Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2021-03-18   Hestia Control Panel 1.3.2 - Arbitrary File Write 35 WEB numan türle
2021-03-18   SEO Panel 4.8.0 - 'order_col' Blind SQL Injection (1) 41 WEB Piyush Patil
2021-03-18   rConfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (1) 33 WEB Murat ŞEKER
2021-03-18   VestaCP 0.9.8 - 'v_interface' Add IP Stored XSS 31 WEB numan türle
2021-03-17   VestaCP 0.9.8 - File Upload CSRF 38 WEB Fady Mohammed Osman
2021-03-17   WoWonder Social Network Platform 3.1 - 'event_id' SQL Injection 31 WEB securityforeveryone.com
2021-03-16   Alphaware E-Commerce System 1.0 - Unauthenicated Remote Code Execution (File Upload + SQL injection) 48 WEB Christian Vierschilling
2021-03-15   SonLogger 4.2.3.3 - Unauthenticated Arbitrary File Upload (Metasploit) 37 WEB Berkan Er
2021-03-15   Sonlogger 4.2.3.3 - SuperAdmin Account Creation / Information Disclosure 34 WEB Berkan Er
2021-03-15   openMAINT openMAINT 2.1-3.3-b - 'Multiple' Persistent Cross-Site Scripting 33 WEB Hosein Vita
2021-03-15   rConfig 3.9.6 - 'path' Local File Inclusion (Authenticated) 34 WEB Murat ŞEKER
2021-03-15   MagpieRSS 0.72 - 'url' Command Injection 31 WEB bl4ckh4ck5
2021-03-15   Zenario CMS 8.8.53370 - 'id' Blind SQL Injection 43 WEB Balaji Ayyasamy
2021-03-12   Monitoring System (Dashboard) 1.0 - File Upload RCE (Authenticated) 33 WEB Richard Jones
2021-03-12   Monitoring System (Dashboard) 1.0 - 'uname' SQL Injection 37 WEB Richard Jones
2021-03-11   Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC) 39 WEB testanull
2021-03-11   CouchCMS 2.2.1 - Persistent Cross-Site Scripting 37 WEB xxcdd
2021-03-11   MyBB OUGC Feedback Plugin 1.8.22 - Cross-Site Scripting 36 WEB 0xB9
2021-03-11   NuCom 11N Wireless Router 5.07.90 - Remote Privilege Escalation 41 WEB LiquidWorm
2021-03-10   Atlassian JIRA 8.11.1 - User Enumeration 38 WEB Dolev Farhi
2021-03-08   GLPI 9.5.3 - 'fromtype' Unsafe Reflection 35 WEB Vadym Soroka
2021-03-08   Joomla JCK Editor 6.4.4 - 'parent' SQL Injection (2) 34 WEB Nicholas Ferreira
2021-03-08   Hotel and Lodge Management System 1.0 - Remote Code Execution (Unauthenticated) 34 WEB Christian Vierschilling
2021-03-05   Fluig 1.7.0 - Path Traversal 43 WEB Lucas Souza
2021-03-04   Textpattern 4.8.3 - Remote code execution (Authenticated) (2) 35 WEB Ricardo Ruiz
2021-03-04   Web Based Quiz System 1.0 - 'eid' Union Based Sql Injection (Authenticated) 38 WEB Deepak Kumar Bharti
2021-03-04   Online Ordering System 1.0 - Blind SQL Injection (Unauthenticated) 37 WEB Suraj Bhosale
2021-03-04   Textpattern CMS 4.9.0-dev - 'Excerpt' Persistent Cross-Site Scripting (XSS) 37 WEB Tushar Vaidya
2021-03-04   Textpattern CMS 4.8.4 - 'Comments' Persistent Cross-Site Scripting (XSS) 35 WEB Tushar Vaidya
2021-03-04   Online Ordering System 1.0 - Arbitrary File Upload 36 WEB Suraj Bhosale
2021-03-04   e107 CMS 2.3.0 - CSRF 42 WEB Tadjmen
2021-03-03   Local Services Search Engine Management System (LSSMES) 1.0 - Blind & Error based SQL injection (Aut 36 WEB Tushar Vaidya
2021-03-03   Local Services Search Engine Management System (LSSMES) 1.0 - 'name' Persistent Cross-Site Scripting 36 WEB Tushar Vaidya
2021-03-02   Zen Cart 1.5.7b - Remote Code Execution (Authenticated) 36 WEB Mücahit Saratar
2021-03-02   Web Based Quiz System 1.0 - 'name' Persistent Cross-Site Scripting 32 WEB P.Naveen Kumar
2021-03-02   Tiny Tiny RSS - Remote Code Execution 34 WEB Daniel Neagaru
2021-03-02   Web Based Quiz System 1.0 - 'MCQ options' Persistent Cross-Site Scripting 36 WEB Praharsh Kumar Singh
2021-03-01   Covid-19 Contact Tracing System 1.0 - Remote Code Execution (Unauthenticated) 52 WEB Christian Vierschilling
2021-03-01   Online Catering Reservation System 1.0 - Remote Code Execution (Unauthenticated) 37 WEB Christian Vierschilling
2021-03-01   VMware vCenter Server 7.0 - Unauthenticated File Upload 35 WEB Photubias
2021-03-01   FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit) 36 WEB Berkan Er
2021-02-26   LightCMS 1.3.4 - 'exclusive' Stored XSS 35 WEB Peithon
2021-02-26   Triconsole 3.75 - Reflected XSS 38 WEB Akash Chathoth
2021-02-26   Simple Employee Records System 1.0 - File Upload RCE (Unauthenticated) 37 WEB sml
2021-02-25   Vehicle Parking Management System 1.0 - 'catename' Persistent Cross-Site Scripting (XSS) 36 WEB Tushar Vaidya
2021-02-24   LayerBB 1.1.4 - 'search_query' SQL Injection 37 WEB Görkem Haşin
2021-02-23   Batflat CMS 1.3.6 - 'multiple' Stored XSS 35 WEB Tadjmen
2021-02-23   Monica 2.19.1 - 'last_name' Stored XSS 32 WEB BouSalman
2021-02-19   Beauty Parlour Management System 1.0 - 'sername' SQL Injection 39 WEB Thinkland Security Team
2021-02-19   OpenText Content Server 20.3 - 'multiple' Stored Cross-Site Scripting 45 WEB Kamil Breński
2021-02-19   Online Exam System With Timer 1.0 - 'email' SQL injection Auth Bypass 34 WEB Suresh Kumar
2021-02-19   Comment System 1.0 - 'multiple' Stored Cross-Site Scripting 41 WEB Pintu Solanki
2021-02-19   PEEL Shopping 9.3.0 - 'Comments' Persistent Cross-Site Scripting 36 WEB Anmol K Sachan
2021-02-18   Batflat CMS 1.3.6 - Remote Code Execution (Authenticated) 53 WEB mari0x00
2021-02-18   Gitea 1.12.5 - Remote Code Execution (Authenticated) 51 WEB Podalirius
2021-02-17   Billing Management System 2.0 - 'email' SQL injection Auth Bypass 43 WEB Pintu Solanki
2021-02-17   Faulty Evaluation System 1.0 - 'multiple' Stored Cross-Site Scripting 35 WEB Suresh Kumar
2021-02-16   BlackCat CMS 1.3.6 - 'Display name' Cross Site Scripting (XSS) 32 WEB Kamaljeet Kumar
2021-02-16   Online Internship Management System 1.0 - 'email' SQL injection Auth Bypass 30 WEB Christian Vierschilling
2021-02-15   Teachers Record Management System 1.0 - 'searchteacher' SQL Injection 33 WEB Soham Bakore
2021-02-15   TestLink 1.9.20 - Unrestricted File Upload (Authenticated) 44 WEB snovvcrash
2021-02-12   School Event Attendance Monitoring System 1.0 - 'Item Name' Stored Cross-Site Scripting 49 WEB Suresh Kumar
2021-02-12   School File Management System 1.0 - 'multiple' Stored Cross-Site Scripting 30 WEB Pintu Solanki
2021-02-11   Online Marriage Registration System (OMRS) 1.0 - Remote code execution (3) 31 WEB Ricardo Ruiz
2021-02-11   Openlitespeed WebServer 1.7.8 - Command Injection (Authenticated) (2) 36 WEB Metin Yunus Kandemir
2021-02-11   b2evolution 6.11.6 - 'tab3' Reflected XSS 33 WEB Nakul Ratti
2021-02-11   b2evolution 6.11.6 - 'redirect_to' Open Redirect 37 WEB Nakul Ratti
2021-02-11   PEEL Shopping 9.3.0 - 'address' Stored Cross-Site Scripting 33 WEB Anmol K Sachan
2021-02-10   Node.JS - 'node-serialize' Remote Code Execution (2) 32 WEB UndeadLarva
2021-02-10   b2evolution 6.11.6 - 'plugin name' Stored XSS 34 WEB Soham Bakore
2021-02-09   Adobe Connect 10 - Username Disclosure 34 WEB h4shur
2021-02-09   Online Car Rental System 1.0 - Stored Cross Site Scripting 35 WEB Naved Shaikh
2021-02-08   WordPress Plugin Supsystic Backup 2.3.9 - Local File Inclusion 36 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Contact Form 1.7.5 - Multiple Vulnerabilities 40 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Data Tables Generator 1.9.96 - Multiple Vulnerabilities 36 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Digital Publications 1.6.9 - Multiple Vulnerabilities 35 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Membership 1.4.7 - 'sidx' SQL injection 30 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Newsletter 1.5.5 - 'sidx' SQL injection 36 WEB Erik David Martin
2021-02-08   Alt-N MDaemon webmail 20.0.0 - 'file name' Stored Cross Site Scripting (XSS) 35 WEB Kailash Bohara
2021-02-08   Alt-N MDaemon webmail 20.0.0 - 'Contact name' Stored Cross Site Scripting (XSS) 29 WEB Kailash Bohara
2021-02-08   YetiShare File Hosting Script 5.1.0 - 'url' Server-Side Request Forgery 28 WEB numan türle
2021-02-08   WordPress Plugin Supsystic Pricing Table 1.8.7 - Multiple Vulnerabilities 37 WEB Erik David Martin
2021-02-08   WordPress Plugin Supsystic Ultimate Maps 1.1.12 - 'sidx' SQL injection 34 WEB Erik David Martin
2021-02-08   WordPress Plugin Welcart e-Commerce 2.0.0 - 'search[order_column][0]' SQL injection 29 WEB Erik David Martin
2021-02-08   Jenzabar 9.2.2 - 'query' Reflected XSS. 36 WEB y0ung_dst
2021-02-08   SmartFoxServer 2X 2.17.0 - God Mode Console WebSocket XSS 31 WEB LiquidWorm
2021-02-05   SEO Panel 4.6.0 - Remote Code Execution (2) 34 WEB Kr0ff
2021-02-05   PhreeBooks 5.2.3 ERP - Remote Code Execution (2) 36 WEB Kr0ff
2021-02-05   LiteSpeed Web Server Enterprise 5.4.11 - Command Injection (Authenticated) 35 WEB SunCSR
2021-02-03   Car Rental Project 2.0 - Arbitrary File Upload to Remote Code Execution 33 WEB Jannick Tiger
2021-02-03   Pixelimity 1.0 - 'password' Cross-Site Request Forgery 33 WEB Noth
2021-02-02   Student Record System 4.0 - 'cid' SQL Injection 34 WEB Jannick Tiger
2021-02-01   WordPress 5.0.0 - Image Remote Code Execution 36 WEB OUSSAMA RAHALI
2021-02-01   Klog Server 2.4.1 - Command Injection (Authenticated) 34 WEB Metin Yunus Kandemir
2021-02-01   Roundcube Webmail 1.2 - File Disclosure 45 WEB stonepresto
2021-02-01   Vehicle Parking Tracker System 1.0 - 'Owner Name' Stored Cross-Site Scripting 30 WEB Anmol K Sachan
2021-02-01   H8 SSRMS - 'id' IDOR 35 WEB Mohammed Farhan
2021-02-01   bloofoxCMS 0.5.2.1 - CSRF (Add user) 32 WEB LiPeiYi
2021-02-01   MyBB Thread Redirect Plugin 0.2.1 - Cross-Site Scripting 32 WEB 0xB9
2021-02-01   MyBB Trending Widget Plugin 1.2 - Cross-Site Scripting 31 WEB 0xB9
2021-02-01   Park Ticketing Management System 1.0 - 'viewid' SQL Injection 33 WEB Zeyad Azima
2021-02-01   User Management System 1.0 - 'uid' SQL Injection 32 WEB Zeyad Azima
2021-02-01   Zoo Management System 1.0 - 'anid' SQL Injection 37 WEB Zeyad Azima
2021-02-01   MyBB Delete Account Plugin 1.4 - Cross-Site Scripting 34 WEB 0xB9
2021-01-29   SonicWall SSL-VPN 8.0.0.0 - 'visualdoor' Remote Code Execution (Unauthenticated) 39 WEB Darren Martyn
2021-01-29   Simple Public Chat Room 1.0 - 'msg' Stored Cross-Site Scripting 34 WEB Richard Jones
2021-01-29   Simple Public Chat Room 1.0 - Authentication Bypass SQLi 31 WEB Richard Jones
2021-01-29   MyBB Hide Thread Content Plugin 1.0 - Information Disclosure 31 WEB 0xB9
2021-01-29   Home Assistant Community Store (HACS) 1.10.0 - Directory Traversal 36 WEB Lyghtnox
2021-01-29   Quick.CMS 6.7 - Remote Code Execution (Authenticated) 32 WEB mari0x00
2021-01-29   Online Grading System 1.0 - 'uname' SQL Injection 34 WEB Ruchi Tiwari
2021-01-29   BloofoxCMS 0.5.2.1 - 'text' Stored Cross Site Scripting 40 WEB LiPeiYi
2021-01-28   WordPress Plugin SuperForms 4.9 - Arbitrary File Upload 41 WEB ABDO10
2021-01-28   Umbraco CMS 7.12.4 - Remote Code Execution (Authenticated) 32 WEB Alexandre ZANNI
2021-01-28   Fuel CMS 1.4.1 - Remote Code Execution (2) 35 WEB Alexandre ZANNI
2021-01-28   OpenEMR 5.0.1 - Remote Code Execution (Authenticated) (2) 30 WEB Alexandre ZANNI
2021-01-28   CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated) 24 WEB Alexandre ZANNI
2021-01-28   EgavilanMedia PHPCRUD 1.0 - 'Full Name' Stored Cross Site Scripting 24 WEB Mahendra Purbia
2021-01-27   Openlitespeed Web Server 1.7.8 - Command Injection (Authenticated) (1) 27 WEB SunCSR
2021-01-27   STVS ProVision 5.9.10 - Cross-Site Request Forgery (Add Admin) 25 WEB LiquidWorm
2021-01-27   STVS ProVision 5.9.10 - File Disclosure (Authenticated) 27 WEB LiquidWorm
2021-01-26   Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated) 30 WEB CHackA0101
2021-01-26   Tenda AC5 AC1200 Wireless - 'WiFi Name & Password' Stored Cross Site Scripting 27 WEB Chiragh Arora
2021-01-26   Simple College Website 1.0 - 'full' Stored Cross Site Scripting 41 WEB Marco Catalano
2021-01-26   Simple College Website 1.0 - 'name' Sql Injection (Authentication Bypass) 31 WEB Marco Catalano