2021-09-13
|
|
ECOA Building Automation System - 'multiple' Cross-Site Request Forgery (CSRF)
|
2 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Directory Traversal Content Disclosure
|
2 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Path Traversal Arbitrary File Upload
|
2 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
ECOA Building Automation System - Weak Default Credentials
|
2 |
WEB
|
Neurogenesia
|
2021-09-13
|
|
Men Salon Management System 1.0 - Multiple Vulnerabilities
|
1 |
WEB
|
Aryan Chehreghani
|
2021-09-09
|
|
Bus Pass Management System 1.0 - 'adminname' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Emre Aslan
|
2021-09-08
|
|
WordPress Plugin TablePress 1.14 - CSV Injection
|
2 |
WEB
|
Nikhil Kapoor
|
2021-09-07
|
|
WordPress Plugin Survey & Poll 1.5.7.3 - 'sss_params' SQL Injection (2)
|
1 |
WEB
|
Mohin Paramasivam
|
2021-09-07
|
|
WordPress Plugin WP Sitemap Page 1.6.4 - Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Nikhil Kapoor
|
2021-09-06
|
|
Antminer Monitor 0.5.0 - Authentication Bypass
|
2 |
WEB
|
Vulnz
|
2021-09-06
|
|
Patient Appointment Scheduler System 1.0 - Persistent Cross-Site Scripting
|
2 |
WEB
|
a-rey
|
2021-09-06
|
|
Patient Appointment Scheduler System 1.0 - Unauthenticated File Upload
|
2 |
WEB
|
a-rey
|
2021-09-06
|
|
Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
|
2 |
WEB
|
sudoninja
|
2021-09-06
|
|
FlatCore CMS 2.0.7 - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
Mason Soroka-Gill
|
2021-09-06
|
|
OpenEMR 6.0.0 - 'noteid' Insecure Direct Object Reference (IDOR)
|
0 |
WEB
|
Allen Enosh Upputori
|
2021-09-03
|
|
OpenSIS 8.0 'modname' - Directory Traversal
|
2 |
WEB
|
Eric Salario
|
2021-09-02
|
|
WordPress Plugin Duplicate Page 4.4.1 - Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Nikhil Kapoor
|
2021-09-02
|
|
WPanel 4.3.1 - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
Sentinal920
|
2021-09-02
|
|
Compro Technology IP Camera - ' mjpegStreamer.cgi' Screenshot Disclosure
|
2 |
WEB
|
icekam
|
2021-09-02
|
|
Compro Technology IP Camera - ' index_MJpeg.cgi' Stream Disclosure
|
2 |
WEB
|
icekam
|
2021-09-02
|
|
Compro Technology IP Camera - 'Multiple' Credential Disclosure
|
2 |
WEB
|
icekam
|
2021-09-02
|
|
Compro Technology IP Camera - RTSP stream disclosure (Unauthenticated)
|
2 |
WEB
|
icekam
|
2021-09-02
|
|
Compro Technology IP Camera - 'killps.cgi' Denial of Service (DoS)
|
2 |
WEB
|
icekam
|
2021-09-02
|
|
OpenSIS Community 8.0 - 'cp_id_miss_attn' SQL Injection
|
2 |
WEB
|
Eric Salario
|
2021-09-02
|
|
Dolibarr ERP 14.0.1 - Privilege Escalation
|
2 |
WEB
|
Vishwaraj Bhattrai
|
2021-09-01
|
|
WordPress Plugin Payments Plugin | GetPaid 2.4.6 - HTML Injection
|
1 |
WEB
|
Niraj Mahajan
|
2021-09-01
|
|
Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
Tagoletta
|
2021-09-01
|
|
Confluence Server 7.12.4 - 'OGNL injection' Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
Fellipe Oliveira
|
2021-08-31
|
|
WordPress Plugin ProfilePress 3.1.3 - Privilege Escalation (Unauthenticated)
|
1 |
WEB
|
Numan Rajkotiya
|
2021-08-31
|
|
Umbraco CMS 8.9.1 - Directory Traversal
|
0 |
WEB
|
BitTheByte
|
2021-08-30
|
|
Projectsend r1295 - 'name' Stored XSS
|
2 |
WEB
|
Abdullah Kala
|
2021-08-30
|
|
Strapi CMS 3.0.0-beta.17.4 - Remote Code Execution (RCE) (Unauthenticated)
|
2 |
WEB
|
Musyoka Ian
|
2021-08-30
|
|
Strapi 3.0.0-beta.17.7 - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
David Utón
|
2021-08-30
|
|
Strapi 3.0.0-beta - Set Password (Unauthenticated)
|
1 |
WEB
|
David Anglada
|
2021-08-30
|
|
Bus Pass Management System 1.0 - 'viewid' SQL Injection
|
1 |
WEB
|
Aryan Chehreghani
|
2021-08-30
|
|
Usermin 1.820 - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
numan türle
|
2021-08-30
|
|
ZesleCP 3.1.9 - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
numan türle
|
2021-08-27
|
|
COMMAX UMS Client ActiveX Control 1.7.0.2 - 'CNC_Ctrl.dll' Heap Buffer Overflow
|
1 |
WEB
|
LiquidWorm
|
2021-08-27
|
|
COMMAX WebViewer ActiveX Control 2.1.4.5 - 'Commax_WebViewer.ocx' Buffer Overflow
|
1 |
WEB
|
LiquidWorm
|
2021-08-27
|
|
CyberPanel 2.1 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
numan türle
|
2021-08-26
|
|
ProcessMaker 3.5.4 - Local File inclusion
|
1 |
WEB
|
Ai Ho
|
2021-08-25
|
|
Online Leave Management System 1.0 - Arbitrary File Upload to Shell (Unauthenticated)
|
1 |
WEB
|
Justin White
|
2021-08-25
|
|
HP OfficeJet 4630/7110 MYM1FN2025AR/2117A - Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Tyler Butler
|
2021-08-25
|
|
WordPress Plugin Mail Masta 1.0 - Local File Inclusion (2)
|
1 |
WEB
|
Matheus Alexandre
|
2021-08-23
|
|
RaspAP 2.6.6 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
Moritz Gruber
|
2021-08-23
|
|
Simple Phone Book 1.0 - 'Username' SQL Injection (Unauthenticated)
|
1 |
WEB
|
Justin White
|
2021-08-23
|
|
Online Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
2 |
WEB
|
Halit AKAYDIN
|
2021-08-20
|
|
Laundry Booking Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Azumah Foresight Xorlali
|
2021-08-20
|
|
Laundry Booking Management System 1.0 - 'Multiple' SQL Injection
|
1 |
WEB
|
Azumah Foresight Xorlali
|
2021-08-20
|
|
Online Traffic Offense Management System 1.0 - 'id' SQL Injection (Authenticated)
|
1 |
WEB
|
Justin White
|
2021-08-19
|
|
Charity Management System CMS 1.0 - Multiple Vulnerabilities
|
1 |
WEB
|
Davide Taraschi
|
2021-08-18
|
|
COVID19 Testing Management System 1.0 - 'Multiple' SQL Injections
|
2 |
WEB
|
Halit AKAYDIN
|
2021-08-18
|
|
Simple Image Gallery 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
2 |
WEB
|
Tagoletta
|
2021-08-18
|
|
Crime records Management System 1.0 - 'Multiple' SQL Injection (Authenticated)
|
2 |
WEB
|
Davide Taraschi
|
2021-08-17
|
|
GeoVision Geowebserver 5.3.3 - Local FIle Inclusion
|
1 |
WEB
|
Ken Pyle
|
2021-08-16
|
|
COMMAX CVD-Axx DVR 5.1.4 - Weak Default Credentials Stream Disclosure
|
1 |
WEB
|
LiquidWorm
|
2021-08-16
|
|
COMMAX Smart Home Ruvie CCTV Bridge DVR Service - Config Write / DoS (Unauthenticated)
|
2 |
WEB
|
LiquidWorm
|
2021-08-16
|
|
COMMAX Smart Home Ruvie CCTV Bridge DVR Service - RTSP Credentials Disclosure
|
2 |
WEB
|
LiquidWorm
|
2021-08-16
|
|
COMMAX Smart Home IoT Control System CDP-1020n - SQL Injection Authentication Bypass
|
1 |
WEB
|
LiquidWorm
|
2021-08-16
|
|
COMMAX Biometric Access Control System 1.0.0 - Authentication Bypass
|
1 |
WEB
|
LiquidWorm
|
2021-08-16
|
|
Simple Water Refilling Station Management System 1.0 - Remote Code Execution (RCE) through File Uplo
|
0 |
WEB
|
Matt Sorrell
|
2021-08-16
|
|
Simple Water Refilling Station Management System 1.0 - Authentication Bypass
|
0 |
WEB
|
Matt Sorrell
|
2021-08-16
|
|
NetGear D1500 V1.0.0.21_1.0.1PE - 'Wireless Repeater' Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
Securityium
|
2021-08-16
|
|
CentOS Web Panel 0.9.8.1081 - Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
Dinesh Mohanty
|
2021-08-13
|
|
RATES SYSTEM 1.0 - Authentication Bypass
|
0 |
WEB
|
Azumah Foresight Xorlali
|
2021-08-13
|
|
Simple Image Gallery System 1.0 - 'id' SQL Injection
|
0 |
WEB
|
Azumah Foresight Xorlali
|
2021-08-13
|
|
Care2x Open Source Hospital Information Management 2.7 Alpha - 'Multiple' Stored XSS
|
0 |
WEB
|
securityforeveryone.com
|
2021-08-13
|
|
Police Crime Record Management System 1.0 - 'casedetails' SQL Injection
|
0 |
WEB
|
Ömer Hasan Durmuş
|
2021-08-13
|
|
Police Crime Record Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
Ömer Hasan Durmuş
|
2021-08-13
|
|
easy-mock 1.6.0 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
LionTree
|
2021-08-13
|
|
4images 1.8 - 'limitnumber' SQL Injection (Authenticated)
|
0 |
WEB
|
Andrey Stoykov
|
2021-08-12
|
|
RATES SYSTEM 1.0 - 'Multiple' SQL Injections
|
2 |
WEB
|
Halit AKAYDIN
|
2021-08-12
|
|
Altova MobileTogether Server 7.3 - XML External Entity Injection (XXE)
|
2 |
WEB
|
RedTeam Pentesting GmbH
|
2021-08-12
|
|
COVID19 Testing Management System 1.0 - 'searchdata' SQL Injection
|
2 |
WEB
|
Ashish Upsham
|
2021-08-10
|
|
Simple Library Management System 1.0 - 'rollno' SQL Injection
|
1 |
WEB
|
Halit AKAYDIN
|
2021-08-10
|
|
WordPress Plugin Picture Gallery 1.4.2 - 'Edit Content URL' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Aryan Chehreghani
|
2021-08-10
|
|
Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection
|
2 |
WEB
|
Brian Ombongi
|
2021-08-10
|
|
IPCop 2.1.9 - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
Mücahit Saratar
|
2021-08-05
|
|
GFI Mail Archiver 15.1 - Telerik UI Component Arbitrary File Upload (Unauthenticated)
|
2 |
WEB
|
Amin Bohio
|
2021-08-05
|
|
Moodle 3.9 - Remote Code Execution (RCE) (Authenticated)
|
2 |
WEB
|
lanz
|
2021-08-05
|
|
CMSuno 1.7 - 'tgo' Stored Cross-Site Scripting (XSS) (Authenticated)
|
2 |
WEB
|
splint3rsec
|
2021-08-04
|
|
ApacheOfBiz 17.12.01 - Remote Command Execution (RCE)
|
1 |
WEB
|
Adrián Díaz
|
2021-08-04
|
|
Client Management System 1.1 - 'cname' Stored Cross-site scripting (XSS)
|
1 |
WEB
|
Mohammad Koochaki
|
2021-08-04
|
|
qdPM 9.2 - Password Exposure (Unauthenticated)
|
0 |
WEB
|
Leon Trappett
|
2021-08-04
|
|
qdPM 9.1 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Leon Trappett
|
2021-08-04
|
|
WordPress Plugin WP Customize Login 1.1 - 'Change Logo Title' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Aryan Chehreghani
|
2021-08-03
|
|
Hotel Management System 1.0 - Cross-Site Scripting (XSS) Arbitrary File Upload Remote Code Execution
|
1 |
WEB
|
Merbin Russel
|
2021-08-02
|
|
Panasonic Sanyo CCTV Network Camera 2.03-0x - Cross-Site Request Forgery (Change Password)
|
1 |
WEB
|
LiquidWorm
|
2021-08-02
|
|
Online Hotel Reservation System 1.0 - 'Multiple' Cross-site scripting (XSS)
|
1 |
WEB
|
Mohammad Koochaki
|
2021-08-02
|
|
Men Salon Management System 1.0 - SQL Injection Authentication Bypass
|
1 |
WEB
|
Akshay Khanna
|
2021-07-29
|
|
Oracle Fatwire 6.3 - Multiple Vulnerabilities
|
1 |
WEB
|
J. Francisco Bolivar
|
2021-07-29
|
|
CloverDX 5.9.0 - Cross-Site Request Forgery (CSRF)
|
1 |
WEB
|
niebardzo
|
2021-07-29
|
|
Care2x Integrated Hospital Info System 2.7 - 'Multiple' SQL Injection
|
0 |
WEB
|
securityforeveryone.com
|
2021-07-29
|
|
IntelliChoice eFORCE Software Suite 2.5.9 - Username Enumeration
|
1 |
WEB
|
LiquidWorm
|
2021-07-29
|
|
Longjing Technology BEMS API 1.21 - Remote Arbitrary File Download
|
1 |
WEB
|
LiquidWorm
|
2021-07-29
|
|
Denver IP Camera SHO-110 - Unauthenticated Snapshot
|
2 |
WEB
|
Ivan Nikolsky
|
2021-07-28
|
|
TripSpark VEO Transportation - Blind SQL Injection
|
1 |
WEB
|
Sedric Louissaint
|
2021-07-28
|
|
Event Registration System with QR Code 1.0 - Authentication Bypass
|
1 |
WEB
|
Javier Olmedo
|
2021-07-27
|
|
Customer Relationship Management System (CRM) 1.0 - Sql Injection Authentication Bypass
|
1 |
WEB
|
Shafique_Wasta
|
2021-07-27
|
|
PHP 7.3.15-3 - 'PHP_SESSION_UPLOAD_PROGRESS' Session Data Injection
|
1 |
WEB
|
S1lv3r
|
2021-07-26
|
|
XOS Shop 1.0.9 - 'Multiple' Arbitrary File Deletion (Authenticated)
|
1 |
WEB
|
faisalfs10x
|
2021-07-26
|
|
NoteBurner 2.35 - Denial Of Service (DoS) (PoC)
|
1 |
WEB
|
stresser
|
2021-07-26
|
|
Elasticsearch ECE 7.13.3 - Anonymous Database Dump
|
1 |
WEB
|
Joan Martinez
|
2021-07-23
|
|
Microsoft SharePoint Server 2019 - Remote Code Execution (2)
|
1 |
WEB
|
Podalirius
|
2021-07-23
|
|
WordPress Plugin Simple Post 1.1 - 'Text field' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Vikas Srivastava
|
2021-07-23
|
|
ElasticSearch 7.13.3 - Memory disclosure
|
1 |
WEB
|
r0ny
|
2021-07-21
|
|
CSZ CMS 1.2.9 - 'Multiple' Arbitrary File Deletion
|
1 |
WEB
|
faisalfs10x
|
2021-07-21
|
|
KevinLAB BEMS 1.0 - File Path Traversal Information Disclosure (Authenticated)
|
1 |
WEB
|
LiquidWorm
|
2021-07-21
|
|
KevinLAB BEMS 1.0 - Authentication Bypass
|
1 |
WEB
|
LiquidWorm
|
2021-07-20
|
|
Webmin 1.973 - 'run.cgi' Cross-Site Request Forgery (CSRF)
|
2 |
WEB
|
Mesh3l_911
|
2021-07-20
|
|
WordPress Plugin KN Fix Your Title 1.0.1 - 'Separator' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Aakash Choudhary
|
2021-07-19
|
|
PEEL Shopping 9.3.0 - 'id' Time-based SQL Injection
|
1 |
WEB
|
faisalfs10x
|
2021-07-19
|
|
WordPress Plugin Mimetic Books 0.2.13 - 'Default Publisher ID field' Stored Cross-Site Scripting (XS
|
1 |
WEB
|
Vikas Srivastava
|
2021-07-19
|
|
WordPress Plugin LearnPress 3.2.6.8 - Privilege Escalation
|
2 |
WEB
|
nhattruong
|
2021-07-19
|
|
WordPress Plugin LearnPress 3.2.6.7 - 'current_items' SQL Injection (Authenticated)
|
3 |
WEB
|
nhattruong
|
2021-07-16
|
|
Seagate BlackArmor NAS sg2000-2000.1331 - Command Injection
|
0 |
WEB
|
Metin Yunus Kandemir
|
2021-07-16
|
|
ForgeRock Access Manager 14.6.3 - Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
Photubias
|
2021-07-15
|
|
WordPress Plugin Popular Posts 5.3.2 - Remote Code Execution (RCE) (Authenticated)
|
1 |
WEB
|
Simone Cristofaro
|
2021-07-15
|
|
osCommerce 2.3.4.1 - Remote Code Execution (2)
|
2 |
WEB
|
Bryan Leong
|
2021-07-14
|
|
WordPress Plugin Current Book 1.0.1 - 'Book Title' Persistent Cross-Site Scripting
|
1 |
WEB
|
Vikas Srivastava
|
2021-07-14
|
|
Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)
|
1 |
WEB
|
Mesh3l_911
|
2021-07-13
|
|
Garbage Collection Management System 1.0 - SQL Injection + Arbitrary File Upload
|
1 |
WEB
|
Luca Bernardi
|
2021-07-13
|
|
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2)
|
1 |
WEB
|
Alexandre ZANNI
|
2021-07-13
|
|
Invoice System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Subhadip Nag
|
2021-07-13
|
|
WordPress Plugin WPFront Notification Bar 1.9.1.04012 - Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Swapnil Subhash Bodekar
|