2025-06-05
|
|
CloudClassroom PHP Project 1.0 - SQL Injection
|
6 |
WEB
|
Sanjay Singh
|
2025-05-29
|
|
Campcodes Online Hospital Management System 1.0 - SQL Injection
|
4 |
WEB
|
Carine Constantino
|
2025-05-29
|
|
WordPress Digits Plugin 8.4.6.1 - Authentication Bypass via OTP Bruteforcing
|
4 |
WEB
|
Saleh Tarawneh
|
2025-05-25
|
|
Java-springboot-codebase 1.1 - Arbitrary File Read
|
4 |
WEB
|
d3sca
|
2025-05-25
|
|
WordPress User Registration & Membership Plugin 4.1.2 - Authentication Bypass
|
3 |
WEB
|
Mohammed Idrees Banyamer
|
2025-05-13
|
|
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
|
4 |
WEB
|
Md Shoriful Islam
|
2025-05-13
|
|
Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)
|
3 |
WEB
|
Alex Messham
|
2025-05-09
|
|
SureTriggers OttoKit Plugin 1.0.82 - Privilege Escalation
|
4 |
WEB
|
Abdualhadi khalifa
|
2025-05-09
|
|
WordPress Depicter Plugin 3.6.1 - SQL Injection
|
4 |
WEB
|
Andrew Long
|
2025-05-06
|
|
ERPNext 14.82.1 - Account Takeover via Cross-Site Request Forgery (CSRF)
|
4 |
WEB
|
Ahmed Thaiban
|
2025-05-06
|
|
Grokability Snipe-IT 8.0.4 - Insecure Direct Object Reference (IDOR)
|
6 |
WEB
|
Sn1p3r-H4ck3r
|
2025-05-06
|
|
Casdoor 1.901.0 - Cross-Site Request Forgery (CSRF)
|
4 |
WEB
|
Van Lam Nguyen
|
2025-04-22
|
|
WordPress Core 6.2 - Directory Traversal
|
3 |
WEB
|
Milad karimi
|
2025-04-19
|
|
FoxCMS 1.2.5 - Remote Code Execution (RCE)
|
4 |
WEB
|
VeryLazyTech
|
2025-04-19
|
|
Drupal 11.x-dev - Full Path Disclosure
|
5 |
WEB
|
Milad karimi
|
2025-04-18
|
|
KiviCare Clinic & Patient Management System (EHR) 3.6.4 - Unauthenticated SQL Injection
|
6 |
WEB
|
samogod
|
2025-04-18
|
|
UJCMS 9.6.3 - User Enumeration via IDOR
|
4 |
WEB
|
Cyd Tseng
|
2025-04-18
|
|
Inventio Lite 4 - SQL Injection
|
5 |
WEB
|
pointedsec
|
2025-04-18
|
|
Apache Commons Text 1.10.0 - Remote Code Execution
|
5 |
WEB
|
Arjun Chaudhary
|
2025-04-18
|
|
Tatsu 3.3.11 - Unauthenticated RCE
|
4 |
WEB
|
Milad karimi
|
2025-04-18
|
|
Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation
|
4 |
WEB
|
Jun Takemura
|
2025-04-17
|
|
compop.ca 3.5.3 - Arbitrary code Execution
|
4 |
WEB
|
dmlino
|
2025-04-17
|
|
Blood Bank & Donor Management System 2.4 - CSRF Improper Input Validation
|
3 |
WEB
|
Kwangyun Keum
|
2025-04-17
|
|
Usermin 2.100 - Username Enumeration
|
3 |
WEB
|
Kjesper
|
2025-04-17
|
|
Angular-Base64-Upload Library 0.1.21 - Unauthenticated Remote Code Execution (RCE)
|
3 |
WEB
|
Ravindu Wickramasinghe
|
2025-04-17
|
|
ABB Cylon Aspect 3.08.02 (ethernetUpdate.php) - Authenticated Path Traversal
|
3 |
WEB
|
LiquidWorm
|
2025-04-17
|
|
ABB Cylon Aspect 3.08.02 (deployStart.php) - Unauthenticated Command Execution
|
2 |
WEB
|
LiquidWorm
|
2025-04-16
|
|
WooCommerce Customers Manager 29.4 - Post-Authenticated SQL Injection
|
2 |
WEB
|
Ivan Spiridonov
|
2025-04-16
|
|
Smart Manager 8.27.0 - Post-Authenticated SQL Injection
|
4 |
WEB
|
Ivan Spiridonov
|
2025-04-16
|
|
KodExplorer 4.52 - Open Redirect
|
3 |
WEB
|
Rahad Chowdhury
|
2025-04-16
|
|
Car Rental Project 1.0 - Remote Code Execution
|
2 |
WEB
|
ub3rsick
|
2025-04-16
|
|
Ethercreative Logs 3.0.3 - Path Traversal
|
2 |
WEB
|
ub3rsick
|
2025-04-16
|
|
FLIR AX8 1.46.16 - Remote Command Injection
|
2 |
WEB
|
ub3rsick
|
2025-04-16
|
|
Garage Management System 1.0 (categoriesName) - Stored XSS
|
1 |
WEB
|
ub3rsick
|
2025-04-16
|
|
ProConf 6.0 - Insecure Direct Object Reference (IDOR)
|
1 |
WEB
|
ub3rsick
|
2025-04-16
|
|
phpMyFAQ 3.2.10 - Unintended File Download Triggered by Embedded Frames
|
2 |
WEB
|
Geo
|
2025-04-16
|
|
ABB Cylon Aspect 3.08.03 (webServerDeviceLabelUpdate.php) - File Write DoS
|
2 |
WEB
|
LiquidWorm
|
2025-04-16
|
|
ABB Cylon Aspect 4.00.00 (factorySaved.php) - Unauthenticated XSS
|
2 |
WEB
|
LiquidWorm
|
2025-04-16
|
|
ABB Cylon Aspect 4.00.00 (factorySetSerialNum.php) - Remote Code Execution
|
2 |
WEB
|
LiquidWorm
|
2025-04-16
|
|
ABB Cylon Aspect 3.08.02 - Cross-Site Request Forgery (CSRF)
|
1 |
WEB
|
LiquidWorm
|
2025-04-16
|
|
Zabbix 7.0.0 - SQL Injection
|
2 |
WEB
|
m4nb4
|
2025-04-16
|
|
NagVis 1.9.33 - Arbitrary File Read
|
2 |
WEB
|
xerosec
|
2025-04-16
|
|
Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Ayato Shitomi @ Fore-Z co.ltd
|
2025-04-16
|
|
phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
|
2 |
WEB
|
CodeSecLab
|
2025-04-15
|
|
Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
D3Ext
|
2025-04-15
|
|
ABB Cylon Aspect 3.08.02 - Cookie User Password Disclosure
|
2 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
ABB Cylon Aspect 3.08.03 - Hard-coded Secrets
|
1 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
ABB Cylon Aspect 3.08.03 (MapServicesHandler) - Authenticated Reflected XSS
|
1 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
ABB Cylon Aspect 3.07.02 (userManagement.php) - Weak Password Policy
|
1 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
ABB Cylon Aspect 3.08.03 (CookieDB) - SQL Injection
|
1 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
ABB Cylon Aspect 3.08.02 (webServerUpdate.php) - Input Validation Config Poisoning
|
2 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
ABB Cylon Aspect 3.08.02 (escDevicesUpdate.php) - Denial of Service (DOS)
|
2 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
|
1 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution
|
2 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
ABB Cylon Aspect 3.08.02 (licenseUpload.php) - Stored Cross-Site Scripting
|
0 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
ABB Cylon Aspect 3.08.02 (licenseServerUpdate.php) - Stored Cross-Site Scripting
|
0 |
WEB
|
LiquidWorm
|
2025-04-15
|
|
IBMi Navigator 7.5 - Server Side Request Forgery (SSRF)
|
0 |
WEB
|
hyp3rlinx
|
2025-04-15
|
|
Plane 0.23.1 - Server side request forgery (SSRF)
|
0 |
WEB
|
Saud Alenazi
|
2025-04-15
|
|
IBMi Navigator 7.5 - HTTP Security Token Bypass
|
0 |
WEB
|
hyp3rlinx
|
2025-04-15
|
|
OpenCMS 17.0 - Stored Cross Site Scripting (XSS)
|
0 |
WEB
|
Siddhartha Naik
|
2025-04-15
|
|
Adapt Authoring Tool 0.11.3 - Remote Command Execution (RCE)
|
0 |
WEB
|
Eui Chul Chung
|
2025-04-15
|
|
Really Simple Security 9.1.1.1 - Authentication Bypass
|
0 |
WEB
|
Antonio Francesco Sardella
|
2025-04-15
|
|
Spring Boot common-user-management 0.1 - Remote Code Execution (RCE)
|
0 |
WEB
|
d3sca
|
2025-04-14
|
|
SilverStripe 5.3.8 - Stored Cross Site Scripting (XSS) (Authenticated)
|
1 |
WEB
|
James Nicoll
|
2025-04-14
|
|
OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Traversal
|
1 |
WEB
|
Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
|
2025-04-14
|
|
OpenPanel 0.3.4 - OS Command Injection
|
1 |
WEB
|
Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
|
2025-04-14
|
|
OpenPanel 0.3.4 - Incorrect Access Control
|
1 |
WEB
|
Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
|
2025-04-14
|
|
OpenPanel 0.3.4 - Directory Traversal
|
1 |
WEB
|
Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
|
2025-04-14
|
|
Pimcore 11.4.2 - Stored cross site scripting
|
0 |
WEB
|
maeitsec
|
2025-04-14
|
|
Pimcore customer-data-framework 4.2.0 - SQL injection
|
1 |
WEB
|
maeitsec
|
2025-04-14
|
|
Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection
|
1 |
WEB
|
hyp3rlinx
|
2025-04-14
|
|
ZTE ZXHN H168N 3.1 - Remote Code Execution (RCE) via authentication bypass
|
1 |
WEB
|
tasos meletlidis
|
2025-04-11
|
|
GeoVision GV-ASManager 6.1.0.0 - Broken Access Control
|
1 |
WEB
|
Giorgi Dograshvili
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
GeoVision GV-ASManager 6.1.1.0 - CSRF
|
0 |
WEB
|
Giorgi Dograshvili
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - Remote Code Execution (RCE)
|
1 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
WebFileSys 2.31.0 - Directory Path Traversal
|
1 |
WEB
|
Korn Chaisuwan_ Charanin Thongudom_ Pongtorn Angsu
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - WebSocket Command Spawning
|
1 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
Netman 204 - Remote command without authentication
|
1 |
WEB
|
Parsa Rezaie Khiabanloo
|
2025-04-11
|
|
ABB Cylon Aspect 3.08.02 - PHP Session Fixation
|
1 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
CMU CERT/CC VINCE 2.0.6 - Stored XSS
|
1 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - Cross-Site Request Forgery
|
1 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - Default Credentials
|
1 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
ABB Cylon FLXeon 9.3.4 - System Logs Information Disclosure
|
1 |
WEB
|
LiquidWorm
|
2025-04-11
|
|
Nagios Log Server 2024R1.3.1 - API Key Exposure
|
0 |
WEB
|
Seth Kraft
|
2025-04-11
|
|
phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
|
0 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
MiniCMS 1.1 - Cross Site Scripting (XSS)
|
0 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
NEWS-BUZZ News Management System 1.0 - SQL Injection
|
0 |
WEB
|
egsec
|
2025-04-11
|
|
Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
|
0 |
WEB
|
AmirZargham
|
2025-04-11
|
|
CyberPanel 2.3.6 - Remote Code Execution (RCE)
|
0 |
WEB
|
Luka Petrovic (refr4g)
|
2025-04-11
|
|
LearnPress WordPress LMS Plugin 4.2.7 - SQL Injection
|
0 |
WEB
|
Francisco Moraga (BTshell)
|
2025-04-11
|
|
MagnusSolution magnusbilling 7.3.0 - Command Injection
|
0 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
RosarioSIS 7.6 - SQL Injection
|
0 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
|
0 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
Gnuboard5 5.3.2.8 - SQL Injection
|
0 |
WEB
|
CodeSecLab
|
2025-04-11
|
|
flatCore 1.5 - Cross Site Request Forgery (CSRF)
|
0 |
WEB
|
CodeSecLab
|
2025-04-10
|
|
flatCore 1.5.5 - Arbitrary File Upload
|
0 |
WEB
|
CodeSecLab
|
2025-04-10
|
|
AquilaCMS 1.409.20 - Remote Command Execution (RCE)
|
0 |
WEB
|
Eui Chul Chung
|
2025-04-10
|
|
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
cyberaz0r
|
2025-04-10
|
|
Typecho 1.3.0 - Race Condition
|
0 |
WEB
|
cyberaz0r
|
2025-04-10
|
|
Cosy+ firmware 21.2s7 - Command Injection
|
0 |
WEB
|
CodeB0ss
|
2025-04-10
|
|
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
|
0 |
WEB
|
Raj Nandi
|
2025-04-10
|
|
PandoraFMS 7.0NG.772 - SQL Injection
|
0 |
WEB
|
Osama Yousef
|
2025-04-10
|
|
Centron 19.04 - Remote Code Execution (RCE)
|
0 |
WEB
|
Starry Sky
|
2025-04-10
|
|
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
|
0 |
WEB
|
Mohammed Adel
|
2025-04-10
|
|
Feng Office 3.11.1.2 - SQL Injection
|
0 |
WEB
|
Andrey Stoykov
|
2025-04-09
|
|
PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
|
0 |
WEB
|
Vuln Seeker Cybersecurity Team
|
2025-04-09
|
|
ChurchCRM 5.9.1 - SQL Injection
|
0 |
WEB
|
Sanan Qasimzada
|
2025-04-09
|
|
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
|
0 |
WEB
|
Andrew Lemon/Red Threat
|
2025-04-09
|
|
ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
Jeremia Geraldi Sihombing
|
2025-04-09
|
|
Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
|
0 |
WEB
|
Yesith Alvarez
|
2025-04-09
|
|
Zohocorp ManageEngine ADManager Plus 7210 - Elevation of Privilege
|
0 |
WEB
|
Metin Yunus Kandemir
|
2025-04-09
|
|
Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS)
|
0 |
WEB
|
Ahmet Ümit BAYRAM
|
2025-04-09
|
|
Artica Proxy 4.50 - Remote Code Execution (RCE)
|
0 |
WEB
|
Madan
|
2025-04-09
|
|
DocsGPT 0.12.0 - Remote Code Execution
|
0 |
WEB
|
Shreyas Malhotra
|
2025-04-08
|
|
GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
|
0 |
WEB
|
Giorgi Dograshvili
|
2025-04-08
|
|
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
|
0 |
WEB
|
xOryus
|
2025-04-08
|
|
Jasmin Ransomware - Arbitrary File Download (Authenticated)
|
0 |
WEB
|
bRpsd
|
2025-04-08
|
|
UNA CMS 14.0.0-RC - PHP Object Injection
|
0 |
WEB
|
Egidio Romano
|
2025-04-08
|
|
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
|
0 |
WEB
|
Calil Khalil
|
2025-04-08
|
|
WordPress User Registration & Membership Plugin 4.1.1 - Unauthenticated Privilege Escalation
|
0 |
WEB
|
Al Baradi Joy
|
2025-04-07
|
|
XWiki Platform 15.10.10 - Remote Code Execution
|
0 |
WEB
|
Al Baradi Joy
|
2025-04-07
|
|
YesWiki 4.5.1 - Unauthenticated Path Traversal
|
0 |
WEB
|
Al Baradi Joy
|
2025-04-07
|
|
Apache Tomcat 11.0.3 - Remote Code Execution
|
0 |
WEB
|
Al Baradi Joy
|
2025-04-06
|
|
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
Ilteris Kaan Pehlivan
|