2021-06-02
|
|
GetSimple CMS 3.3.4 - Information Disclosure
|
1 |
WEB
|
Ron Jost
|
2021-06-02
|
|
Apache Airflow 1.10.10 - 'Example Dag' Remote Code Execution
|
2 |
WEB
|
Pepe Berba
|
2021-06-02
|
|
Thecus N4800Eco Nas Server Control Panel - Comand Injection
|
1 |
WEB
|
Metin Yunus Kandemir
|
2021-06-01
|
|
Atlassian Jira 8.15.0 - Information Disclosure (Username Enumeration)
|
1 |
WEB
|
Mohammed Aloraimi
|
2021-06-01
|
|
CHIYU TCP/IP Converter devices - CRLF injection
|
2 |
WEB
|
sirpedrotavares
|
2021-06-01
|
|
CHIYU IoT devices - 'Multiple' Cross-Site Scripting (XSS)
|
2 |
WEB
|
sirpedrotavares
|
2021-06-01
|
|
WordPress Plugin WP Prayer version 1.6.1 - 'prayer_messages' Stored Cross-Site Scripting (XSS) (Auth
|
2 |
WEB
|
Bastijn Ouwendijk
|
2021-06-01
|
|
Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF)
|
0 |
WEB
|
lated
|
2021-06-01
|
|
ProjeQtOr Project Management 9.1.4 - Remote Code Execution
|
2 |
WEB
|
Temel Demir
|
2021-06-01
|
|
LogonTracer 1.2.0 - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
g0ldm45k
|
2021-05-28
|
|
Selenium 3.141.59 - Remote Code Execution (Firefox/geckodriver)
|
2 |
WEB
|
Jon Stratton
|
2021-05-28
|
|
Trixbox 2.8.0.4 - 'lang' Path Traversal
|
2 |
WEB
|
Ron Jost
|
2021-05-28
|
|
Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
Ron Jost
|
2021-05-28
|
|
WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Captain_hook
|
2021-05-28
|
|
PHPFusion 9.03.50 - Remote Code Execution
|
2 |
WEB
|
g0ldm45k
|
2021-05-27
|
|
Postbird 0.8.4 - Javascript Injection
|
2 |
WEB
|
Debshubra Chakraborty
|
2021-05-26
|
|
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)
|
2 |
WEB
|
Ron Jost
|
2021-05-26
|
|
Codiad 2.8.4 - Remote Code Execution (Authenticated) (3)
|
2 |
WEB
|
Ron Jost
|
2021-05-25
|
|
WordPress Plugin Cookie Law Bar 1.2.1 - 'clb_bar_msg' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Mesut Cetin
|
2021-05-25
|
|
Gadget Works Online Ordering System 1.0 - 'Category' Persistent Cross-Site Scripting (XSS)
|
2 |
WEB
|
Vinay H C
|
2021-05-24
|
|
WordPress Plugin ReDi Restaurant Reservation 21.0307 - 'Comment' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Bastijn Ouwendijk
|
2021-05-24
|
|
Codiad 2.8.4 - Remote Code Execution (Authenticated) (2)
|
2 |
WEB
|
Ron Jost
|
2021-05-24
|
|
Shopizer 2.16.0 - 'Multiple' Cross-Site Scripting (XSS)
|
1 |
WEB
|
Marek Toth
|
2021-05-24
|
|
Schlix CMS 2.2.6-6 - Arbitary File Upload (Authenticated)
|
2 |
WEB
|
Emir Polat
|
2021-05-21
|
|
Microsoft Exchange 2019 - Unauthenticated Email Download (Metasploit)
|
2 |
WEB
|
mekhalleh
|
2021-05-21
|
|
WordPress Plugin WP Statistics 13.0.7 - Time-Based Blind SQL Injection (Unauthenticated)
|
1 |
WEB
|
Mansoor R
|
2021-05-21
|
|
Spotweb 1.4.9 - DOM Based Cross-Site Scripting (XSS)
|
2 |
WEB
|
nu11secur1ty
|
2021-05-19
|
|
COVID19 Testing Management System 1.0 - 'Admin name' Cross-Site Scripting (XSS)
|
1 |
WEB
|
Rohit Burke
|
2021-05-19
|
|
COVID19 Testing Management System 1.0 - SQL Injection (Auth Bypass)
|
2 |
WEB
|
Rohit Burke
|
2021-05-19
|
|
ManageEngine ADSelfService Plus 6.1 - CSV Injection
|
2 |
WEB
|
Metin Yunus Kandemir
|
2021-05-19
|
|
In4Suit ERP 3.2.74.1370 - 'txtLoginId' SQL injection
|
2 |
WEB
|
Gulab Mondal
|
2021-05-19
|
|
WordPress Plugin Stop Spammers 2021.8 - 'log' Reflected Cross-site Scripting (XSS)
|
2 |
WEB
|
Hosein Vita
|
2021-05-18
|
|
Microsoft Exchange 2019 - Unauthenticated Email Download
|
2 |
WEB
|
Gonzalo Villegas
|
2021-05-18
|
|
EgavilanMedia PHPCRUD 1.0 - 'First Name' SQL Injection
|
1 |
WEB
|
Dimitrios Mitakos
|
2021-05-17
|
|
Printable Staff ID Card Creator System 1.0 - 'email' SQL Injection
|
1 |
WEB
|
bwnz
|
2021-05-17
|
|
Subrion CMS 4.2.1 - Arbitrary File Upload
|
2 |
WEB
|
Fellipe Oliveira
|
2021-05-17
|
|
Advanced Guestbook 2.4.4 - 'Smilies' Persistent Cross-Site Scripting (XSS)
|
2 |
WEB
|
Abdulkadir AYDOGAN
|
2021-05-17
|
|
Billing Management System 2.0 - Union based SQL injection (Authenticated)
|
2 |
WEB
|
Mohammad Koochaki
|
2021-05-17
|
|
Simple Chatbot Application 1.0 - 'Category' Stored Cross site Scripting
|
1 |
WEB
|
Vani K G
|
2021-05-17
|
|
Dental Clinic Appointment Reservation System 1.0 - Cross Site Request Forgery (Add Admin)
|
0 |
WEB
|
Reza Afsahi
|
2021-05-17
|
|
Dental Clinic Appointment Reservation System 1.0 - 'Firstname' Persistent Cross Site Scripting (Auth
|
1 |
WEB
|
Reza Afsahi
|
2021-05-17
|
|
IPFire 2.25 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Mücahit Saratar
|
2021-05-17
|
|
Customer Relationship Management (CRM) System 1.0 - 'Category' Persistent Cross site Scripting
|
1 |
WEB
|
Vani K G
|
2021-05-14
|
|
Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
M. Cory Billington
|
2021-05-14
|
|
Podcast Generator 3.1 - 'Long Description' Persistent Cross-Site Scripting (XSS)
|
1 |
WEB
|
Ayşenur KARAASLAN
|
2021-05-14
|
|
Student Management System 1.0 - 'message' Persistent Cross-Site Scripting (Authenticated)
|
0 |
WEB
|
mohsen khashei
|
2021-05-13
|
|
ZeroShell 3.9.0 - Remote Command Execution
|
1 |
WEB
|
Fellipe Oliveira
|
2021-05-13
|
|
Dental Clinic Appointment Reservation System 1.0 - 'date' UNION based SQL Injection (Authenticated)
|
2 |
WEB
|
Mesut Cetin
|
2021-05-13
|
|
Dental Clinic Appointment Reservation System 1.0 - Authentication Bypass (SQLi)
|
2 |
WEB
|
Mesut Cetin
|
2021-05-12
|
|
Chevereto 3.17.1 - Cross Site Scripting (Stored)
|
2 |
WEB
|
Akıner Kısa
|
2021-05-10
|
|
Microweber CMS 1.1.20 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
sl1nki
|
2021-05-10
|
|
Human Resource Information System 0.1 - 'First Name' Persistent Cross-Site Scripting (Authenticate
|
0 |
WEB
|
Reza Afsahi
|
2021-05-10
|
|
PHP Timeclock 1.04 - 'Multiple' Cross Site Scripting (XSS)
|
2 |
WEB
|
Tyler Butler
|
2021-05-07
|
|
PHP Timeclock 1.04 - Time and Boolean Based Blind SQL Injection
|
1 |
WEB
|
Tyler Butler
|
2021-05-07
|
|
Human Resource Information System 0.1 - Remote Code Execution (Unauthenticated)
|
1 |
WEB
|
Reza Afsahi
|
2021-05-07
|
|
Voting System 1.0 - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
secure77
|
2021-05-07
|
|
Voting System 1.0 - Authentication Bypass (SQLI)
|
1 |
WEB
|
secure77
|
2021-05-06
|
|
b2evolution 7-2-2 - 'cf_name' SQL Injection
|
1 |
WEB
|
nu11secur1ty
|
2021-05-06
|
|
Wordpress Plugin WP Super Edit 2.5.4 - Remote File Upload
|
2 |
WEB
|
h4shur
|
2021-05-06
|
|
Schlix CMS 2.2.6-6 - Remote Code Execution (Authenticated)
|
2 |
WEB
|
Eren Saraç
|
2021-05-06
|
|
Schlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated)
|
2 |
WEB
|
Emircan Baş
|
2021-05-05
|
|
Anote 1.0 - Persistent Cross-Site Scripting
|
0 |
WEB
|
TaurusOmar
|
2021-05-05
|
|
Markdownify 1.2.0 - Persistent Cross-Site Scripting
|
1 |
WEB
|
TaurusOmar
|
2021-05-05
|
|
Markright 1.0 - Persistent Cross-Site Scripting
|
0 |
WEB
|
TaurusOmar
|
2021-05-05
|
|
Freeter 1.2.1 - Persistent Cross-Site Scripting
|
0 |
WEB
|
TaurusOmar
|
2021-05-05
|
|
StudyMD 0.3.2 - Persistent Cross-Site Scripting
|
0 |
WEB
|
TaurusOmar
|
2021-05-05
|
|
Marky 0.0.1 - Persistent Cross-Site Scripting
|
0 |
WEB
|
TaurusOmar
|
2021-05-05
|
|
Moeditor 0.2.0 - Persistent Cross-Site Scripting
|
0 |
WEB
|
TaurusOmar
|
2021-05-05
|
|
SnipCommand 0.1.0 - Persistent Cross-Site Scripting
|
0 |
WEB
|
TaurusOmar
|
2021-05-05
|
|
Tagstoo 2.0.1 - Persistent Cross-Site Scripting
|
0 |
WEB
|
TaurusOmar
|
2021-05-05
|
|
Xmind 2020 - Persistent Cross-Site Scripting
|
1 |
WEB
|
TaurusOmar
|
2021-05-05
|
|
Markdown Explorer 0.1.1 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Taurus Omar
|
2021-05-05
|
|
Savsoft Quiz 5 - 'User Account Settings' Persistent Cross-Site Scripting
|
2 |
WEB
|
strider
|
2021-05-04
|
|
Internship Portal Management System 1.0 - Remote Code Execution(Unauthenticated)
|
2 |
WEB
|
argenestel
|
2021-05-03
|
|
GitLab Community Edition (CE) 13.10.3 - 'Sign_Up' User Enumeration
|
2 |
WEB
|
4D0niiS
|
2021-05-03
|
|
GitLab Community Edition (CE) 13.10.3 - User Enumeration
|
0 |
WEB
|
4D0niiS
|
2021-05-03
|
|
Piwigo 11.3.0 - 'language' SQL
|
1 |
WEB
|
nu11secur1ty
|
2021-05-03
|
|
Voting System 1.0 - Time based SQLI (Unauthenticated SQL injection)
|
1 |
WEB
|
Syed Sheeraz Ali
|
2021-05-03
|
|
GetSimple CMS Custom JS 0.1 - Cross-Site Request Forgery
|
1 |
WEB
|
boku
|
2021-04-30
|
|
Moodle 3.6.1 - Persistent Cross-Site Scripting (XSS)
|
1 |
WEB
|
Fariskhi Vidyan
|
2021-04-29
|
|
NodeBB Plugin Emoji 3.2.1 - Arbitrary File Write
|
0 |
WEB
|
1F98D
|
2021-04-29
|
|
FOGProject 1.5.9 - File Upload RCE (Authenticated)
|
1 |
WEB
|
sml
|
2021-04-29
|
|
Cacti 1.2.12 - 'filter' SQL Injection
|
1 |
WEB
|
Leonardo Paiva
|
2021-04-28
|
|
Kirby CMS 3.5.3.1 - 'file' Cross-Site Scripting (XSS)
|
1 |
WEB
|
Sreenath Raghunathan
|
2021-04-27
|
|
Montiorr 1.7.6m - Persistent Cross-Site Scripting
|
1 |
WEB
|
Ahmad Shakla
|
2021-04-27
|
|
Kimai 1.14 - CSV Injection
|
1 |
WEB
|
Mohammed Aloraimi
|
2021-04-26
|
|
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (2)
|
1 |
WEB
|
nu11secur1ty
|
2021-04-26
|
|
OpenPLC 3 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Fellipe Oliveira
|
2021-04-26
|
|
Hasura GraphQL 1.3.3 - Remote Code Execution
|
1 |
WEB
|
Dolev Farhi
|
2021-04-23
|
|
Sipwise C5 NGCP CSC - Click2Dial Cross-Site Request Forgery (CSRF)
|
1 |
WEB
|
LiquidWorm
|
2021-04-23
|
|
Sipwise C5 NGCP CSC - 'Multiple' Persistent Cross-Site Scripting (XSS)
|
0 |
WEB
|
LiquidWorm
|
2021-04-23
|
|
DzzOffice 2.02.1 - 'Multiple' Cross-Site Scripting (XSS)
|
0 |
WEB
|
nu11secur1ty
|
2021-04-23
|
|
GetSimple CMS My SMTP Contact Plugin 1.1.2 - Persistent Cross-Site Scripting
|
0 |
WEB
|
boku
|
2021-04-23
|
|
Moodle 3.10.3 - 'url' Persistent Cross Site Scripting
|
1 |
WEB
|
UVision
|
2021-04-22
|
|
RemoteClinic 2.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
1 |
WEB
|
Saud Ahmad
|
2021-04-22
|
|
OTRS 6.0.1 - Remote Command Execution (2)
|
1 |
WEB
|
Hex_26
|
2021-04-22
|
|
CMS Made Simple 2.2.15 - 'title' Cross-Site Scripting (XSS)
|
2 |
WEB
|
bt0
|
2021-04-21
|
|
Hasura GraphQL 1.3.3 - Service Side Request Forgery (SSRF)
|
2 |
WEB
|
Dolev Farhi
|
2021-04-21
|
|
Hasura GraphQL 1.3.3 - Local File Read
|
2 |
WEB
|
Dolev Farhi
|
2021-04-21
|
|
GravCMS 1.10.7 - Unauthenticated Arbitrary File Write (Metasploit)
|
2 |
WEB
|
Mehmet Ince
|
2021-04-21
|
|
Adtran Personal Phone Manager 10.8.1 - DNS Exfiltration
|
2 |
WEB
|
3ndG4me
|
2021-04-21
|
|
Adtran Personal Phone Manager 10.8.1 - 'Multiple' Reflected Cross-Site Scripting (XSS)
|
1 |
WEB
|
3ndG4me
|
2021-04-21
|
|
Adtran Personal Phone Manager 10.8.1 - 'emailAddress' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
3ndG4me
|
2021-04-21
|
|
OpenEMR 5.0.2.1 - Remote Code Execution
|
2 |
WEB
|
Hato0
|
2021-04-21
|
|
rconfig 3.9.6 - Arbitrary File Upload
|
2 |
WEB
|
Vishwaraj Bhattrai
|
2021-04-21
|
|
RemoteClinic 2 - 'Multiple' Cross-Site Scripting (XSS)
|
2 |
WEB
|
nu11secur1ty
|
2021-04-21
|
|
BlackCat CMS 1.3.6 - 'Multiple' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Ömer Hasan Durmuş
|
2021-04-21
|
|
WordPress Plugin RSS for Yandex Turbo 1.29 - Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
Himamshu Dilip Kulkarni
|
2021-04-21
|
|
Fast PHP Chat 1.3 - 'my_item_search' SQL Injection
|
2 |
WEB
|
Fatih Coskun
|
2021-04-21
|
|
Multilaser Router RE018 AC1200 - Cross-Site Request Forgery (Enable Remote Access)
|
2 |
WEB
|
Rodolfo Mariano
|
2021-04-16
|
|
GetSimple CMS My SMTP Contact Plugin 1.1.1 - Cross-Site Request Forgery
|
3 |
WEB
|
boku
|
2021-04-15
|
|
htmly 2.8.0 - 'description' Stored Cross-Site Scripting (XSS)
|
2 |
WEB
|
nu11secur1ty
|
2021-04-15
|
|
Tileserver-gl 3.0.0 - 'key' Reflected Cross-Site Scripting (XSS)
|
1 |
WEB
|
Akash Chathoth
|
2021-04-15
|
|
Horde Groupware Webmail 5.2.22 - Stored XSS
|
1 |
WEB
|
nu11secur1ty
|
2021-04-14
|
|
jQuery 1.0.3 - Cross-Site Scripting (XSS)
|
1 |
WEB
|
Central InfoSec
|
2021-04-14
|
|
jQuery 1.2 - Cross-Site Scripting (XSS)
|
1 |
WEB
|
Central InfoSec
|
2021-04-14
|
|
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE
|
0 |
WEB
|
Jay Sharma
|
2021-04-14
|
|
CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
|
1 |
WEB
|
skysbsb
|
2021-04-14
|
|
CITSmart ITSM 9.1.2.22 - LDAP Injection
|
2 |
WEB
|
skysbsb
|
2021-04-14
|
|
Digital Crime Report Management System 1.0 - SQL Injection (Authentication Bypass)
|
2 |
WEB
|
GaluhID
|
2021-04-13
|
|
ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow
|
2 |
WEB
|
Jai Kumar Sharma
|
2021-04-13
|
|
Blitar Tourism 1.0 - Authentication Bypass SQLi
|
2 |
WEB
|
sigeri94
|
2021-04-13
|
|
Simple Student Information System 1.0 - SQL Injection (Authentication Bypass)
|
2 |
WEB
|
GaluhID
|
2021-04-09
|
|
PrestaShop 1.7.6.7 - 'location' Blind Sql Injection
|
1 |
WEB
|
Vanshal Gaur
|
2021-04-08
|
|
Composr 10.0.36 - Remote Code Execution
|
2 |
WEB
|
Orion Hridoy
|