Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2025-06-05   CloudClassroom PHP Project 1.0 - SQL Injection 6 WEB Sanjay Singh
2025-05-29   Campcodes Online Hospital Management System 1.0 - SQL Injection 4 WEB Carine Constantino
2025-05-29   WordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP Bruteforcing 4 WEB Saleh Tarawneh
2025-05-25   Java-springboot-codebase 1.1 - Arbitrary File Read 4 WEB d3sca
2025-05-25   WordPress User Registration & Membership Plugin 4.1.2 - Authentication Bypass 3 WEB Mohammed Idrees Banyamer
2025-05-13   WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation 4 WEB Md Shoriful Islam
2025-05-13   Kentico Xperience 13.0.178 - Cross Site Scripting (XSS) 3 WEB Alex Messham
2025-05-09   SureTriggers OttoKit Plugin 1.0.82 - Privilege Escalation 4 WEB Abdualhadi khalifa
2025-05-09   WordPress Depicter Plugin 3.6.1 - SQL Injection 4 WEB Andrew Long
2025-05-06   ERPNext 14.82.1 - Account Takeover via Cross-Site Request Forgery (CSRF) 4 WEB Ahmed Thaiban
2025-05-06   Grokability Snipe-IT 8.0.4 - Insecure Direct Object Reference (IDOR) 6 WEB Sn1p3r-H4ck3r
2025-05-06   Casdoor 1.901.0 - Cross-Site Request Forgery (CSRF) 4 WEB Van Lam Nguyen
2025-04-22   WordPress Core 6.2 - Directory Traversal 3 WEB Milad karimi
2025-04-19   FoxCMS 1.2.5 - Remote Code Execution (RCE) 4 WEB VeryLazyTech
2025-04-19   Drupal 11.x-dev - Full Path Disclosure 5 WEB Milad karimi
2025-04-18   KiviCare Clinic & Patient Management System (EHR) 3.6.4 - Unauthenticated SQL Injection 6 WEB samogod
2025-04-18   UJCMS 9.6.3 - User Enumeration via IDOR 4 WEB Cyd Tseng
2025-04-18   Inventio Lite 4 - SQL Injection 5 WEB pointedsec
2025-04-18   Apache Commons Text 1.10.0 - Remote Code Execution 5 WEB Arjun Chaudhary
2025-04-18   Tatsu 3.3.11 - Unauthenticated RCE 4 WEB Milad karimi
2025-04-18   Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation 4 WEB Jun Takemura
2025-04-17   compop.ca 3.5.3 - Arbitrary code Execution 4 WEB dmlino
2025-04-17   Blood Bank & Donor Management System 2.4 - CSRF Improper Input Validation 3 WEB Kwangyun Keum
2025-04-17   Usermin 2.100 - Username Enumeration 3 WEB Kjesper
2025-04-17   Angular-Base64-Upload Library 0.1.21 - Unauthenticated Remote Code Execution (RCE) 3 WEB Ravindu Wickramasinghe
2025-04-17   ABB Cylon Aspect 3.08.02 (ethernetUpdate.php) - Authenticated Path Traversal 3 WEB LiquidWorm
2025-04-17   ABB Cylon Aspect 3.08.02 (deployStart.php) - Unauthenticated Command Execution 2 WEB LiquidWorm
2025-04-16   WooCommerce Customers Manager 29.4 - Post-Authenticated SQL Injection 2 WEB Ivan Spiridonov
2025-04-16   Smart Manager 8.27.0 - Post-Authenticated SQL Injection 4 WEB Ivan Spiridonov
2025-04-16   KodExplorer 4.52 - Open Redirect 3 WEB Rahad Chowdhury
2025-04-16   Car Rental Project 1.0 - Remote Code Execution 2 WEB ub3rsick
2025-04-16   Ethercreative Logs 3.0.3 - Path Traversal 2 WEB ub3rsick
2025-04-16   FLIR AX8 1.46.16 - Remote Command Injection 2 WEB ub3rsick
2025-04-16   Garage Management System 1.0 (categoriesName) - Stored XSS 1 WEB ub3rsick
2025-04-16   ProConf 6.0 - Insecure Direct Object Reference (IDOR) 1 WEB ub3rsick
2025-04-16   phpMyFAQ 3.2.10 - Unintended File Download Triggered by Embedded Frames 2 WEB Geo
2025-04-16   ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) - File Write DoS 2 WEB LiquidWorm
2025-04-16   ABB Cylon Aspect 4.00.00 (factorySaved.php) - Unauthenticated XSS 2 WEB LiquidWorm
2025-04-16   ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) - Remote Code Execution 2 WEB LiquidWorm
2025-04-16   ABB Cylon Aspect 3.08.02 - Cross-Site Request Forgery (CSRF) 1 WEB LiquidWorm
2025-04-16   Zabbix 7.0.0 - SQL Injection 2 WEB m4nb4
2025-04-16   NagVis 1.9.33 - Arbitrary File Read 2 WEB xerosec
2025-04-16   Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS) 1 WEB Ayato Shitomi @ Fore-Z co.ltd
2025-04-16   phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS) 2 WEB CodeSecLab
2025-04-15   Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated) 1 WEB D3Ext
2025-04-15   ABB Cylon Aspect 3.08.02 - Cookie User Password Disclosure 2 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.03 - Hard-coded Secrets 1 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.03 (MapServicesHandler) - Authenticated Reflected XSS 1 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.07.02 (userManagement.php) - Weak Password Policy 1 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.03 (CookieDB) - SQL Injection 1 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (webServerUpdate.php) - Input Validation Config Poisoning 2 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (escDevicesUpdate.php) - Denial of Service (DOS) 2 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution 1 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution 2 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (licenseUpload.php) - Stored Cross-Site Scripting 0 WEB LiquidWorm
2025-04-15   ABB Cylon Aspect 3.08.02 (licenseServerUpdate.php) - Stored Cross-Site Scripting 0 WEB LiquidWorm
2025-04-15   IBMi Navigator 7.5 - Server Side Request Forgery (SSRF) 0 WEB hyp3rlinx
2025-04-15   Plane 0.23.1 - Server side request forgery (SSRF) 0 WEB Saud Alenazi
2025-04-15   IBMi Navigator 7.5 - HTTP Security Token Bypass 0 WEB hyp3rlinx
2025-04-15   OpenCMS 17.0 - Stored Cross Site Scripting (XSS) 0 WEB Siddhartha Naik
2025-04-15   Adapt Authoring Tool 0.11.3 - Remote Command Execution (RCE) 0 WEB Eui Chul Chung
2025-04-15   Really Simple Security 9.1.1.1 - Authentication Bypass 0 WEB Antonio Francesco Sardella
2025-04-15   Spring Boot common-user-management 0.1 - Remote Code Execution (RCE) 0 WEB d3sca
2025-04-14   SilverStripe 5.3.8 - Stored Cross Site Scripting (XSS) (Authenticated) 1 WEB James Nicoll
2025-04-14   OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Traversal 1 WEB Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
2025-04-14   OpenPanel 0.3.4 - OS Command Injection 1 WEB Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
2025-04-14   OpenPanel 0.3.4 - Incorrect Access Control 1 WEB Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
2025-04-14   OpenPanel 0.3.4 - Directory Traversal 1 WEB Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
2025-04-14   Pimcore 11.4.2 - Stored cross site scripting 0 WEB maeitsec
2025-04-14   Pimcore customer-data-framework 4.2.0 - SQL injection 1 WEB maeitsec
2025-04-14   Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection 1 WEB hyp3rlinx
2025-04-14   ZTE ZXHN H168N 3.1 - Remote Code Execution (RCE) via authentication bypass 1 WEB tasos meletlidis
2025-04-11   GeoVision GV-ASManager 6.1.0.0 - Broken Access Control 1 WEB Giorgi Dograshvili
2025-04-11   ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated) 1 WEB LiquidWorm
2025-04-11   GeoVision GV-ASManager 6.1.1.0 - CSRF 0 WEB Giorgi Dograshvili
2025-04-11   ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE) 1 WEB LiquidWorm
2025-04-11   WebFileSys 2.31.0 - Directory Path Traversal 1 WEB Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
2025-04-11   ABB Cylon FLXeon 9.3.4 - WebSocket Command Spawning 1 WEB LiquidWorm
2025-04-11   Netman 204 - Remote command without authentication 1 WEB Parsa Rezaie Khiabanloo
2025-04-11   ABB Cylon Aspect 3.08.02 - PHP Session Fixation 1 WEB LiquidWorm
2025-04-11   CMU CERT/CC VINCE 2.0.6 - Stored XSS 1 WEB LiquidWorm
2025-04-11   ABB Cylon FLXeon 9.3.4 - Cross-Site Request Forgery 1 WEB LiquidWorm
2025-04-11   ABB Cylon FLXeon 9.3.4 - Default Credentials 1 WEB LiquidWorm
2025-04-11   ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure 1 WEB LiquidWorm
2025-04-11   Nagios Log Server 2024R1.3.1 - API Key Exposure 0 WEB Seth Kraft
2025-04-11   phpIPAM 1.6 - Reflected Cross Site Scripting (XSS) 0 WEB CodeSecLab
2025-04-11   MiniCMS 1.1 - Cross Site Scripting (XSS) 0 WEB CodeSecLab
2025-04-11   NEWS-BUZZ News Management System 1.0 - SQL Injection 0 WEB egsec
2025-04-11   Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS) 0 WEB AmirZargham
2025-04-11   CyberPanel 2.3.6 - Remote Code Execution (RCE) 0 WEB Luka Petrovic (refr4g)
2025-04-11   LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection 0 WEB Francisco Moraga (BTshell)
2025-04-11   MagnusSolution magnusbilling 7.3.0 - Command Injection 0 WEB CodeSecLab
2025-04-11   RosarioSIS 7.6 - SQL Injection 0 WEB CodeSecLab
2025-04-11   GetSimpleCMS 3.3.16 - Remote Code Execution (RCE) 0 WEB CodeSecLab
2025-04-11   Gnuboard5 5.3.2.8 - SQL Injection 0 WEB CodeSecLab
2025-04-11   flatCore 1.5 - Cross Site Request Forgery (CSRF) 0 WEB CodeSecLab
2025-04-10   flatCore 1.5.5 - Arbitrary File Upload 0 WEB CodeSecLab
2025-04-10   AquilaCMS 1.409.20 - Remote Command Execution (RCE) 0 WEB Eui Chul Chung
2025-04-10   Typecho 1.3.0 - Stored Cross-Site Scripting (XSS) 0 WEB cyberaz0r
2025-04-10   Typecho 1.3.0 - Race Condition 0 WEB cyberaz0r
2025-04-10   Cosy+ firmware 21.2s7 - Command Injection 0 WEB CodeB0ss
2025-04-10   CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS) 0 WEB Raj Nandi
2025-04-10   PandoraFMS 7.0NG.772 - SQL Injection 0 WEB Osama Yousef
2025-04-10   Centron 19.04 - Remote Code Execution (RCE) 0 WEB Starry Sky
2025-04-10   Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover 0 WEB Mohammed Adel
2025-04-10   Feng Office 3.11.1.2 - SQL Injection 0 WEB Andrey Stoykov
2025-04-09   PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF) 0 WEB Vuln Seeker Cybersecurity Team
2025-04-09   ChurchCRM 5.9.1 - SQL Injection 0 WEB Sanan Qasimzada
2025-04-09   Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE) 0 WEB Andrew Lemon/Red Threat
2025-04-09   ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS) 0 WEB Jeremia Geraldi Sihombing
2025-04-09   Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE) 0 WEB Yesith Alvarez
2025-04-09   Zohocorp ManageEngine ADManager Plus 7210 - Elevation of Privilege 0 WEB Metin Yunus Kandemir
2025-04-09   Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS) 0 WEB Ahmet Ümit BAYRAM
2025-04-09   Artica Proxy 4.50 - Remote Code Execution (RCE) 0 WEB Madan
2025-04-09   DocsGPT 0.12.0 - Remote Code Execution 0 WEB Shreyas Malhotra
2025-04-08   GeoVision GV-ASManager 6.1.0.0 - Information Disclosure 0 WEB Giorgi Dograshvili
2025-04-08   jQuery 3.3.1 - Prototype Pollution & XSS Exploit 0 WEB xOryus
2025-04-08   Jasmin Ransomware - Arbitrary File Download (Authenticated) 0 WEB bRpsd
2025-04-08   UNA CMS 14.0.0-RC - PHP Object Injection 0 WEB Egidio Romano
2025-04-08   Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE) 0 WEB Calil Khalil
2025-04-08   WordPress User Registration & Membership Plugin 4.1.1 - Unauthenticated Privilege Escalation 0 WEB Al Baradi Joy
2025-04-07   XWiki Platform 15.10.10 - Remote Code Execution 0 WEB Al Baradi Joy
2025-04-07   YesWiki 4.5.1 - Unauthenticated Path Traversal 0 WEB Al Baradi Joy
2025-04-07   Apache Tomcat 11.0.3 - Remote Code Execution 0 WEB Al Baradi Joy
2025-04-06   Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS) 0 WEB Ilteris Kaan Pehlivan