| 
					2023-03-29	
				 | 
				
										 
				 | 
								
									  Human Resource Management System 1.0 - SQL Injection (unauthenticated)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Matthijs van der Vaart (eMVee)										
				 | 
			
            	
			
				| 
					2023-03-29	
				 | 
				
										 
				 | 
								
									  Book Store Management System 1.0.0 - Stored Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Rajeshwar Singh										
				 | 
			
            	
			
				| 
					2023-03-29	
				 | 
				
										 
				 | 
								
									  WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												AkuCyberSec										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  rukovoditel 3.2.1 - Cross-Site Scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  Senayan Library Management System v9.5.0 - SQL Injection
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  iBooking v1.0.8 - Arbitrary File Upload
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												d1z1n370/oPty										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  ReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Okan Kurtulus										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  Social-Share-Buttons v2.2.3 - SQL Injection
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  Moodle LMS 4.0 - Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Saud Alenazi										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  OPSWAT Metadefender Core - Privilege Escalation
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Ulascan Yildirim										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  ZKTeco ZEM/ZMM 8.88 - Missing Authentication
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												RedTeam Pentesting GmbH										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  Subrion CMS 4.2.1 - Stored Cross-Site Scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Sinem Şahin										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  Label Studio 1.5.0 - Authenticated Server Side Request Forgery (SSRF)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Ryan Smith										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												zetc0de										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  Jetpack 11.4 - Cross Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Behrouz Mansoori										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  Online shopping system advanced 1.0 - Multiple Vulnerabilities
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Rafael Pedrero										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  YouPHPTube<= 7.8 - Multiple Vulnerabilities
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Rafael Pedrero										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  Pega Platform 8.1.0 - Remote Code Execution (RCE)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Marcin Wolak										
				 | 
			
            	
			
				| 
					2023-03-28	
				 | 
				
										 
				 | 
								
									  Beauty-salon v1.0 - Remote Code Execution (RCE)
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Felipe Alcantara										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  WebTareas 2.4 - RCE (Authorized)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  WebTareas 2.4 - Reflected XSS (Unauthorised)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  WebTareas 2.4 - SQL Injection (Unauthorised)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Atom CMS v2.0 - SQL Injection (no auth)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Aero CMS v0.0.1 - PHP Code Injection (auth)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Aero CMS v0.0.1 - SQL Injection (no auth)
								 | 
								
					13			 | 
				
                     WEB
			   | 
								
												Hubert Wojciechowski										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Desktop Central 9.1.0 - Multiple Vulnerabilities
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Rafael Pedrero										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  WPN-XM Serverstack for Windows 0.8.6 - Multiple Vulnerabilities
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Rafael Pedrero										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) & Remote Command Execution (RCE)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Rafael Pedrero										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Grafana <=6.2.4 - HTML Injection
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												SimranJeet Singh										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Trenches of IT										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Clansphere CMS 2011.4 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Sinem Şahin										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Zentao Project Management System 17.0 - Authenticated Remote Code Execution (RCE)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												mister0xf										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  FlatCore CMS 2.1.1 - Stored Cross-Site Scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Sinem Şahin										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												ErPaciocco										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Canteen-Management v1.0 - SQL Injection
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-03-27	
				 | 
				
										 
				 | 
								
									  Canteen-Management v1.0 - XSS-Reflected
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  PHPGurukul Online Birth Certificate System V 1.2 - Blind XSS
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Prasheek Kamble										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Sarang Tumne										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Sarang Tumne										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  Abantecart v1.3.2 - Authenticated Remote Code Execution
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Sarang Tumne										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Sarang Tumne										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  ImpressCMS v1.4.3 - Authenticated SQL Injection
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Sarang Tumne										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  Password Manager for IIS v2.0 - XSS
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												VP4TR10T										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Ali Alipour										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  GuppY CMS v6.00.10 - Remote Code Execution
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												Chokri Hammedi										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  Lavalite v9.0.0 - XSRF-TOKEN cookie File path traversal
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  Employee Performance Evaluation System v1.0 - File Inclusion and RCE
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  Yoga Class Registration System v1.0 - Multiple SQLi
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Abdulhakim Öner										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  Human Resources Management System v1.0 - Multiple SQLi
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Abdulhakim Öner										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  Online Diagnostic Lab Management System v1.0 - Remote Code Execution (RCE) (Unauthenticated)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												yousef alraddadi										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
								 | 
								
					4			 | 
				
                     WEB
			   | 
								
												Elias Hohl										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Elias Hohl										
				 | 
			
            	
			
				| 
					2023-03-25	
				 | 
				
										 
				 | 
								
									  _camp_ Raspberry Pi camera server 1.0 -  Authentication Bypass
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Elias Hohl										
				 | 
			
            	
			
				| 
					2023-03-23	
				 | 
				
										 
				 | 
								
									  Bitbucket v7.0.0 -  RCE
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												khal4n1										
				 | 
			
            	
			
				| 
					2023-03-23	
				 | 
				
										 
				 | 
								
									  wkhtmltopdf 0.12.6 -  Server Side Request Forgery
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												Momen Eldawakhly										
				 | 
			
            	
			
				| 
					2023-03-23	
				 | 
				
										 
				 | 
								
									  WorkOrder CMS 0.1.0 - SQL Injection
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Chokri Hammedi										
				 | 
			
            	
			
				| 
					2023-03-23	
				 | 
				
										 
				 | 
								
									  MAN-EAM-0003 V3.2.4 - XXE
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Ahmed Alroky										
				 | 
			
            	
			
				| 
					2023-03-23	
				 | 
				
										 
				 | 
								
									  Owlfiles File Manager 12.0.1 - Multiple Vulnerabilities
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Chokri Hammedi										
				 | 
			
            	
			
				| 
					2023-03-22	
				 | 
				
										 
				 | 
								
									  Linksys AX3200 V1.1.00 - Command Injection
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Ahmed Alroky										
				 | 
			
            	
			
				| 
					2023-03-22	
				 | 
				
										 
				 | 
								
									  VIAVIWEB Wallpaper Admin 1.0 - Multiple Vulnerabilities
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Edd13Mora										
				 | 
			
            	
			
				| 
					2023-02-20	
				 | 
				
										 
				 | 
								
									  pfBlockerNG 2.1.4_26 - Remote Code Execution (RCE)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												IHTeam										
				 | 
			
            	
			
				| 
					2022-11-11	
				 | 
				
										 
				 | 
								
									  CVAT 2.0 - Server Side Request Forgery
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Emir Polat										
				 | 
			
            	
			
				| 
					2022-11-11	
				 | 
				
										 
				 | 
								
									  Open Web Analytics 1.7.3 - Remote Code Execution
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Jacob Ebben										
				 | 
			
            	
			
				| 
					2022-10-17	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin ImageMagick-Engine 1.7.4 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												ABDO10										
				 | 
			
            	
			
				| 
					2022-10-06	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLi
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Rizacan Tufan										
				 | 
			
            	
			
				| 
					2022-09-23	
				 | 
				
										 
				 | 
								
									  Testa 3.5.1 Online Test Management System - Reflected Cross-Site Scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Ashkan Moghaddas										
				 | 
			
            	
			
				| 
					2022-09-23	
				 | 
				
										 
				 | 
								
									  Aero CMS v0.0.1 - SQLi
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2022-09-23	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin 3dady real-time web stats 1.0 - Stored Cross Site Scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												UnD3sc0n0c1d0										
				 | 
			
            	
			
				| 
					2022-09-23	
				 | 
				
										 
				 | 
								
									  Wordpress Plugin WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												UnD3sc0n0c1d0										
				 | 
			
            	
			
				| 
					2022-09-23	
				 | 
				
										 
				 | 
								
									  Feehi CMS 2.1.1 - Remote Code Execution (Authenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												yuyudhn										
				 | 
			
            	
			
				| 
					2022-09-23	
				 | 
				
										 
				 | 
								
									  TP-Link Tapo c200 1.1.15 - Remote Code Execution (RCE)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												hacefresko										
				 | 
			
            	
			
				| 
					2022-09-20	
				 | 
				
										 
				 | 
								
									  Bookwyrm v0.4.3 - Authentication Bypass
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Akshay Ravi										
				 | 
			
            	
			
				| 
					2022-09-20	
				 | 
				
										 
				 | 
								
									  Buffalo TeraStation Network Attached Storage (NAS) 1.66 - Authentication Bypass
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Jordan Glover										
				 | 
			
            	
			
				| 
					2022-09-15	
				 | 
				
										 
				 | 
								
									  Gitea 1.16.6 - Remote Code Execution (RCE) (Metasploit)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												samguy										
				 | 
			
            	
			
				| 
					2022-09-02	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Netroics Blog Posts Grid 1.0 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Luqman Hakim Zahari										
				 | 
			
            	
			
				| 
					2022-09-02	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Testimonial Slider and Showcase 2.2.6 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Luqman Hakim Zahari										
				 | 
			
            	
			
				| 
					2022-09-02	
				 | 
				
										 
				 | 
								
									  Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Aryan Chehreghani										
				 | 
			
            	
			
				| 
					2022-08-09	
				 | 
				
										 
				 | 
								
									  ThingsBoard 3.3.1 'description' - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Steffen Langenfeld										
				 | 
			
            	
			
				| 
					2022-08-09	
				 | 
				
										 
				 | 
								
									  ThingsBoard 3.3.1 'name' - Stored Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Steffen Langenfeld										
				 | 
			
            	
			
				| 
					2022-08-09	
				 | 
				
										 
				 | 
								
									  Feehi CMS 2.1.1 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Shivam Singh										
				 | 
			
            	
			
				| 
					2022-08-09	
				 | 
				
										 
				 | 
								
									  Prestashop blockwishlist module 2.1.0 - SQLi
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Karthik UJ										
				 | 
			
            	
			
				| 
					2022-08-01	
				 | 
				
										 
				 | 
								
									  Webmin 1.996 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Emir Polat										
				 | 
			
            	
			
				| 
					2022-08-01	
				 | 
				
										 
				 | 
								
									  NanoCMS v0.4 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												p1ckzi										
				 | 
			
            	
			
				| 
					2022-08-01	
				 | 
				
										 
				 | 
								
									  mPDF 7.0 - Local File Inclusion
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Musyoka Ian										
				 | 
			
            	
			
				| 
					2022-08-01	
				 | 
				
										 
				 | 
								
									  CuteEditor for PHP 6.6 - Directory Traversal
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Stefan Hesselman										
				 | 
			
            	
			
				| 
					2022-08-01	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Duplicator 1.4.7 - Information Disclosure
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												SecuriTrust										
				 | 
			
            	
			
				| 
					2022-08-01	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Duplicator 1.4.6 - Unauthenticated Backup Download
								 | 
								
					4			 | 
				
                     WEB
			   | 
								
												SecuriTrust										
				 | 
			
            	
			
				| 
					2022-08-01	
				 | 
				
										 
				 | 
								
									  Wavlink WN530HG4 - Password Disclosure
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Ahmed Alroky										
				 | 
			
            	
			
				| 
					2022-08-01	
				 | 
				
										 
				 | 
								
									  Wavlink WN533A8 - Password Disclosure
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Ahmed Alroky										
				 | 
			
            	
			
				| 
					2022-08-01	
				 | 
				
										 
				 | 
								
									  Wavlink WN533A8 - Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Ahmed Alroky										
				 | 
			
            	
			
				| 
					2022-07-29	
				 | 
				
										 
				 | 
								
									  WordPress Plugin WP-UserOnline 2.87.6 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Steffin Stanly										
				 | 
			
            	
			
				| 
					2022-07-29	
				 | 
				
										 
				 | 
								
									  Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Directory Traversal
								 | 
								
					4			 | 
				
                     WEB
			   | 
								
												LiquidWorm										
				 | 
			
            	
			
				| 
					2022-07-29	
				 | 
				
										 
				 | 
								
									  Dingtian-DT-R002 3.1.276A - Authentication Bypass
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Victor Hanna										
				 | 
			
            	
			
				| 
					2022-07-29	
				 | 
				
										 
				 | 
								
									  Geonetwork 4.2.0 - XML External Entity (XXE)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Amel BOUZIANE-LEBLOND										
				 | 
			
            	
			
				| 
					2022-07-26	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Visual Slide Box Builder 3.2.9 - SQLi
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2022-07-21	
				 | 
				
										 
				 | 
								
									  OctoBot WebInterface 0.4.3 - Remote Code Execution (RCE)
								 | 
								
					4			 | 
				
                     WEB
			   | 
								
												Samy Younsi										
				 | 
			
            	
			
				| 
					2022-07-21	
				 | 
				
										 
				 | 
								
									  CodoForum v5.1 - Remote Code Execution (RCE)
								 | 
								
					4			 | 
				
                     WEB
			   | 
								
												Krish Pandey										
				 | 
			
            	
			
				| 
					2022-07-21	
				 | 
				
										 
				 | 
								
									  Magnolia CMS 6.2.19 - Stored Cross-Site Scripting (XSS)
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Giulio Garzia Ozozuz										
				 | 
			
            	
			
				| 
					2022-06-27	
				 | 
				
										 
				 | 
								
									  Mailhog 1.0.1 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Vulnz										
				 | 
			
            	
			
				| 
					2022-06-27	
				 | 
				
										 
				 | 
								
									  WSO2 Management Console (Multiple Products) - Unauthenticated Reflected Cross-Site Scripting (XSS)
								 | 
								
					4			 | 
				
                     WEB
			   | 
								
												cxosmo										
				 | 
			
            	
			
				| 
					2022-06-27	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Weblizar 8.9 - Backdoor
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Sobhan Mahmoodi										
				 | 
			
            	
			
				| 
					2022-06-14	
				 | 
				
										 
				 | 
								
									  SolarView Compact 6.00 - 'pow' Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Ahmed Alroky										
				 | 
			
            	
			
				| 
					2022-06-14	
				 | 
				
										 
				 | 
								
									  SolarView Compact 6.00 - 'time_begin' Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Ahmed Alroky										
				 | 
			
            	
			
				| 
					2022-06-14	
				 | 
				
										 
				 | 
								
									  Old Age Home Management System 1.0 - SQLi Authentication Bypass
								 | 
								
					9			 | 
				
                     WEB
			   | 
								
												twseptian										
				 | 
			
            	
			
				| 
					2022-06-14	
				 | 
				
										 
				 | 
								
									  ChurchCRM 4.4.5 - SQLi
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												nu11secur1ty										
				 | 
			
            	
			
				| 
					2022-06-14	
				 | 
				
										 
				 | 
								
									  phpIPAM 1.4.5 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Guilherme Alves										
				 | 
			
            	
			
				| 
					2022-06-14	
				 | 
				
										 
				 | 
								
									  Pandora FMS v7.0NG.742 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												UNICORD										
				 | 
			
            	
			
				| 
					2022-06-14	
				 | 
				
										 
				 | 
								
									  Avantune Genialcloud ProJ 10 - Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Andrea Intilangelo										
				 | 
			
            	
			
				| 
					2022-06-10	
				 | 
				
										 
				 | 
								
									  Confluence Data Center 7.18.0 - Remote Code Execution (RCE)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Fellipe Oliveira										
				 | 
			
            	
			
				| 
					2022-06-10	
				 | 
				
										 
				 | 
								
									  WordPress Plugin Motopress Hotel Booking Lite 4.2.4 - Stored Cross-Site Scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Sanjay Singh										
				 | 
			
            	
			
				| 
					2022-06-03	
				 | 
				
										 
				 | 
								
									  Microweber CMS 1.2.15 - Account Takeover
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Manojkumar J										
				 | 
			
            	
			
				| 
					2022-06-03	
				 | 
				
										 
				 | 
								
									  Contao 4.13.2 - Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Chetanya Sharma										
				 | 
			
            	
			
				| 
					2022-05-25	
				 | 
				
										 
				 | 
								
									  qdPM 9.1 - Remote Code Execution (RCE) (Authenticated) (v2)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												RedHatAugust										
				 | 
			
            	
			
				| 
					2022-05-23	
				 | 
				
										 
				 | 
								
									  m1k1o's Blog v.10 - Remote Code Execution (RCE) (Authenticated)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Malte V										
				 | 
			
            	
			
				| 
					2022-05-23	
				 | 
				
										 
				 | 
								
									  OpenCart v3.x Newsletter Module - Blind SQLi
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Saud Alenazi										
				 | 
			
            	
			
				| 
					2022-05-17	
				 | 
				
										 
				 | 
								
									  Showdoc 2.10.3 - Stored Cross-Site Scripting (XSS)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Akshay Ravi										
				 | 
			
            	
			
				| 
					2022-05-17	
				 | 
				
										 
				 | 
								
									  T-Soft E-Commerce 4 - SQLi (Authenticated)
								 | 
								
					10			 | 
				
                     WEB
			   | 
								
												Alperen Ergel										
				 | 
			
            	
			
				| 
					2022-05-17	
				 | 
				
										 
				 | 
								
									  T-Soft E-Commerce 4 - 'UrunAdi' Stored Cross-Site Scripting (XSS)
								 | 
								
					8			 | 
				
                     WEB
			   | 
								
												Alperen Ergel										
				 | 
			
            	
			
				| 
					2022-05-17	
				 | 
				
										 
				 | 
								
									  Survey Sparrow Enterprise Survey Software 2022 - Stored Cross-Site Scripting (XSS)
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Pankaj Kumar Thakur										
				 | 
			
            	
			
				| 
					2022-05-12	
				 | 
				
										 
				 | 
								
									  TLR-2005KSH - Arbitrary File Delete
								 | 
								
					6			 | 
				
                     WEB
			   | 
								
												Ahmed Alroky										
				 | 
			
            	
			
				| 
					2022-05-12	
				 | 
				
										 
				 | 
								
									  Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Eren Gozaydin										
				 | 
			
            	
			
				| 
					2022-05-12	
				 | 
				
										 
				 | 
								
									  College Management System 1.0 - 'course_code' SQL Injection (Authenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Eren Gozaydin										
				 | 
			
            	
			
				| 
					2022-05-11	
				 | 
				
										 
				 | 
								
									  TLR-2005KSH - Arbitrary File Upload
								 | 
								
					5			 | 
				
                     WEB
			   | 
								
												Ahmed Alroky										
				 | 
			
            	
			
				| 
					2022-05-11	
				 | 
				
										 
				 | 
								
									  WordPress Plugin stafflist 3.1.2 - SQLi (Authenticated)
								 | 
								
					7			 | 
				
                     WEB
			   | 
								
												Hassan Khan Yusufzai										
				 |