideoXpert 1.12.105 - Information Disclosure
|
10 |
WEB
|
LiquidWorm
|
|
2017-07-10
|
|
Pelco VideoXpert 1.12.105 - Directory Traversal
|
10 |
WEB
|
LiquidWorm
|
|
2017-07-10
|
|
Pelco Sarix/Spectra Cameras - Remote Code Execution
|
10 |
WEB
|
LiquidWorm
|
|
2017-07-10
|
|
Pelco Sarix/Spectra Cameras - Cross-Site Request Forgery (Enable SSH Root Access)
|
10 |
WEB
|
LiquidWorm
|
|
2017-07-10
|
|
Pelco Sarix/Spectra Cameras - Cross-Site Request Forgery / Cross-Site Scripting
|
10 |
WEB
|
LiquidWorm
|
|
2017-07-10
|
|
NfSen < 1.3.7 / AlienVault OSSIM 5.3.4 - Command Injection
|
11 |
WEB
|
Paul Taylor
|
|
2017-07-03
|
|
OpenDreamBox 2.0.0 Plugin WebAdmin - Remote Code Execution
|
11 |
WEB
|
Jonatas Fil
|
|
2017-07-03
|
|
WordPress Plugin WatuPRO 5.5.1 - SQL Injection
|
8 |
WEB
|
Manich Koomsusi
|
|
2017-06-20
|
|
BOA Web Server 0.94.14rc21 - Arbitrary File Access
|
9 |
WEB
|
Miguel Mendez Z
|
|
2017-06-30
|
|
Humax HG100R 2.0.6 - Backup File Download
|
8 |
WEB
|
gambler
|
|
2017-06-28
|
|
Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities
|
8 |
WEB
|
Core Security
|
|
2017-06-28
|
|
Easy File Sharing Web Server 7.2 - Unrestricted File Upload
|
8 |
WEB
|
Chako
|
|
2017-06-27
|
|
WordPress Plugin Ultimate Product Catalogue 4.2.2 - SQL Injection
|
7 |
WEB
|
Lenon Leite
|
|
2017-06-27
|
|
GLPI 0.90.4 - SQL Injection
|
8 |
WEB
|
Eric CARTER
|
|
2017-06-26
|
|
Eltek SmartPack - Backdoor Account
|
9 |
WEB
|
Saeed reza Zamanian
|
|
2017-06-21
|
|
PHPMailer < 5.2.20 with Exim MTA - Remote Code Execution
|
9 |
WEB
|
phackt_ul
|
|
2017-06-19
|
|
WonderCMS 2.1.0 - Cross-Site Request Forgery
|
7 |
WEB
|
Ehsan Hosseini
|
|
2017-06-18
|
|
D-Link DSL-2640B ADSL Router - 'dnscfg' Remote DNS Change
|
8 |
WEB
|
Todor Donev
|
|
2017-06-17
|
|
Beetel BCM96338 Router - DNS Change
|
8 |
WEB
|
Todor Donev
|
|
2017-06-17
|
|
D-Link DSL-2640U - DNS Change
|
7 |
WEB
|
Todor Donev
|
|
2017-06-17
|
|
UTstarcom WA3002G4 - DNS Change
|
8 |
WEB
|
Todor Donev
|
|
2017-06-09
|
|
nuevoMailer 6.0 - SQL Injection
|
9 |
WEB
|
Oleg Boytsev
|
|
2017-06-16
|
|
iBall Baton iB-WRA150N - DNS Change
|
8 |
WEB
|
Todor Donev
|
|
2017-06-16
|
|
IBM Informix Dynamic Server - Code Injection / Remote Code Execution
|
8 |
WEB
|
IMgod
|
|
2017-06-15
|
|
Joomla! Component JoomRecipe 1.0.3 - SQL Injection
|
6 |
WEB
|
EziBilisim
|
|
2017-06-14
|
|
KBVault MySQL 0.16a - Arbitrary File Upload
|
8 |
WEB
|
Fatih Emiral
|
|
2017-05-22
|
|
Aerohive HiveOS 5.1r5 < 6.1r5 - Remote Code Execution
|
11 |
WEB
|
Ike-Clinton
|
|
2017-06-04
|
|
WordPress Plugin Event List < 0.7.8 - SQL Injection
|
6 |
WEB
|
Dimitrios Tsagkarakis
|
|
2017-06-11
|
|
WordPress Plugin WP Jobs < 1.5 - SQL Injection
|
7 |
WEB
|
Dimitrios Tsagkarakis
|
|
2017-06-12
|
|
Real Estate Classifieds Script - SQL Injection
|
7 |
WEB
|
EziBilisim
|
|
2017-06-03
|
|
WordPress Plugin WP-Testimonials < 3.4.1 - SQL Injection
|
7 |
WEB
|
Dimitrios Tsagkarakis
|
|
2017-06-09
|
|
Nuevomailer < 6.0 - SQL Injection
|
7 |
WEB
|
Oleg Boytsev
|
|
2017-06-10
|
|
PaulShop - SQL Injection
|
7 |
WEB
|
Se0pHpHack3r
|
|
2017-06-09
|
|
EFS Easy Chat Server 3.1 - Password Reset
|
7 |
WEB
|
Aitezaz Mohsin
|
|
2017-06-09
|
|
EFS Easy Chat Server 3.1 - Password Disclosure
|
7 |
WEB
|
Aitezaz Mohsin
|
|
2017-06-10
|
|
eCom Cart 1.3 - SQL Injection
|
7 |
WEB
|
Alperen Eymen Ozcan
|
|
2017-06-09
|
|
Uniview NVR - Password Disclosure
|
7 |
WEB
|
B1t
|
|
2017-06-09
|
|
IPFire 2.19 - Remote Code Execution
|
7 |
WEB
|
0x09AL
|
|
2017-06-08
|
|
Craft CMS 2.6 - Cross-Site Scripting
|
7 |
WEB
|
Ahsan Tahir
|
|
2017-06-07
|
|
Robert 0.5 - Multiple Vulnerabilities
|
7 |
WEB
|
Cyril Vallicari
|
|
2017-06-07
|
|
Xavier 2.4 - SQL Injection
|
7 |
WEB
|
Vulnerability-Lab
|
|
2017-06-07
|
|
Grav CMS 1.4.2 Admin Plugin - Cross-Site Scripting
|
7 |
WEB
|
Ahsan Tahir
|
|
2017-06-06
|
|
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclos
|
6 |
WEB
|
X41 D-Sec GmbH
|
|
2017-06-06
|
|
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclos
|
6 |
WEB
|
X41 D-Sec GmbH
|
|
2017-06-06
|
|
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclos
|
10 |
WEB
|
X41 D-Sec GmbH
|
|
2017-06-06
|
|
WordPress Plugin Tribulant Newsletters 4.6.4.2 - File Disclosure / Cross-Site Scripting
|
9 |
WEB
|
defensecode
|
|
2017-06-05
|
|
Kronos Telestaff < 2.92EU29 - SQL Injection
|
11 |
WEB
|
Goran Tuzovic
|
|
2017-06-05
|
|
Subsonic 6.1.1 - Cross-Site Request Forgery / Cross-Site Scripting
|
8 |
WEB
|
hyp3rlinx
|
|
2017-06-05
|
|
Subsonic 6.1.1 - Server-Side Request Forgery
|
8 |
WEB
|
hyp3rlinx
|
|
2017-06-05
|
|
Subsonic 6.1.1 - Cross-Site Request Forgery
|
7 |
WEB
|
hyp3rlinx
|
|
2017-06-04
|
|
EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 - Remote Code Execution
|
6 |
WEB
|
LiquidWorm
|
|
2017-06-03
|
|
Joomla! Component Payage 2.05 - 'aid' SQL Injection
|
9 |
WEB
|
Persian Hack Team
|
|
2017-06-02
|
|
Sungard eTRAKiT3 <= 3.2.1.17 - SQL Injection
|
7 |
WEB
|
Goran Tuzovic
|
|
2017-06-01
|
|
WebKit - 'Document::prepareForDestruction' / 'CachedFrame' Universal Cross-Site Scripting
|
7 |
WEB
|
Google Security Research
|
|
2017-06-01
|
|
WebKit - 'CachedFrameBase::restore' Universal Cross-Site Scripting
|
7 |
WEB
|
Google Security Research
|
|
2017-06-01
|
|
WebKit - CachedFrame does not Detach Openers Universal Cross-Site Scripting
|
9 |
WEB
|
Google Security Research
|
|
2017-06-01
|
|
Riverbed SteelHead VCX 9.6.0a - Arbitrary File Read
|
8 |
WEB
|
Gregory Draperi
|
|
2017-05-31
|
|
Piwigo Plugin Facetag 0.0.3 - Cross-Site Scripting
|
8 |
WEB
|
Touhid M.Shaikh
|
|
2017-05-31
|
|
OV3 Online Administration 3.0 - SQL Injection
|
9 |
WEB
|
LiquidWorm
|
|
2017-05-31
|
|
OV3 Online Administration 3.0 - Remote Code Execution
|
7 |
WEB
|
LiquidWorm
|
|
2017-05-31
|
|
OV3 Online Administration 3.0 - Directory Traversal
|
7 |
WEB
|
LiquidWorm
|
|
2017-05-30
|
|
Piwigo Plugin Facetag 0.0.3 - SQL Injection
|
7 |
WEB
|
Touhid M.Shaikh
|
|
2017-05-30
|
|
TerraMaster F2-420 NAS TOS 3.0.30 - Root Remote Code Execution
|
7 |
WEB
|
Simone Margaritelli
|
|
2017-05-30
|
|
IBM Informix Dynamic Server / Informix Open Admin Tool - DLL Injection / Remote Code Execution / Hea
|
7 |
WEB
|
SecuriTeam
|
|
2017-05-30
|
|
KEMP LoadMaster 7.135.0.13245 - Persistent Cross-Site Scripting / Remote Code Execution
|
7 |
WEB
|
SecuriTeam
|
|
2017-05-30
|
|
Trend Micro Deep Security 6.5 - XML External Entity Injection / Local Privilege Escalation / Remote
|
7 |
WEB
|
SecuriTeam
|
|
2017-05-30
|
|
uc-http Daemon - Local File Inclusion / Directory Traversal
|
7 |
WEB
|
Project Insecurity
|
|
2017-05-29
|
|
WordPress Plugin Huge-IT Video Gallery 2.0.4 - SQL Injection
|
7 |
WEB
|
defensecode
|
|
2017-05-26
|
|
QWR-1104 Wireless-N Router - Cross-Site Scripting
|
7 |
WEB
|
Touhid M.Shaikh
|
|
2017-02-22
|
|
D-Link DCS Series Cameras - Insecure Crossdomain
|
6 |
WEB
|
SlidingWindow
|
|
2017-05-25
|
|
Apple Safari 10.0.3(12602.4.8) / WebKit - 'HTMLObjectElement::updateWidget' Universal Cross-Site Scr
|
7 |
WEB
|
Google Security Research
|
|
2017-05-25
|
|
WebKit - 'FrameLoader::clear' Stealing Variables via Page Navigation
|
6 |
WEB
|
Google Security Research
|
|
2017-05-25
|
|
WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting
|
6 |
WEB
|
Google Security Research
|
|
2017-05-25
|
|
WebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site Scripting
|
8 |
WEB
|
Google Security Research
|