2021-07-13
|
|
Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
|
1 |
WEB
|
Central InfoSec
|
2021-07-13
|
|
Apache Tomcat 9.0.0.M1 - Open Redirect
|
1 |
WEB
|
Central InfoSec
|
2021-07-09
|
|
Zoo Management System 1.0 - 'Multiple' Persistent Cross-Site-Scripting (XSS)
|
0 |
WEB
|
Subhadip Nag
|
2021-07-09
|
|
Church Management System 1.0 - SQL Injection (Authentication Bypass) + Arbitrary File Upload + RCE
|
0 |
WEB
|
Eleonora Guardini
|
2021-07-08
|
|
Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (RCE) (Authenticated)
|
0 |
WEB
|
Ron Jost
|
2021-07-08
|
|
Online Covid Vaccination Scheduler System 1.0 - Arbitrary File Upload to Remote Code Execution (Unau
|
0 |
WEB
|
faisalfs10x
|
2021-07-08
|
|
Wyomind Help Desk 1.3.6 - Remote Code Execution (RCE)
|
0 |
WEB
|
Patrik Lantz
|
2021-07-08
|
|
Employee Record Management System 1.2 - Stored Cross-Site Scripting (XSS)
|
0 |
WEB
|
Subhadip Nag
|
2021-07-08
|
|
Exam Hall Management System 1.0 - Unrestricted File Upload + RCE (Unauthenticated)
|
0 |
WEB
|
Davide \'yth1n\' Bianchin
|
2021-07-07
|
|
WordPress Plugin Plainview Activity Monitor 20161228 - Remote Code Execution (RCE) (Authenticated) (
|
0 |
WEB
|
Beren Kuday GÖRÜN
|
2021-07-07
|
|
Online Covid Vaccination Scheduler System 1.0 - 'username' time-based blind SQL Injection
|
0 |
WEB
|
faisalfs10x
|
2021-07-07
|
|
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2)
|
0 |
WEB
|
enox
|
2021-07-06
|
|
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 - Directory Traversal
|
0 |
WEB
|
TheSmuggler
|
2021-07-06
|
|
Phone Shop Sales Managements System 1.0 - Arbitrary File Upload
|
0 |
WEB
|
faisalfs10x
|
2021-07-06
|
|
Phone Shop Sales Managements System 1.0 - Authentication Bypass (SQLi)
|
0 |
WEB
|
faisalfs10x
|
2021-07-06
|
|
Visual Tools DVR VX16 4.2.28 - Local Privilege Escalation
|
1 |
WEB
|
Andrea D\'Ubaldo
|
2021-07-06
|
|
Exam Hall Management System 1.0 - Unrestricted File Upload (Unauthenticated)
|
1 |
WEB
|
Thamer Almohammadi
|
2021-07-06
|
|
Billing System Project 1.0 - Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
Talha DEMİRSOY
|
2021-07-06
|
|
Pallets Werkzeug 0.15.4 - Path Traversal
|
1 |
WEB
|
faisalfs10x
|
2021-07-06
|
|
Black Box Kvm Extender 3.4.31307 - Local File Inclusion
|
1 |
WEB
|
Ferhat Çil
|
2021-07-06
|
|
Netgear DGN2200v1 - Remote Command Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
SivertPL
|
2021-07-06
|
|
Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated)
|
1 |
WEB
|
Andrea D\'Ubaldo
|
2021-07-06
|
|
perfexcrm 1.10 - 'State' Stored Cross-site scripting (XSS)
|
1 |
WEB
|
Alhasan Abbas
|
2021-07-05
|
|
Ricon Industrial Cellular Router S9922XL - Remote Command Execution (RCE)
|
1 |
WEB
|
LiquidWorm
|
2021-07-05
|
|
TextPattern CMS 4.9.0-dev - Remote Command Execution (RCE) (Authenticated)
|
1 |
WEB
|
Mevlüt Akçam
|
2021-07-05
|
|
Simple Client Management System 1.0 - Remote Code Execution (RCE)
|
1 |
WEB
|
Ishan Saha
|
2021-07-05
|
|
Wordpress Plugin Backup Guard 1.5.8 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Ron Jost
|
2021-07-05
|
|
Church Management System 1.0 - 'password' SQL Injection (Authentication Bypass)
|
1 |
WEB
|
Murat DEMİRCİ
|
2021-07-05
|
|
Church Management System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Murat DEMİRCİ
|
2021-07-05
|
|
Church Management System 1.0 - Arbitrary File Upload (Authenticated)
|
1 |
WEB
|
Murat DEMİRCİ
|
2021-07-05
|
|
Online Birth Certificate System 1.1 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Subhadip Nag
|
2021-07-05
|
|
Online Voting System 1.0 - SQLi (Authentication Bypass) + Remote Code Execution (RCE)
|
1 |
WEB
|
Geiseric
|
2021-07-05
|
|
OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) (2)
|
1 |
WEB
|
Alexandre ZANNI
|
2021-07-05
|
|
WordPress Plugin WP Learn Manager 1.1.2 - Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Mohammed Adam
|
2021-07-02
|
|
Garbage Collection Management System 1.0 - SQL Injection (Unauthenticated)
|
1 |
WEB
|
ircashem
|
2021-07-02
|
|
Wordpress Plugin Modern Events Calendar 5.16.2 - Event export (Unauthenticated)
|
0 |
WEB
|
Ron Jost
|
2021-07-02
|
|
Wordpress Plugin Modern Events Calendar 5.16.2 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Ron Jost
|
2021-07-02
|
|
b2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF)
|
1 |
WEB
|
Alperen Ergel
|
2021-07-02
|
|
AKCP sensorProbe SPX476 - 'Multiple' Cross-Site Scripting (XSS)
|
2 |
WEB
|
Tyler Butler
|
2021-07-02
|
|
Scratch Desktop 3.17 - Remote Code Execution
|
2 |
WEB
|
Stig Magnus Baugstø
|
2021-07-01
|
|
Vianeos OctoPUS 5 - 'login_user' SQLi
|
1 |
WEB
|
Audencia Business SCHOOL Red Team
|
2021-07-01
|
|
Wordpress Plugin XCloner 4.2.12 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Ron Jost
|
2021-07-01
|
|
Online Voting System 1.0 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Salman Asad
|
2021-07-01
|
|
Online Voting System 1.0 - Authentication Bypass (SQLi)
|
2 |
WEB
|
Salman Asad
|
2021-06-30
|
|
Doctors Patients Management System 1.0 - SQL Injection (Authentication Bypass)
|
2 |
WEB
|
Murat DEMİRCİ
|
2021-06-30
|
|
Simple Traffic Offense System 1.0 - Stored Cross Site Scripting (XSS)
|
2 |
WEB
|
Barış Yıldızoğlu
|
2021-06-30
|
|
Apache Superset 1.1.0 - Time-Based Account Enumeration
|
2 |
WEB
|
Dolev Farhi
|
2021-06-30
|
|
phpAbook 0.9i - SQL Injection
|
2 |
WEB
|
Alejandro Perez
|
2021-06-28
|
|
Netgear WNAP320 2.0.3 - 'macAddress' Remote Code Execution (RCE) (Unauthenticated)
|
2 |
WEB
|
Bryan Leong
|
2021-06-28
|
|
Atlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)
|
1 |
WEB
|
Captain_hook
|
2021-06-28
|
|
WordPress Plugin YOP Polls 6.2.7 - Stored Cross Site Scripting (XSS)
|
2 |
WEB
|
Toby Jackson
|
2021-06-25
|
|
Lightweight facebook-styled blog 1.3 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
|
2 |
WEB
|
Maide Ilkay Aydogdu
|
2021-06-25
|
|
Simple Client Management System 1.0 - 'uemail' SQL Injection (Unauthenticated)
|
2 |
WEB
|
Barış Yıldızoğlu
|
2021-06-25
|
|
Seeddms 5.1.10 - Remote Command Execution (RCE) (Authenticated)
|
1 |
WEB
|
Bryan Leong
|
2021-06-24
|
|
TP-Link TL-WR841N - Command Injection
|
1 |
WEB
|
Koh You Liang
|
2021-06-24
|
|
Adobe ColdFusion 8 - Remote Command Execution (RCE)
|
2 |
WEB
|
Pergyz
|
2021-06-24
|
|
VMware vCenter Server 7.0 - Remote Code Execution (RCE) (Unauthenticated)
|
1 |
WEB
|
CHackA0101
|
2021-06-23
|
|
Simple CRM 3.0 - 'email' SQL injection (Authentication Bypass)
|
2 |
WEB
|
Rinku Kumar
|
2021-06-23
|
|
Online Library Management System 1.0 - Arbitrary File Upload Remote Code Execution (Unauthenticated)
|
1 |
WEB
|
Berk Can Geyikci
|
2021-06-23
|
|
Online Library Management System 1.0 - 'Search' SQL Injection
|
1 |
WEB
|
Berk Can Geyikci
|
2021-06-23
|
|
WordPress Plugin Poll_ Survey_ Questionnaire and Voting system 1.5.2 - 'date_answers' Blind SQL Inje
|
2 |
WEB
|
Toby Jackson
|
2021-06-23
|
|
WordPress Plugin WP Google Maps 8.1.11 - Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Mohammed Adam
|
2021-06-22
|
|
Phone Shop Sales Managements System 1.0 - Insecure Direct Object Reference (IDOR)
|
2 |
WEB
|
Pratik Khalane
|
2021-06-22
|
|
Responsive Tourism Website 3.1 - Remote Code Execution (RCE) (Unauthenticated)
|
0 |
WEB
|
Tagoletta
|
2021-06-21
|
|
Customer Relationship Management System (CRM) 1.0 - Remote Code Execution
|
0 |
WEB
|
Ishan Saha
|
2021-06-21
|
|
Simple CRM 3.0 - 'name' Stored Cross site scripting (XSS)
|
1 |
WEB
|
Riadh Benlamine
|
2021-06-21
|
|
Simple CRM 3.0 - 'Change user information' Cross-Site Request Forgery (CSRF)
|
2 |
WEB
|
Riadh Benlamine
|
2021-06-21
|
|
Websvn 2.6.0 - Remote Code Execution (Unauthenticated)
|
1 |
WEB
|
g0ldm45k
|
2021-06-21
|
|
OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated)
|
1 |
WEB
|
Ron Jost
|
2021-06-18
|
|
Node.JS - 'node-serialize' Remote Code Execution (3)
|
1 |
WEB
|
Beren Kuday GÖRÜN
|
2021-06-18
|
|
ICE Hrm 29.0.0.OS - 'xml upload' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Piyush Patil
|
2021-06-18
|
|
ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Request Forgery (CSRF)
|
2 |
WEB
|
Piyush Patil
|
2021-06-17
|
|
Online Shopping Portal 3.1 - Remote Code Execution (Unauthenticated)
|
1 |
WEB
|
Tagoletta
|
2021-06-17
|
|
Zoho ManageEngine ServiceDesk Plus MSP 9.4 - User Enumeration
|
1 |
WEB
|
Ricardo Ruiz
|
2021-06-17
|
|
Unified Office Total Connect Now 1.0 - 'data' SQL Injection
|
1 |
WEB
|
Ajaikumar Nadar
|
2021-06-16
|
|
CKEditor 3 - Server-Side Request Forgery (SSRF)
|
1 |
WEB
|
ahmed
|
2021-06-16
|
|
Teachers Record Management System 1.0 - 'email' Stored Cross-site Scripting (XSS)
|
2 |
WEB
|
nhattruong
|
2021-06-16
|
|
Teachers Record Management System 1.0 - 'Multiple' SQL Injection (Authenticated)
|
2 |
WEB
|
nhattruong
|
2021-06-16
|
|
OpenEMR 5.0.1.3 - Authentication Bypass
|
2 |
WEB
|
Ron Jost
|
2021-06-16
|
|
Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting
|
1 |
WEB
|
Fatih İLGİN
|
2021-06-15
|
|
Client Management System 1.1 - 'Search' SQL Injection
|
1 |
WEB
|
BHAVESH KAUL
|
2021-06-15
|
|
Client Management System 1.1 - 'username' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
BHAVESH KAUL
|
2021-06-14
|
|
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated)
|
1 |
WEB
|
Ron Jost
|
2021-06-14
|
|
TextPattern CMS 4.8.7 - Remote Command Execution (Authenticated)
|
0 |
WEB
|
Mert Daş
|
2021-06-14
|
|
Small CRM 3.0 - 'Authentication Bypass' SQL Injection
|
1 |
WEB
|
BHAVESH KAUL
|
2021-06-14
|
|
Stock Management System 1.0 - 'user_id' Blind SQL injection (Authenticated)
|
1 |
WEB
|
Riadh Benlamine
|
2021-06-14
|
|
COVID19 Testing Management System 1.0 - 'State' Stored Cross-Site-Scripting (XSS)
|
1 |
WEB
|
BHAVESH KAUL
|
2021-06-14
|
|
GLPI 9.4.5 - Remote Code Execution (RCE)
|
1 |
WEB
|
Brian Peters
|
2021-06-14
|
|
Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure Direct Object References (IDOR)
|
1 |
WEB
|
Abdulazeez Alaseeri
|
2021-06-14
|
|
Accela Civic Platform 21.1 - 'successURL' Cross-Site-Scripting (XSS)
|
1 |
WEB
|
Abdulazeez Alaseeri
|
2021-06-11
|
|
WoWonder Social Network Platform 3.1 - Authentication Bypass
|
1 |
WEB
|
securityforeveryone.com
|
2021-06-11
|
|
Zenario CMS 8.8.52729 - 'cID' SQL injection (Authenticated)
|
1 |
WEB
|
Avinash R
|
2021-06-11
|
|
Solar-Log 500 2.8.2 - Unprotected Storage of Credentials
|
0 |
WEB
|
Luca.Chiou
|
2021-06-11
|
|
Solar-Log 500 2.8.2 - Incorrect Access Control
|
1 |
WEB
|
Luca.Chiou
|
2021-06-11
|
|
Grocery crud 1.6.4 - 'order_by' SQL Injection
|
2 |
WEB
|
TonyShavez
|
2021-06-11
|
|
WordPress Plugin Database Backups 1.2.2.6 - 'Database Backup Download' CSRF
|
2 |
WEB
|
0xB9
|
2021-06-11
|
|
OpenEMR 5.0.0 - Remote Code Execution (Authenticated)
|
2 |
WEB
|
Ron Jost
|
2021-06-11
|
|
Microsoft SharePoint Server 16.0.10372.20060 - 'GetXmlDataFromDataSource' Server-Side Request Forger
|
2 |
WEB
|
Alex Birnberg
|
2021-06-11
|
|
Cerberus FTP Web Service 11 - 'svg' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Mohammad Hossein Kaviyany
|
2021-06-11
|
|
Accela Civic Platform 21.1 - 'servProvCode' Cross-Site-Scripting (XSS)
|
2 |
WEB
|
Abdulazeez Alaseeri
|
2021-06-10
|
|
TextPattern CMS 4.8.7 - Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Mert Daş
|
2021-06-10
|
|
Student Result Management System 1.0 - 'class' SQL Injection
|
2 |
WEB
|
Riadh Benlamine
|
2021-06-09
|
|
GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)
|
2 |
WEB
|
legend
|
2021-06-09
|
|
WordPress Plugin visitors-app 0.3 - 'user-agent' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Mesut Cetin
|
2021-06-09
|
|
OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
|
2 |
WEB
|
Mert Daş
|
2021-06-09
|
|
OpenCart 3.0.3.7 - 'Change Password' Cross-Site Request Forgery (CSRF)
|
2 |
WEB
|
Mert Daş
|
2021-06-09
|
|
Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF)
|
2 |
WEB
|
Rodolfo Mariano
|
2021-06-08
|
|
WordPress Plugin wpDiscuz 7.0.4 - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
Fellipe Oliveira
|
2021-06-07
|
|
Wordpress Plugin wpDiscuz 7.0.4 - Arbitrary File Upload (Unauthenticated)
|
2 |
WEB
|
UnD3sc0n0c1d0
|
2021-06-07
|
|
Grav CMS 1.7.10 - Server-Side Template Injection (SSTI) (Authenticated)
|
2 |
WEB
|
enox
|
2021-06-07
|
|
Rocket.Chat 3.12.1 - NoSQL Injection (Unauthenticated)
|
1 |
WEB
|
enox
|
2021-06-07
|
|
WordPress Plugin Smart Slider-3 3.5.0.8 - 'name' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Hardik Solanki
|
2021-06-07
|
|
OptiLink ONT1GEW GPON 2.1.11_X101 Build 1127.190306 - Remote Code Execution (Authenticated)
|
2 |
WEB
|
SecNigma
|
2021-06-04
|
|
Gitlab 13.10.2 - Remote Code Execution (Authenticated)
|
2 |
WEB
|
enox
|
2021-06-04
|
|
Monstra CMS 3.0.4 - Remote Code Execution (Authenticated)
|
2 |
WEB
|
Ron Jost
|
2021-06-03
|
|
4Images 1.8 - 'redirect' Reflected XSS
|
2 |
WEB
|
Piyush Patil
|
2021-06-03
|
|
Gitlab 13.9.3 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
enox
|
2021-06-03
|
|
FUDForum 3.1.0 - 'author' Reflected XSS
|
1 |
WEB
|
Piyush Patil
|
2021-06-03
|
|
FUDForum 3.1.0 - 'srch' Reflected XSS
|
2 |
WEB
|
Piyush Patil
|
2021-06-03
|
|
CHIYU IoT Devices - Denial of Service (DoS)
|
1 |
WEB
|
sirpedrotavares
|
2021-06-03
|
|
Seo Panel 4.8.0 - 'from_time' Reflected XSS
|
2 |
WEB
|
Piyush Patil
|
2021-06-03
|
|
PHP 8.1.0-dev - 'User-Agentt' Remote Code Execution
|
2 |
WEB
|
flast101
|
2021-06-02
|
|
Seo Panel 4.8.0 - 'category' Reflected XSS
|
1 |
WEB
|
Piyush Patil
|
2021-06-02
|
|
Seo Panel 4.8.0 - 'search_name' Reflected XSS
|
2 |
WEB
|
Piyush Patil
|
2021-06-02
|
|
Products.PluggableAuthService 2.6.0 - Open Redirect
|
1 |
WEB
|
Piyush Patil
|