2025-04-14
|
|
OpenPanel 0.3.4 - Directory Traversal
|
6 |
WEB
|
Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
|
2025-04-14
|
|
Pimcore 11.4.2 - Stored cross site scripting
|
9 |
WEB
|
maeitsec
|
2025-04-14
|
|
Pimcore customer-data-framework 4.2.0 - SQL injection
|
9 |
WEB
|
maeitsec
|
2025-04-14
|
|
Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection
|
8 |
WEB
|
hyp3rlinx
|
2025-04-14
|
|
ZTE ZXHN H168N 3.1 - Remote Code Execution (RCE) via authentication bypass
|
15 |
WEB
|
tasos meletlidis
|
2025-04-11
|
|
GeoVision GV-ASManager 6.1.0.0 - Broken Access Control
|
9 |
WEB
|
Giorgi Dograshvili
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated)
|
6 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
GeoVision GV-ASManager 6.1.1.0 - CSRF
|
6 |
WEB
|
Giorgi Dograshvili
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE)
|
9 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
WebFileSys 2.31.0 - Directory Path Traversal
|
10 |
WEB
|
Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - WebSocket Command Spawning
|
8 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
Netman 204 - Remote command without authentication
|
8 |
WEB
|
Parsa Rezaie Khiabanloo
|
2025-04-11
|
|
ABB Cylon Aspect 3.08.02 - PHP Session Fixation
|
9 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
CMU CERT/CC VINCE 2.0.6 - Stored XSS
|
8 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - Cross-Site Request Forgery
|
8 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - Default Credentials
|
6 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure
|
7 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
Nagios Log Server 2024R1.3.1 - API Key Exposure
|
7 |
WEB
|
Seth Kraft
|
2025-04-11
|
|
phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
|
8 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
MiniCMS 1.1 - Cross Site Scripting (XSS)
|
8 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
NEWS-BUZZ News Management System 1.0 - SQL Injection
|
8 |
WEB
|
egsec
|
2025-04-11
|
|
Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
|
7 |
WEB
|
AmirZargham
|
2025-04-11
|
|
CyberPanel 2.3.6 - Remote Code Execution (RCE)
|
10 |
WEB
|
Luka Petrovic (refr4g)
|
2025-04-11
|
|
LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection
|
8 |
WEB
|
Francisco Moraga (BTshell)
|
2025-04-11
|
|
MagnusSolution magnusbilling 7.3.0 - Command Injection
|
10 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
RosarioSIS 7.6 - SQL Injection
|
7 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
|
9 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
Gnuboard5 5.3.2.8 - SQL Injection
|
8 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
flatCore 1.5 - Cross Site Request Forgery (CSRF)
|
7 |
WEB
|
CodeSecLab
|
2025-04-10
|
|
flatCore 1.5.5 - Arbitrary File Upload
|
6 |
WEB
|
CodeSecLab
|
2025-04-10
|
|
AquilaCMS 1.409.20 - Remote Command Execution (RCE)
|
10 |
WEB
|
Eui Chul Chung
|
2025-04-10
|
|
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
|
7 |
WEB
|
cyberaz0r
|
2025-04-10
|
|
Typecho 1.3.0 - Race Condition
|
8 |
WEB
|
cyberaz0r
|
2025-04-10
|
|
Cosy+ firmware 21.2s7 - Command Injection
|
9 |
WEB
|
CodeB0ss
|
2025-04-10
|
|
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
|
7 |
WEB
|
Raj Nandi
|
2025-04-10
|
|
PandoraFMS 7.0NG.772 - SQL Injection
|
6 |
WEB
|
Osama Yousef
|
2025-04-10
|
|
Centron 19.04 - Remote Code Execution (RCE)
|
11 |
WEB
|
Starry Sky
|
2025-04-10
|
|
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
|
7 |
WEB
|
Mohammed Adel
|
2025-04-10
|
|
Feng Office 3.11.1.2 - SQL Injection
|
9 |
WEB
|
Andrey Stoykov
|
2025-04-09
|
|
PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
|
7 |
WEB
|
Vuln Seeker Cybersecurity Team
|
2025-04-09
|
|
ChurchCRM 5.9.1 - SQL Injection
|
10 |
WEB
|
Sanan Qasimzada
|
2025-04-09
|
|
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
|
10 |
WEB
|
Andrew Lemon/Red Threat
|
2025-04-09
|
|
ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
|
8 |
WEB
|
Jeremia Geraldi Sihombing
|
2025-04-09
|
|
Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
|
10 |
WEB
|
Yesith Alvarez
|
2025-04-09
|
|
Zohocorp ManageEngine ADManager Plus 7210 - Elevation of Privilege
|
9 |
WEB
|
Metin Yunus Kandemir
|
2025-04-09
|
|
Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS)
|
7 |
WEB
|
Ahmet Ümit BAYRAM
|
2025-04-09
|
|
Artica Proxy 4.50 - Remote Code Execution (RCE)
|
14 |
WEB
|
Madan
|
2025-04-09
|
|
DocsGPT 0.12.0 - Remote Code Execution
|
7 |
WEB
|
Shreyas Malhotra
|
2025-04-08
|
|
GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
|
8 |
WEB
|
Giorgi Dograshvili
|
2025-04-08
|
|
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
|
7 |
WEB
|
xOryus
|
2025-04-08
|
|
Jasmin Ransomware - Arbitrary File Download (Authenticated)
|
7 |
WEB
|
bRpsd
|
2025-04-08
|
|
UNA CMS 14.0.0-RC - PHP Object Injection
|
8 |
WEB
|
Egidio Romano
|
2025-04-08
|
|
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
|
10 |
WEB
|
Calil Khalil
|
2025-04-08
|
|
WordPress User Registration & Membership Plugin 4.1.1 - Unauthenticated Privilege Escalation
|
6 |
WEB
|
Al Baradi Joy
|
2025-04-07
|
|
XWiki Platform 15.10.10 - Remote Code Execution
|
7 |
WEB
|
Al Baradi Joy
|
2025-04-07
|
|
YesWiki 4.5.1 - Unauthenticated Path Traversal
|
7 |
WEB
|
Al Baradi Joy
|
2025-04-07
|
|
Apache Tomcat 11.0.3 - Remote Code Execution
|
9 |
WEB
|
Al Baradi Joy
|
2025-04-06
|
|
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
|
4 |
WEB
|
Ilteris Kaan Pehlivan
|
2025-04-06
|
|
WBCE CMS 1.6.3 - Authenticated Remote Code Execution (RCE)
|
5 |
WEB
|
Swammers8
|
2025-04-06
|
|
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
|
7 |
WEB
|
Al Baradi Joy
|
2025-04-06
|
|
Watcharr 1.43.0 - Remote Code Execution (RCE)
|
8 |
WEB
|
Suphawith Phusanbai
|
2025-04-06
|
|
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
|
6 |
WEB
|
ByteHunter
|
2025-04-06
|
|
DataEase 2.4.0 - Database Configuration Information Exposure
|
5 |
WEB
|
ByteHunter
|
2025-04-05
|
|
Royal Elementor Addons and Templates 1.3.78 - Unauthenticated Arbitrary File Upload
|
7 |
WEB
|
4m3rr0r
|
2025-04-05
|
|
Exclusive Addons for Elementor 2.6.9 - Stored Cross-Site Scripting (XSS)
|
8 |
WEB
|
Al Baradi Joy
|
2025-04-05
|
|
Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)
|
6 |
WEB
|
4m3rr0r
|
2025-04-05
|
|
Next.js Middleware 15.2.2 - Authorization Bypass
|
9 |
WEB
|
kOaDT
|
2025-04-05
|
|
IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
|
6 |
WEB
|
Giulio Garzia
|
2025-04-03
|
|
AppSmith 1.47 - Remote Code Execution (RCE)
|
5 |
WEB
|
Nishanth Gaddam
|
2025-04-03
|
|
Nagios Log Server 2024R1.3.1 - Stored XSS
|
9 |
WEB
|
Seth Kraft
|
2025-04-03
|
|
ABB Cylon Aspect 3.07.02 - File Disclosure
|
7 |
WEB
|
LiquidWorm
|
2025-04-03
|
|
Webmin Usermin 2.100 - Username Enumeration
|
9 |
WEB
|
Kjesper
|
2025-04-03
|
|
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
|
8 |
WEB
|
LiquidWorm
|
2025-04-02
|
|
ABB Cylon Aspect 3.08.01 - Arbitrary File Delete
|
7 |
WEB
|
LiquidWorm
|
2025-04-02
|
|
ABB Cylon Aspect 3.08.01 - Remote Code Execution (RCE)
|
7 |
WEB
|
LiquidWorm
|
2025-04-02
|
|
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
|
8 |
WEB
|
arfaoui haythem
|
2025-03-29
|
|
XWiki Standard 14.10 - Remote Code Execution (RCE)
|
12 |
WEB
|
Mehran Seifalinia
|
2025-03-28
|
|
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
|
8 |
WEB
|
VeryLazyTech
|
2025-03-28
|
|
Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
|
9 |
WEB
|
VeryLazyTech
|
2025-03-28
|
|
Sonatype Nexus Repository 3.53.0-01 - Path Traversal
|
7 |
WEB
|
VeryLazyTech
|
2025-03-28
|
|
CodeCanyon RISE CRM 3.7.0 - SQL Injection
|
9 |
WEB
|
Jobyer From Bytium
|
2025-03-28
|
|
Litespeed Cache 6.5.0.1 - Authentication Bypass
|
6 |
WEB
|
Caner Tercan
|
2025-03-27
|
|
X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
|
7 |
WEB
|
Okan Kurtulus
|
2025-03-27
|
|
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
|
7 |
WEB
|
Okan Kurtulus
|
2025-03-27
|
|
MoziloCMS 3.0 - Remote Code Execution (RCE)
|
8 |
WEB
|
Olakojo Olaoluwa Joshua
|
2025-03-22
|
|
TeamPass 3.0.0.21 - SQL Injection
|
9 |
WEB
|
Max Meyer - Rivendell
|
2025-03-21
|
|
Jasmin Ransomware - SQL Injection Login Bypass
|
10 |
WEB
|
Buğra Enis Dönmez
|
2025-03-20
|
|
FluxBB 1.5.11 - Stored Cross-Site Scripting (XSS)
|
6 |
WEB
|
Chokri Hammedi
|
2025-03-20
|
|
JUX Real Estate 3.4.0 - SQL Injection
|
6 |
WEB
|
CraCkEr
|
2025-03-19
|
|
Gitea 1.24.0 - HTML Injection
|
8 |
WEB
|
Mikail KOCADAĞ
|
2025-03-19
|
|
TranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
6 |
WEB
|
ABABANK REDTEAM
|
2025-03-19
|
|
Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
|
9 |
WEB
|
Ravina
|
2025-03-19
|
|
Loaded Commerce 6.6 - Client-Side Template Injection(CSTI)
|
7 |
WEB
|
tmrswrr
|
2025-03-18
|
|
Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
|
8 |
WEB
|
Mohamed Kamel BOUZEKRIA
|
2024-11-15
|
|
SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)
|
7 |
WEB
|
cybersploit
|
2024-10-01
|
|
reNgine 2.2.0 - Command Injection (Authenticated)
|
7 |
WEB
|
Caner Tercan
|
2024-10-01
|
|
openSIS 9.1 - SQLi (Authenticated)
|
7 |
WEB
|
Devrim Dıragumandan
|
2024-10-01
|
|
dizqueTV 1.5.3 - Remote Code Execution (RCE)
|
12 |
WEB
|
Ahmed Said Saud Al-Busaidi
|
2024-08-28
|
|
NoteMark < 0.13.0 - Stored XSS
|
7 |
WEB
|
Alessio Romano (sfoffo)
|
2024-08-28
|
|
Gitea 1.22.0 - Stored XSS
|
12 |
WEB
|
Catalin Iovita_ Alexandru Postolache
|
2024-08-28
|
|
Invesalius3 - Remote Code Execution
|
34 |
WEB
|
Alessio Romano (sfoffo)_ Riccardo Degli Esposti (p
|
2024-08-24
|
|
Aurba 501 - Authenticated RCE
|
34 |
WEB
|
Hosein Vita
|
2024-08-24
|
|
HughesNet HT2000W Satellite Modem - Password Reset
|
8 |
WEB
|
Simon Greenblatt
|
2024-08-24
|
|
Elber Wayber Analog/Digital Audio STL 4.00 - Device Config Disclosure
|
7 |
WEB
|
LiquidWorm
|
2024-08-24
|
|
Elber Wayber Analog/Digital Audio STL 4.00 - Authentication Bypass
|
10 |
WEB
|
LiquidWorm
|
2024-08-24
|
|
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Device Config
|
6 |
WEB
|
LiquidWorm
|
2024-08-24
|
|
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Authentication Bypass
|
7 |
WEB
|
LiquidWorm
|
2024-08-23
|
|
Helpdeskz v2.0.2 - Stored XSS
|
6 |
WEB
|
Md. Sadikul Islam
|
2024-08-23
|
|
Calibre-web 0.6.21 - Stored XSS
|
8 |
WEB
|
Catalin Iovita_ Alexandru Postolache
|
2024-08-04
|
|
Devika v1 - Path Traversal via 'snapshot_path'
|
12 |
WEB
|
Alperen Ergel
|
2024-08-04
|
|
Ivanti vADC 9.9 - Authentication Bypass
|
9 |
WEB
|
ohnoisploited
|
2024-07-01
|
|
Xhibiter NFT Marketplace 1.10.2 - SQL Injection
|
10 |
WEB
|
Sohel Yousef
|
2024-07-01
|
|
Azon Dominator Affiliate Marketing Script - SQL Injection
|
7 |
WEB
|
Buğra Enis Dönmez
|
2024-07-01
|
|
Microweber 2.0.15 - Stored XSS
|
7 |
WEB
|
tmrswrr
|
2024-07-01
|
|
Customer Support System 1.0 - Stored XSS
|
6 |
WEB
|
Geraldo Alcantara
|
2024-06-26
|
|
Automad 2.0.0-alpha.4 - Stored Cross-Site Scripting (XSS)
|
7 |
WEB
|
Jerry Thomas
|
2024-06-26
|
|
SolarWinds Platform 2024.1 SR1 - Race Condition
|
6 |
WEB
|
Elhussain Fathy
|
2024-06-26
|
|
Flatboard 3.2 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
7 |
WEB
|
tmrswrr
|
2024-06-26
|
|
Poultry Farm Management System v1.0 - Remote Code Execution (RCE)
|
11 |
WEB
|
Jerry Thomas
|
2024-06-14
|
|
Boelter Blue System Management 1.3 - SQL Injection
|
8 |
WEB
|
CBKB
|
2024-06-14
|
|
WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS) (Authenticated)
|
7 |
WEB
|
Onur Göğebakan
|
2024-06-14
|
|
PHP < 8.3.8 - Remote Code Execution (Unauthenticated) (Windows)
|
8 |
WEB
|
Yesith Alvarez
|
2024-06-14
|
|
AEGON LIFE v1.0 Life Insurance Management System - SQL injection vulnerability.
|
8 |
WEB
|
Aslam Anwar Mahimkar
|
2024-06-14
|
|
XMB 1.9.12.06 - Stored XSS
|
7 |
WEB
|
Chokri Hammedi
|
2024-06-14
|
|
Carbon Forum 5.9.0 - Stored XSS
|
5 |
WEB
|
Chokri Hammedi
|