2021-01-08
|
|
Online Doctor Appointment System 1.0 - 'Multiple' Stored XSS
|
0 |
WEB
|
Mohamed habib Smidi
|
2021-01-08
|
|
Life Insurance Management System 1.0 - Multiple Stored XSS
|
1 |
WEB
|
Arnav Tripathy
|
2021-01-07
|
|
CRUD Operation 1.0 - Multiple Stored XSS
|
1 |
WEB
|
Arnav Tripathy
|
2021-01-07
|
|
ECSIMAGING PACS 6.21.5 - SQL injection
|
1 |
WEB
|
shoxxdj
|
2021-01-07
|
|
Curfew e-Pass Management System 1.0 - Stored XSS
|
2 |
WEB
|
Arnav Tripathy
|
2021-01-07
|
|
Cockpit CMS 0.6.1 - Remote Code Execution
|
1 |
WEB
|
Rafael Resende
|
2021-01-07
|
|
Employee Record System 1.0 - Unrestricted File Upload to Remote Code Execution
|
2 |
WEB
|
Saeed Bala Ahmed
|
2021-01-07
|
|
ECSIMAGING PACS 6.21.5 - Remote code execution
|
2 |
WEB
|
shoxxdj
|
2021-01-07
|
|
iBall-Baton WRA150N Rom-0 Backup - File Disclosure (Sensitive Information)
|
2 |
WEB
|
h4cks1n
|
2021-01-06
|
|
Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
1F98D
|
2021-01-06
|
|
Gitea 1.7.5 - Remote Code Execution
|
1 |
WEB
|
1F98D
|
2021-01-06
|
|
Resumes Management and Job Application Website 1.0 - RCE (Unauthenticated)
|
2 |
WEB
|
Arnav Tripathy
|
2021-01-06
|
|
Newgen Correspondence Management System (corms) eGov 12.0 - IDOR
|
1 |
WEB
|
ALI AL SINAN
|
2021-01-06
|
|
WordPress Plugin WP24 Domain Check 1.6.2 - 'fieldnameDomain' Stored Cross Site Scripting
|
2 |
WEB
|
Mehmet Kelepçe
|
2021-01-06
|
|
Responsive E-Learning System 1.0 - Stored Cross Site Scripting
|
2 |
WEB
|
Kshitiz Raj
|
2021-01-06
|
|
Responsive E-Learning System 1.0 - Unrestricted File Upload to RCE
|
2 |
WEB
|
Kshitiz Raj
|
2021-01-06
|
|
WordPress Plugin litespeed cache 3.6 - 'server_ip' Cross-Site Scripting
|
2 |
WEB
|
Nhat Ha
|
2021-01-06
|
|
Expense Tracker 1.0 - 'Expense Name' Stored Cross-Site Scripting
|
2 |
WEB
|
Shivam Verma
|
2021-01-06
|
|
IPeakCMS 3.5 - Boolean-based blind SQLi
|
1 |
WEB
|
MoeAlBarbari
|
2021-01-06
|
|
Advanced Webhost Billing System 3.7.0 - Cross-Site Request Forgery (CSRF)
|
1 |
WEB
|
Rahul Ramakant Singh
|
2021-01-05
|
|
EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Persistent Cross-Site Scriptin
|
2 |
WEB
|
Mesut Cetin
|
2021-01-05
|
|
Klog Server 2.4.1 - Command Injection (Unauthenticated)
|
2 |
WEB
|
B3KC4T
|
2021-01-05
|
|
Online Learning Management System 1.0 - RCE (Authenticated)
|
2 |
WEB
|
Bedri Sertkaya
|
2021-01-05
|
|
CSZ CMS 1.2.9 - Multiple Cross-Site Scripting
|
2 |
WEB
|
SunCSR
|
2021-01-05
|
|
Cassandra Web 0.5.0 - Remote File Read
|
2 |
WEB
|
Jeremy Brown
|
2021-01-05
|
|
HPE Edgeline Infrastructure Manager 1.0 - Multiple Remote Vulnerabilities
|
2 |
WEB
|
Jeremy Brown
|
2021-01-05
|
|
Zoom Meeting Connector 4.6.239.20200613 - Remote Root Exploit (Authenticated)
|
2 |
WEB
|
Jeremy Brown
|
2021-01-05
|
|
Responsive FileManager 9.13.4 - 'path' Path Traversal
|
2 |
WEB
|
Sun* Cyber Security Research Team
|
2021-01-05
|
|
Baby Care System 1.0 - 'Post title' Stored XSS
|
2 |
WEB
|
Hardik Solanki
|
2021-01-05
|
|
Responsive E-Learning System 1.0 - 'id' Sql Injection
|
2 |
WEB
|
Kshitiz Raj
|
2021-01-05
|
|
Online Movie Streaming 1.0 - Authentication Bypass
|
2 |
WEB
|
Kshitiz Raj
|
2021-01-05
|
|
WordPress Plugin WP-Paginate 2.1.3 - 'preset' Stored XSS
|
2 |
WEB
|
Park Won Seok
|
2021-01-05
|
|
WordPress Plugin Stripe Payments 2.0.39 - 'AcceptStripePayments-settings[currency_code]' Stored XSS
|
2 |
WEB
|
Park Won Seok
|
2021-01-05
|
|
Resumes Management and Job Application Website 1.0 - Authentication Bypass
|
3 |
WEB
|
Kshitiz Raj
|
2021-01-05
|
|
IncomCMS 2.0 - Insecure File Upload
|
1 |
WEB
|
MoeAlBarbari
|
2021-01-04
|
|
Arteco Web Client DVR/NVR - 'SessionId' Brute Force
|
1 |
WEB
|
LiquidWorm
|
2021-01-04
|
|
Click2Magic 1.1.5 - Stored Cross-Site Scripting
|
2 |
WEB
|
Shivam Verma
|
2021-01-04
|
|
Subrion CMS 4.2.1 - 'avatar[path]' XSS
|
2 |
WEB
|
icekam
|
2021-01-04
|
|
CMS Made Simple 2.2.15 - RCE (Authenticated)
|
1 |
WEB
|
Andrey Stoykov
|
2021-01-04
|
|
sar2html 3.2.1 - 'plot' Remote Code Execution
|
2 |
WEB
|
Musyoka Ian
|
2021-01-04
|
|
Advanced Comment System 1.0 - 'ACS_path' Path Traversal
|
2 |
WEB
|
Francisco Javier Santiago Vázquez
|
2021-01-04
|
|
Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
|
1 |
WEB
|
EthicalHCOP
|
2021-01-04
|
|
4images v1.7.11 - 'Profile Image' Stored Cross-Site Scripting
|
2 |
WEB
|
Ritesh Gohil
|
2021-01-04
|
|
Wordpress Core 5.2.2 - 'post previews' XSS
|
2 |
WEB
|
gx1
|
2020-12-24
|
|
Apartment Visitors Management System 1.0 - Authentication Bypass
|
1 |
WEB
|
Kshitiz Raj
|
2020-12-24
|
|
GitLab 11.4.7 - RCE (Authenticated) (2)
|
2 |
WEB
|
Norbert Hofmann
|
2020-12-24
|
|
WordPress Plugin WP-PostRatings 1.86 - 'postratings_image' Cross-Site Scripting
|
2 |
WEB
|
Park Won Seok
|
2020-12-24
|
|
WordPress Plugin Adning Advertising 1.5.5 - Arbitrary File Upload
|
2 |
WEB
|
spacehen
|
2020-12-23
|
|
Baby Care System 1.0 - 'roleid' SQL Injection
|
1 |
WEB
|
Vijay Sachdeva
|
2020-12-23
|
|
TerraMaster TOS 4.2.06 - Unauthenticated Remote Code Execution (Metasploit)
|
1 |
WEB
|
AkkuS
|
2020-12-23
|
|
Sales and Inventory System for Grocery Store 1.0 - Multiple Stored XSS
|
2 |
WEB
|
Vijay Sachdeva
|
2020-12-23
|
|
Wordpress Epsilon Framework Multiple Themes - Unauthenticated Function Injection
|
1 |
WEB
|
gx1
|
2020-12-23
|
|
Online Learning Management System 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Aakash Madaan
|
2020-12-23
|
|
Online Learning Management System 1.0 - Multiple Stored XSS
|
1 |
WEB
|
Aakash Madaan
|
2020-12-23
|
|
Online Learning Management System 1.0 - Authentication Bypass
|
2 |
WEB
|
Aakash Madaan
|
2020-12-23
|
|
Class Scheduling System 1.0 - Multiple Stored XSS
|
1 |
WEB
|
Aakash Madaan
|
2020-12-22
|
|
TerraMaster TOS 4.2.06 - RCE (Unauthenticated)
|
1 |
WEB
|
IHTeam
|
2020-12-22
|
|
Faculty Evaluation System 1.0 - Stored XSS
|
2 |
WEB
|
Vijay Sachdeva
|
2020-12-22
|
|
Artworks Gallery Management System 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Vijay Sachdeva
|
2020-12-22
|
|
Webmin 1.962 - 'Package Updates' Escape Bypass RCE (Metasploit)
|
2 |
WEB
|
AkkuS
|
2020-12-22
|
|
WordPress Plugin W3 Total Cache - Unauthenticated Arbitrary File Read (Metasploit)
|
1 |
WEB
|
SunCSR Team
|
2020-12-22
|
|
Multi Branch School Management System 3.5 - _Create Branch_ Stored XSS
|
2 |
WEB
|
Kislay Kumar
|
2020-12-22
|
|
Library Management System 3.0 - _Add Category_ Stored XSS
|
1 |
WEB
|
Kislay Kumar
|
2020-12-22
|
|
CSE Bookstore 1.0 - Multiple SQL Injection
|
2 |
WEB
|
Musyoka Ian
|
2020-12-22
|
|
Pandora FMS 7.0 NG 750 - 'Network Scan' SQL Injection (Authenticated)
|
2 |
WEB
|
Matthew Aberegg
|
2020-12-22
|
|
Victor CMS 1.0 - File Upload To RCE
|
2 |
WEB
|
Mosaaed
|
2020-12-16
|
|
Sony Playstation 4 (PS4) < 7.02 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code
|
1 |
WEB
|
ChendoChap
|
2020-11-12
|
|
Sony Playstation 4 (PS4) < 6.72 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code
|
0 |
WEB
|
Synacktiv
|
2020-12-21
|
|
Online Marriage Registration System 1.0 - 'searchdata' SQL Injection
|
1 |
WEB
|
Raffaele Sabato
|
2020-12-21
|
|
Point of Sale System 1.0 - Multiple Stored XSS
|
1 |
WEB
|
Saeed Bala Ahmed
|
2020-12-21
|
|
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
|
1 |
WEB
|
Marco Nappi
|
2020-12-21
|
|
Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS
|
1 |
WEB
|
Marco Nappi
|
2020-12-21
|
|
Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS
|
1 |
WEB
|
Marco Nappi
|
2020-12-21
|
|
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS
|
1 |
WEB
|
Marco Nappi
|
2020-12-21
|
|
SCO Openserver 5.0.7 - 'outputform' Command Injection
|
1 |
WEB
|
Ramikan
|
2020-12-21
|
|
SCO Openserver 5.0.7 - 'section' Reflected XSS
|
1 |
WEB
|
Ramikan
|
2020-12-21
|
|
Spiceworks 7.5 - HTTP Header Injection
|
1 |
WEB
|
Ramikan
|
2020-12-21
|
|
Academy-LMS 4.3 - Stored XSS
|
0 |
WEB
|
Vinicius Alves
|
2020-12-21
|
|
Spotweb 1.4.9 - 'search' SQL Injection
|
1 |
WEB
|
BouSalman
|
2020-12-21
|
|
Queue Management System 4.0.0 - _Add User_ Stored XSS
|
1 |
WEB
|
Kislay Kumar
|
2020-12-18
|
|
Xeroneit Library Management System 3.1 - _Add Book Category _ Stored XSS
|
1 |
WEB
|
Kislay Kumar
|
2020-12-18
|
|
SyncBreeze 10.0.28 - 'login' Denial of Service (Poc)
|
1 |
WEB
|
Ahmed Elkhressy
|
2020-12-18
|
|
Smart Hospital 3.1 - _Add Patient_ Stored XSS
|
1 |
WEB
|
Kislay Kumar
|
2020-12-18
|
|
Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read (Metasploit)
|
1 |
WEB
|
SunCSR Team
|
2020-12-18
|
|
Alumni Management System 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Aakash Madaan
|
2020-12-18
|
|
Alumni Management System 1.0 - _Course Form_ Stored XSS
|
1 |
WEB
|
Aakash Madaan
|
2020-12-18
|
|
Alumni Management System 1.0 - Unrestricted File Upload To RCE
|
1 |
WEB
|
Aakash Madaan
|
2020-12-18
|
|
Point of Sale System 1.0 - Authentication Bypass
|
1 |
WEB
|
Saeed Bala Ahmed
|
2020-12-17
|
|
Victor CMS 1.0 - Multiple SQL Injection (Authenticated)
|
1 |
WEB
|
Furkan Göksel
|
2020-12-17
|
|
PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting)
|
1 |
WEB
|
Andrea Intilangelo
|
2020-12-17
|
|
Employee Record System 1.0 - Multiple Stored XSS
|
1 |
WEB
|
Saeed Bala Ahmed
|
2020-12-17
|
|
Interview Management System 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Saeed Bala Ahmed
|
2020-12-17
|
|
Interview Management System 1.0 - Stored XSS in Add New Question
|
1 |
WEB
|
Saeed Bala Ahmed
|
2020-12-17
|
|
Online Tours & Travels Management System 1.0 - _id_ SQL Injection
|
1 |
WEB
|
Saeed Bala Ahmed
|
2020-12-17
|
|
Customer Support System 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Saeed Bala Ahmed
|
2020-12-17
|
|
Customer Support System 1.0 - _First Name_ & _Last Name_ Stored XSS
|
1 |
WEB
|
Saeed Bala Ahmed
|
2020-12-17
|
|
Medical Center Portal Management System 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Saeed Bala Ahmed
|
2020-12-17
|
|
Content Management System 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Zhaiyi
|
2020-12-17
|
|
Content Management System 1.0 - 'email' SQL Injection
|
1 |
WEB
|
Zhaiyi
|
2020-12-17
|
|
Content Management System 1.0 - 'First Name' Stored XSS
|
1 |
WEB
|
Zhaiyi
|
2020-12-17
|
|
Linksys RE6500 1.0.11.001 - Unauthenticated RCE
|
1 |
WEB
|
RE-Solver
|
2020-12-17
|
|
Dolibarr ERP-CRM 12.0.3 - Remote Code Execution (Authenticated)
|
2 |
WEB
|
Yilmaz Degirmenci
|
2020-12-16
|
|
Seotoaster 3.2.0 - Stored XSS on Edit page properties
|
1 |
WEB
|
Hardik Solanki
|
2020-12-16
|
|
PrestaShop ProductComments 4.2.0 - 'id_products' Time Based Blind SQL Injection
|
1 |
WEB
|
Frederic ADAM
|
2020-12-16
|
|
Magic Home Pro 1.5.1 - Authentication Bypass
|
1 |
WEB
|
Victor Hanna
|
2020-12-16
|
|
Raysync 3.3.3.8 - RCE
|
1 |
WEB
|
james
|
2020-12-16
|
|
Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting
|
2 |
WEB
|
Sagar Banwa
|
2020-12-15
|
|
Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
|
2 |
WEB
|
Freakyclown
|
2020-12-15
|
|
Online Marriage Registration System (OMRS) 1.0 - Remote Code Execution (2)
|
1 |
WEB
|
Andrea Bruschi
|
2020-12-15
|
|
Task Management System 1.0 - 'page' Local File Inclusion
|
1 |
WEB
|
İsmail BOZKURT
|
2020-12-14
|
|
GitLab 11.4.7 - Remote Code Execution (Authenticated) (1)
|
2 |
WEB
|
Fortunato Lodari
|
2020-12-14
|
|
Macally WIFISD2-2A82 2.000.010 - Guest to Root Privilege Escalation
|
2 |
WEB
|
Maximilian Barz
|
2020-12-14
|
|
Rumble Mail Server 0.51.3135 - 'username' Stored XSS
|
2 |
WEB
|
Mohammed Alshehri
|
2020-12-14
|
|
Rumble Mail Server 0.51.3135 - 'domain and path' Stored XSS
|
2 |
WEB
|
Mohammed Alshehri
|
2020-12-14
|
|
Rumble Mail Server 0.51.3135 - 'servername' Stored XSS
|
1 |
WEB
|
Mohammed Alshehri
|
2020-12-14
|
|
WordPress Plugin Total Upkeep 1.14.9 - Database and Files Backup Download
|
2 |
WEB
|
Wadeek
|
2020-12-14
|
|
Seacms 11.1 - 'checkuser' Stored XSS
|
2 |
WEB
|
j5s
|
2020-12-14
|
|
Seacms 11.1 - 'file' Local File Inclusion
|
2 |
WEB
|
j5s
|
2020-12-14
|
|
Seacms 11.1 - 'ip and weburl' Remote Command Execution
|
2 |
WEB
|
j5s
|
2020-12-14
|
|
MiniWeb HTTP Server 0.8.19 - Buffer Overflow (PoC)
|
1 |
WEB
|
securityforeveryone.com
|
2020-12-14
|
|
LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection
|
1 |
WEB
|
Hodorsec
|
2020-12-14
|
|
Rukovoditel 2.6.1 - Cross-Site Request Forgery (Change password)
|
1 |
WEB
|
KeopssGroup0day_Inc
|
2020-12-14
|
|
Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS
|
1 |
WEB
|
gx1
|
2020-12-11
|
|
Courier Management System 1.0 - 'ref_no' SQL Injection
|
1 |
WEB
|
Zhaiyi
|
2020-12-11
|
|
Courier Management System 1.0 - 'MULTIPART street ((custom) ' SQL Injection
|
1 |
WEB
|
Zhaiyi
|