| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Forminator 1.24.6 - Unauthenticated Remote Command Execution
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Mehmet Kelepçe										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  WordPress adivaha Travel Plugin 2.3 - Reflected XSS
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  Webedition CMS v2.9.8.8 - Stored XSS
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  Webutler v3.2 - Remote Code Execution (RCE)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Miguel Santareno										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Miguel Santareno										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Rajdip Dey Sarkar										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  WordPress adivaha Travel Plugin 2.3 - SQL Injection
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  Academy LMS 6.0 - Reflected XSS
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  PHPJabbers Rental Property Booking 2.0 - Reflected XSS
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  PHPJabbers Taxi Booking 2.0 - Reflected XSS
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  PHPJabbers Cleaning Business 1.0 - Reflected XSS
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  PHPJabbers Night Club Booking 1.0 - Reflected XSS
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  PHPJabbers Service Booking Script 1.0 - Reflected XSS
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  JLex GuestBook 1.6.4 - Reflected XSS
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  Ozeki SMS Gateway 10.3.208 - Arbitrary File Read (Unauthenticated)
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												Ahmet Ümit BAYRAM										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  Joomla JLex Review 6.0.1 - Reflected XSS
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Mehran Seifalinia										
				 | 
			
            	
			
				| 
					2023-08-04	
				 | 
				
										 
				 | 
								
									  Adiscon LogAnalyzer v.4.1.13 - Cross Site Scripting
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Pedro										
				 | 
			
            	
			
				| 
					2023-07-31	
				 | 
				
										 
				 | 
								
									  Joomla iProperty Real Estate 4.1.1 - Reflected XSS
								 | 
								
					12			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-07-31	
				 | 
				
										 
				 | 
								
									  Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)
								 | 
								
					11			 | 
				
                     WEB
			   | 
								
												Daniel Barros										
				 | 
			
            	
			
				| 
					2023-07-31	
				 | 
				
										 
				 | 
								
									  Joomla Solidres 2.13.3 - Reflected XSS
								 | 
								
					13			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  copyparty 1.8.2 - Directory Traversal
								 | 
								
					13			 | 
				
                     WEB
			   | 
								
												Vartamtezidis Theodoros										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  copyparty v1.8.6 - Reflected Cross Site Scripting (XSS)
								 | 
								
					26			 | 
				
                     WEB
			   | 
								
												Vartamtezidis Theodoros										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  WordPress Plugin AN_Gradebook 5.0.1 - SQLi
								 | 
								
					11			 | 
				
                     WEB
			   | 
								
												Lukas Kinneberg										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  Joomla VirtueMart Shopping Cart 4.0.12 - Reflected XSS
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  October CMS v3.4.4 - Stored Cross-Site Scripting (XSS) (Authenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Okan Kurtulus										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  Joomla HikaShop 4.7.4 - Reflected XSS
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  mooDating 1.2 - Reflected Cross-site scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  Perch v3.2 - Persistent Cross Site Scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Dinesh Mohanty										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  Availability Booking Calendar v1.0 - Multiple Cross-site scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Andrey Stoykov										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  Zomplog 3.9 - Cross-site scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  zomplog 3.9 - Remote Code Execution (RCE)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-28	
				 | 
				
										 
				 | 
								
									  RosarioSIS 10.8.4 - CSV Injection
								 | 
								
					12			 | 
				
                     WEB
			   | 
								
												Ranjeet Jaiswal										
				 | 
			
            	
			
				| 
					2023-07-21	
				 | 
				
										 
				 | 
								
									  Perch v3.2 - Stored XSS
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-21	
				 | 
				
										 
				 | 
								
									  Perch v3.2 - Remote Code Execution (RCE)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-20	
				 | 
				
										 
				 | 
								
									  RWS WorldServer 11.7.3 - Session Token Enumeration
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												RedTeam Pentesting GmbH										
				 | 
			
            	
			
				| 
					2023-07-20	
				 | 
				
										 
				 | 
								
									  PaulPrinting CMS - Multiple Cross Site Web Vulnerabilities
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2023-07-20	
				 | 
				
										 
				 | 
								
									  Aures Booking & POS Terminal - Local Privilege Escalation
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2023-07-20	
				 | 
				
										 
				 | 
								
									  Webile v1.0.1 - Multiple Cross Site Scripting
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2023-07-20	
				 | 
				
										 
				 | 
								
									  Dooblou WiFi File Explorer 1.13.3 - Multiple Vulnerabilities
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2023-07-20	
				 | 
				
										 
				 | 
								
									  PaulPrinting CMS - (Search Delivery) Cross Site Scripting
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2023-07-20	
				 | 
				
										 
				 | 
								
									  Active Super Shop CMS v2.5 - HTML Injection Vulnerabilities
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2023-07-20	
				 | 
				
										 
				 | 
								
									  Boom CMS v8.0.7 - Cross Site Scripting
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												Vulnerability-Lab										
				 | 
			
            	
			
				| 
					2023-07-20	
				 | 
				
										 
				 | 
								
									  Wifi Soft Unibox Administration 3.0 & 3.1 - SQL Injection
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Ansh Jain										
				 | 
			
            	
			
				| 
					2023-07-20	
				 | 
				
										 
				 | 
								
									  pfSense v2.7.0 - OS Command Injection
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Emir Polat										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  TP-Link TL-WR740N - Authenticated Directory Transversal
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Anish Feroz										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  Blackcat Cms v1.4 - Remote Code Execution (RCE)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  Blackcat Cms v1.4 - Stored XSS
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  ABB FlowX v4.00 - Exposure of Sensitive Information
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Paul Smith										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  Statamic 4.7.0 - File-Inclusion
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  CmsMadeSimple v2.2.17 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  CmsMadeSimple v2.2.17 - Remote Code Execution (RCE)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  CmsMadeSimple v2.2.17 - session hijacking via Server-Side Template Injection (SSTI)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  Online Piggery Management System v1.0 - unauthenticated file upload vulnerability
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												1337kid										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  Backdrop Cms v1.25.1 - Stored Cross-Site Scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  Vaidya-Mitra 1.0 - Multiple SQLi
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  Joomla! com_booking component 2.4.9 - Information Leak (Account enumeration)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												qw3rTyTy										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  phpfm v1.7.9 - Authentication type juggling
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												thoughtfault										
				 | 
			
            	
			
				| 
					2023-07-19	
				 | 
				
										 
				 | 
								
									  PimpMyLog v1.7.14 - Improper access control
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												thoughtfault										
				 | 
			
            	
			
				| 
					2023-07-15	
				 | 
				
										 
				 | 
								
									  Pluck v4.7.18 - Remote Code Execution (RCE)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-15	
				 | 
				
										 
				 | 
								
									  WinterCMS < 1.2.3 - Persistent Cross-Site Scripting
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												abhishek morla										
				 | 
			
            	
			
				| 
					2023-07-15	
				 | 
				
										 
				 | 
								
									  Admidio v4.2.10 - Remote Code Execution (RCE)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-15	
				 | 
				
										 
				 | 
								
									  Cisco UCS-IMC Supervisor 2.2.0.0 - Authentication Bypass
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Fatih Sencer										
				 | 
			
            	
			
				| 
					2023-07-15	
				 | 
				
										 
				 | 
								
									  ProjeQtOr Project Management System v10.4.1 - Multiple XSS
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-15	
				 | 
				
										 
				 | 
								
									  News Portal v4.0 - SQL Injection (Unauthorized)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2023-07-15	
				 | 
				
										 
				 | 
								
									  Icinga Web 2.10 - Authenticated Remote Code Execution
								 | 
								
					11			 | 
				
                     WEB
			   | 
								
												Dante Corona										
				 | 
			
            	
			
				| 
					2023-07-11	
				 | 
				
										 
				 | 
								
									  Ateme TITAN File 3.9 - SSRF File Enumeration
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												LiquidWorm										
				 | 
			
            	
			
				| 
					2023-07-11	
				 | 
				
										 
				 | 
								
									  BuildaGate5library v5 - Reflected Cross-Site Scripting (XSS)
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Idan Malihi										
				 | 
			
            	
			
				| 
					2023-07-11	
				 | 
				
										 
				 | 
								
									  Frappe Framework (ERPNext) 13.4.0 - Remote Code Execution (Authenticated)
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												Sander Ferdinand										
				 | 
			
            	
			
				| 
					2023-07-11	
				 | 
				
										 
				 | 
								
									  Spring Cloud 3.2.2 - Remote Command Execution (RCE)
								 | 
								
					17			 | 
				
                     WEB
			   | 
								
												GatoGamer1155										
				 | 
			
            	
			
				| 
					2023-07-11	
				 | 
				
										 
				 | 
								
									  Netlify CMS 2.10.192 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												tmrswrr										
				 | 
			
            	
			
				| 
					2023-07-07	
				 | 
				
										 
				 | 
								
									  Faculty Evaluation System v1.0 - SQL Injection
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Andrey Stoykov										
				 | 
			
            	
			
				| 
					2023-07-06	
				 | 
				
										 
				 | 
								
									  Piwigo v13.7.0 - Stored Cross-Site Scripting (XSS) (Authenticated)
								 | 
								
					11			 | 
				
                     WEB
			   | 
								
												Okan Kurtulus										
				 | 
			
            	
			
				| 
					2023-07-06	
				 | 
				
										 
				 | 
								
									  Lost and Found Information System v1.0 - SQL Injection
								 | 
								
					11			 | 
				
                     WEB
			   | 
								
												Amirhossein Bahramizadeh										
				 | 
			
            	
			
				| 
					2023-07-06	
				 | 
				
										 
				 | 
								
									  Gila CMS 1.10.9 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Omer Shaik										
				 | 
			
            	
			
				| 
					2023-07-04	
				 | 
				
										 
				 | 
								
									  Beauty Salon Management System v1.0 - SQLi
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Fatih Nacar										
				 | 
			
            	
			
				| 
					2023-07-04	
				 | 
				
										 
				 | 
								
									  Car Rental Script 1.8 - Stored Cross-site scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  WBCE CMS 1.6.1 - Open Redirect & CSRF
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  PodcastGenerator 3.2.9 - Blind SSRF via XML Injection
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  Alkacon OpenCMS 15.0 - Multiple Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												tmrswrr										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  Prestashop 8.0.4 - Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  Vacation Rental 1.8 - Stored Cross-Site Scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  WP AutoComplete 1.0.4 - Unauthenticated SQLi
								 | 
								
					11			 | 
				
                     WEB
			   | 
								
												matitanium										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  GZ Forum Script 1.8 - Stored Cross-Site Scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  Time Slot Booking Calendar 1.8 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												CraCkEr										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  spip v4.1.10 - Spoofing Admin account
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  D-Link DAP-1325 - Broken Access Control
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												ieduardogoncalves										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  WebsiteBaker v2.13.3 - Directory Traversal
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  WebsiteBaker v2.13.3 - Stored XSS
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												yuyudhn										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  FuguHub 8.1 - Remote Code Execution
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												redfire359										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Amirhossein Bahramizadeh										
				 | 
			
            	
			
				| 
					2023-07-03	
				 | 
				
										 
				 | 
								
									  Rukovoditel 3.4.1 - Multiple Stored XSS
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-06-26	
				 | 
				
										 
				 | 
								
									  Xenforo Version 2.2.13 - Authenticated Stored XSS
								 | 
								
					14			 | 
				
                     WEB
			   | 
								
												Furkan Karaarslan										
				 | 
			
            	
			
				| 
					2023-06-26	
				 | 
				
										 
				 | 
								
									  PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												Amirhossein Bahramizadeh										
				 | 
			
            	
			
				| 
					2023-06-26	
				 | 
				
										 
				 | 
								
									  Microsoft SharePoint Enterprise Server 2016 - Spoofing
								 | 
								
					11			 | 
				
                     WEB
			   | 
								
												Amirhossein Bahramizadeh										
				 | 
			
            	
			
				| 
					2023-06-23	
				 | 
				
										 
				 | 
								
									  MCL-Net 4.3.5.8788 - Information Disclosure
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Victor A. Morales										
				 | 
			
            	
			
				| 
					2023-06-23	
				 | 
				
										 
				 | 
								
									  Bludit < 3.13.1 Backup Plugin - Arbitrary File Download (Authenticated)
								 | 
								
					11			 | 
				
                     WEB
			   | 
								
												Antonio Cuomo										
				 | 
			
            	
			
				| 
					2023-06-22	
				 | 
				
										 
				 | 
								
									  Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
								 | 
								
					11			 | 
				
                     WEB
			   | 
								
												Tejas Pingulkar										
				 | 
			
            	
			
				| 
					2023-06-21	
				 | 
				
										 
				 | 
								
									  HiSecOS 04.0.01 - Privilege Escalation
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												dreizehnutters										
				 | 
			
            	
			
				| 
					2023-06-20	
				 | 
				
										 
				 | 
								
									  SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												nuts7										
				 | 
			
            	
			
				| 
					2023-06-20	
				 | 
				
										 
				 | 
								
									  Super Socializer 7.13.52 - Reflected XSS
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Amirhossein Bahramizadeh										
				 | 
			
            	
			
				| 
					2023-06-20	
				 | 
				
										 
				 | 
								
									  WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Amirhossein Bahramizadeh										
				 | 
			
            	
			
				| 
					2023-06-14	
				 | 
				
										 
				 | 
								
									  PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Gabriel Lima										
				 | 
			
            	
			
				| 
					2023-06-19	
				 | 
				
										 
				 | 
								
									  WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Amirhossein Bahramizadeh										
				 | 
			
            	
			
				| 
					2023-06-19	
				 | 
				
										 
				 | 
								
									  Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Harshit Joshi										
				 | 
			
            	
			
				| 
					2023-06-19	
				 | 
				
										 
				 | 
								
									  Diafan CMS 6.0 - Reflected Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												tmrswrr										
				 | 
			
            	
			
				| 
					2023-06-19	
				 | 
				
										 
				 | 
								
									  Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												VIVEK CHOUDHARY										
				 | 
			
            	
			
				| 
					2023-06-19	
				 | 
				
										 
				 | 
								
									  Jobpilot v2.61 - SQL Injection
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Ahmet Ümit BAYRAM										
				 | 
			
            	
			
				| 
					2023-06-19	
				 | 
				
										 
				 | 
								
									  Groomify v1.0 - SQL Injection
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Ahmet Ümit BAYRAM										
				 | 
			
            	
			
				| 
					2023-06-19	
				 | 
				
										 
				 | 
								
									  The Shop v2.5 - SQL Injection
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Ahmet Ümit BAYRAM										
				 | 
			
            	
			
				| 
					2023-06-15	
				 | 
				
										 
				 | 
								
									  Online Art gallery project 1.0 - Arbitrary File Upload (Unauthenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Ramil Mustafayev										
				 | 
			
            	
			
				| 
					2023-06-14	
				 | 
				
										 
				 | 
								
									  Textpattern CMS v4.8.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												tmrswrr										
				 | 
			
            	
			
				| 
					2023-06-14	
				 | 
				
										 
				 | 
								
									  Online Thesis Archiving System v1.0 - Multiple-SQLi
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-06-14	
				 | 
				
										 
				 | 
								
									  Xoops CMS 2.5.10 - Stored Cross-Site Scripting (XSS) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												tmrswrr										
				 | 
			
            	
			
				| 
					2023-06-14	
				 | 
				
										 
				 | 
								
									  Monstra 3.0.4 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												tmrswrr										
				 | 
			
            	
			
				| 
					2023-06-14	
				 | 
				
										 
				 | 
								
									  projectSend r1605 - Stored XSS
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-06-14	
				 | 
				
										 
				 | 
								
									  projectSend r1605 - CSV injection
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Mirabbas Ağalarov										
				 | 
			
            	
			
				| 
					2023-06-13	
				 | 
				
										 
				 | 
								
									  Sales Tracker Management System v1.0 - Multiple Vulnerabilities
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												AFFAN AHMED										
				 | 
			
            	
			
				| 
					2023-06-13	
				 | 
				
										 
				 | 
								
									  Teachers Record Management System 1.0 - File Upload Type Validation
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												AFFAN AHMED										
				 | 
			
            	
			
				| 
					2023-06-13	
				 | 
				
										 
				 | 
								
									  Online Examination System Project 1.0 - Cross-site request forgery (CSRF)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Ramil Mustafayev										
				 | 
			
            	
			
				| 
					2023-06-09	
				 | 
				
										 
				 | 
								
									  WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Mohammad Hossein Khanaki										
				 |