2022-05-11
|
|
e107 CMS v3.2.1 - Multiple Vulnerabilities
|
5 |
WEB
|
Hubert Wojciechowski
|
2022-05-11
|
|
Cyclos 4.14.7 - 'groupId' DOM Based Cross-Site Scripting (XSS)
|
4 |
WEB
|
Tin Pham
|
2022-05-11
|
|
Cyclos 4.14.7 - DOM Based Cross-Site Scripting (XSS)
|
4 |
WEB
|
Tin Pham
|
2022-05-11
|
|
CSZ CMS 1.3.0 - 'Multiple' Blind SQLi
|
4 |
WEB
|
Dogukan Dincer
|
2022-05-11
|
|
Bitrix24 - Remote Code Execution (RCE) (Authenticated)
|
7 |
WEB
|
heinjame
|
2022-05-11
|
|
Magento eCommerce CE v2.3.5-p2 - Blind SQLi
|
3 |
WEB
|
Aydin Naserifard
|
2022-05-11
|
|
WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
|
4 |
WEB
|
Roel van Beurden
|
2022-05-11
|
|
WebTareas 2.4 - Blind SQLi (Authenticated)
|
2 |
WEB
|
Behrad Taher
|
2022-05-11
|
|
Microfinance Management System 1.0 - 'customer_number' SQLi
|
4 |
WEB
|
Eren Gozaydin
|
2022-05-11
|
|
ImpressCMS v1.4.4 - Unrestricted File Upload
|
4 |
WEB
|
Ünsal Furkan Harani
|
2022-04-26
|
|
GitLab 14.9 - Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Greenwolf
|
2022-04-26
|
|
Gitlab 14.9 - Authentication Bypass
|
4 |
WEB
|
Greenwolf
|
2022-04-19
|
|
Fuel CMS 1.5.0 - Cross-Site Request Forgery (CSRF)
|
4 |
WEB
|
Ali J
|
2022-04-19
|
|
WordPress Plugin Elementor 3.6.2 - Remote Code Execution (RCE) (Authenticated)
|
6 |
WEB
|
AkuCyberSec
|
2022-04-19
|
|
PKP Open Journals System 3.3 - Cross-Site Scripting (XSS)
|
4 |
WEB
|
Hemant Kashyap
|
2022-04-19
|
|
REDCap 11.3.9 - Stored Cross Site Scripting
|
4 |
WEB
|
Kendrick Lam
|
2022-04-19
|
|
WordPress Plugin Popup Maker 1.16.5 - Stored Cross-Site Scripting (Authenticated)
|
5 |
WEB
|
Roel van Beurden
|
2022-04-19
|
|
WordPress Plugin Videos sync PDF 1.7.4 - Stored Cross Site Scripting (XSS)
|
3 |
WEB
|
UnD3sc0n0c1d0
|
2022-04-19
|
|
Scriptcase 9.7 - Remote Code Execution (RCE)
|
3 |
WEB
|
luckyt0mat0
|
2022-04-19
|
|
Easy Appointments 1.4.2 - Information Disclosure
|
5 |
WEB
|
Alexandre ZANNI
|
2022-04-19
|
|
WordPress Plugin Motopress Hotel Booking Lite 4.2.4 - SQL Injection
|
4 |
WEB
|
Mohsen Dehghani
|
2022-04-11
|
|
Razer Sila - Command Injection
|
3 |
WEB
|
Kevin Randall
|
2022-04-11
|
|
Razer Sila - Local File Inclusion (LFI)
|
4 |
WEB
|
Kevin Randall
|
2022-04-11
|
|
Telesquare TLR-2855KS6 - Arbitrary File Deletion
|
5 |
WEB
|
Momen Eldawakhly
|
2022-04-11
|
|
Telesquare TLR-2855KS6 - Arbitrary File Creation
|
6 |
WEB
|
Momen Eldawakhly
|
2022-04-11
|
|
SAM SUNNY TRIPOWER 5.0 - Insecure Direct Object Reference (IDOR)
|
4 |
WEB
|
Momen Eldawakhly
|
2022-04-07
|
|
ICEHRM 31.0.0.0S - Cross-site Request Forgery (CSRF) to Account Deletion
|
5 |
WEB
|
Devansh Bordia
|
2022-04-07
|
|
qdPM 9.2 - Cross-site Request Forgery (CSRF)
|
4 |
WEB
|
Chetanya Sharma
|
2022-04-07
|
|
minewebcms 1.15.2 - Cross-site Scripting (XSS)
|
3 |
WEB
|
Chetanya Sharma
|
2022-04-07
|
|
KLiK Social Media Website 1.0 - 'Multiple' SQLi
|
5 |
WEB
|
corpse
|
2022-04-07
|
|
Zenario CMS 9.0.54156 - Remote Code Execution (RCE) (Authenticated)
|
6 |
WEB
|
minhnq22
|
2022-03-30
|
|
WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSS
|
5 |
WEB
|
0xB9
|
2022-03-30
|
|
CSZ CMS 1.2.9 - 'Multiple' Blind SQLi(Authenticated)
|
3 |
WEB
|
Rahad Chowdhury
|
2022-03-30
|
|
WordPress Plugin admin-word-count-column 2.2 - Local File Read
|
4 |
WEB
|
Hassan Khan Yusufzai
|
2022-03-30
|
|
WordPress Plugin video-synchro-pdf 1.7.4 - Local File Inclusion
|
3 |
WEB
|
Hassan Khan Yusufzai
|
2022-03-30
|
|
WordPress Plugin cab-fare-calculator 1.0.3 - Local File Inclusion
|
3 |
WEB
|
Hassan Khan Yusufzai
|
2022-03-30
|
|
WordPress Plugin Curtain 1.0.2 - Cross-site Request Forgery (CSRF)
|
4 |
WEB
|
Hassan Khan Yusufzai
|
2022-03-30
|
|
Drupal avatar_uploader v7.x-1.0-beta8 - Cross Site Scripting (XSS)
|
3 |
WEB
|
Milad karimi
|
2022-03-30
|
|
Atom CMS 2.0 - Remote Code Execution (RCE)
|
5 |
WEB
|
Ashish Koli
|
2022-03-30
|
|
ImpressCMS 1.4.2 - Remote Code Execution (RCE)
|
4 |
WEB
|
Egidio Romano
|
2022-03-23
|
|
WordPress Plugin amministrazione-aperta 3.7.3 - Local File Read - Unauthenticated
|
3 |
WEB
|
Hassan Khan Yusufzai
|
2022-03-22
|
|
ICEHRM 31.0.0.0S - Cross-site Request Forgery (CSRF) to Account Takeover
|
5 |
WEB
|
Devansh Bordia
|
2022-03-21
|
|
Wordpress Plugin iQ Block Country 1.2.13 - Arbitrary File Deletion via Zip Slip (Authenticated)
|
4 |
WEB
|
Ceylan BOZOĞULLARINDAN
|
2022-03-16
|
|
Tiny File Manager 2.4.6 - Remote Code Execution (RCE)
|
8 |
WEB
|
FEBIN MON SAJI
|
2022-03-16
|
|
Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated)
|
6 |
WEB
|
Ashish Koli
|
2022-03-16
|
|
Moodle 3.11.5 - SQLi (Authenticated)
|
5 |
WEB
|
Chris Anastasio
|
2022-03-14
|
|
Baixar GLPI Project 9.4.6 - SQLi
|
4 |
WEB
|
Prof. Joas Antonio
|
2022-03-10
|
|
Zabbix 5.0.17 - Remote Code Execution (RCE) (Authenticated)
|
5 |
WEB
|
Hussien Misbah
|
2022-03-09
|
|
Webmin 1.984 - Remote Code Execution (Authenticated)
|
5 |
WEB
|
faisalfs10x
|
2022-03-07
|
|
Hasura GraphQL 2.2.0 - Information Disclosure
|
7 |
WEB
|
Dolev Farhi
|
2022-03-07
|
|
Attendance and Payroll System v1.0 - SQLi Authentication Bypass
|
7 |
WEB
|
pr0z
|
2022-03-07
|
|
Attendance and Payroll System v1.0 - Remote Code Execution (RCE)
|
9 |
WEB
|
pr0z
|
2022-03-07
|
|
part-db 0.5.11 - Remote Code Execution (RCE)
|
7 |
WEB
|
Chetanya Sharma
|
2022-03-07
|
|
Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE)
|
5 |
WEB
|
Carlos E. Vieira
|
2022-03-02
|
|
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
|
6 |
WEB
|
Momen Eldawakhly
|
2022-03-02
|
|
Xerte 3.9 - Remote Code Execution (RCE) (Authenticated)
|
6 |
WEB
|
Rik Lutz
|
2022-03-02
|
|
Xerte 3.10.3 - Directory Traversal (Authenticated)
|
6 |
WEB
|
Rik Lutz
|
2022-02-28
|
|
Casdoor 1.13.0 - SQL Injection (Unauthenticated)
|
5 |
WEB
|
Mayank Deshmukh
|
2022-02-28
|
|
Cipi Control Panel 3.1.15 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
5 |
WEB
|
Ghuliev
|
2022-02-23
|
|
Microweber CMS 1.2.10 - Local File Inclusion (Authenticated) (Metasploit)
|
5 |
WEB
|
Talha Karakumru
|
2022-02-23
|
|
WebHMI 4.1 - Stored Cross Site Scripting (XSS) (Authenticated)
|
4 |
WEB
|
Antonio Cuomo
|
2022-02-23
|
|
WebHMI 4.1.1 - Remote Code Execution (RCE) (Authenticated)
|
7 |
WEB
|
Antonio Cuomo
|
2022-02-23
|
|
Student Record System 1.0 - 'cid' SQLi (Authenticated)
|
5 |
WEB
|
Mohd. Anees
|
2022-02-23
|
|
aaPanel 6.8.21 - Directory Traversal (Authenticated)
|
7 |
WEB
|
Ghuliev
|
2022-02-23
|
|
Air Cargo Management System v1.0 - SQLi
|
5 |
WEB
|
nu11secur1ty
|
2022-02-23
|
|
Simple Real Estate Portal System 1.0 - 'id' SQLi
|
7 |
WEB
|
Mosaaed
|
2022-02-21
|
|
Dbltek GoIP - Local File Inclusion
|
6 |
WEB
|
Valtteri Lehtinen
|
2022-02-21
|
|
FileCloud 21.2 - Cross-Site Request Forgery (CSRF)
|
5 |
WEB
|
Masashi Fujiwara
|
2022-02-21
|
|
WordPress Plugin WP User Frontend 3.5.25 - SQLi (Authenticated)
|
5 |
WEB
|
Ron Jost
|
2022-02-21
|
|
Thinfinity VirtualUI 2.5.26.2 - Information Disclosure
|
5 |
WEB
|
Daniel Morales
|
2022-02-21
|
|
Thinfinity VirtualUI 2.5.41.0 - IFRAME Injection
|
7 |
WEB
|
Daniel Morales
|
2022-02-21
|
|
Cab Management System 1.0 - Remote Code Execution (RCE) (Authenticated)
|
7 |
WEB
|
Alperen Ergel
|
2022-02-21
|
|
Microweber 1.2.11 - Remote Code Execution (RCE) (Authenticated)
|
7 |
WEB
|
Chetanya Sharma
|
2022-02-21
|
|
Cab Management System 1.0 - 'id' SQLi (Authenticated)
|
6 |
WEB
|
Alperen Ergel
|
2022-02-21
|
|
WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
|
7 |
WEB
|
Ron Jost
|
2022-02-18
|
|
Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
|
5 |
WEB
|
Braiant Giraldo Villa
|
2022-02-18
|
|
Hotel Druid 3.0.3 - Remote Code Execution (RCE)
|
8 |
WEB
|
0z09e
|
2022-02-18
|
|
WordPress Plugin dzs-zoomsounds 6.60 - Remote Code Execution (RCE) (Unauthenticated)
|
7 |
WEB
|
Overthinker1877
|
2022-02-18
|
|
WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation
|
5 |
WEB
|
numan türle
|
2022-02-16
|
|
WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)
|
5 |
WEB
|
Ceylan BOZOĞULLARINDAN
|
2022-02-16
|
|
Network Video Recorder NVR304-16EP - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
|
4 |
WEB
|
Luis Martínez
|
2022-02-16
|
|
ServiceNow - Username Enumeration
|
5 |
WEB
|
Victor Hanna
|
2022-02-16
|
|
Simple Student Quarterly Result/Grade System 1.0 - SQLi Authentication Bypass
|
6 |
WEB
|
Saud Alenazi
|
2022-02-16
|
|
Multi-Vendor Online Groceries Management System 1.0 - 'id' Blind SQL Injection
|
5 |
WEB
|
Saud Alenazi
|
2022-02-11
|
|
Kyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated)
|
5 |
WEB
|
Luis Martínez
|
2022-02-11
|
|
Subrion CMS 4.2.1 - Cross Site Request Forgery (CSRF) (Add Amin)
|
4 |
WEB
|
Aryan Chehreghani
|
2022-02-11
|
|
Accounting Journal Management System 1.0 - 'id' SQLi (Authenticated)
|
5 |
WEB
|
Alperen Ergel
|
2022-02-10
|
|
WordPress Plugin Jetpack 9.1 - Cross Site Scripting (XSS)
|
5 |
WEB
|
Milad karimi
|
2022-02-10
|
|
WordPress Plugin Contact Form Builder 1.6.1 - Cross-Site Scripting (XSS)
|
5 |
WEB
|
Milad karimi
|
2022-02-10
|
|
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthent
|
5 |
WEB
|
Ron Jost
|
2022-02-10
|
|
Home Owners Collection Management System 1.0 - 'id' Blind SQL Injection
|
4 |
WEB
|
Saud Alenazi
|
2022-02-10
|
|
Home Owners Collection Management System 1.0 - Remote Code Execution (RCE) (Authenticated)
|
6 |
WEB
|
Saud Alenazi
|
2022-02-10
|
|
Home Owners Collection Management System 1.0 - Account Takeover (Unauthenticated)
|
10 |
WEB
|
Saud Alenazi
|
2022-02-10
|
|
Hospital Management Startup 1.0 - 'Multiple' SQLi
|
3 |
WEB
|
nu11secur1ty
|
2022-02-09
|
|
AtomCMS v2.0 - SQLi
|
4 |
WEB
|
Luca Cuzzolin
|
2022-02-09
|
|
Exam Reviewer Management System 1.0 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
Juli Agarwal
|
2022-02-09
|
|
Exam Reviewer Management System 1.0 - ‘id’ SQL Injection
|
6 |
WEB
|
Juli Agarwal
|
2022-02-08
|
|
WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS)
|
5 |
WEB
|
Shweta Mahajan
|
2022-02-08
|
|
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
|
4 |
WEB
|
Shweta Mahajan
|
2022-02-08
|
|
Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion
|
5 |
WEB
|
Ven3xy
|
2022-02-08
|
|
WordPress Plugin International Sms For Contact Form 7 Integration V1.2 - Cross Site Scripting (XSS)
|
6 |
WEB
|
Milad karimi
|
2022-02-08
|
|
Hospital Management System 4.0 - 'multiple' SQL Injection
|
4 |
WEB
|
nu11secur1ty
|
2022-02-08
|
|
FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)
|
5 |
WEB
|
FEBIN MON SAJI
|
2022-02-08
|
|
Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit)
|
6 |
WEB
|
WackyH4cker
|
2022-02-08
|
|
Hotel Reservation System 1.0 - SQLi (Unauthenticated)
|
6 |
WEB
|
Nefrit ID
|
2022-02-04
|
|
Servisnet Tessa - Add sysAdmin User (Unauthenticated) (Metasploit)
|
5 |
WEB
|
AkkuS
|
2022-02-04
|
|
Servisnet Tessa - MQTT Credentials Dump (Unauthenticated) (Metasploit)
|
4 |
WEB
|
AkkuS
|
2022-02-04
|
|
Servisnet Tessa - Privilege Escalation (Metasploit)
|
3 |
WEB
|
AkkuS
|
2022-02-04
|
|
WordPress Plugin IP2Location Country Blocker 2.26.7 - Stored Cross Site Scripting (XSS) (Authenticat
|
7 |
WEB
|
Ahmet Serkan Ari
|
2022-02-04
|
|
WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)
|
4 |
WEB
|
Antonio Cuomo
|
2022-02-02
|
|
WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming
|
6 |
WEB
|
Ceylan BOZOĞULLARINDAN
|
2022-02-02
|
|
WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS)
|
4 |
WEB
|
0xB9
|
2022-02-02
|
|
WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
|
5 |
WEB
|
0xB9
|
2022-02-02
|
|
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
|
5 |
WEB
|
0xB9
|
2022-02-02
|
|
PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated)
|
4 |
WEB
|
souzo
|
2022-02-02
|
|
Huawei DG8045 Router 1.0 - Credential Disclosure
|
5 |
WEB
|
Abdalrahman Gamal
|
2022-02-02
|
|
Moodle 3.11.4 - SQL Injection
|
5 |
WEB
|
lavclash75
|
2022-02-02
|
|
PHP Restaurants 1.0 - SQLi (Unauthenticated)
|
4 |
WEB
|
Nefrit ID
|
2022-02-02
|
|
Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated)
|
4 |
WEB
|
Ron Jost
|
2022-02-02
|
|
WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
|
5 |
WEB
|
Ceylan BOZOĞULLARINDAN
|
2022-02-02
|
|
Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
|
4 |
WEB
|
Ron Jost
|
2022-02-02
|
|
Chamilo LMS 1.11.14 - Account Takeover
|
6 |
WEB
|
sirpedrotavares
|
2022-02-02
|
|
uBidAuction v2.0.1 - 'Multiple' Cross Site Scripting (XSS)
|
5 |
WEB
|
Vulnerability-Lab
|
2022-02-02
|
|
Ametys CMS v4.4.1 - Cross Site Scripting (XSS)
|
2 |
WEB
|
Vulnerability-Lab
|
2022-01-27
|
|
WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated)
|
5 |
WEB
|
Ron Jost
|