Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2017-08-02   EDUMOD Pro 1.3 - SQL Injection 9 WEB Kaan KAMIS
2017-08-02   Premium Servers List Tracker 1.0 - SQL Injection 7 WEB Kaan KAMIS
2017-08-02   Joomla! Component Ultimate Property Listing 1.0.2 - SQL Injection 9 WEB Ihsan Sencan
2017-08-02   Joomla! Component Event Registration Pro Calendar 4.1.3 - SQL Injection 7 WEB Ihsan Sencan
2017-08-02   Joomla! Component LMS King Professional 3.2.4.0 - SQL Injection 7 WEB Ihsan Sencan
2017-08-02   Joomla! Component PHP-Bridge 1.2.3 - SQL Injection 7 WEB Ihsan Sencan
2017-08-02   Joomla! Component SIMGenealogy 2.1.5 - SQL Injection 7 WEB Ihsan Sencan
2017-08-02   Entrepreneur B2B Script - 'pid' SQL Injection 8 WEB Meisam Monsef
2017-08-01   JoySale 2.2.1 - Arbitrary File Upload 8 WEB Mutlu Benmutlu
2017-08-01   SOL.Connect ISET-mpp meter 1.2.4.2 - SQL Injection 8 WEB Andy Tan
2017-08-01   VehicleWorkshop - Arbitrary File Upload 7 WEB Touhid M.Shaikh
2017-08-01   VehicleWorkshop - Authentication Bypass 7 WEB Touhid M.Shaikh
2017-08-01   Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload 7 WEB James Fitts
2017-08-01   Advantech SUSIAccess < 3.0 - Directory Traversal / Information Disclosure (Metasploit) 8 WEB James Fitts
2017-07-28   VehicleWorkshop - SQL Injection 8 WEB Shahab Shamsi
2017-03-15   GitHub Enterprise < 2.8.7 - Remote Code Execution 8 WEB orange
2017-07-28   Fortinet FortiOS < 5.6.0 - Cross-Site Scripting 8 WEB patryk_bogdan
2017-07-27   Joomla! Component CCNewsLetter 2.1.9 - 'sbid' SQL Injection 7 WEB Shahab Shamsi
2017-07-26   Friends in War Make or Break 1.7 - Cross-Site Request Forgery (Change Admin Password) 7 WEB shinnai
2017-07-26   Friends in War Make or Break 1.7 - SQL Injection 7 WEB Ihsan Sencan
2017-07-25   WordPress Plugin Ads Pro < 3.4 - Cross-Site Scripting / SQL Injection 6 WEB 8bitsec
2017-07-25   Friends in War Make or Break 1.7 - Authentication Bypass 7 WEB Adam
2017-07-25   WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting 8 WEB Google Security Research
2017-07-24   REDDOXX Appliance Build 2032 / 2.0.625 - Arbitrary File Disclosure 10 WEB RedTeam Pentesting
2017-07-24   REDDOXX Appliance Build 2032 / 2.0.625 - Remote Command Execution 9 WEB RedTeam Pentesting
2017-07-24   PaulShop - SQL Injection / Cross-Site Scripting 7 WEB BTIS Team
2017-07-24   ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit) 9 WEB Kacper Szurek
2017-07-21   NEC UNIVERGE UM4730 < 11.8 - SQL Injection 10 WEB b0x41s
2017-07-20   VACRON VIG-US731VE 1.0.18-09-B727 IP Camera - Authentication Bypass 10 WEB Viktoras
2017-07-20   WordPress Plugin IBPS Online Exam 1.0 - SQL Injection / Cross-Site Scripting 10 WEB 8bitsec
2017-07-20   Tilde CMS 1.01 - Multiple Vulnerabilities 10 WEB Raffaele Forte
2017-07-20   Joomla! Component JoomRecipe 1.0.4 - 'search_author' SQL Injection 10 WEB Teng
2017-07-19   Citrix CloudBridge - 'CAKEPHP' Cookie Command Injection 9 WEB xort
2017-07-19   Netscaler SD-WAN 9.1.2.26.561201 - Command Injection (Metasploit) 7 WEB xort
2017-07-19   Sonicwall < 8.1.0.2-14sv - 'sitecustomization.cgi' Command Injection (Metasploit) 8 WEB xort
2017-07-19   Sonicwall < 8.1.0.6-21sv - 'gencsr.cgi' Command Injection (Metasploit) 8 WEB xort
2017-07-19   Sonicwall Secure Remote Access 8.1.0.2-14sv - Command Injection 11 WEB xort
2017-07-19   Oracle E-Business Suite 12.x - Server-Side Request Forgery 11 WEB Sarath Nair
2017-07-18   PEGA Platform <= 7.2 ML0 - Missing Access Control / Cross-Site Scripting 10 WEB Daniel Correa
2017-07-18   Barracuda Load Balancer Firmware < 6.0.1.006 - Remote Command Injection (Metasploit) 10 WEB xort
2017-07-18   Sophos Web Appliance 4.3.0.2 - 'trafficType' Remote Command Injection (Metasploit) 12 WEB xort
2017-07-16   Orangescrum 1.6.1 - Multiple Vulnerabilities 10 WEB tomplixsee
2017-07-14   WDTV Live SMP 2.03.20 - Remote Password Reset 11 WEB Sw1tCh
2017-07-07   Apache Struts 2.3.x Showcase - Remote Code Execution 10 WEB Vex Woo
2017-07-13   Dasan Networks GPON ONT WiFi Router H64X Series - Configuration Download 9 WEB LiquidWorm
2017-07-13   Dasan Networks GPON ONT WiFi Router H64X Series - Privilege Escalation 9 WEB LiquidWorm
2017-07-13   Dasan Networks GPON ONT WiFi Router H64X Series - Cross-Site Request Forgery 11 WEB LiquidWorm
2017-07-13   Dasan Networks GPON ONT WiFi Router H64X Series - Authentication Bypass 10 WEB LiquidWorm
2017-07-12   WordPress Plugin Sabai Discuss - Cross-Site Scripting 10 WEB Hesam Bazvand
2017-07-11   NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection 10 WEB Paul Taylor
2017-07-11   DataTaker DT80 dEX 1.50.012 - Information Disclosure 10 WEB Nassim Asrir
2017-07-10   Pelco VideoXpert 1.12.105 - Information Disclosure 10 WEB LiquidWorm
2017-07-10   Pelco VideoXpert 1.12.105 - Directory Traversal 10 WEB LiquidWorm
2017-07-10   Pelco Sarix/Spectra Cameras - Remote Code Execution 10 WEB LiquidWorm
2017-07-10   Pelco Sarix/Spectra Cameras - Cross-Site Request Forgery (Enable SSH Root Access) 10 WEB LiquidWorm
2017-07-10   Pelco Sarix/Spectra Cameras - Cross-Site Request Forgery / Cross-Site Scripting 10 WEB LiquidWorm
2017-07-10   NfSen < 1.3.7 / AlienVault OSSIM 5.3.4 - Command Injection 11 WEB Paul Taylor
2017-07-03   OpenDreamBox 2.0.0 Plugin WebAdmin - Remote Code Execution 11 WEB Jonatas Fil
2017-07-03   WordPress Plugin WatuPRO 5.5.1 - SQL Injection 8 WEB Manich Koomsusi
2017-06-20   BOA Web Server 0.94.14rc21 - Arbitrary File Access 9 WEB Miguel Mendez Z
2017-06-30   Humax HG100R 2.0.6 - Backup File Download 8 WEB gambler
2017-06-28   Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities 8 WEB Core Security
2017-06-28   Easy File Sharing Web Server 7.2 - Unrestricted File Upload 8 WEB Chako
2017-06-27   WordPress Plugin Ultimate Product Catalogue 4.2.2 - SQL Injection 7 WEB Lenon Leite
2017-06-27   GLPI 0.90.4 - SQL Injection 8 WEB Eric CARTER
2017-06-26   Eltek SmartPack - Backdoor Account 9 WEB Saeed reza Zamanian
2017-06-21   PHPMailer < 5.2.20 with Exim MTA - Remote Code Execution 9 WEB phackt_ul
2017-06-19   WonderCMS 2.1.0 - Cross-Site Request Forgery 7 WEB Ehsan Hosseini
2017-06-18   D-Link DSL-2640B ADSL Router - 'dnscfg' Remote DNS Change 8 WEB Todor Donev
2017-06-17   Beetel BCM96338 Router - DNS Change 8 WEB Todor Donev
2017-06-17   D-Link DSL-2640U - DNS Change 7 WEB Todor Donev
2017-06-17   UTstarcom WA3002G4 - DNS Change 8 WEB Todor Donev
2017-06-09   nuevoMailer 6.0 - SQL Injection 9 WEB Oleg Boytsev
2017-06-16   iBall Baton iB-WRA150N - DNS Change 8 WEB Todor Donev
2017-06-16   IBM Informix Dynamic Server - Code Injection / Remote Code Execution 8 WEB IMgod
2017-06-15   Joomla! Component JoomRecipe 1.0.3 - SQL Injection 6 WEB EziBilisim
2017-06-14   KBVault MySQL 0.16a - Arbitrary File Upload 8 WEB Fatih Emiral
2017-05-22   Aerohive HiveOS 5.1r5 < 6.1r5 - Remote Code Execution 11 WEB Ike-Clinton
2017-06-04   WordPress Plugin Event List < 0.7.8 - SQL Injection 6 WEB Dimitrios Tsagkarakis
2017-06-11   WordPress Plugin WP Jobs < 1.5 - SQL Injection 7 WEB Dimitrios Tsagkarakis
2017-06-12   Real Estate Classifieds Script - SQL Injection 7 WEB EziBilisim
2017-06-03   WordPress Plugin WP-Testimonials < 3.4.1 - SQL Injection 7 WEB Dimitrios Tsagkarakis
2017-06-09   Nuevomailer < 6.0 - SQL Injection 7 WEB Oleg Boytsev
2017-06-10   PaulShop - SQL Injection 7 WEB Se0pHpHack3r
2017-06-09   EFS Easy Chat Server 3.1 - Password Reset 7 WEB Aitezaz Mohsin
2017-06-09   EFS Easy Chat Server 3.1 - Password Disclosure 7 WEB Aitezaz Mohsin
2017-06-10   eCom Cart 1.3 - SQL Injection 7 WEB Alperen Eymen Ozcan
2017-06-09   Uniview NVR - Password Disclosure 7 WEB B1t
2017-06-09   IPFire 2.19 - Remote Code Execution 7 WEB 0x09AL
2017-06-08   Craft CMS 2.6 - Cross-Site Scripting 7 WEB Ahsan Tahir
2017-06-07   Robert 0.5 - Multiple Vulnerabilities 7 WEB Cyril Vallicari
2017-06-07   Xavier 2.4 - SQL Injection 7 WEB Vulnerability-Lab
2017-06-07   Grav CMS 1.4.2 Admin Plugin - Cross-Site Scripting 7 WEB Ahsan Tahir
2017-06-06   Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclos 6 WEB X41 D-Sec GmbH
2017-06-06   Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclos 6 WEB X41 D-Sec GmbH
2017-06-06   Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclos 10 WEB X41 D-Sec GmbH
2017-06-06   WordPress Plugin Tribulant Newsletters 4.6.4.2 - File Disclosure / Cross-Site Scripting 9 WEB defensecode
2017-06-05   Kronos Telestaff < 2.92EU29 - SQL Injection 11 WEB Goran Tuzovic
2017-06-05   Subsonic 6.1.1 - Cross-Site Request Forgery / Cross-Site Scripting 8 WEB hyp3rlinx
2017-06-05   Subsonic 6.1.1 - Server-Side Request Forgery 8 WEB hyp3rlinx
2017-06-05   Subsonic 6.1.1 - Cross-Site Request Forgery 7 WEB hyp3rlinx
2017-06-04   EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 - Remote Code Execution 6 WEB LiquidWorm
2017-06-03   Joomla! Component Payage 2.05 - 'aid' SQL Injection 9 WEB Persian Hack Team
2017-06-02   Sungard eTRAKiT3 <= 3.2.1.17 - SQL Injection 7 WEB Goran Tuzovic
2017-06-01   WebKit - 'Document::prepareForDestruction' / 'CachedFrame' Universal Cross-Site Scripting 7 WEB Google Security Research
2017-06-01   WebKit - 'CachedFrameBase::restore' Universal Cross-Site Scripting 7 WEB Google Security Research
2017-06-01   WebKit - CachedFrame does not Detach Openers Universal Cross-Site Scripting 9 WEB Google Security Research
2017-06-01   Riverbed SteelHead VCX 9.6.0a - Arbitrary File Read 8 WEB Gregory Draperi
2017-05-31   Piwigo Plugin Facetag 0.0.3 - Cross-Site Scripting 8 WEB Touhid M.Shaikh
2017-05-31   OV3 Online Administration 3.0 - SQL Injection 9 WEB LiquidWorm
2017-05-31   OV3 Online Administration 3.0 - Remote Code Execution 7 WEB LiquidWorm
2017-05-31   OV3 Online Administration 3.0 - Directory Traversal 7 WEB LiquidWorm
2017-05-30   Piwigo Plugin Facetag 0.0.3 - SQL Injection 7 WEB Touhid M.Shaikh
2017-05-30   TerraMaster F2-420 NAS TOS 3.0.30 - Root Remote Code Execution 7 WEB Simone Margaritelli
2017-05-30   IBM Informix Dynamic Server / Informix Open Admin Tool - DLL Injection / Remote Code Execution / Hea 7 WEB SecuriTeam
2017-05-30   KEMP LoadMaster 7.135.0.13245 - Persistent Cross-Site Scripting / Remote Code Execution 7 WEB SecuriTeam
2017-05-30   Trend Micro Deep Security 6.5 - XML External Entity Injection / Local Privilege Escalation / Remote 7 WEB SecuriTeam
2017-05-30   uc-http Daemon - Local File Inclusion / Directory Traversal 7 WEB Project Insecurity
2017-05-29   WordPress Plugin Huge-IT Video Gallery 2.0.4 - SQL Injection 7 WEB defensecode
2017-05-26   QWR-1104 Wireless-N Router - Cross-Site Scripting 7 WEB Touhid M.Shaikh
2017-02-22   D-Link DCS Series Cameras - Insecure Crossdomain 6 WEB SlidingWindow
2017-05-25   Apple Safari 10.0.3(12602.4.8) / WebKit - 'HTMLObjectElement::updateWidget' Universal Cross-Site Scr 7 WEB Google Security Research
2017-05-25   WebKit - 'FrameLoader::clear' Stealing Variables via Page Navigation 6 WEB Google Security Research
2017-05-25   WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting 6 WEB Google Security Research
2017-05-25   WebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site Scripting 8 WEB Google Security Research