2021-04-14
|
|
CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
|
2 |
WEB
|
skysbsb
|
2021-04-14
|
|
CITSmart ITSM 9.1.2.22 - LDAP Injection
|
2 |
WEB
|
skysbsb
|
2021-04-14
|
|
Digital Crime Report Management System 1.0 - SQL Injection (Authentication Bypass)
|
2 |
WEB
|
GaluhID
|
2021-04-13
|
|
ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow
|
2 |
WEB
|
Jai Kumar Sharma
|
2021-04-13
|
|
Blitar Tourism 1.0 - Authentication Bypass SQLi
|
2 |
WEB
|
sigeri94
|
2021-04-13
|
|
Simple Student Information System 1.0 - SQL Injection (Authentication Bypass)
|
2 |
WEB
|
GaluhID
|
2021-04-09
|
|
PrestaShop 1.7.6.7 - 'location' Blind Sql Injection
|
1 |
WEB
|
Vanshal Gaur
|
2021-04-08
|
|
Composr 10.0.36 - Remote Code Execution
|
2 |
WEB
|
Orion Hridoy
|
2021-04-08
|
|
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
|
2 |
WEB
|
Issac Briones
|
2021-04-08
|
|
CMSimple 5.2 - 'External' Stored XSS
|
1 |
WEB
|
Quadron Research Lab
|
2021-04-07
|
|
Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
|
2 |
WEB
|
Rhino Security Labs
|
2021-04-07
|
|
Composr CMS 10.0.36 - Cross Site Scripting
|
2 |
WEB
|
Orion Hridoy
|
2021-04-07
|
|
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
|
1 |
WEB
|
Captain_hook
|
2021-04-06
|
|
Mini Mouse 9.3.0 - Local File inclusion
|
1 |
WEB
|
gosh
|
2021-04-05
|
|
Mini Mouse 9.2.0 - Path Traversal
|
0 |
WEB
|
gosh
|
2021-04-05
|
|
Mini Mouse 9.2.0 - Remote Code Execution
|
1 |
WEB
|
gosh
|
2021-04-05
|
|
OpenEMR 4.1.0 - 'u' SQL Injection
|
2 |
WEB
|
Michael Ikua
|
2021-04-05
|
|
Basic Shopping Cart 1.0 - Authentication Bypass
|
1 |
WEB
|
Viren Saroha
|
2021-04-05
|
|
Simple Food Website 1.0 - Authentication Bypass
|
0 |
WEB
|
Viren Saroha
|
2021-04-02
|
|
F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated)
|
1 |
WEB
|
Al1ex
|
2021-04-02
|
|
ZBL EPON ONU Broadband Router 1.0 - Remote Privilege Escalation
|
2 |
WEB
|
LiquidWorm
|
2021-04-01
|
|
phpPgAdmin 7.13.0 - COPY FROM PROGRAM Command Execution (Authenticated)
|
3 |
WEB
|
Valerio Severini
|
2021-04-01
|
|
ScadaBR 1.0 - Arbitrary File Upload (Authenticated) (2)
|
1 |
WEB
|
Fellipe Oliveira
|
2021-04-01
|
|
ScadaBR 1.0 - Arbitrary File Upload (Authenticated) (1)
|
1 |
WEB
|
Fellipe Oliveira
|
2021-04-01
|
|
Latrix 0.6.0 - 'txtaccesscode' SQL Injection
|
2 |
WEB
|
cptsticky
|
2021-03-31
|
|
CourseMS 2.1 - 'name' Stored XSS
|
1 |
WEB
|
cptsticky
|
2021-03-31
|
|
Zabbix 3.4.7 - Stored XSS
|
1 |
WEB
|
Radmil Gazizov
|
2021-03-30
|
|
Openlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting
|
1 |
WEB
|
cmOs
|
2021-03-30
|
|
GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting
|
2 |
WEB
|
boku
|
2021-03-29
|
|
SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow
|
1 |
WEB
|
Filipe Oliveira
|
2021-03-29
|
|
Novel Boutique House-plus 3.5.1 - Arbitrary File Download
|
1 |
WEB
|
tuyiqiang
|
2021-03-29
|
|
Budget Management System 1.0 - 'Budget title' Stored XSS
|
1 |
WEB
|
Jitendra Kumar Tripathi
|
2021-03-29
|
|
Equipment Inventory System 1.0 - 'multiple' Stored XSS
|
2 |
WEB
|
Jitendra Kumar Tripathi
|
2021-03-29
|
|
Concrete5 8.5.4 - 'name' Stored XSS
|
1 |
WEB
|
Quadron Research Lab
|
2021-03-29
|
|
TP-Link Devices - 'setDefaultHostname' Stored Cross-site Scripting (Unauthenticated)
|
1 |
WEB
|
Smriti Gaba
|
2021-03-29
|
|
WordPress Plugin WP Super Cache 1.7.1 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
m0ze
|
2021-03-26
|
|
Moodle 3.10.3 - 'label' Persistent Cross Site Scripting
|
1 |
WEB
|
Vincent666
|
2021-03-26
|
|
Regis Inventory And Monitoring System 1.0 - 'Item List' Persistent Cross-Site Scripting
|
1 |
WEB
|
George Tsimpidas
|
2021-03-26
|
|
'customhs_js_content' - 'customhs_js_content' Cross-Site Request Forgery
|
1 |
WEB
|
Abhishek Joshi
|
2021-03-25
|
|
Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
|
1 |
WEB
|
Andrea Gonzalez
|
2021-03-25
|
|
Genexis Platinum-4410 P4410-V2-1.31A - 'start_addr' Persistent Cross-Site Scripting
|
1 |
WEB
|
Jithin KS
|
2021-03-25
|
|
Linksys EA7500 2.0.8.194281 - Cross-Site Scripting
|
0 |
WEB
|
MiningOmerta
|
2021-03-25
|
|
Ovidentia 6 - 'id' SQL injection (Authenticated)
|
1 |
WEB
|
Felipe Prates Donato
|
2021-03-23
|
|
Codiad 2.8.4 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
WangYihang
|
2021-03-23
|
|
Hotel And Lodge Management System 1.0 - 'Customer Details' Stored XSS
|
2 |
WEB
|
Jitendra Kumar Tripathi
|
2021-03-23
|
|
MyBB 1.8.25 - Poll Vote Count SQL Injection
|
1 |
WEB
|
SivertPL
|
2021-03-22
|
|
MyBB 1.8.25 - Chained Remote Command Execution
|
1 |
WEB
|
SivertPL
|
2021-03-22
|
|
WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
|
1 |
WEB
|
Nicholas Ferreira
|
2021-03-19
|
|
Online News Portal 1.0 - 'Multiple' Stored Cross-Site Scripting
|
1 |
WEB
|
Richard Jones
|
2021-03-19
|
|
Online News Portal 1.0 - 'name' SQL Injection
|
2 |
WEB
|
Richard Jones
|
2021-03-19
|
|
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Config Download (Unauthenticated)
|
2 |
WEB
|
LiquidWorm
|
2021-03-19
|
|
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Factory Reset (Unauthenticated)
|
2 |
WEB
|
LiquidWorm
|
2021-03-19
|
|
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Remote Code Execution
|
2 |
WEB
|
LiquidWorm
|
2021-03-19
|
|
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Authentication Bypass
|
1 |
WEB
|
LiquidWorm
|
2021-03-19
|
|
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 - Command Injection (Authenticated)
|
1 |
WEB
|
LiquidWorm
|
2021-03-19
|
|
SOYAL Biometric Access Control System 5.0 - 'Change Admin Password' CSRF
|
1 |
WEB
|
LiquidWorm
|
2021-03-19
|
|
SOYAL Biometric Access Control System 5.0 - Master Code Disclosure
|
2 |
WEB
|
LiquidWorm
|
2021-03-19
|
|
CouchCMS 2.2.1 - Server-Side Request Forgery
|
2 |
WEB
|
xxcdd
|
2021-03-19
|
|
VestaCP 0.9.8 - 'v_sftp_licence' Command Injection
|
1 |
WEB
|
numan türle
|
2021-03-19
|
|
Profiling System for Human Resource Management 1.0 - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
Christian Vierschilling
|
2021-03-19
|
|
Boonex Dolphin 7.4.2 - 'width' Stored XSS
|
0 |
WEB
|
Piyush Patil
|
2021-03-19
|
|
LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS
|
2 |
WEB
|
Clément Cruchet
|
2021-03-19
|
|
Plone CMS 5.2.3 - 'Title' Stored XSS
|
2 |
WEB
|
Piyush Patil
|
2021-03-18
|
|
Hestia Control Panel 1.3.2 - Arbitrary File Write
|
2 |
WEB
|
numan türle
|
2021-03-18
|
|
SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (1)
|
2 |
WEB
|
Piyush Patil
|
2021-03-18
|
|
rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (1)
|
1 |
WEB
|
Murat ŞEKER
|
2021-03-18
|
|
VestaCP 0.9.8 - 'v_interface' Add IP Stored XSS
|
1 |
WEB
|
numan türle
|
2021-03-17
|
|
VestaCP 0.9.8 - File Upload CSRF
|
1 |
WEB
|
Fady Mohammed Osman
|
2021-03-17
|
|
WoWonder Social Network Platform 3.1 - 'event_id' SQL Injection
|
2 |
WEB
|
securityforeveryone.com
|
2021-03-16
|
|
Alphaware E-Commerce System 1.0 - Unauthenicated Remote Code Execution (File Upload + SQL injection)
|
2 |
WEB
|
Christian Vierschilling
|
2021-03-15
|
|
SonLogger 4.2.3.3 - Unauthenticated Arbitrary File Upload (Metasploit)
|
2 |
WEB
|
Berkan Er
|
2021-03-15
|
|
Sonlogger 4.2.3.3 - SuperAdmin Account Creation / Information Disclosure
|
1 |
WEB
|
Berkan Er
|
2021-03-15
|
|
openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scripting
|
1 |
WEB
|
Hosein Vita
|
2021-03-15
|
|
rConfig 3.9.6 - 'path' Local File Inclusion (Authenticated)
|
1 |
WEB
|
Murat ŞEKER
|
2021-03-15
|
|
MagpieRSS 0.72 - 'url' Command Injection
|
1 |
WEB
|
bl4ckh4ck5
|
2021-03-15
|
|
Zenario CMS 8.8.53370 - 'id' Blind SQL Injection
|
2 |
WEB
|
Balaji Ayyasamy
|
2021-03-12
|
|
Monitoring System (Dashboard) 1.0 - File Upload RCE (Authenticated)
|
1 |
WEB
|
Richard Jones
|
2021-03-12
|
|
Monitoring System (Dashboard) 1.0 - 'uname' SQL Injection
|
2 |
WEB
|
Richard Jones
|
2021-03-11
|
|
Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)
|
2 |
WEB
|
testanull
|
2021-03-11
|
|
CouchCMS 2.2.1 - Persistent Cross-Site Scripting
|
1 |
WEB
|
xxcdd
|
2021-03-11
|
|
MyBB OUGC Feedback Plugin 1.8.22 - Cross-Site Scripting
|
2 |
WEB
|
0xB9
|
2021-03-11
|
|
NuCom 11N Wireless Router 5.07.90 - Remote Privilege Escalation
|
2 |
WEB
|
LiquidWorm
|
2021-03-10
|
|
Atlassian JIRA 8.11.1 - User Enumeration
|
2 |
WEB
|
Dolev Farhi
|
2021-03-08
|
|
GLPI 9.5.3 - 'fromtype' Unsafe Reflection
|
2 |
WEB
|
Vadym Soroka
|
2021-03-08
|
|
Joomla JCK Editor 6.4.4 - 'parent' SQL Injection (2)
|
1 |
WEB
|
Nicholas Ferreira
|
2021-03-08
|
|
Hotel and Lodge Management System 1.0 - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
Christian Vierschilling
|
2021-03-05
|
|
Fluig 1.7.0 - Path Traversal
|
2 |
WEB
|
Lucas Souza
|
2021-03-04
|
|
Textpattern 4.8.3 - Remote code execution (Authenticated) (2)
|
1 |
WEB
|
Ricardo Ruiz
|
2021-03-04
|
|
Web Based Quiz System 1.0 - 'eid' Union Based Sql Injection (Authenticated)
|
1 |
WEB
|
Deepak Kumar Bharti
|
2021-03-04
|
|
Online Ordering System 1.0 - Blind SQL Injection (Unauthenticated)
|
1 |
WEB
|
Suraj Bhosale
|
2021-03-04
|
|
Textpattern CMS 4.9.0-dev - 'Excerpt' Persistent Cross-Site Scripting (XSS)
|
1 |
WEB
|
Tushar Vaidya
|
2021-03-04
|
|
Textpattern CMS 4.8.4 - 'Comments' Persistent Cross-Site Scripting (XSS)
|
1 |
WEB
|
Tushar Vaidya
|
2021-03-04
|
|
Online Ordering System 1.0 - Arbitrary File Upload
|
1 |
WEB
|
Suraj Bhosale
|
2021-03-04
|
|
e107 CMS 2.3.0 - CSRF
|
1 |
WEB
|
Tadjmen
|
2021-03-03
|
|
Local Services Search Engine Management System (LSSMES) 1.0 - Blind & Error based SQL injection (Aut
|
1 |
WEB
|
Tushar Vaidya
|
2021-03-03
|
|
Local Services Search Engine Management System (LSSMES) 1.0 - 'name' Persistent Cross-Site Scripting
|
1 |
WEB
|
Tushar Vaidya
|
2021-03-02
|
|
Zen Cart 1.5.7b - Remote Code Execution (Authenticated)
|
2 |
WEB
|
Mücahit Saratar
|
2021-03-02
|
|
Web Based Quiz System 1.0 - 'name' Persistent Cross-Site Scripting
|
1 |
WEB
|
P.Naveen Kumar
|
2021-03-02
|
|
Tiny Tiny RSS - Remote Code Execution
|
1 |
WEB
|
Daniel Neagaru
|
2021-03-02
|
|
Web Based Quiz System 1.0 - 'MCQ options' Persistent Cross-Site Scripting
|
1 |
WEB
|
Praharsh Kumar Singh
|
2021-03-01
|
|
Covid-19 Contact Tracing System 1.0 - Remote Code Execution (Unauthenticated)
|
1 |
WEB
|
Christian Vierschilling
|
2021-03-01
|
|
Online Catering Reservation System 1.0 - Remote Code Execution (Unauthenticated)
|
1 |
WEB
|
Christian Vierschilling
|
2021-03-01
|
|
VMware vCenter Server 7.0 - Unauthenticated File Upload
|
1 |
WEB
|
Photubias
|
2021-03-01
|
|
FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit)
|
1 |
WEB
|
Berkan Er
|
2021-02-26
|
|
LightCMS 1.3.4 - 'exclusive' Stored XSS
|
1 |
WEB
|
Peithon
|
2021-02-26
|
|
Triconsole 3.75 - Reflected XSS
|
1 |
WEB
|
Akash Chathoth
|
2021-02-26
|
|
Simple Employee Records System 1.0 - File Upload RCE (Unauthenticated)
|
1 |
WEB
|
sml
|
2021-02-25
|
|
Vehicle Parking Management System 1.0 - 'catename' Persistent Cross-Site Scripting (XSS)
|
1 |
WEB
|
Tushar Vaidya
|
2021-02-24
|
|
LayerBB 1.1.4 - 'search_query' SQL Injection
|
1 |
WEB
|
Görkem Haşin
|
2021-02-23
|
|
Batflat CMS 1.3.6 - 'multiple' Stored XSS
|
2 |
WEB
|
Tadjmen
|
2021-02-23
|
|
Monica 2.19.1 - 'last_name' Stored XSS
|
2 |
WEB
|
BouSalman
|
2021-02-19
|
|
Beauty Parlour Management System 1.0 - 'sername' SQL Injection
|
2 |
WEB
|
Thinkland Security Team
|
2021-02-19
|
|
OpenText Content Server 20.3 - 'multiple' Stored Cross-Site Scripting
|
1 |
WEB
|
Kamil Breński
|
2021-02-19
|
|
Online Exam System With Timer 1.0 - 'email' SQL injection Auth Bypass
|
2 |
WEB
|
Suresh Kumar
|
2021-02-19
|
|
Comment System 1.0 - 'multiple' Stored Cross-Site Scripting
|
2 |
WEB
|
Pintu Solanki
|
2021-02-19
|
|
PEEL Shopping 9.3.0 - 'Comments' Persistent Cross-Site Scripting
|
2 |
WEB
|
Anmol K Sachan
|
2021-02-18
|
|
Batflat CMS 1.3.6 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
mari0x00
|
2021-02-18
|
|
Gitea 1.12.5 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Podalirius
|
2021-02-17
|
|
Billing Management System 2.0 - 'email' SQL injection Auth Bypass
|
3 |
WEB
|
Pintu Solanki
|
2021-02-17
|
|
Faulty Evaluation System 1.0 - 'multiple' Stored Cross-Site Scripting
|
2 |
WEB
|
Suresh Kumar
|
2021-02-16
|
|
BlackCat CMS 1.3.6 - 'Display name' Cross Site Scripting (XSS)
|
2 |
WEB
|
Kamaljeet Kumar
|
2021-02-16
|
|
Online Internship Management System 1.0 - 'email' SQL injection Auth Bypass
|
1 |
WEB
|
Christian Vierschilling
|
2021-02-15
|
|
Teachers Record Management System 1.0 - 'searchteacher' SQL Injection
|
1 |
WEB
|
Soham Bakore
|
2021-02-15
|
|
TestLink 1.9.20 - Unrestricted File Upload (Authenticated)
|
2 |
WEB
|
snovvcrash
|
2021-02-12
|
|
School Event Attendance Monitoring System 1.0 - 'Item Name' Stored Cross-Site Scripting
|
2 |
WEB
|
Suresh Kumar
|