Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2025-08-03   Copyparty 1.18.6 - Reflected Cross-Site Scripting (XSS) 32 WEB Byte Reaper
2025-08-03   Gandia Integra Total 4.4.2236.1 - SQL Injection 28 WEB Byte Reaper
2025-07-28   Adobe ColdFusion 2023.6 - Remote File Read 43 WEB İbrahimsql
2025-07-28   Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS) 71 WEB Kevin Dicks
2025-07-28   XWiki 14 - SQL Injection via getdeleteddocuments.vm 31 WEB Byte Reaper
2025-07-28   Invision Community 4.7.20 - (calendar/view.php) SQL Injection 53 WEB Egidio Romano
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field 66 WEB Manojkumar J
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function 31 WEB Manojkumar J
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages 26 WEB Manojkumar J
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field 27 WEB Manojkumar J
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surname 25 WEB Manojkumar J
2025-07-22   LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username 30 WEB Manojkumar J
2025-07-22   Discourse 3.1.1 - Unauthenticated Chat Message Access 34 WEB İbrahimsql
2025-07-22   Joomla JS Jobs plugin 1.4.2 - SQL injection 31 WEB Adam Wallwork
2025-07-22   Simple File List WordPress Plugin 4.2.2 - File Upload to RCE 44 WEB Md Amanat Ullah (xSwads)
2025-07-22   Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE 30 WEB Md Amanat Ullah (xSwads)
2025-07-16   WP Publications WordPress Plugin 1.2 - Stored XSS 67 WEB Zeynalxan Quliyev
2025-07-16   White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI) 74 WEB Imraan Khan (Lich-Sec)
2025-07-16   SugarCRM 14.0.0 - SSRF/Code Injection 61 WEB Egidio Romano
2025-07-16   Langflow 1.2.x - Remote Code Execution (RCE) 61 WEB Raghad Abdallah Al-syouf
2025-07-16   TOTOLINK N300RB 8.54 - Command Execution 73 WEB Skander BELABED - Magellan Sécurité
2025-07-16   PivotX 3.0.0 RC3 - Remote Code Execution (RCE) 119 WEB HayToN
2025-07-08   Discourse 3.2.x - Anonymous Cache Poisoning 74 WEB İbrahimsql
2025-07-08   Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover 77 WEB stealthcopter
2025-07-02   Moodle 4.4.0 - Authenticated Remote Code Execution 79 WEB Likhith Appalaneni
2025-06-26   Social Warfare WordPress Plugin 3.5.2 - Remote Code Execution (RCE) 107 WEB Huseyin Mardinli
2025-06-26   Sitecore 10.4 - Remote Code Execution (RCE) 63 WEB Yesith Alvarez
2025-06-26   Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE) 60 WEB Zen-kun04
2025-06-15   Skyvern 0.1.85 - Remote Code Execution (RCE) via SSTI 68 WEB Cristian Branet
2025-06-15   PHP CGI Module 8.3.4 - Remote Code Execution (RCE) 81 WEB İbrahimsql
2025-06-15   Litespeed Cache WordPress Plugin 6.3.0.1 - Privilege Escalation 50 WEB Milad karimi
2025-06-15   Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS) 47 WEB /bin/neko
2025-06-13   Roundcube 1.6.10 - Remote Code Execution (RCE) 83 WEB Maksim Rogov
2025-06-09   Laravel Pulse 1.3.1 - Arbitrary Code Injection 86 WEB Mohammed Idrees Banyamer
2025-06-05   CloudClassroom PHP Project 1.0 - SQL Injection 41 WEB Sanjay Singh
2025-05-29   Campcodes Online Hospital Management System 1.0 - SQL Injection 79 WEB Carine Constantino
2025-05-29   WordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP Bruteforcing 52 WEB Saleh Tarawneh
2025-05-25   Java-springboot-codebase 1.1 - Arbitrary File Read 56 WEB d3sca
2025-05-25   WordPress User Registration & Membership Plugin 4.1.2 - Authentication Bypass 44 WEB Mohammed Idrees Banyamer
2025-05-13   WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation 71 WEB Md Shoriful Islam
2025-05-13   Kentico Xperience 13.0.178 - Cross Site Scripting (XSS) 37 WEB Alex Messham
2025-05-09   SureTriggers OttoKit Plugin 1.0.82 - Privilege Escalation 41 WEB Abdualhadi khalifa
2025-05-09   WordPress Depicter Plugin 3.6.1 - SQL Injection 59 WEB Andrew Long
2025-05-06   ERPNext 14.82.1 - Account Takeover via Cross-Site Request Forgery (CSRF) 66 WEB Ahmed Thaiban
2025-05-06   Grokability Snipe-IT 8.0.4 - Insecure Direct Object Reference (IDOR) 68 WEB Sn1p3r-H4ck3r
2025-05-06   Casdoor 1.901.0 - Cross-Site Request Forgery (CSRF) 62 WEB Van Lam Nguyen
2025-04-22   WordPress Core 6.2 - Directory Traversal 37 WEB Milad karimi
2025-04-19   FoxCMS 1.2.5 - Remote Code Execution (RCE) 54 WEB VeryLazyTech
2025-04-19   Drupal 11.x-dev - Full Path Disclosure 35 WEB Milad karimi
2025-04-18   KiviCare Clinic & Patient Management System (EHR) 3.6.4 - Unauthenticated SQL Injection 37 WEB samogod
2025-04-18   UJCMS 9.6.3 - User Enumeration via IDOR 42 WEB Cyd Tseng
2025-04-18   Inventio Lite 4 - SQL Injection 36 WEB pointedsec
2025-04-18   Apache Commons Text 1.10.0 - Remote Code Execution 37 WEB Arjun Chaudhary
2025-04-18   Tatsu 3.3.11 - Unauthenticated RCE 36 WEB Milad karimi
2025-04-18   Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation 40 WEB Jun Takemura
2025-04-17   compop.ca 3.5.3 - Arbitrary code Execution 33 WEB dmlino
2025-04-17   Blood Bank & Donor Management System 2.4 - CSRF Improper Input Validation 38 WEB Kwangyun Keum
2025-04-17   Usermin 2.100 - Username Enumeration 38 WEB Kjesper
2025-04-17   Angular-Base64-Upload Library 0.1.21 - Unauthenticated Remote Code Execution (RCE) 35 WEB Ravindu Wickramasinghe
2025-04-17   ABB Cylon Aspect 3.08.02 (ethernetUpdate.php) - Authenticated Path Traversal 39 WEB LiquidWorm
2025-04-17   ABB Cylon Aspect 3.08.02 (deployStart.php) - Unauthenticated Command Execution 36 WEB LiquidWorm
2025-04-16   WooCommerce Customers Manager 29.4 - Post-Authenticated SQL Injection 40 WEB Ivan Spiridonov
2025-04-16   Smart Manager 8.27.0 - Post-Authenticated SQL Injection 33 WEB Ivan Spiridonov
2025-04-16   KodExplorer 4.52 - Open Redirect 38 WEB Rahad Chowdhury
2025-04-16   Car Rental Project 1.0 - Remote Code Execution 40 WEB ub3rsick
2025-04-16   Ethercreative Logs 3.0.3 - Path Traversal 33 WEB ub3rsick
2025-04-16   FLIR AX8 1.46.16 - Remote Command Injection 37 WEB ub3rsick
2025-04-16   Garage Management System 1.0 (categoriesName) - Stored XSS 32 WEB ub3rsick
2025-04-16   ProConf 6.0 - Insecure Direct Object Reference (IDOR) 44 WEB ub3rsick
2025-04-16   phpMyFAQ 3.2.10 - Unintended File Download Triggered by Embedded Frames 32 WEB Geo
2025-04-16   ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) - File Write DoS 30 WEB LiquidWorm
2025-04-16   ABB Cylon Aspect 4.00.00 (factorySaved.php) - Unauthenticated XSS 30 WEB LiquidWorm
2025-04-16   ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) - Remote Code Execution 29 WEB LiquidWorm
2025-04-16   ABB Cylon Aspect 3.08.02 - Cross-Site Request Forgery (CSRF) 26 WEB LiquidWorm
2025-04-16   Zabbix 7.0.0 - SQL Injection 36 WEB m4nb4
2025-04-16   NagVis 1.9.33 - Arbitrary File Read 30 WEB xerosec
2025-04-16   Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS) 22 WEB Ayato Shitomi @ Fore-Z co.ltd
2025-04-16   phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS) 30 WEB CodeSecLab
2025-04-15   Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated) 34 WEB D3Ext
2025-04-15   ABB Cylon Aspect 3.08.02 - Cookie User Password Disclosure 25 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.03 - Hard-coded Secrets 27 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.03 (MapServicesHandler) - Authenticated Reflected XSS 27 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.07.02 (userManagement.php) - Weak Password Policy 29 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.03 (CookieDB) - SQL Injection 28 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (webServerUpdate.php) - Input Validation Config Poisoning 32 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (escDevicesUpdate.php) - Denial of Service (DOS) 29 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution 25 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution 26 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (licenseUpload.php) - Stored Cross-Site Scripting 25 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (licenseServerUpdate.php) - Stored Cross-Site Scripting 27 WEB LiquidWorm
2025-04-15   IBMi Navigator 7.5 - Server Side Request Forgery (SSRF) 29 WEB hyp3rlinx
2025-04-15   Plane 0.23.1 - Server side request forgery (SSRF) 35 WEB Saud Alenazi
2025-04-15   IBMi Navigator 7.5 - HTTP Security Token Bypass 32 WEB hyp3rlinx
2025-04-15   OpenCMS 17.0 - Stored Cross Site Scripting (XSS) 32 WEB Siddhartha Naik
2025-04-15   Adapt Authoring Tool 0.11.3 - Remote Command Execution (RCE) 33 WEB Eui Chul Chung
2025-04-15   Really Simple Security 9.1.1.1 - Authentication Bypass 32 WEB Antonio Francesco Sardella
2025-04-15   Spring Boot common-user-management 0.1 - Remote Code Execution (RCE) 46 WEB d3sca
2025-04-14   SilverStripe 5.3.8 - Stored Cross Site Scripting (XSS) (Authenticated) 27 WEB James Nicoll
2025-04-14   OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Traversal 27 WEB Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
2025-04-14   OpenPanel 0.3.4 - OS Command Injection 33 WEB Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
2025-04-14   OpenPanel 0.3.4 - Incorrect Access Control 25 WEB Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
2025-04-14   OpenPanel 0.3.4 - Directory Traversal 27 WEB Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
2025-04-14   Pimcore 11.4.2 - Stored cross site scripting 33 WEB maeitsec
2025-04-14   Pimcore customer-data-framework 4.2.0 - SQL injection 32 WEB maeitsec
2025-04-14   Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection 28 WEB hyp3rlinx
2025-04-14   ZTE ZXHN H168N 3.1 - Remote Code Execution (RCE) via authentication bypass 36 WEB tasos meletlidis
2025-04-11   GeoVision GV-ASManager 6.1.0.0 - Broken Access Control 28 WEB Giorgi Dograshvili
2025-04-11   ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated) 27 WEB LiquidWorm
2025-04-11   GeoVision GV-ASManager 6.1.1.0 - CSRF 23 WEB Giorgi Dograshvili
2025-04-11   ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE) 34 WEB LiquidWorm
2025-04-11   WebFileSys 2.31.0 - Directory Path Traversal 29 WEB Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
2025-04-11   ABB Cylon FLXeon 9.3.4 - WebSocket Command Spawning 26 WEB LiquidWorm
2025-04-11   Netman 204 - Remote command without authentication 34 WEB Parsa Rezaie Khiabanloo
2025-04-11   ABB Cylon Aspect 3.08.02 - PHP Session Fixation 33 WEB LiquidWorm
2025-04-11   CMU CERT/CC VINCE 2.0.6 - Stored XSS 38 WEB LiquidWorm
2025-04-11   ABB Cylon FLXeon 9.3.4 - Cross-Site Request Forgery 30 WEB LiquidWorm
2025-04-11   ABB Cylon FLXeon 9.3.4 - Default Credentials 38 WEB LiquidWorm
2025-04-11   ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure 26 WEB LiquidWorm
2025-04-11   Nagios Log Server 2024R1.3.1 - API Key Exposure 26 WEB Seth Kraft
2025-04-11   phpIPAM 1.6 - Reflected Cross Site Scripting (XSS) 26 WEB CodeSecLab
2025-04-11   MiniCMS 1.1 - Cross Site Scripting (XSS) 40 WEB CodeSecLab
2025-04-11   NEWS-BUZZ News Management System 1.0 - SQL Injection 27 WEB egsec
2025-04-11   Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS) 27 WEB AmirZargham
2025-04-11   CyberPanel 2.3.6 - Remote Code Execution (RCE) 33 WEB Luka Petrovic (refr4g)
2025-04-11   LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection 29 WEB Francisco Moraga (BTshell)