2012-11-16
|
|
Friends in War The FAQ Manager - 'question' SQL Injection
|
3 |
WEB
|
unsuprise
|
2012-11-19
|
|
Omni-Secure - 'dir' Multiple File Disclosure Vulnerabilities
|
3 |
WEB
|
HaCkeR_EgY
|
2012-07-19
|
|
WebKit Cross-Site Scripting Filter - 'Cross-Site ScriptingAuditor.cpp' Security Bypass
|
5 |
WEB
|
Tushar Dalvi
|
2012-11-16
|
|
WordPress Plugin Tagged Albums - 'id' SQL Injection
|
4 |
WEB
|
Ashiyane Digital Security Team
|
2012-11-16
|
|
WordPress Theme Dailyedition-mouss - 'id' SQL Injection
|
4 |
WEB
|
Ashiyane Digital Security Team
|
2012-11-09
|
|
WordPress Plugin Eco-annu - 'eid' SQL Injection
|
5 |
WEB
|
Ashiyane Digital Security Team
|
2012-11-09
|
|
WordPress Plugin PHP Event Calendar - 'cid' SQL Injection
|
4 |
WEB
|
Ashiyane Digital Security Team
|
2012-11-09
|
|
WordPress Theme Kakao - 'ID' SQL Injection
|
3 |
WEB
|
sil3nt
|
2012-11-09
|
|
ESRI ArcGIS for Server - 'where' SQL Injection
|
4 |
WEB
|
anonymous
|
2012-11-08
|
|
AR Web Content Manager (AWCM) - 'cookie_gen.php' Arbitrary Cookie Generation
|
4 |
WEB
|
Sooel Son
|
2012-11-07
|
|
WordPress Plugin FLV Player - 'id' SQL Injection
|
8 |
WEB
|
Ashiyane Digital Security Team
|
2012-11-07
|
|
OrangeHRM - 'sortField' SQL Injection
|
4 |
WEB
|
High-Tech Bridge
|
2012-11-06
|
|
VeriCentre - Multiple SQL Injections
|
4 |
WEB
|
Cory Eubanks
|
2012-11-04
|
|
AWAuctionScript CMS - Multiple Remote Vulnerabilities
|
6 |
WEB
|
X-Cisadane
|
2012-11-03
|
|
Joomla! Component Parcoauto - 'idVeicolo' SQL Injection
|
5 |
WEB
|
Andrea Bocchetti
|
2012-11-02
|
|
DCForum - 'auth_user_file.txt' File Multiple Information Disclosure Vulnerabilities
|
5 |
WEB
|
r45c4l
|
2012-10-31
|
|
BloofoxCMS 0.3.5 - Multiple Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
Canberk BOLAT
|
2015-08-29
|
|
Samsung SyncThruWeb 2.01.00.26 - SMB Hash Disclosure
|
7 |
WEB
|
Shad Malloy
|
2015-08-28
|
|
Pluck CMS 4.7.3 - Multiple Vulnerabilities
|
4 |
WEB
|
smash
|
2015-08-28
|
|
Wolf CMS - Arbitrary File Upload / Execution
|
4 |
WEB
|
Narendra Bhati
|
2015-08-28
|
|
Jenkins 1.626 - Cross-Site Request Forgery / Code Execution
|
4 |
WEB
|
smash
|
2015-08-28
|
|
WordPress Plugin Responsive Thumbnail Slider 1.0 - Arbitrary File Upload
|
3 |
WEB
|
Arash Khazaei
|
2012-10-31
|
|
SolarWinds Orion IP Address Manager (IPAM) - 'search.aspx' Cross-Site Scripting
|
5 |
WEB
|
Anthony Trummer
|
2012-10-31
|
|
NetCat CMS - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Security Effect Team
|
2012-10-30
|
|
Joomla! Component com_quiz - SQL Injection
|
5 |
WEB
|
Daniel Barragan
|
2012-10-28
|
|
CorePlayer - 'callback' Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2012-10-16
|
|
WANem - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Brendan Coles
|
2015-08-27
|
|
Invision Power Board (IP.Board) 4.x - Persistent Cross-Site Scripting
|
5 |
WEB
|
snop
|
2012-10-26
|
|
EasyITSP - 'customers_edit.php' Authentication Bypass
|
4 |
WEB
|
Michal Blaszczak
|
2012-10-29
|
|
TP-Link TL-WR841N Router - Local File Inclusion
|
4 |
WEB
|
Matan Azugi
|
2012-10-26
|
|
VicBlog - Multiple SQL Injections
|
5 |
WEB
|
Geek
|
2012-10-25
|
|
Gramophone - 'rs' Cross-Site Scripting
|
4 |
WEB
|
G13
|
2015-08-26
|
|
Magento eCommerce - Remote Code Execution
|
4 |
WEB
|
Manish Tanwar
|
2012-10-26
|
|
Inventory - Multiple Cross-Site Scripting / SQL Injections
|
4 |
WEB
|
G13
|
2012-10-23
|
|
SMF - 'view' Cross-Site Scripting
|
4 |
WEB
|
Am!r
|
2012-10-22
|
|
WHMCompleteSolution (WHMCS) 4.5.2 - 'googlecheckout.php' SQL Injection
|
4 |
WEB
|
Starware Security Team
|
2012-10-18
|
|
WordPress Plugin Wordfence Security - Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2012-10-19
|
|
CMS Mini 0.2.2 - 'index.php' Script Cross-Site Scripting
|
4 |
WEB
|
Netsparker
|
2015-08-25
|
|
Keeper IP Camera 3.2.2.10 - Authentication Bypass
|
4 |
WEB
|
RAT - ThiefKing
|
2012-10-18
|
|
Amateur Photographer's Image Gallery - 'fullscreen.php?albumid' SQL Injection
|
4 |
WEB
|
cr4wl3r
|
2012-10-18
|
|
Amateur Photographer's Image Gallery - 'plist.php?albumid' Cross-Site Scripting
|
4 |
WEB
|
cr4wl3r
|
2012-10-18
|
|
Amateur Photographer's Image Gallery - 'plist.php?albumid' SQL Injection
|
4 |
WEB
|
cr4wl3r
|
2012-10-18
|
|
Amateur Photographer's Image Gallery - 'force-download.php?File' Information Disclosure
|
4 |
WEB
|
cr4wl3r
|
2012-10-18
|
|
BSW Gallery - 'uploadpic.php' Arbitrary File Upload
|
4 |
WEB
|
cr4wl3r
|
2015-08-24
|
|
WordPress Theme GeoPlaces3 - Arbitrary File Upload
|
4 |
WEB
|
Mdn_Newbie
|
2015-08-24
|
|
Pligg CMS 2.0.2 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
Arash Khazaei
|
2012-10-17
|
|
jCore - '/admin/index.php?path' Cross-Site Scripting
|
5 |
WEB
|
High-Tech Bridge
|
2012-10-17
|
|
WordPress Plugin Slideshow - Multiple Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
waraxe
|
2012-10-15
|
|
WordPress Plugin Crayon Syntax Highlighter - 'wp_load' Remote File Inclusion
|
4 |
WEB
|
Charlie Eriksen
|
2012-10-15
|
|
SilverStripe CMS 2.4.x - 'BackURL' Open Redirection
|
4 |
WEB
|
Aung Khant
|
2012-06-16
|
|
vBSEO - 'u' Cross-Site Scripting
|
3 |
WEB
|
MegaMan
|
2012-10-20
|
|
WebTitan - 'logs-x.php' Directory Traversal
|
4 |
WEB
|
Richard Conner
|
2012-01-06
|
|
SenseSites CommonSense CMS - 'article.php?id' SQL Injection
|
4 |
WEB
|
H4ckCity Security Team
|
2012-01-06
|
|
SenseSites CommonSense CMS - 'special.php?id' SQL Injection
|
3 |
WEB
|
H4ckCity Security Team
|
2012-01-06
|
|
SenseSites CommonSense CMS - 'id' SQL Injection
|
3 |
WEB
|
H4ckCity Security Team
|
2012-08-11
|
|
FileContral - Local File Inclusion / Local File Disclosure
|
3 |
WEB
|
Ashiyane Digital Security Team
|
2012-10-10
|
|
OpenX 2.8.10 - 'plugin-index.php' Cross-Site Scripting
|
4 |
WEB
|
High-Tech Bridge
|
2012-10-06
|
|
Open Realty - 'select_users_lang' Local File Inclusion
|
4 |
WEB
|
L0n3ly-H34rT
|
2012-10-08
|
|
Interspire Email Marketer - Cross-Site Scripting / HTML Injection / SQL Injection
|
4 |
WEB
|
Ibrahim El-Sayed
|
2012-10-05
|
|
WordPress Plugin Shopp - Multiple Vulnerabilities
|
5 |
WEB
|
T0x!c
|
2015-08-21
|
|
Netsweeper 4.0.8 - Authentication Bypass (via New Profile Creation)
|
3 |
WEB
|
Anastasios Monachos
|
2015-08-21
|
|
Netsweeper 4.0.8 - Arbitrary File Upload / Execution
|
4 |
WEB
|
Anastasios Monachos
|
2015-08-21
|
|
Netsweeper 3.0.6 - Authentication Bypass
|
3 |
WEB
|
Anastasios Monachos
|
2015-08-21
|
|
Netsweeper 4.0.9 - Arbitrary File Upload / Execution
|
4 |
WEB
|
Anastasios Monachos
|
2015-08-21
|
|
Netsweeper 4.0.8 - Authentication Bypass (via Disabling of IP Quarantine)
|
4 |
WEB
|
Anastasios Monachos
|
2015-08-21
|
|
Netsweeper 4.0.8 - SQL Injection / Authentication Bypass
|
5 |
WEB
|
Anastasios Monachos
|
2015-08-21
|
|
Netsweeper 4.0.4 - SQL Injection
|
3 |
WEB
|
Anastasios Monachos
|
2015-08-21
|
|
Netsweeper 2.6.29.8 - SQL Injection
|
3 |
WEB
|
Anastasios Monachos
|
2015-08-21
|
|
WordPress Plugin MDC Private Message 1.0.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Chris Kellum
|
2015-08-21
|
|
WordPress Plugin Googmonify 0.8.1 - Cross-Site Scripting / Cross-Site Request Forgery
|
4 |
WEB
|
Ehsan Hosseini
|
2012-10-01
|
|
Omnistar Mailer - Multiple SQL Injections / HTML Injection Vulnerabilities
|
4 |
WEB
|
Vulnerability Laboratory
|
2012-10-02
|
|
ZenPhoto - 'admin-news-articles.php' Cross-Site Scripting
|
4 |
WEB
|
Scott Herbert
|
2012-10-01
|
|
WordPress Plugin Akismet - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Tapco Security
|
2012-09-30
|
|
AlamFifa CMS - 'user_name_cookie' SQL Injection
|
5 |
WEB
|
L0n3ly-H34rT
|
2012-10-02
|
|
Switchvox - Multiple HTML Injection Vulnerabilities
|
5 |
WEB
|
Ibrahim El-Sayed
|
2012-09-26
|
|
WordPress Plugin ABC Test - 'id' Cross-Site Scripting
|
4 |
WEB
|
Scott Herbert
|
2015-08-20
|
|
Pligg CMS 2.0.2 - Arbitrary Code Execution
|
4 |
WEB
|
Arash Khazaei
|
2015-08-20
|
|
Vifi Radio 1.0 - Cross-Site Request Forgery
|
4 |
WEB
|
KnocKout
|
2015-08-20
|
|
Aruba Mobility Controller 6.4.2.8 - Multiple Vulnerabilities
|
4 |
WEB
|
Itzik Chen
|
2015-08-19
|
|
up.time 7.5.0 - Upload and Execute
|
4 |
WEB
|
LiquidWorm
|
2015-08-19
|
|
up.time 7.5.0 - Arbitrary File Disclose and Delete
|
4 |
WEB
|
LiquidWorm
|
2015-08-19
|
|
up.time 7.5.0 - Cross-Site Scripting / Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
LiquidWorm
|
2015-08-19
|
|
up.time 7.5.0 - Superadmin Privilege Escalation
|
4 |
WEB
|
LiquidWorm
|
2011-12-30
|
|
Neturf eCommerce Shopping Cart - 'searchFor' Cross-Site Scripting
|
5 |
WEB
|
farbodmahini
|
2012-09-22
|
|
WordPress Plugin Sexy Add Template - Cross-Site Request Forgery
|
4 |
WEB
|
the_cyber_nuxbie
|
2012-09-25
|
|
WordPress Plugin Token Manager - 'tid' Cross-Site Scripting
|
4 |
WEB
|
TheCyberNuxbie
|
2012-09-22
|
|
WordPress Core 3.4.2 - Cross-Site Request Forgery
|
5 |
WEB
|
AkaStep
|
2012-09-21
|
|
YCommerce - Multiple SQL Injections
|
6 |
WEB
|
Ricardo Almeida
|
2012-09-24
|
|
ZEN Load Balancer - Multiple Vulnerabilities
|
4 |
WEB
|
Brendan Coles
|
2012-09-20
|
|
WordPress Plugin MF Gig Calendar - Cross-Site Scripting
|
4 |
WEB
|
Chris Cooper
|
2012-09-20
|
|
Poweradmin - 'index.php' Cross-Site Scripting
|
4 |
WEB
|
Siavash
|
2012-09-07
|
|
WordPress Theme Purity - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Matan Azugi
|
2012-09-18
|
|
WordPress Core 3.4.2 - Multiple Path Disclosure Vulnerabilities
|
3 |
WEB
|
AkaStep
|
2015-08-18
|
|
WordPress Plugin WP Symposium 15.1 - 'get_album_item.php' SQL Injection
|
4 |
WEB
|
PizzaHatHacker
|
2015-08-18
|
|
WordPress Plugin WP Symposium 15.1 - Blind SQL Injection
|
3 |
WEB
|
dxw
|
2015-08-18
|
|
BigTree CMS 4.2.3 - (Authenticated) SQL Injection
|
4 |
WEB
|
Curesec Research Team
|
2015-08-18
|
|
CodoForum 3.3.1 - Multiple SQL Injections
|
4 |
WEB
|
Curesec Research Team
|
2015-08-18
|
|
PHPfileNavigator 2.3.3 - Privilege Escalation
|
4 |
WEB
|
hyp3rlinx
|
2015-08-18
|
|
PHPfileNavigator 2.3.3 - Cross-Site Request Forgery
|
5 |
WEB
|
hyp3rlinx
|
2015-08-18
|
|
PHPfileNavigator 2.3.3 - Cross-Site Scripting
|
4 |
WEB
|
hyp3rlinx
|
2015-08-18
|
|
Cisco Unified Communications Manager - Multiple Vulnerabilities
|
5 |
WEB
|
Bernhard Mueller
|
2015-08-18
|
|
vBulletin < 4.2.2 - Memcache Remote Code Execution
|
4 |
WEB
|
Joshua Rogers
|
2015-08-18
|
|
Magento CE < 1.9.0.1 - (Authenticated) Remote Code Execution
|
5 |
WEB
|
Ebrietas0
|
2015-08-17
|
|
Nuts CMS - PHP Remote Code Injection / Execution
|
5 |
WEB
|
Yakir Wizman
|
2012-09-18
|
|
vBulletin 4.1.12 - 'blog_plugin_useradmin.php' SQL Injection
|
5 |
WEB
|
Am!r
|
2012-09-18
|
|
AxisInternet VoIP Manager - Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
Benjamin Kunz Mejri
|
2012-09-18
|
|
TAGWORX.CMS - 'cid' SQL Injection
|
4 |
WEB
|
Crim3R
|
2012-09-17
|
|
minimal Gallery - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
5 |
WEB
|
ayastar
|
2012-09-15
|
|
IFOBS - 'regclientprint.jsp' Multiple HTML Injection Vulnerabilities
|
5 |
WEB
|
MustLive
|
2015-08-17
|
|
Sagemcom F@ST 3864 V2 - Get Admin Password
|
6 |
WEB
|
Cade Bull
|
2012-09-12
|
|
Atlassian Confluence 3.4.x - Error Page Cross-Site Scripting
|
5 |
WEB
|
D. Niedermaier
|
2012-09-11
|
|
FBDj - 'id' SQL Injection
|
5 |
WEB
|
TUNISIAN CYBER
|
2012-09-06
|
|
OpenFiler 2.3 - Multiple Cross-Site Scripting / Information Disclosure Vulnerabilities
|
4 |
WEB
|
Brendan Coles
|
2012-08-30
|
|
WordPress Plugin Download Monitor - 'dlsearch' Cross-Site Scripting
|
4 |
WEB
|
Chris Cooper
|
2012-09-10
|
|
DELTAScripts PHP Links - Multiple SQL Injections
|
4 |
WEB
|
L0n3ly-H34rT
|
2012-09-10
|
|
VICIDIAL Call Center Suite - Multiple SQL Injections
|
4 |
WEB
|
Ertebat Gostar Co
|
2012-09-08
|
|
Pinterestclones - Security Bypass / HTML Injection
|
4 |
WEB
|
DaOne
|
2012-09-06
|
|
web@all - Local File Inclusion / Multiple Arbitrary File Upload Vulnerabilities
|
4 |
WEB
|
KedAns-Dz
|
2012-09-05
|
|
Extcalendar 2.0 - Multiple SQL Injections / HTML Injection Vulnerabilities
|
4 |
WEB
|
Ashiyane Digital Security Team
|
2012-09-05
|
|
Flogr - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
4 |
WEB
|
High-Tech Bridge
|
2015-08-15
|
|
Security IP Camera Star Vision DVR - Authentication Bypass
|
4 |
WEB
|
Meisam Monsef
|
2015-08-15
|
|
Joomla! Component com_informations - SQL Injection
|
4 |
WEB
|
Omar
|
2015-08-15
|
|
Joomla! Component com_memorix - SQL Injection
|
3 |
WEB
|
Omar
|
2015-08-15
|
|
TOTOLINK Routers - Backdoor / Remote Code Execution
|
3 |
WEB
|
MadMouse
|
2015-08-15
|
|
Gkplugins Picasaweb - Download File
|
3 |
WEB
|
TMT zno
|