Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2016-11-10   MyBB 1.8.6 - Cross-Site Scripting 27 WEB Curesec Research Team
2016-11-09   e107 CMS 2.1.2 - Privilege Escalation 25 WEB Kacper Szurek
2016-11-09   Adobe Connect 9.5.7 - Cross-Site Scripting 26 WEB Vulnerability-Lab
2016-11-08   WordPress Plugin WassUp Real Time Analytics 1.9 - Persistent Cross-Site Scripting 27 WEB Burak Kelebek
2016-11-08   WordPress Plugin 404 to 301 2.2.8 - Persistent Cross-Site Scripting 25 WEB Alyssa Milburn
2016-11-07   Sophos Web Appliance 4.2.1.3 - Remote Code Execution 20 WEB KoreLogic
2016-11-07   Piwik 2.16.0 - 'layout' PHP Object Injection 22 WEB Egidio Romano
2016-11-07   NodCMS - PHP Code Execution 24 WEB Ashiyane Digital Security Team
2016-11-07   Schoolhos CMS 2.29 - 'kelas' SQL Injection 23 WEB Vulnerability-Lab
2016-11-06   SweetRice 1.5.1 - Backup Disclosure 23 WEB Ashiyane Digital Security Team
2016-11-06   SweetRice 1.5.1 - Arbitrary File Upload 19 WEB Ashiyane Digital Security Team
2016-11-03   Redaxo 5.2.0 - Cross-Site Request Forgery 24 WEB Amir.ght
2016-11-03   nodCMS - Cross-Site Request Forgery 21 WEB Amir.ght
2016-11-03   sNews 1.7.1 - Arbitrary File Upload 25 WEB Amir.ght
2016-11-03   sNews 1.7.1 - Cross-Site Request Forgery 26 WEB Amir.ght
2016-11-03   ETchat 3.7 - Cross-Site Request Forgery 28 WEB Hesam Bazvand
2016-11-03   SweetRice 1.5.1 - Cross-Site Request Forgery / PHP Code Execution 25 WEB Ashiyane Digital Security Team
2016-11-03   SweetRice 1.5.1 - Arbitrary File Download 19 WEB Ashiyane Digital Security Team
2016-11-02   SweetRice 1.5.1 - Cross-Site Request Forgery 25 WEB Ashiyane Digital Security Team
2016-11-02   LifeSize Room 5.0.9 - Multiple Vulnerabilities 29 WEB Xiphos Research Ltd
2016-11-02   Alienvault OSSIM/USM 5.3.1 - SQL Injection 26 WEB Peter Lapp
2016-11-02   Alienvault OSSIM/USM 5.3.1 - Persistent Cross-Site Scripting 18 WEB Peter Lapp
2016-11-02   Alienvault OSSIM/USM 5.3.1 - PHP Object Injection 22 WEB Peter Lapp
2016-11-01   My Little Forum 2.3.7 - Multiple Vulnerabilities 25 WEB Ashiyane Digital Security Team
2016-11-01   School Registration and Fee System - Authentication Bypass 24 WEB opt1lc
2016-10-31   S9Y Serendipity 2.0.4 - Cross-Site Scripting 27 WEB Besim
2016-10-28   InfraPower PPS-02-S Q213V1 - Cross-Site Request Forgery 19 WEB LiquidWorm
2016-10-28   InfraPower PPS-02-S Q213V1 - Authentication Bypass 22 WEB LiquidWorm
2016-10-28   InfraPower PPS-02-S Q213V1 - Insecure Direct Object Reference 25 WEB LiquidWorm
2016-10-28   InfraPower PPS-02-S Q213V1 - Local File Disclosure 23 WEB LiquidWorm
2016-10-28   InfraPower PPS-02-S Q213V1 - Multiple Cross-Site Scripting Vulnerabilities 19 WEB LiquidWorm
2016-10-28   InfraPower PPS-02-S Q213V1 - Remote Command Execution 20 WEB LiquidWorm
2016-10-27   Joomla! 3.4.4 < 3.6.4 - Account Creation / Privilege Escalation 23 WEB Xiphos Research Ltd
2016-10-26   Boonex Dolphin 7.3.2 - Authentication Bypass 24 WEB Saadi Siddiqui
2016-10-24   Industrial Secure Routers EDR-810 / EDR-G902 / EDR-G903 - Insecure Configuration Management 20 WEB Sniper Pex
2016-10-24   EC-CUBE 2.12.6 - Server-Side Request Forgery 22 WEB Wadeek
2016-10-24   Orange Inventel LiveBox 5.08.3-sp - Cross-Site Request Forgery 25 WEB BlackMamba
2016-10-23   Zenbership 107 - Multiple Vulnerabilities 24 WEB Besim
2016-10-21   FreePBX 13 - Remote Command Execution / Privilege Escalation 23 WEB Christopher Davis
2016-10-21   Just Dial Clone Script - 'srch' SQL Injection 29 WEB Arbin Godar
2016-10-20   SPIP 3.1.2 - Cross-Site Request Forgery 20 WEB Sysdream
2016-10-20   SPIP 3.1.1/3.1.2 - File Enumeration / Path Traversal 23 WEB Sysdream
2016-10-20   SPIP 3.1.2 Template Compiler/Composer - PHP Code Execution 23 WEB Sysdream
2016-10-20   Event Calendar PHP 1.5 - SQL Injection 21 WEB Ehsan Hosseini
2016-10-20   Classifieds Rental Script - SQL Injection 21 WEB Arbin Godar
2016-10-20   Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection 18 WEB Jakub Palaczynski
2016-10-19   Intel(R) PROSet/Wireless WiFi Software 15.01.1000.0927 - Unquoted Service Path Privilege Escalation 26 WEB Joey Lane
2016-10-19   XhP CMS 0.5.1 - Cross-Site Request Forgery / Persistent Cross-Site Scripting 19 WEB Ahsan Tahir
2016-10-19   CNDSOFT 2.3 - Cross-Site Request Forgery / Arbitrary File Upload 19 WEB Besim
2016-10-18   Cgiemail 1.6 - Source Code Disclosure 24 WEB Finbar Crago
2016-10-18   ManageEngine ServiceDesk Plus 9.2 Build 9207 - Unauthorized Information Disclosure 21 WEB p0z
2016-10-18   Pluck CMS 4.7.3 - Cross-Site Request Forgery (Add Page) 21 WEB Ahsan Tahir
2016-10-17   PHP Business Directory - Multiple Vulnerabilities 26 WEB larrycompress
2016-10-14   School Full CBT 0.1 - SQL Injection 22 WEB lahilote
2016-10-16   PHP NEWS 1.3.0 - Cross-Site Request Forgery (Add Admin) 21 WEB Meryem AKDOĞAN
2016-10-14   Simple Shopping Cart Application 0.1 - SQL Injection 23 WEB lahilote
2016-10-16   PHP Image Database - Multiple Vulnerabilities 23 WEB larrycompress
2016-10-17   Subrion CMS 4.0.5 - Cross-Site Request Forgery Bypass / Persistent Cross-Site Scripting 23 WEB Ahsan Tahir
2016-10-16   PHP Telephone Directory - Multiple Vulnerabilities 24 WEB larrycompress
2016-10-14   Health Record System 0.1 - Authentication Bypass 26 WEB lahilote
2016-10-14   Fashion Shopping Cart 0.1 - SQL Injection 27 WEB lahilote
2016-10-14   Learning Management System 0.1 - Authentication Bypass 23 WEB lahilote
2016-10-14   Simple Dynamic Web 0.1 - SQL Injection 19 WEB lahilote
2016-10-14   Web Based Alumni Tracking System 0.1 - SQL Injection 20 WEB lahilote
2016-10-14   Student Information System (SIS) 0.1 - Authentication Bypass 26 WEB lahilote
2016-10-14   YouTube Automated CMS 1.0.7 - Cross-Site Request Forgery / Persistent Cross-Site Scripting 21 WEB Arbin Godar
2016-10-14   Simple Forum PHP 2.4 - Cross-Site Request Forgery (Edit Options) 21 WEB Ehsan Hosseini
2016-10-14   Simple Forum PHP 2.4 - SQL Injection 22 WEB Ehsan Hosseini
2016-10-13   JonhCMS 4.5.1 - SQL Injection 21 WEB Besim
2016-10-13   RSS News AutoPilot Script 1.0.1/3.1.0 - Admin Panel Authentication Bypass 18 WEB Arbin Godar
2016-10-13   Colorful Blog - Cross-Site Request Forgery (Change Admin Password) 24 WEB Besim
2016-10-13   Colorful Blog - Persistent Cross-Site Scripting 22 WEB Besim
2016-10-13   Thatware 0.4.6 - SQL Injection 19 WEB Besim
2016-10-13   Simple Blog PHP 2.0 - SQL Injection 22 WEB Ehsan Hosseini
2016-10-13   Simple Blog PHP 2.0 - Multiple Vulnerabilities 19 WEB Ehsan Hosseini
2016-10-12   ApPHP MicroCMS 3.9.5 - Cross-Site Request Forgery (Add Admin) 20 WEB Besim
2016-10-12   ApPHP MicroCMS 3.9.5 - Persistent Cross-Site Scripting 22 WEB Besim
2016-10-12   OpenCimetiere 3.0.0-a5 - Blind SQL Injection 21 WEB Wadeek
2016-10-12   NetBilletterie 2.8 - Multiple Vulnerabilities 21 WEB Wadeek
2016-10-12   Categorizator 0.3.1 - SQL Injection 24 WEB Wadeek
2016-10-11   ApPHP MicroBlog 1.0.2 - Cross-Site Request Forgery (Add New Author) 25 WEB Besim
2016-10-11   ApPHP MicroBlog 1.0.2 - Persistent Cross-Site Scripting 19 WEB Besim
2016-10-11   RSA Enterprise Compromise Assessment Tool 4.1.0.1 - XML External Entity Injection 22 WEB SEC Consult
2016-10-11   AVTECH IP Camera / NVR / DVR Devices - Multiple Vulnerabilities 22 WEB Gergely Eberhardt
2016-10-11   phpEnter 4.2.7 - Cross-Site Request Forgery (Add New Post) 23 WEB Besim
2016-10-11   BirdBlog 1.4.0 - Cross-Site Request Forgery (Add New Post) 20 WEB Besim
2016-10-10   Spacemarc News - Cross-Site Request Forgery (Add New Post) 27 WEB Besim
2016-10-10   Maian Weblog 4.0 - Cross-Site Request Forgery (Add New Post) 21 WEB Besim
2016-10-09   PHP Press Release - Persistent Cross-Site Scripting 23 WEB Besim
2016-10-09   PHP Press Release - Cross-Site Request Forgery (Add Admin) 22 WEB Besim
2016-09-19   ShoreTel Connect ONSITE - Blind SQL Injection 32 WEB Iraklis Mathiopoulos
2016-10-09   miniblog 1.0.1 - Cross-Site Request Forgery (Add New Post) 29 WEB Besim
2016-10-07   Entrepreneur Job Portal Script 2.06 - SQL Injection 19 WEB OoN_Boy
2016-10-07   Simple PHP Blog 0.8.4 - Cross-Site Request Forgery (Add Admin) 26 WEB Besim
2016-10-06   Just Dial Clone Script - 'fid' SQL Injection 21 WEB OoN_Boy
2016-10-06   MLM Unilevel Plan Script 1.0.2 - SQL Injection 23 WEB N4TuraL
2016-10-06   B2B Portal Script - Blind SQL Injection 36 WEB OoN_Boy
2016-10-06   PHP Classifieds Rental Script - Blind SQL Injection 20 WEB OoN_Boy
2016-10-06   Advance MLM Script - SQL Injection 22 WEB OoN_Boy
2016-10-05   Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion 21 WEB KoreLogic
2016-10-05   Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution 19 WEB KoreLogic
2016-10-05   Witbe - Remote Code Execution 25 WEB BeLmar
2016-10-05   Picosafe Web GUI - Multiple Vulnerabilities 26 WEB Shahab Shamsi
2016-09-28   Symantec Messaging Gateway 10.6.1 - Directory Traversal 23 WEB R-73eN
2016-09-27   TP-Link Archer CR-700 - Cross-Site Scripting 22 WEB Ayushman Dutta
2016-09-26   Joomla! Component Event Booking 2.10.1 - SQL Injection 22 WEB Persian Hack Team
2016-09-22   Matrimonial Website Script 1.0.2 - SQL Injection 28 WEB N4TuraL
2016-09-22   Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities 28 WEB SEC Consult
2016-09-22   Joomla! Component com_videogallerylite 1.0.9 - SQL Injection 28 WEB Larry W. Cashdollar
2016-09-22   Exponent CMS 2.3.9 - Blind SQL Injection 25 WEB Manuel García Cárdenas
2016-09-22   Microix Timesheet Module - SQL Injection 29 WEB Anthony Cole
2016-09-20   Dolphin 7.3.0 - Error-Based SQL Injection 25 WEB Kacper Szurek
2016-09-20   VegaDNS 0.13.2 - Remote Command Injection 27 WEB Wireghoul
2016-09-19   ZineBasic 1.1 - Arbitrary File Disclosure 25 WEB bd0rk
2016-09-19   MuM MapEdit 3.2.6.0 - Multiple Vulnerabilities 22 WEB Paul Baade & Sven Krewitt
2016-09-19   MyBB 1.8.6 - SQL Injection 23 WEB Curesec Research Team
2016-09-19   Kajona 4.7 - Cross-Site Scripting / Directory Traversal 26 WEB Curesec Research Team
2016-09-19   WordPress Plugin Order Export Import for WooCommerce - Order Information Disclosure 30 WEB david-peltier
2016-09-19   BuilderEngine 3.5.0 - Arbitrary File Upload 22 WEB metanubix
2016-09-16   AnoBBS 1.0.1 - Remote File Inclusion 23 WEB bd0rk
2016-09-15   Cisco EPC 3925 - Multiple Vulnerabilities 27 WEB Patryk Bogdan
2016-09-13   Open-Xchange App Suite 7.8.2 - Cross-Site Scripting 20 WEB Jakub A>>oczek
2016-09-13   Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities 25 WEB Benjamin Daniel Mussler
2016-09-13   ASUS DSL-X11 ADSL Router - DNS Change 25 WEB Todor Donev
2016-09-13   COMTREND ADSL Router CT-5367 C01_R12 / CT-5624 C01_R03 - DNS Change 25 WEB Todor Donev