2022-01-05
|
|
Movie Rating System 1.0 - Broken Access Control (Admin Account Creation) (Unauthenticated)
|
1 |
WEB
|
Tagoletta
|
2022-01-05
|
|
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
|
0 |
WEB
|
Ron Jost
|
2022-01-05
|
|
WordPress Plugin Contact Form Entries 1.1.6 - Cross Site Scripting (XSS) (Unauthenticated)
|
1 |
WEB
|
Gaetano Perrone
|
2022-01-05
|
|
RiteCMS 3.1.0 - Remote Code Execution (RCE) (Authenticated)
|
0 |
WEB
|
faisalfs10x
|
2022-01-05
|
|
RiteCMS 3.1.0 - Arbitrary File Deletion (Authenticated)
|
1 |
WEB
|
faisalfs10x
|
2022-01-05
|
|
RiteCMS 3.1.0 - Arbitrary File Overwrite (Authenticated)
|
1 |
WEB
|
faisalfs10x
|
2022-01-05
|
|
CMSimple 5.4 - Cross Site Scripting (XSS)
|
1 |
WEB
|
heinjame
|
2021-12-20
|
|
Exponent CMS 2.6 - Multiple Vulnerabilities
|
1 |
WEB
|
heinjame
|
2021-12-20
|
|
phpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
Halit AKAYDIN
|
2021-12-20
|
|
WBCE CMS 1.5.1 - Admin Password Reset
|
1 |
WEB
|
citril
|
2021-12-16
|
|
Arunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF)
|
1 |
WEB
|
=(L_L)=
|
2021-12-16
|
|
Croogo 3.0.2 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Enes Özeser
|
2021-12-16
|
|
Croogo 3.0.2 - Unrestricted File Upload
|
2 |
WEB
|
Enes Özeser
|
2021-12-16
|
|
Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration
|
2 |
WEB
|
Daniel Morales
|
2021-12-14
|
|
Online Thesis Archiving System 1.0 - SQLi Authentication Bypass
|
1 |
WEB
|
Yehia Elghaly
|
2021-12-14
|
|
meterN v1.2.3 - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
LiquidWorm
|
2021-12-14
|
|
Zucchetti Axess CLOKI Access Control 1.64 - Cross Site Request Forgery (CSRF)
|
1 |
WEB
|
LiquidWorm
|
2021-12-14
|
|
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
|
2 |
WEB
|
0sunday
|
2021-12-14
|
|
WordPress Plugin Typebot 1.4.3 - Stored Cross Site Scripting (XSS) (Authenticated)
|
0 |
WEB
|
Mansi Singh
|
2021-12-13
|
|
WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
Jeremiasz Pluta
|
2021-12-10
|
|
Free School Management Software 1.0 - Remote Code Execution (RCE)
|
1 |
WEB
|
fuzzyap1
|
2021-12-10
|
|
Free School Management Software 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
fuzzyap1
|
2021-12-10
|
|
OpenCATS 0.9.4 - Remote Code Execution (RCE)
|
1 |
WEB
|
Nicholas Ferreira
|
2021-12-09
|
|
Employees Daily Task Management System 1.0 - 'multiple' Cross Site Scripting (XSS)
|
1 |
WEB
|
able403
|
2021-12-09
|
|
Employees Daily Task Management System 1.0 - 'username' SQLi Authentication Bypass
|
0 |
WEB
|
able403
|
2021-12-09
|
|
Grafana 8.3.0 - Directory Traversal and Arbitrary File Read
|
1 |
WEB
|
s1gh
|
2021-12-09
|
|
Wordpress Plugin Catch Themes Demo Import 1.6.1 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
Ron Jost
|
2021-12-09
|
|
Student Management System 1.0 - SQLi Authentication Bypass
|
1 |
WEB
|
Enes Özeser
|
2021-12-09
|
|
TestLink 1.19 - Arbitrary File Download (Unauthenticated)
|
2 |
WEB
|
Gonzalo Villegas
|
2021-12-09
|
|
LimeSurvey 5.2.4 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
Y1LD1R1M
|
2021-12-09
|
|
Chikitsa Patient Management System 2.0.2 - 'backup' Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
0z09e
|
2021-12-09
|
|
Chikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
0z09e
|
2021-12-06
|
|
Croogo 3.0.2 - Remote Code Execution (Authenticated)
|
2 |
WEB
|
Deha Berkin Bir
|
2021-12-03
|
|
WordPress Plugin DZS Zoomsounds 6.45 - Arbitrary File Read (Unauthenticated)
|
2 |
WEB
|
Uriel Yochpaz
|
2021-12-03
|
|
WordPress Plugin Slider by Soliloquy 2.6.2 - 'title' Stored Cross Site Scripting (XSS) (Authenticate
|
1 |
WEB
|
Abdurrahman Erkan
|
2021-12-03
|
|
WordPress Plugin All-in-One Video Gallery plugin 2.4.9 - Local File Inclusion (LFI)
|
1 |
WEB
|
Mohamed Magdy Abumusilm
|
2021-12-03
|
|
Online Magazine Management System 1.0 - SQLi Authentication Bypass
|
2 |
WEB
|
Mohamed habib Smidi
|
2021-12-03
|
|
Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass
|
0 |
WEB
|
Mohamed habib Smidi
|
2021-12-01
|
|
Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting
|
1 |
WEB
|
Tushar Jadhav
|
2021-11-30
|
|
Laundry Booking Management System 1.0 - Remote Code Execution (RCE)
|
2 |
WEB
|
Pablo Santiago
|
2021-11-29
|
|
opencart 3.0.3.8 - Sessjion Injection
|
2 |
WEB
|
Hubert Wojciechowski
|
2021-11-29
|
|
orangescrum 1.8.0 - 'Multiple' Cross-Site Scripting (XSS) (Authenticated)
|
1 |
WEB
|
Hubert Wojciechowski
|
2021-11-29
|
|
orangescrum 1.8.0 - 'Multiple' SQL Injection (Authenticated)
|
1 |
WEB
|
Hubert Wojciechowski
|
2021-11-29
|
|
orangescrum 1.8.0 - Privilege escalation (Authenticated)
|
2 |
WEB
|
Hubert Wojciechowski
|
2021-11-26
|
|
Bagisto 1.3.3 - Client-Side Template Injection
|
2 |
WEB
|
Mohamed Abdellatif Jaber
|
2021-11-24
|
|
CMSimple 5.4 - Local file inclusion (LFI) to Remote code execution (RCE) (Authenticated)
|
1 |
WEB
|
S1lv3r
|
2021-11-23
|
|
FLEX 1085 Web 1.6.0 - HTML Injection
|
1 |
WEB
|
Mr Empy
|
2021-11-23
|
|
Bus Pass Management System 1.0 - 'Search' SQL injection
|
2 |
WEB
|
Abhijeet Singh
|
2021-11-23
|
|
Webrun 3.6.0.42 - 'P_0' SQL Injection
|
1 |
WEB
|
Vinicius Alves
|
2021-11-23
|
|
Wordpress Plugin WP Guppy 1.1 - WP-JSON API Sensitive Information Disclosure
|
1 |
WEB
|
Keyvan Hardani
|
2021-11-22
|
|
Aimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection
|
2 |
WEB
|
Ilker Burak ADIYAMAN
|
2021-11-17
|
|
Wordpress Plugin Smart Product Review 1.0.4 - Arbitrary File Upload
|
1 |
WEB
|
Keyvan Hardani
|
2021-11-17
|
|
GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)
|
2 |
WEB
|
Jacob Baines
|
2021-11-17
|
|
SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
|
2 |
WEB
|
M. Cory Billington
|
2021-11-17
|
|
Quick.CMS 6.7 - Cross Site Request Forgery (CSRF) to Cross Site Scripting (XSS) (Authenticated)
|
2 |
WEB
|
Rahad Chowdhury
|
2021-11-17
|
|
Bludit 3.13.1 - 'username' Cross Site Scripting (XSS)
|
2 |
WEB
|
Vasu
|
2021-11-16
|
|
CMDBuild 3.3.2 - 'Multiple' Cross Site Scripting (XSS)
|
1 |
WEB
|
Hosein Vita
|
2021-11-16
|
|
Online Learning System 2.0 - Remote Code Execution (RCE)
|
1 |
WEB
|
djebbaranon
|
2021-11-15
|
|
PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
|
1 |
WEB
|
Hosein Vita
|
2021-11-15
|
|
WordPress Plugin Contact Form to Email 1.3.24 - Stored Cross Site Scripting (XSS) (Authenticated)
|
1 |
WEB
|
Mohammed Aadhil Ashfaq
|
2021-11-15
|
|
Fuel CMS 1.4.13 - 'col' Blind SQL Injection (Authenticated)
|
1 |
WEB
|
Rahad Chowdhury
|
2021-11-15
|
|
Simple Subscription Website 1.0 - SQLi Authentication Bypass
|
1 |
WEB
|
Daniel Haro
|
2021-11-15
|
|
KONGA 0.14.9 - Privilege Escalation
|
1 |
WEB
|
Fabricio Salomao
|
2021-11-15
|
|
WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
|
2 |
WEB
|
Davide Taraschi
|
2021-11-12
|
|
Mumara Classic 2.93 - 'license' SQL Injection (Unauthenticated)
|
1 |
WEB
|
Shain Lakin
|
2021-11-12
|
|
WordPress Plugin AccessPress Social Icons 1.8.2 - 'icon title' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Murat DEMİRCİ
|
2021-11-12
|
|
WordPress Plugin WP Symposium Pro 2021.10 - 'wps_admin_forum_add_name' Stored Cross-Site Scripting (
|
1 |
WEB
|
Murat DEMİRCİ
|
2021-11-11
|
|
FormaLMS 2.4.4 - Authentication Bypass
|
2 |
WEB
|
Cristian \'void\' Giustini
|
2021-11-11
|
|
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
|
2 |
WEB
|
Valentin Lobstein
|
2021-11-11
|
|
YeaLink SIP-TXXXP 53.84.0.15 - 'cmd' Command Injection (Authenticated)
|
2 |
WEB
|
tahaafarooq
|
2021-11-10
|
|
Employee and Visitor Gate Pass Logging System 1.0 - 'name' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
İlhami Selamet
|
2021-11-10
|
|
Employee Daily Task Management System 1.0 - 'Name' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Ragavender A G
|
2021-11-08
|
|
FusionPBX 4.5.29 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
Luska
|
2021-11-08
|
|
WordPress Plugin Backup and Restore 1.0.3 - Arbitrary File Deletion
|
0 |
WEB
|
Murat DEMİRCİ
|
2021-11-08
|
|
Froxlor 0.10.29.1 - SQL Injection (Authenticated)
|
1 |
WEB
|
Martin Cernac
|
2021-11-08
|
|
Money Transfer Management System 1.0 - Authentication Bypass
|
1 |
WEB
|
Aryan Chehreghani
|
2021-11-08
|
|
Kmaleon 1.1.0.205 - 'tipocomb' SQL Injection (Authenticated)
|
1 |
WEB
|
Amel BOUZIANE-LEBLOND
|
2021-11-08
|
|
Simple Client Management System 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Sentinal920
|
2021-11-08
|
|
Simple Client Management System 1.0 - SQLi (Authentication Bypass)
|
1 |
WEB
|
Sentinal920
|
2021-11-05
|
|
ImportExportTools NG 10.0.4 - HTML Injection
|
1 |
WEB
|
Vulnerability-Lab
|
2021-11-05
|
|
Payment Terminal 3.1 - 'Multiple' Cross-Site Scripting (XSS)
|
0 |
WEB
|
Vulnerability-Lab
|
2021-11-04
|
|
Opencart 3 Extension TMD Vendor System - Blind SQL Injection
|
1 |
WEB
|
Muhammad Zaki Sulistya
|
2021-11-03
|
|
Ultimate POS 4.4 - 'name' Cross-Site Scripting (XSS)
|
2 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Vanguard 2.1 - 'Search' Cross-Site Scripting (XSS)
|
2 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Isshue Shopping Cart 3.5 - 'Title' Cross Site Scripting (XSS)
|
1 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Mult-e-Cart Ultimate 2.4 - 'id' SQL Injection
|
1 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
PHP Melody 3.0 - Persistent Cross-Site Scripting (XSS)
|
1 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
PHP Melody 3.0 - 'vid' SQL Injection
|
2 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
PHP Melody 3.0 - 'Multiple' Cross-Site Scripting (XSS)
|
2 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Sonicwall SonicOS 6.5.4 - 'Common Name' Cross-Site Scripting (XSS)
|
1 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Simplephpscripts Simple CMS 2.1 - 'Multiple' SQL Injection
|
1 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
Simplephpscripts Simple CMS 2.1 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
OpenAM 13.0 - LDAP Injection
|
2 |
WEB
|
Charlton Trezevant
|
2021-11-03
|
|
WordPress Plugin Popup Anything 2.0.3 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Luca Schembri
|
2021-11-03
|
|
Eclipse Jetty 11.0.5 - Sensitive File Disclosure
|
1 |
WEB
|
Mayank Deshmukh
|
2021-11-03
|
|
Fuel CMS 1.4.1 - Remote Code Execution (3)
|
1 |
WEB
|
Padsala Trushal
|
2021-11-03
|
|
WordPress Plugin Hotel Listing 3 - 'Multiple' Cross-Site Scripting (XSS)
|
1 |
WEB
|
Vulnerability-Lab
|
2021-11-03
|
|
PHPJabbers Simple CMS 5 - 'name' Persistent Cross-Site Scripting (XSS)
|
2 |
WEB
|
Vulnerability-Lab
|
2021-11-02
|
|
Codiad 2.8.4 - Remote Code Execution (Authenticated) (4)
|
1 |
WEB
|
P4p4_M4n3
|
2021-11-02
|
|
i3 International Annexxus Cameras Ax-n 5.2.0 - Application Logic Flaw
|
1 |
WEB
|
LiquidWorm
|
2021-11-02
|
|
Ericsson Network Location MPS GMPC21 - Privilege Escalation (Metasploit)
|
1 |
WEB
|
AkkuS
|
2021-11-02
|
|
Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit)
|
1 |
WEB
|
AkkuS
|
2021-11-02
|
|
Employee Record Management System 1.2 - 'empid' SQL injection (Unauthenticated)
|
2 |
WEB
|
Anubhav Singh
|
2021-10-29
|
|
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
|
1 |
WEB
|
Charl-Alexandre Le Brun
|
2021-10-29
|
|
WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS)
|
2 |
WEB
|
3ndG4me
|
2021-10-29
|
|
Umbraco v8.14.1 - 'baseUrl' SSRF
|
2 |
WEB
|
NgoAnhDuc
|
2021-10-28
|
|
PHPGurukul Hostel Management System 2.1 - Cross-site request forgery (CSRF) to Cross-site Scripting
|
1 |
WEB
|
Anubhav Singh
|
2021-10-28
|
|
WordPress Plugin Supsystic Contact Form 1.7.18 - 'label' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Murat DEMİRCİ
|
2021-10-26
|
|
WordPress Plugin Filterable Portfolio Gallery 1.0 - 'title' Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
Murat DEMİRCİ
|
2021-10-25
|
|
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
|
1 |
WEB
|
samguy
|
2021-10-25
|
|
Wordpress 4.9.6 - Arbitrary File Deletion (Authenticated) (2)
|
1 |
WEB
|
samguy
|
2021-10-25
|
|
WordPress Plugin Ninja Tables 4.1.7 - Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
Akash Patil
|
2021-10-25
|
|
WordPress Plugin Media-Tags 3.2.0.2 - Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Akash Patil
|
2021-10-25
|
|
Engineers Online Portal 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Alon Leviev
|
2021-10-25
|
|
Engineers Online Portal 1.0 - 'multiple' Authentication Bypass
|
2 |
WEB
|
Alon Leviev
|
2021-10-25
|
|
Engineers Online Portal 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Alon Leviev
|
2021-10-25
|
|
Online Event Booking and Reservation System 1.0 - 'reason' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Alon Leviev
|
2021-10-25
|
|
Balbooa Joomla Forms Builder 2.0.6 - SQL Injection (Unauthenticated)
|
1 |
WEB
|
blockomat2100
|
2021-10-25
|
|
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)
|
2 |
WEB
|
ThelastVvV
|
2021-10-25
|
|
Build Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)
|
2 |
WEB
|
Nehru Sethuraman
|
2021-10-25
|
|
Engineers Online Portal 1.0 - File Upload Remote Code Execution (RCE)
|
1 |
WEB
|
SadKris
|
2021-10-25
|
|
WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
1 |
WEB
|
Akash Patil
|
2021-10-25
|
|
Hikvision Web Server Build 210702 - Command Injection
|
1 |
WEB
|
bashis
|
2021-10-22
|
|
Online Course Registration 1.0 - Blind Boolean-Based SQL Injection (Authenticated)
|
2 |
WEB
|
Sam Ferguson
|
2021-10-22
|
|
Clinic Management System 1.0 - SQL injection to Remote Code Execution
|
1 |
WEB
|
Pablo Santiago
|