2013-05-16
|
|
WordPress Plugin Mail On Update - Cross-Site Request Forgery
|
4 |
WEB
|
Henri Salo
|
2013-05-14
|
|
Open Flash Chart - 'get-data' Cross-Site Scripting
|
4 |
WEB
|
Deepankar Arora
|
2013-05-15
|
|
WordPress Plugin wp-FileManager - 'path' Arbitrary File Download
|
5 |
WEB
|
ByEge
|
2015-10-22
|
|
Beckhoff CX9020 CPU Module - Remote Code Execution
|
6 |
WEB
|
Photubias
|
2013-05-14
|
|
Gallery Server Pro - Arbitrary File Upload
|
7 |
WEB
|
Drew Calcott
|
2013-05-11
|
|
WordPress Plugin Securimage-WP - 'siwp_test.php' Cross-Site Scripting
|
5 |
WEB
|
Gjoko Krstic
|
2013-05-10
|
|
Securimage - 'example_form.php' Cross-Site Scripting
|
7 |
WEB
|
Gjoko Krstic
|
2013-05-07
|
|
MyBB Game Section Plugin - 'games.php' Multiple Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
anonymous
|
2013-05-07
|
|
NetApp OnCommand System Manager - '/zapiServlet' User Management Interface Multiple Cross-Site Scrip
|
5 |
WEB
|
M. Heinzl
|
2013-05-07
|
|
NetApp OnCommand System Manager - '/zapiServlet' CIFS Configuration Management Interface Multiple Cr
|
5 |
WEB
|
M. Heinzl
|
2013-04-27
|
|
PHPValley Micro Jobs Site Script - Spoofing
|
4 |
WEB
|
Jason Whelan
|
2015-10-19
|
|
RealtyScript 4.0.2 - Multiple Blind SQL Injections
|
4 |
WEB
|
LiquidWorm
|
2015-10-19
|
|
RealtyScript 4.0.2 - Multiple Cross-Site Request Forgery / Persistent Cross-Site Scripting Vulnerabi
|
6 |
WEB
|
LiquidWorm
|
2013-04-24
|
|
WordPress Plugin WP Super Cache - PHP Remote Code Execution
|
5 |
WEB
|
anonymous
|
2013-04-23
|
|
SMF - '/index.php' HTML Injection / Multiple PHP Code Injection Vulnerabilities
|
5 |
WEB
|
Jakub Galczyk
|
2015-10-19
|
|
Belkin N150 Router 1.00.08/1.00.09 - Directory Traversal
|
5 |
WEB
|
Rahul Pratap Singh
|
2013-04-21
|
|
WordPress Theme Colormix - Multiple Vulnerabilities
|
4 |
WEB
|
MustLive
|
2015-10-18
|
|
WordPress Plugin Ajax Load More < 2.8.2 - Arbitrary File Upload
|
5 |
WEB
|
PizzaHatHacker
|
2013-04-19
|
|
Crafty Syntax Live Help 3.1.2 - Remote File Inclusion / Full Path Disclosure
|
4 |
WEB
|
ITTIHACK
|
2013-04-18
|
|
Fork CMS - 'js.php' Local File Inclusion
|
4 |
WEB
|
Rafay Baloch
|
2013-03-06
|
|
Matrix42 Service Store - 'default.aspx' Cross-Site Scripting
|
5 |
WEB
|
43zsec
|
2013-04-17
|
|
Sosci Survey - Multiple Vulnerabilities
|
3 |
WEB
|
T. Lazauninkas
|
2013-04-14
|
|
Todoo Forum 2.0 - 'todooforum.php' Multiple SQL Injections
|
4 |
WEB
|
Chiekh Bouchenafa
|
2013-04-14
|
|
Todoo Forum 2.0 - 'todooforum.php' Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Chiekh Bouchenafa
|
2015-10-15
|
|
PROLiNK H5004NK ADSL Wireless Modem - Multiple Vulnerabilities
|
3 |
WEB
|
Karn Ganeshen
|
2015-10-15
|
|
netis RealTek Wireless Router / ADSL Modem - Multiple Vulnerabilities
|
4 |
WEB
|
Karn Ganeshen
|
2013-04-13
|
|
Aibolit - Information Disclosure
|
6 |
WEB
|
MustLive
|
2013-04-10
|
|
Hero Framework - '/users/forgot_password?error' Cross-Site Scripting
|
5 |
WEB
|
High-Tech Bridge
|
2013-04-10
|
|
Hero Framework - '/users/login?Username' Cross-Site Scripting
|
5 |
WEB
|
High-Tech Bridge
|
2013-03-29
|
|
jPlayer - 'Jplayer.swf' Script Cross-Site Scripting
|
3 |
WEB
|
Malte Batram
|
2013-04-11
|
|
Request Tracker - 'ShowPending' SQL Injection
|
4 |
WEB
|
cheki
|
2013-04-11
|
|
WordPress Plugin Spider Video Player - 'theme' SQL Injection
|
3 |
WEB
|
Ashiyane Digital Security Team
|
2015-10-14
|
|
ZYXEL PMG5318-B20A - OS Command Injection
|
4 |
WEB
|
Karn Ganeshen
|
2015-10-13
|
|
Kerio Control 8.6.1 - Multiple Vulnerabilities
|
4 |
WEB
|
Raschin Tavakoli
|
2015-10-13
|
|
Netgear Voice Gateway 2.3.0.23_2.3.23 - Multiple Vulnerabilities
|
4 |
WEB
|
Karn Ganeshen
|
2015-10-13
|
|
F5 Big-IP 10.2.4 Build 595.0 Hotfix HF3 - Directory Traversal
|
4 |
WEB
|
Karn Ganeshen
|
2015-10-11
|
|
Dream CMS 2.3.0 - Cross-Site Request Forgery (Add Extension) / Arbitrary File Upload / PHP Code Exec
|
4 |
WEB
|
LiquidWorm
|
2015-10-11
|
|
Joomla! Component com_realestatemanager 3.7 - SQL Injection
|
4 |
WEB
|
Omer Ramić
|
2015-10-11
|
|
Liferay 6.1.0 CE - Privilege Escalation
|
4 |
WEB
|
Massimo De Luca
|
2013-04-10
|
|
WordPress Plugin Spiffy XSPF Player - 'playlist_id' SQL Injection
|
4 |
WEB
|
Ashiyane Digital Security Team
|
2013-04-09
|
|
phpMyAdmin - 'tbl_gis_visualization.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
waraxe
|
2013-04-09
|
|
WordPress Plugin Traffic Analyzer - 'aoid' Cross-Site Scripting
|
5 |
WEB
|
Beni_Vanda
|
2013-04-09
|
|
EasyPHP - '/index.php' Authentication Bypass / Remote PHP Code Injection
|
4 |
WEB
|
KedAns-Dz
|
2013-04-05
|
|
Zimbra - 'aspell.php' Cross-Site Scripting
|
2 |
WEB
|
Michael Scherer
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/admin_index.php?q' SQL Injection
|
4 |
WEB
|
Jurgen Voorneveld
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/checklogin.php?Username' SQL Injection
|
4 |
WEB
|
Jurgen Voorneveld
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/user_add_save.php?email' SQL Injection
|
4 |
WEB
|
Jurgen Voorneveld
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/traffic.php?var' SQL Injection
|
4 |
WEB
|
Jurgen Voorneveld
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/router.php?BasicLogin' Cookie SQL Injection
|
4 |
WEB
|
Jurgen Voorneveld
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/reset_password_save.php' Multiple SQL Injections
|
4 |
WEB
|
Jurgen Voorneveld
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/reset_password.php' Multiple SQL Injections
|
4 |
WEB
|
Jurgen Voorneveld
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/linktick.php?site' SQL Injection
|
3 |
WEB
|
Jurgen Voorneveld
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/edit_user_save.php' Multiple SQL Injections
|
4 |
WEB
|
Jurgen Voorneveld
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/edit_user.php?id' SQL Injection
|
4 |
WEB
|
Jurgen Voorneveld
|
2013-04-05
|
|
PHP Address Book - '/addressbook/register/delete_user.php?id' SQL Injection
|
4 |
WEB
|
Jurgen Voorneveld
|
2015-10-08
|
|
Kallithea 0.2.9 - 'came_from' HTTP Response Splitting
|
3 |
WEB
|
LiquidWorm
|
2013-04-03
|
|
FUDforum - Multiple Remote PHP Code Injection Vulnerabilities
|
5 |
WEB
|
High-Tech Bridge
|
2013-04-03
|
|
Symphony - 'sort' SQL Injection
|
4 |
WEB
|
High-Tech Bridge
|
2013-04-03
|
|
e107 - 'content_preset.php' Cross-Site Scripting
|
4 |
WEB
|
Simon Bieber
|
2013-04-03
|
|
C2 WebResource - 'File' Cross-Site Scripting
|
4 |
WEB
|
anonymous
|
2013-03-30
|
|
WordPress Plugin Feedweb - 'wp_post_id' Cross-Site Scripting
|
4 |
WEB
|
Stefan Schurtz
|
2013-03-27
|
|
OrionDB Web Directory - Multiple Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
3spi0n
|
2015-10-07
|
|
Zope Management Interface 4.3.7 - Cross-Site Request Forgery
|
5 |
WEB
|
hyp3rlinx
|
2013-03-25
|
|
WordPress Plugin Banners Lite - 'wpbanners_show.php' HTML Injection
|
5 |
WEB
|
Fernando A. Lagos B
|
2015-10-06
|
|
ZTE ZXHN H108N Router - Configuration Disclosure
|
5 |
WEB
|
Todor Donev
|
2013-03-23
|
|
Jaow CMS - 'add_ons' Cross-Site Scripting
|
5 |
WEB
|
Metropolis
|
2015-10-06
|
|
GLPI 0.85.5 - Arbitrary File Upload / Filter Bypass / Remote Code Execution
|
5 |
WEB
|
Raffaele Forte
|
2015-10-06
|
|
PHP-Fusion 7.02.07 - Blind SQL Injection
|
4 |
WEB
|
Manuel García Cárdenas
|
2015-10-05
|
|
Alienvault Open Source SIEM (OSSIM) 4.3 - Cross-Site Request Forgery
|
5 |
WEB
|
MohamadReza Mohajerani
|
2015-10-05
|
|
ManageEngine ServiceDesk Plus 9.1 build 9110 - Directory Traversal
|
4 |
WEB
|
xistence
|
2013-03-19
|
|
WordPress Plugin Occasions - Cross-Site Request Forgery
|
5 |
WEB
|
m3tamantra
|
2013-03-14
|
|
Petite Annonce - Cross-Site Scripting
|
5 |
WEB
|
Metropolis
|
2013-03-11
|
|
PHPBoost - Arbitrary File Upload / Information Disclosure
|
5 |
WEB
|
KedAns-Dz
|
2013-03-11
|
|
KindEditor - Multiple Arbitrary File Upload Vulnerabilities
|
5 |
WEB
|
KedAns-Dz
|
2015-10-02
|
|
ElasticSearch 1.6.0 - Arbitrary File Download
|
5 |
WEB
|
Pedro Andujar
|
2015-10-02
|
|
FTGate 7 - Cross-Site Request Forgery
|
4 |
WEB
|
hyp3rlinx
|
2015-10-02
|
|
FTGate 2009 Build 6.4.00 - Multiple Vulnerabilities
|
4 |
WEB
|
hyp3rlinx
|
2013-03-11
|
|
Privoxy Proxy - Authentication Information Disclosure
|
4 |
WEB
|
Chris John Riley
|
2013-03-11
|
|
WordPress Plugin podPress - 'playerID' Cross-Site Scripting
|
4 |
WEB
|
hiphop
|
2013-03-10
|
|
Asteriskguru Queue Statistics - 'warning' Cross-Site Scripting
|
3 |
WEB
|
Manuel García Cárdenas
|
2013-03-10
|
|
SWFupload - Multiple Content Spoofing / Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
MustLive
|
2013-03-08
|
|
WordPress Plugin Terillion Reviews - Profile Id HTML Injection
|
5 |
WEB
|
Aditya Balapure
|
2013-03-01
|
|
Question2Answer - Cross-Site Request Forgery
|
4 |
WEB
|
MustLive
|
2015-10-01
|
|
Bosch Security Systems Dinion NBN-498 - Web Interface XML Injection
|
4 |
WEB
|
neom22
|
2013-03-08
|
|
Your Own Classifieds - Cross-Site Scripting
|
4 |
WEB
|
Rafay Baloch
|
2013-02-06
|
|
Verax NMS - Multiple Method Authentication Bypass
|
5 |
WEB
|
Andrew Brooks
|
2013-02-23
|
|
File Manager - HTML Injection / Local File Inclusion
|
4 |
WEB
|
Benjamin Kunz Mejri
|
2013-03-05
|
|
WordPress Plugin Count Per Day - 'daytoshow' Cross-Site Scripting
|
4 |
WEB
|
alejandr0.m0f0
|
2013-03-04
|
|
HP Intelligent Management Center - 'topoContent.jsf' Cross-Site Scripting
|
4 |
WEB
|
Julien Ahrens
|
2013-03-01
|
|
WordPress Plugin Uploader - 'blog' Cross-Site Scripting
|
4 |
WEB
|
CodeV
|
2013-03-02
|
|
Plogger - Multiple Input Validation Vulnerabilities
|
4 |
WEB
|
Saadat Ullah
|
2015-09-29
|
|
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2)
|
6 |
WEB
|
Pedro Ribeiro
|
2015-09-29
|
|
Western Digital My Cloud 04.01.03-421/04.01.04-422 - Command Injection
|
4 |
WEB
|
absane
|
2015-09-28
|
|
vTiger CRM 6.3.0 - (Authenticated) Remote Code Execution
|
5 |
WEB
|
Benjamin Daniel Mussler
|
2015-09-28
|
|
Photos in Wifi 1.0.1 iOS - Arbitrary File Upload
|
3 |
WEB
|
Vulnerability-Lab
|
2015-09-28
|
|
My.WiFi USB Drive 1.0 iOS - Local File Inclusion
|
4 |
WEB
|
Vulnerability-Lab
|
2015-09-28
|
|
Centreon 2.6.1 - Multiple Vulnerabilities
|
5 |
WEB
|
LiquidWorm
|
2015-09-28
|
|
Mango Automation 2.6.0 - Multiple Vulnerabilities
|
3 |
WEB
|
LiquidWorm
|
2013-02-27
|
|
Geeklog - Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge
|
2013-02-26
|
|
JForum - 'jforum.page' Multiple Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
ZeroDayLab
|
2013-02-25
|
|
phpMyRecipes - Multiple HTML Injection Vulnerabilities
|
4 |
WEB
|
PDS
|
2013-03-01
|
|
Batavi - 'index.php' Cross-Site Scripting
|
4 |
WEB
|
Dognaedis
|
2013-02-25
|
|
WordPress Plugin Smart Flv - 'jwplayer.swf' Multiple Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
Henri Salo
|
2013-02-20
|
|
ZeroClipboard 1.9.x - 'id' Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2013-02-21
|
|
OpenEMR - 'site' Cross-Site Scripting
|
4 |
WEB
|
Gjoko Krstic
|
2013-02-21
|
|
PHPmyGallery 1.5 - Local File Disclosure / Cross-Site Scripting
|
5 |
WEB
|
TheMirkin
|
2013-02-20
|
|
ZenPhoto - 'index.php' SQL Injection
|
5 |
WEB
|
HosseinNsn
|
2013-02-20
|
|
WordPress Plugin Pretty Link - Cross-Site Scripting
|
8 |
WEB
|
hiphop
|
2015-09-25
|
|
X2Engine 4.2 - Arbitrary File Upload
|
3 |
WEB
|
Portcullis
|
2013-02-19
|
|
CKEditor - 'posteddata.php' Cross-Site Scripting
|
4 |
WEB
|
AkaStep
|
2015-09-25
|
|
X2Engine 4.2 - Cross-Site Request Forgery
|
4 |
WEB
|
Portcullis
|
2013-02-19
|
|
Squirrelcart - 'table' Cross-Site Scripting
|
4 |
WEB
|
Gjoko Krstic
|
2013-02-18
|
|
MIMEsweeper For SMTP - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Anastasios Monachos
|
2015-09-25
|
|
FortiManager 5.2.2 - Persistent Cross-Site Scripting
|
4 |
WEB
|
hyp3rlinx
|
2013-02-12
|
|
Sonar - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
DevilTeam
|
2013-02-14
|
|
WordPress Plugin NextGEN Gallery - Full Path Disclosure
|
5 |
WEB
|
Henrique Montenegro
|
2013-02-12
|
|
BlackNova Traders - 'news.php' SQL Injection
|
5 |
WEB
|
ITTIHACK
|
2013-02-12
|
|
osCommerce - Cross-Site Request Forgery
|
6 |
WEB
|
Jakub Galczyk
|
2015-09-24
|
|
SMF (Simple Machine Forum) 2.0.10 - Remote Memory Exfiltration
|
4 |
WEB
|
Filippo Roncari
|
2013-02-09
|
|
WordPress Theme Pinboard - 'tab' Cross-Site Scripting
|
4 |
WEB
|
Henrique Montenegro
|
2013-01-31
|
|
WordPress Plugin Audio Player - 'playerID' Cross-Site Scripting
|
4 |
WEB
|
hiphop
|
2013-02-06
|
|
WordPress Plugin Wysija Newsletters - Multiple SQL Injections
|
3 |
WEB
|
High-Tech Bridge
|
2013-02-06
|
|
WordPress Plugin CommentLuv - '_ajax_nonce' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge
|
2013-02-06
|
|
ezStats for Battlefield 3 - '/ezStats2/compare.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
L0n3ly-H34rT
|
2013-02-06
|
|
ezStats2 - 'style.php' Local File Inclusion
|
4 |
WEB
|
L0n3ly-H34rT
|