2021-10-22
|
|
Jetty 9.4.37.v20210219 - Information Disclosure
|
2 |
WEB
|
Mayank Deshmukh
|
2021-10-21
|
|
Easy Chat Server 3.1 - Directory Traversal and Arbitrary File Read
|
2 |
WEB
|
z4nd3r
|
2021-10-21
|
|
Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Ghuliev
|
2021-10-20
|
|
Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
|
1 |
WEB
|
Oscar Gil Gutierrez
|
2021-10-20
|
|
SonicWall SMA 10.2.1.0-17sv - Password Reset
|
0 |
WEB
|
Jacob Baines
|
2021-10-19
|
|
Online Motorcycle (Bike) Rental System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
|
1 |
WEB
|
Chase Comardelle
|
2021-10-19
|
|
myfactory FMS 7.1-911 - 'Multiple' Reflected Cross-Site Scripting (XSS)
|
0 |
WEB
|
RedTeam Pentesting GmbH
|
2021-10-19
|
|
WordPress Theme Enfold 4.8.3 - Reflected Cross-Site Scripting (XSS)
|
0 |
WEB
|
David Álvarez Robles
|
2021-10-18
|
|
Plastic SCM 10.0.16.5622 - WebAdmin Server Access
|
1 |
WEB
|
Basavaraj Banakar
|
2021-10-18
|
|
Company's Recruitment Management System 1.0 - 'Add New user' Cross-Site Request Forgery (CSRF)
|
1 |
WEB
|
Aniket Deshmane
|
2021-10-18
|
|
Company's Recruitment Management System 1.0 - 'description' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Aniket Deshmane
|
2021-10-18
|
|
Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
|
1 |
WEB
|
Hamit CİBO
|
2021-10-18
|
|
Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
|
1 |
WEB
|
Hamit CİBO
|
2021-10-18
|
|
Company's Recruitment Management System 1.0. - 'title' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Aniket Deshmane
|
2021-10-18
|
|
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
|
2 |
WEB
|
nam3lum
|
2021-10-18
|
|
Support Board 3.3.4 - 'Message' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
John Jefferson Li
|
2021-10-15
|
|
i-Panel Administration System 2.0 - Reflected Cross-site Scripting (XSS)
|
2 |
WEB
|
Forster Chiu
|
2021-10-14
|
|
TextPattern CMS 4.8.7 - Remote Command Execution (RCE) (Authenticated)
|
0 |
WEB
|
Mert Daş
|
2021-10-13
|
|
Sonicwall SonicOS 7.0 - Host Header Injection
|
2 |
WEB
|
Ramikan
|
2021-10-13
|
|
Logitech Media Server 8.2.0 - 'Title' Cross-Site Scripting (XSS)
|
1 |
WEB
|
Mert Daş
|
2021-10-13
|
|
Student Quarterly Grading System 1.0 - 'grade' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Hüseyin Serkan Balkanli
|
2021-10-13
|
|
Simple Issue Tracker System 1.0 - SQLi Authentication Bypass
|
1 |
WEB
|
Bekir Bugra TURKOGLU
|
2021-10-13
|
|
Online Learning System 2.0 - 'Multiple' SQLi Authentication Bypass
|
1 |
WEB
|
Blackhan
|
2021-10-13
|
|
Pharmacy Point of Sale System 1.0 - 'Add New User' Cross-Site Request Forgery (CSRF)
|
1 |
WEB
|
Murat DEMİRCİ
|
2021-10-13
|
|
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
|
2 |
WEB
|
Lucas Souza
|
2021-10-13
|
|
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
|
2 |
WEB
|
Mayank Deshmukh
|
2021-10-13
|
|
Company's Recruitment Management System 1.0 - 'Multiple' SQL Injection (Unauthenticated)
|
1 |
WEB
|
Yash Mahajan
|
2021-10-13
|
|
Simple Payroll System 1.0 - SQLi Authentication Bypass
|
2 |
WEB
|
Yash Mahajan
|
2021-10-08
|
|
Loan Management System 1.0 - SQLi Authentication Bypass
|
1 |
WEB
|
Merve Oral
|
2021-10-08
|
|
Online Employees Work From Home Attendance System 1.0 - SQLi Authentication Bypass
|
2 |
WEB
|
Merve Oral
|
2021-10-08
|
|
Online Enrollment Management System 1.0 - Authentication Bypass
|
2 |
WEB
|
Amine ismail
|
2021-10-08
|
|
Simple Online College Entrance Exam System 1.0 - 'Multiple' SQL injection
|
2 |
WEB
|
Amine ismail
|
2021-10-08
|
|
Simple Online College Entrance Exam System 1.0 - Account Takeover
|
1 |
WEB
|
Amine ismail
|
2021-10-08
|
|
Simple Online College Entrance Exam System 1.0 - Unauthenticated Admin Creation
|
1 |
WEB
|
Amine ismail
|
2021-10-08
|
|
WordPress Plugin Pie Register 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)
|
1 |
WEB
|
Lotfi13-DZ
|
2021-10-08
|
|
Maian-Cart 3.8 - Remote Code Execution (RCE) (Unauthenticated)
|
0 |
WEB
|
DreyAnd
|
2021-10-08
|
|
django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
Raven Security Associates
|
2021-10-08
|
|
Online Traffic Offense Management System 1.0 - Privilage escalation (Unauthenticated)
|
0 |
WEB
|
snup
|
2021-10-08
|
|
IFSC Code Finder Project 1.0 - SQL injection (Unauthenticated)
|
0 |
WEB
|
Yash Mahajan
|
2021-10-07
|
|
Simple Online College Entrance Exam System 1.0 - SQLi Authentication Bypass
|
0 |
WEB
|
Mevlüt Yılmaz
|
2021-10-07
|
|
Online Traffic Offense Management System 1.0 - Multiple RCE (Unauthenticated)
|
0 |
WEB
|
snup
|
2021-10-07
|
|
Online Traffic Offense Management System 1.0 - Multiple XSS (Unauthenticated)
|
0 |
WEB
|
snup
|
2021-10-07
|
|
Online Traffic Offense Management System 1.0 - Multiple SQL Injection (Unauthenticated)
|
2 |
WEB
|
snup
|
2021-10-07
|
|
Online DJ Booking Management System 1.0 - 'Multiple' Blind Cross-Site Scripting
|
1 |
WEB
|
Yash Mahajan
|
2021-10-06
|
|
Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)
|
0 |
WEB
|
Lucas Souza
|
2021-10-06
|
|
Wordpress Plugin BulletProof Security 5.1 - Sensitive Information Disclosure
|
2 |
WEB
|
Ron Jost
|
2021-10-06
|
|
Odine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection
|
0 |
WEB
|
Emel Basayar
|
2021-10-06
|
|
Atlassian Jira Server Data Center 8.16.0 - Arbitrary File Read
|
2 |
WEB
|
Mayank Deshmukh
|
2021-10-05
|
|
Wordpress Plugin MStore API 2.0.6 - Arbitrary File Upload
|
2 |
WEB
|
spacehen
|
2021-10-05
|
|
Wordpress Plugin TheCartPress 1.5.3.6 - Privilege Escalation (Unauthenticated)
|
0 |
WEB
|
spacehen
|
2021-10-05
|
|
Atlassian Confluence 7.12.2 - Pre-Authorization Arbitrary File Read
|
0 |
WEB
|
Mayank Deshmukh
|
2021-10-05
|
|
Student Quarterly Grading System 1.0 - SQLi Authentication Bypass
|
1 |
WEB
|
Blackhan
|
2021-10-04
|
|
Young Entrepreneur E-Negosyo System 1.0 - 'PRODESC' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Jordan Glover
|
2021-10-04
|
|
Young Entrepreneur E-Negosyo System 1.0 - SQL Injection Authentication Bypass
|
1 |
WEB
|
Jordan Glover
|
2021-10-04
|
|
Open Game Panel - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
prey
|
2021-10-04
|
|
Lodging Reservation Management System 1.0 - Authentication Bypass
|
2 |
WEB
|
Nitin Sharma
|
2021-10-04
|
|
Payara Micro Community 5.2021.6 - Directory Traversal
|
2 |
WEB
|
Yasser Khan
|
2021-10-01
|
|
Directory Management System 1.0 - SQL Injection Authentication Bypass
|
1 |
WEB
|
Sanjay Singh
|
2021-10-01
|
|
CMSimple_XH 1.7.4 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
Halit AKAYDIN
|
2021-10-01
|
|
WhatsUpGold 21.0.3 - Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
Andreas Finstad
|
2021-10-01
|
|
Dairy Farm Shop Management System 1.0 - SQL Injection Authentication Bypass
|
1 |
WEB
|
Sanjay Singh
|
2021-10-01
|
|
Vehicle Service Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
Ghuliev
|
2021-10-01
|
|
Phpwcms 1.9.30 - Arbitrary File Upload
|
1 |
WEB
|
Okan Kurtulus
|
2021-10-01
|
|
Blood Bank System 1.0 - Authentication Bypass
|
0 |
WEB
|
Nitin Sharma
|
2021-10-01
|
|
Drupal Module MiniorangeSAML 8.x-2.22 - Privilege escalation
|
0 |
WEB
|
Cristian \'void\' Giustini
|
2021-10-01
|
|
Exam Form Submission System 1.0 - SQL Injection Authentication Bypass
|
0 |
WEB
|
Nitin Sharma
|
2021-09-30
|
|
Pharmacy Point of Sale System 1.0 - 'Multiple' SQL Injection (SQLi)
|
0 |
WEB
|
Murat
|
2021-09-30
|
|
Cmsimple 5.4 - Remote Code Execution (RCE) (Authenticated)
|
0 |
WEB
|
pussycat0x
|
2021-09-30
|
|
Cyber Cafe Management System Project (CCMS) 1.0 - SQL Injection Authentication Bypass
|
1 |
WEB
|
Sanjay Singh
|
2021-09-29
|
|
Pet Shop Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
Mr.Gedik
|
2021-09-29
|
|
OpenSIS 8.0 - 'cp_id_miss_attn' Reflected Cross-Site Scripting (XSS)
|
1 |
WEB
|
Eric Salario
|
2021-09-29
|
|
WordPress Plugin Redirect 404 to Parent 1.3.0 - Reflected Cross-Site Scripting
|
1 |
WEB
|
0xB9
|
2021-09-29
|
|
WordPress Plugin Select All Categories and Taxonomies 1.3.1 - Reflected Cross-Site Scripting (XSS)
|
1 |
WEB
|
0xB9
|
2021-09-29
|
|
Storage Unit Rental Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
Ghuliev
|
2021-09-28
|
|
WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
|
1 |
WEB
|
0xB9
|
2021-09-28
|
|
WordPress Plugin Ultimate Maps 1.2.4 - Reflected Cross-Site Scripting (XSS)
|
1 |
WEB
|
0xB9
|
2021-09-28
|
|
WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
|
1 |
WEB
|
0xB9
|
2021-09-28
|
|
WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
|
1 |
WEB
|
Nosa Shandy
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Remote Privilege Escalation
|
0 |
WEB
|
LiquidWorm
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Hidden Backdoor Account (Write Access)
|
0 |
WEB
|
LiquidWorm
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - Config Download (Unauthenticated)
|
1 |
WEB
|
LiquidWorm
|
2021-09-28
|
|
FatPipe Networks WARP 10.2.2 - Authorization Bypass
|
1 |
WEB
|
LiquidWorm
|
2021-09-28
|
|
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 - 'Add Admin' Cross-Site Request Forgery (CSRF)
|
0 |
WEB
|
LiquidWorm
|
2021-09-27
|
|
Library System 1.0 - 'student_id' SQL injection (Authenticated)
|
2 |
WEB
|
Vinay Bhuria
|
2021-09-27
|
|
WordPress Plugin Wappointment 2.2.4 - Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Renos Nikolaou
|
2021-09-24
|
|
Pharmacy Point of Sale System 1.0 - SQLi Authentication BYpass
|
1 |
WEB
|
Janik Wehrli
|
2021-09-24
|
|
SmarterTools SmarterTrack 7922 - 'Multiple' Information Disclosure
|
2 |
WEB
|
Andrei Manole
|
2021-09-23
|
|
Police Crime Record Management Project 1.0 - Time Based SQLi
|
2 |
WEB
|
()t/\\/\\1
|
2021-09-23
|
|
Budget and Expense Tracker System 1.0 - Arbitrary File Upload
|
1 |
WEB
|
()t/\\/\\1
|
2021-09-23
|
|
WordPress Plugin Fitness Calculators 1.9.5 - Cross-Site Request Forgery (CSRF)
|
0 |
WEB
|
0xB9
|
2021-09-23
|
|
WordPress Plugin Advanced Order Export For WooCommerce 3.1.7 - Reflected Cross-Site Scripting (XSS)
|
2 |
WEB
|
0xB9
|
2021-09-23
|
|
Backdrop CMS 1.20.0 - 'Multiple' Cross-Site Request Forgery (CSRF)
|
2 |
WEB
|
V1n1v131r4
|
2021-09-23
|
|
Wordpress Plugin 3DPrint Lite 1.9.1.4 - Arbitrary File Upload
|
1 |
WEB
|
spacehen
|
2021-09-23
|
|
Gurock Testrail 7.2.0.3014 - 'files.md5' Improper Access Control
|
2 |
WEB
|
Sick Codes
|
2021-09-22
|
|
Online Reviewer System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
2 |
WEB
|
Abdullah Khawaja
|
2021-09-22
|
|
Sentry 8.2.0 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
Mohin Paramasivam
|
2021-09-22
|
|
Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)
|
2 |
WEB
|
Akıner Kısa
|
2021-09-22
|
|
OpenCats 0.9.4-2 - 'docx ' XML External Entity Injection (XXE)
|
2 |
WEB
|
Jake Ruston
|
2021-09-22
|
|
e107 CMS 2.3.0 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
Halit AKAYDIN
|
2021-09-22
|
|
Filerun 2021.03.26 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
syntegris information solutions GmbH
|
2021-09-22
|
|
Simple Attendance System 1.0 - Unauthenticated Blind SQLi
|
2 |
WEB
|
()t/\\/\\1
|
2021-09-21
|
|
WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
Halit AKAYDIN
|
2021-09-21
|
|
Budget and Expense Tracker System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
0 |
WEB
|
Abdullah Khawaja
|
2021-09-20
|
|
Budget and Expense Tracker System 1.0 - Authenticated Bypass
|
1 |
WEB
|
Prunier Charles-Yves
|
2021-09-20
|
|
Church Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
Abdullah Khawaja
|
2021-09-20
|
|
Online Food Ordering System 2.0 - Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
Abdullah Khawaja
|
2021-09-20
|
|
WordPress 5.7 - 'Media Library' XML External Entity Injection (XXE) (Authenticated)
|
1 |
WEB
|
David Utón
|
2021-09-20
|
|
Church Management System 1.0 - 'search' SQL Injection (Unauthenticated)
|
1 |
WEB
|
Erwin Krazek
|
2021-09-20
|
|
T-Soft E-Commerce 4 - change 'admin credentials' Cross-Site Request Forgery (CSRF)
|
1 |
WEB
|
Alperen Ergel
|
2021-09-17
|
|
Simple Attendance System 1.0 - Authenticated bypass
|
1 |
WEB
|
Abdullah Khawaja
|
2021-09-17
|
|
Library Management System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
|
1 |
WEB
|
boku
|
2021-09-17
|
|
WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass
|
1 |
WEB
|
0xB455
|
2021-09-16
|
|
ImpressCMS 1.4.2 - Remote Code Execution (RCE) (Authenticated)
|
0 |
WEB
|
Halit AKAYDIN
|
2021-09-15
|
|
AlphaWeb XE - File Upload Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
Ricardo Ruiz
|
2021-09-15
|
|
Evolution CMS 3.1.6 - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
Halit AKAYDIN
|
2021-09-15
|
|
Seowon 130-SLC router - 'queriesCnt' Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
Aryan Chehreghani
|
2021-09-15
|
|
Support Board 3.3.3 - 'Multiple' SQL Injection (Unauthenticated)
|
2 |
WEB
|
John Jefferson Li
|
2021-09-14
|
|
Purchase Order Management System 1.0 - Remote File Upload
|
1 |
WEB
|
Aryan Chehreghani
|
2021-09-13
|
|
Apartment Visitor Management System (AVMS) 1.0 - 'username' SQL Injection
|
1 |
WEB
|
mari0x00
|
2021-09-13
|
|
Wordpress Plugin Download From Files 1.48 - Arbitrary File Upload
|
2 |
WEB
|
spacehen
|
2021-09-13
|
|
ECOA Building Automation System - Arbitrary File Deletion
|
2 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Local File Disclosure
|
2 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Remote Privilege Escalation
|
1 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Configuration Download Information Disclosure
|
2 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Cookie Poisoning Authentication Bypass
|
2 |
WEB
|
Neurogenesia
|