Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-12-14   Seacms 11.1 - 'checkuser' Stored XSS 3 WEB j5s
2020-12-14   Seacms 11.1 - 'file' Local File Inclusion 3 WEB j5s
2020-12-14   Seacms 11.1 - 'ip and weburl' Remote Command Execution 3 WEB j5s
2020-12-14   MiniWeb HTTP Server 0.8.19 - Buffer Overflow (PoC) 2 WEB securityforeveryone.com
2020-12-14   LibreNMS 1.46 - MAC Accounting Graph Authenticated SQL Injection 2 WEB Hodorsec
2020-12-14   Rukovoditel 2.6.1 - Cross-Site Request Forgery (Change password) 3 WEB KeopssGroup0day_Inc
2020-12-14   Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS 2 WEB gx1
2020-12-11   Courier Management System 1.0 - 'ref_no' SQL Injection 2 WEB Zhaiyi
2020-12-11   Courier Management System 1.0 - 'MULTIPART street ((custom) ' SQL Injection 3 WEB Zhaiyi
2020-12-11   Courier Management System 1.0 - 'First Name' Stored XSS 2 WEB Zhaiyi
2020-12-11   Dolibarr 12.0.3 - SQLi to RCE 2 WEB coiffeur
2020-12-11   Supply Chain Management System - Auth Bypass SQL Injection 2 WEB Piyush Malviya
2020-12-11   Rukovoditel 2.6.1 - RCE (1) 2 WEB coiffeur
2020-12-11   Jenkins 2.235.3 - 'Description' Stored XSS 2 WEB gx1
2020-12-11   Medical Center Portal Management System 1.0 - Multiple Stored XSS 2 WEB Saeed Bala Ahmed
2020-12-11   Openfire 4.6.0 - 'sql' Stored XSS 2 WEB j5s
2020-12-11   Openfire 4.6.0 - 'users' Stored XSS 2 WEB j5s
2020-12-11   Openfire 4.6.0 - 'groupchatJID' Stored XSS 2 WEB j5s
2020-12-11   Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting 3 WEB gx1
2020-12-10   WordPress Plugin Popup Builder 3.69.6 - Multiple Stored Cross Site Scripting 2 WEB Ilca Lucian Florin
2020-12-10   Library Management System 2.0 - Auth Bypass SQL Injection 3 WEB Manish Solanki
2020-12-10   Openfire 4.6.0 - 'path' Stored XSS 3 WEB j5s
2020-12-10   OpenCart 3.0.3.6 - Cross Site Request Forgery 4 WEB Mahendra Purbia
2020-12-10   Barcodes generator 1.0 - 'name' Stored Cross Site Scripting 3 WEB Nikhil Kumar
2020-12-09   Task Management System 1.0 - 'id' SQL Injection 2 WEB Saeed Bala Ahmed
2020-12-09   Task Management System 1.0 - Unrestricted File Upload to Remote Code Execution 3 WEB Saeed Bala Ahmed
2020-12-09   Task Management System 1.0 - 'First Name and Last Name' Stored XSS 3 WEB Saeed Bala Ahmed
2020-12-09   VestaCP 0.9.8-26 - 'backup' Information Disclosure 4 WEB Vulnerability-Lab
2020-12-09   VestaCP 0.9.8-26 - 'LoginAs' Insufficient Session Validation 5 WEB Vulnerability-Lab
2020-12-08   Employee Performance Evaluation System 1.0 - 'Task and Description' Persistent Cross Site Scripting 3 WEB Ritesh Gohil
2020-12-08   Online Bus Ticket Reservation 1.0 - SQL Injection 3 WEB Sakshi Sharma
2020-12-07   vBulletin 5.6.3 - 'group' Cross Site Scripting 3 WEB Vincent666
2020-12-07   Savsoft Quiz 5 - 'Skype ID' Stored XSS 4 WEB Dipak Panchal
2020-12-07   Cyber Cafe Management System Project (CCMS) 1.0 - Persistent Cross-Site Scripting 3 WEB Pruthvi Nekkanti
2020-12-04   Zabbix 5.0.0 - Stored XSS via URL Widget Iframe 3 WEB Shwetabh Vishnoi
2020-12-04   CMS Made Simple 2.2.15 - Stored Cross-Site Scripting via SVG File Upload (Authenticated) 5 WEB Eshan Singh
2020-12-04   Laravel Nova 3.7.0 - 'range' DoS 4 WEB iqzer0
2020-12-04   Forma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting 4 WEB Hemant Patidar
2020-12-04   Savsoft Quiz 5 - 'field_title' Stored Cross-Site Scripting 3 WEB Dhruv Patel
2020-12-04   Testa Online Test Management System 3.4.7 - 'q' SQL Injection 3 WEB Ultra Security Team
2020-12-04   MiniCMS 1.10 - 'content box' Stored XSS 3 WEB yudp
2020-12-04   Phpscript-sgh 0.1.0 - Time Based Blind SQL Injection 2 WEB KeopssGroup0day_Inc
2020-12-04   Composr CMS 10.0.34 - 'banners' Persistent Cross Site Scripting 3 WEB Parshwa Bhavsar
2020-12-04   Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated) 3 WEB Pankaj Verma
2020-12-03   Invision Community 4.5.4 - 'Field Name' Stored Cross-Site Scripting 3 WEB Hemant Patidar
2020-12-03   Sony BRAVIA Digital Signage 1.7.8 - System API Information Disclosure 3 WEB LiquidWorm
2020-12-03   Sony BRAVIA Digital Signage 1.7.8 - Unauthenticated Remote File Inclusion 2 WEB LiquidWorm
2020-12-03   mojoPortal forums 2.7.0.0 - 'Title' Persistent Cross-Site Scripting 2 WEB Sagar Banwa
2020-12-03   Online Matrimonial Project 1.0 - Authenticated Remote Code Execution 3 WEB Valerio Alessandroni
2020-12-03   EgavilanMedia Address Book 1.0 Exploit - SQLi Auth Bypass 3 WEB Mayur Parmar
2020-12-03   Coastercms 5.8.18 - Stored XSS 3 WEB Hardik Solanki
2020-12-03   User Registration & Login and User Management System 2.1 - Cross Site Request Forgery 3 WEB Dipak Panchal
2020-12-02   WordPress Plugin Wp-FileManager 6.8 - RCE 3 WEB Mansoor R
2020-12-02   Car Rental Management System 1.0 - SQL Injection / Local File include 4 WEB Mosaaed
2020-12-02   Simple College Website 1.0 - 'page' Local File Inclusion 4 WEB Mosaaed
2020-12-02   Anuko Time Tracker 1.19.23.5311 - Password Reset leading to Account Takeover 5 WEB Mufaddal Masalawala
2020-12-02   Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality 4 WEB Mufaddal Masalawala
2020-12-02   ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS) 4 WEB Mufaddal Masalawala
2020-12-02   ChurchCRM 4.2.0 - CSV/Formula Injection 2 WEB Mufaddal Masalawala
2020-12-02   WebDamn User Registration & Login System with User Panel - SQLi Auth Bypass 4 WEB Aakash Madaan
2020-12-02   DotCMS 20.11 - Stored Cross-Site Scripting 4 WEB Hardik Solanki
2020-12-02   Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile 5 WEB Shahrukh Iqbal Mirza
2020-12-02   Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Add Artwork 4 WEB Shahrukh Iqbal Mirza
2020-12-02   Employee Record Management System 1.1 - Login Bypass SQL Injection 3 WEB Anurag Kumar
2020-12-02   WonderCMS 3.1.3 - 'Menu' Persistent Cross-Site Scripting 3 WEB Hemant Patidar
2020-12-02   Local Service Search Engine Management System 1.0 - SQLi Authentication Bypass 3 WEB Aditya Wakhlu
2020-12-02   Online News Portal System 1.0 - 'Title' Stored Cross Site Scripting 3 WEB Parshwa Bhavsar
2020-12-02   Bakeshop Online Ordering System 1.0 - 'Owner' Persistent Cross-site scripting 6 WEB Parshwa Bhavsar
2020-12-02   NewsLister - Authenticated Persistent Cross-Site Scripting 3 WEB Emre Aslan
2020-12-02   Online Voting System Project in PHP - 'username' Persistent Cross-Site Scripting 2 WEB Sagar Banwa
2020-12-02   PRTG Network Monitor 20.4.63.1412 - 'maps' Stored XSS 3 WEB Amin Rawah
2020-12-02   WonderCMS 3.1.3 - Authenticated Remote Code Execution 3 WEB zetc0de
2020-12-02   WonderCMS 3.1.3 - Authenticated SSRF to Remote Remote Code Execution 2 WEB zetc0de
2020-12-02   EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Stored Cross Site Scripting 3 WEB Soushikta Chowdhury
2020-12-02   Student Result Management System 1.0 - Authentication Bypass SQL Injection 3 WEB Ritesh Gohil
2020-12-02   EgavilanMedia User Registration & Login System with Admin Panel 1.0 - CSRF 3 WEB Hardik Solanki
2020-12-02   Under Construction Page with CPanel 1.0 - SQL injection 3 WEB Mayur Parmar
2020-12-02   Pharmacy Store Management System 1.0 - 'id' SQL Injection 3 WEB Aydın Baran Ertemir
2020-12-02   ILIAS Learning Management System 4.3 - SSRF 2 WEB Dot
2020-12-02   Expense Management System - 'description' Stored Cross Site Scripting 2 WEB Nikhil Kumar
2020-12-01   Tendenci 12.3.1 - CSV/ Formula Injection 2 WEB Mufaddal Masalawala
2020-12-01   Social Networking Site - Authentication Bypass (SQli) 2 WEB gh1mau
2020-12-01   Pandora FMS 7.0 NG 749 - Multiple Persistent Cross-Site Scripting Vulnerabilities 3 WEB Matthew Aberegg
2020-12-01   Medical Center Portal Management System 1.0 - 'login' SQL Injection 5 WEB Aydın Baran Ertemir
2020-12-01   LEPTON CMS 4.7.0 - 'URL' Persistent Cross-Site Scripting 4 WEB Sagar Banwa
2020-12-01   Tailor Management System 1.0 - Unrestricted File Upload to Remote Code Execution 5 WEB Saeed Bala Ahmed
2020-12-01   Multi Restaurant Table Reservation System 1.0 - Multiple Persistent XSS 3 WEB yunaranyancat
2020-12-01   Setelsa Conacwin 3.7.1.2 - Local File Inclusion 3 WEB Bryan Rodriguez Martin
2020-12-01   Pharmacy/Medical Store & Sale Point 1.0 - 'email' SQL Injection 4 WEB naivenom
2020-12-01   Online Shopping Alphaware 1.0 - Error Based SQL injection 4 WEB Moaaz Taha
2020-12-01   Wordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site Scripting 6 WEB B3KC4T
2020-12-01   Joomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File Upload 5 WEB ThelastVvV
2020-12-01   TypeSetter 5.1 - CSRF (Change admin e-mail) 5 WEB Alperen Ergel
2020-11-30   Intelbras Router RF 301K 1.1.2 - Authentication Bypass 5 WEB Kaio Amaral
2020-11-30   Rejetto HttpFileServer 2.3.x - Remote Command Execution (3) 7 WEB Óscar Andreu
2020-11-30   ATX MiniCMTS200a Broadband Gateway 2.0 - Credential Disclosure 6 WEB Zagros Bingol
2020-11-27   Best Support System 3.0.4 - 'ticket_body' Persistent XSS (Authenticated) 5 WEB Ex.Mi
2020-11-27   ElkarBackup 1.3.3 - 'Policy[name]' and 'Policy[Description]' Stored Cross-site Scripting 5 WEB Vyshnav nk
2020-11-27   House Rental 1.0 - 'keywords' SQL Injection 5 WEB boku
2020-11-27   Wordpress Theme Accesspress Social Icons 1.7.9 - SQL injection (Authenticated) 4 WEB SunCSR
2020-11-27   Moodle 3.8 - Unrestricted File Upload 3 WEB Sirwan Veisi
2020-11-27   Acronis Cyber Backup 12.5 Build 16341 - Unauthenticated SSRF 4 WEB Julien Ahrens
2020-11-27   Laravel Administrator 4 - Unrestricted File Upload (Authenticated) 4 WEB Xavi Beltran
2020-11-27   Ruckus IoT Controller (Ruckus vRIoT) 1.5.1.0.21 - Remote Code Execution 5 WEB Emre SUREN
2020-11-27   WonderCMS 3.1.3 - 'uploadFile' Stored Cross-Site Scripting 3 WEB Sun* Cyber Security Research Team
2020-11-27   Wordpress Theme Wibar 1.1.8 - 'Brand Component' Stored Cross Site Scripting 4 WEB Ilca Lucian Florin
2020-11-25   SyncBreeze 10.0.28 - 'password' Remote Buffer Overflow 4 WEB Abdessalam king
2020-11-25   osCommerce 2.3.4.1 - 'title' Persistent Cross-Site Scripting 4 WEB Emre Aslan
2020-11-25   WonderCMS 3.1.3 - 'page' Persistent Cross-Site Scripting 5 WEB Mayur Parmar
2020-11-24   OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting 2 WEB Hemant Patidar
2020-11-24   OpenCart 3.0.3.6 - 'Profile Image' Stored Cross-Site Scripting (Authenticated) 4 WEB Hemant Patidar
2020-11-24   Seowon 130-SLC router 1.0.11 - 'ipAddr' RCE (Authenticated) 3 WEB maj0rmil4d
2020-11-24   ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit) 3 WEB Giuseppe Fuggiano
2020-11-24   Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service 2 WEB SunCSR
2020-11-24   nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting 4 WEB Hemant Patidar
2020-11-23   TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass 4 WEB malwrforensics
2020-11-23   LifeRay 7.2.1 GA2 - Stored XSS 4 WEB 3ndG4me
2020-11-23   VTiger v7.0 CRM - 'To' Persistent XSS 3 WEB Vulnerability-Lab
2020-11-20   WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting 4 WEB Hemant Patidar
2020-11-19   Nagios Log Server 2.1.7 - Persistent Cross-Site Scripting 4 WEB Emre ÖVÜNÇ
2020-11-19   M/Monit 3.7.4 - Password Disclosure 4 WEB Dolev Farhi
2020-11-19   M/Monit 3.7.4 - Privilege Escalation 5 WEB Dolev Farhi
2020-11-19   Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection 4 WEB Gabriele Zuddas
2020-11-19   TestBox CFML Test Framework 4.1.0 - Directory Traversal 4 WEB Darren King
2020-11-19   TestBox CFML Test Framework 4.1.0 - Arbitrary File Write and Remote Code Execution 4 WEB Darren King