2020-10-16
|
|
Hotel Management System 1.0 - Remote Code Execution (Authenticated)
|
0 |
WEB
|
Aporlorxl23
|
2020-10-16
|
|
Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated)
|
0 |
WEB
|
Rahul Ramkumar
|
2020-10-16
|
|
aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated)
|
0 |
WEB
|
Ünsal Furkan Harani
|
2020-10-16
|
|
Restaurant Reservation System 1.0 - 'date' SQL Injection (Authenticated)
|
1 |
WEB
|
b1nary
|
2020-10-16
|
|
Company Visitor Management System (CVMS) 1.0 - Authentication Bypass
|
0 |
WEB
|
Oğuz Türkgenç
|
2020-10-16
|
|
Alumni Management System 1.0 - Authentication Bypass
|
1 |
WEB
|
Ankita Pal
|
2020-10-16
|
|
Employee Management System 1.0 - Authentication Bypass
|
0 |
WEB
|
Ankita Pal
|
2020-10-16
|
|
Employee Management System 1.0 - Cross Site Scripting (Stored)
|
1 |
WEB
|
Ankita Pal
|
2020-10-15
|
|
Zoo Management System 1.0 - Authentication Bypass
|
1 |
WEB
|
Jyotsna Adhana
|
2020-10-15
|
|
Simple Grocery Store Sales And Inventory System 1.0 - Authentication Bypass
|
3 |
WEB
|
Saurav Shukla
|
2020-10-15
|
|
rConfig 3.9.5 - Remote Code Execution (Unauthenticated)
|
4 |
WEB
|
Daniel Monzón
|
2020-10-15
|
|
Vehicle Parking Management System 1.0 - Authentication Bypass
|
2 |
WEB
|
BKpatron
|
2020-10-14
|
|
NodeBB Forum 1.12.2-1.14.2 - Account Takeover
|
3 |
WEB
|
Muhammed Eren Uygun
|
2020-07-23
|
|
TimeClock Software 1.01 0 - (Authenticated) Time-Based SQL Injection
|
2 |
WEB
|
François Bibeau
|
2020-10-13
|
|
berliCRM 1.0.24 - 'src_record' SQL Injection
|
4 |
WEB
|
Ahmet Ümit BAYRAM
|
2020-10-12
|
|
Cisco ASA and FTD 9.6.4.42 - Path Traversal
|
3 |
WEB
|
3ndG4me
|
2020-10-12
|
|
Online Students Management System 1.0 - 'username' SQL Injections
|
3 |
WEB
|
George Tsimpidas
|
2020-10-12
|
|
Liman 0.7 - Cross-Site Request Forgery (Change Password)
|
3 |
WEB
|
George Tsimpidas
|
2020-10-12
|
|
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
bzyo
|
2020-10-12
|
|
Small CRM 2.0 - 'email' SQL Injection
|
3 |
WEB
|
Ahmet Ümit BAYRAM
|
2020-10-09
|
|
openMAINT 1.1-2.4.2 - Arbitrary File Upload
|
2 |
WEB
|
mrb3n
|
2020-10-09
|
|
DynPG 4.9.1 - Persistent Cross-Site Scripting (Authenticated)
|
3 |
WEB
|
Enes Özeser
|
2020-10-09
|
|
Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
|
2 |
WEB
|
Ataberk YAVUZER
|
2020-10-08
|
|
D-Link DSR-250N 3.12 - Denial of Service (PoC)
|
1 |
WEB
|
RedTeam Pentesting GmbH
|
2020-10-08
|
|
SEO Panel 4.6.0 - Remote Code Execution (1)
|
3 |
WEB
|
Kiko Andreu
|
2020-10-07
|
|
Textpattern CMS 4.6.2 - 'body' Persistent Cross-Site Scripting
|
4 |
WEB
|
Alperen Ergel
|
2020-10-06
|
|
EasyPMS 1.0.0 - Authentication Bypass
|
3 |
WEB
|
Jok3r
|
2020-10-06
|
|
Karel IP Phone IP1211 Web Management Panel - Directory Traversal
|
3 |
WEB
|
berat isler
|
2020-10-05
|
|
SpamTitan 7.07 - Unauthenticated Remote Code Execution
|
4 |
WEB
|
Felipe Molina
|
2020-10-02
|
|
Photo Share Website 1.0 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Augkim
|
2020-10-02
|
|
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated)
|
3 |
WEB
|
bzyo
|
2020-10-01
|
|
Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting
|
3 |
WEB
|
Alperen Ergel
|
2020-10-01
|
|
CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)
|
5 |
WEB
|
Roel van Beurden
|
2020-10-01
|
|
GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting (Authenticated)
|
3 |
WEB
|
Roel van Beurden
|
2020-10-01
|
|
WebsiteBaker 2.12.2 - 'display_name' SQL Injection (authenticated)
|
4 |
WEB
|
Roel van Beurden
|
2020-10-01
|
|
MonoCMS Blog 1.0 - Arbitrary File Deletion (Authenticated)
|
4 |
WEB
|
Shahrukh Iqbal Mirza
|
2020-10-01
|
|
SpinetiX Fusion Digital Signage 3.4.8 - Username Enumeration
|
3 |
WEB
|
LiquidWorm
|
2020-10-01
|
|
SpinetiX Fusion Digital Signage 3.4.8 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
LiquidWorm
|
2020-10-01
|
|
SpinetiX Fusion Digital Signage 3.4.8 - Database Backup Disclosure
|
4 |
WEB
|
LiquidWorm
|
2020-10-01
|
|
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - File Delete Path Traversal
|
3 |
WEB
|
LiquidWorm
|
2020-10-01
|
|
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - Server-Side Request Forgery (Unauthenticat
|
3 |
WEB
|
LiquidWorm
|
2020-09-29
|
|
WebsiteBaker 2.12.2 - Remote Code Execution
|
2 |
WEB
|
Enesdex
|
2020-09-28
|
|
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
|
2 |
WEB
|
Ademar Nowasky Junior
|
2020-09-28
|
|
Mida eFramework 2.8.9 - Remote Code Execution
|
2 |
WEB
|
elbae
|
2020-09-25
|
|
B-swiss 3 Digital Signage System 3.6.5 - Database Disclosure
|
3 |
WEB
|
LiquidWorm
|
2020-09-25
|
|
B-swiss 3 Digital Signage System 3.6.5 - Cross-Site Request Forgery (Add Maintenance Admin)
|
3 |
WEB
|
LiquidWorm
|
2020-09-25
|
|
Anchor CMS 0.12.7 - Persistent Cross-Site Scripting (Authenticated)
|
3 |
WEB
|
Sinem Şahin
|
2020-09-25
|
|
BigTree CMS 4.4.10 - Remote Code Execution
|
4 |
WEB
|
SunCSR
|
2020-09-24
|
|
Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Rahul Ramkumar
|
2020-09-24
|
|
Simple Online Food Ordering System 1.0 - 'id' SQL Injection (Unauthenticated)
|
3 |
WEB
|
Aporlorxl23
|
2020-09-23
|
|
Online Food Ordering System 1.0 - Remote Code Execution
|
3 |
WEB
|
Eren Şimşek
|
2020-09-22
|
|
Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Alperen Ergel
|
2020-09-22
|
|
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
|
3 |
WEB
|
Milad Fadavvi
|
2020-09-21
|
|
B-swiss 3 Digital Signage System 3.6.5 - Remote Code Execution
|
4 |
WEB
|
LiquidWorm
|
2020-09-21
|
|
Mida eFramework 2.9.0 - Back Door Access
|
3 |
WEB
|
elbae
|
2020-09-21
|
|
Seat Reservation System 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Augkim
|
2020-09-21
|
|
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
|
2 |
WEB
|
Noth
|
2020-09-21
|
|
Online Shop Project 1.0 - 'p' SQL Injection
|
3 |
WEB
|
Augkim
|
2020-09-18
|
|
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
|
3 |
WEB
|
Nikolas Geiselman
|
2020-09-18
|
|
SpamTitan 7.07 - Remote Code Execution (Authenticated)
|
3 |
WEB
|
Felipe Molina
|
2020-09-16
|
|
Piwigo 2.10.1 - Cross Site Scripting
|
2 |
WEB
|
Iridium
|
2020-09-15
|
|
Tailor MS 1.0 - Reflected Cross-Site Scripting
|
3 |
WEB
|
boku
|
2020-09-15
|
|
ThinkAdmin 6 - Arbitrarily File Read
|
4 |
WEB
|
Hzllaga
|
2020-09-14
|
|
Joomla! paGO Commerce 2.5.9.0 - SQL Injection (Authenticated)
|
3 |
WEB
|
Mehmet Kelepçe
|
2020-09-14
|
|
RAD SecFlow-1v SF_0290_2.3.01.26 - Cross-Site Request Forgery (Reboot)
|
2 |
WEB
|
Jonatan Schor
|
2020-09-14
|
|
RAD SecFlow-1v SF_0290_2.3.01.26 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Jonatan Schor
|
2020-09-11
|
|
Tea LaTex 1.0 - Remote Code Execution (Unauthenticated)
|
4 |
WEB
|
nepska
|
2020-09-11
|
|
VTENEXT 19 CE - Remote Code Execution
|
2 |
WEB
|
Marco Ruela
|
2020-09-10
|
|
ZTE Router F602W - Captcha Bypass
|
3 |
WEB
|
Hritik Vijay
|
2020-09-10
|
|
CuteNews 2.1.2 - Remote Code Execution
|
3 |
WEB
|
Musyoka Ian
|
2020-09-10
|
|
Tiandy IPC and NVR 9.12.7 - Credential Disclosure
|
3 |
WEB
|
zb3
|
2020-09-09
|
|
Scopia XT Desktop 8.3.915.4 - Cross-Site Request Forgery (change admin password)
|
4 |
WEB
|
V1n1v131r4
|
2020-09-09
|
|
Tailor Management System - 'id' SQL Injection
|
1 |
WEB
|
Mosaaed
|
2020-09-07
|
|
ManageEngine Applications Manager 14700 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Hodorsec
|
2020-09-07
|
|
grocy 2.7.1 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Mufaddal Masalawala
|
2020-09-07
|
|
Cabot 0.11.12 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Abhiram V
|
2020-09-03
|
|
SiteMagic CMS 4.4.2 - Arbitrary File Upload (Authenticated)
|
1 |
WEB
|
V1n1v131r4
|
2020-09-03
|
|
Daily Tracker System 1.0 - Authentication Bypass
|
2 |
WEB
|
Adeeb Shah
|
2020-09-03
|
|
BloodX CMS 1.0 - Authentication Bypass
|
2 |
WEB
|
BKpatron
|
2020-09-03
|
|
Savsoft Quiz Enterprise Version 5.5 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Hemant Patidar
|
2020-09-02
|
|
Rukovoditel 2.7.1 - Remote Code Execution (2) (Authenticated)
|
2 |
WEB
|
danyx07
|
2020-09-02
|
|
Stock Management System 1.0 - Cross-Site Request Forgery (Change Username)
|
2 |
WEB
|
boku
|
2020-09-01
|
|
moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)
|
3 |
WEB
|
Abdulkadir Kaya
|
2020-09-01
|
|
Mara CMS 7.5 - Remote Code Execution (Authenticated)
|
2 |
WEB
|
0blio_
|
2020-08-31
|
|
CMS Made Simple 2.2.14 - Arbitrary File Upload (Authenticated)
|
2 |
WEB
|
Luis Noriega
|
2020-08-31
|
|
Fuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated)
|
3 |
WEB
|
c0mpu7er
|
2020-08-31
|
|
Mara CMS 7.5 - Reflective Cross-Site Scripting
|
1 |
WEB
|
George Tsimpidas
|
2020-08-31
|
|
Online Book Store 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Moaaz Taha
|
2020-08-28
|
|
Eibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation
|
2 |
WEB
|
LiquidWorm
|
2020-08-28
|
|
SymphonyCMS 3.0.0 - Persistent Cross-Site Scripting
|
2 |
WEB
|
SunCSR
|
2020-08-28
|
|
Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Jinson Varghese Behanan
|
2020-08-28
|
|
Online Shopping Alphaware 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Moaaz Taha
|
2020-08-27
|
|
Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
|
1 |
WEB
|
SunCSR Team
|
2020-08-27
|
|
Mida eFramework 2.9.0 - Remote Code Execution
|
1 |
WEB
|
elbae
|
2020-08-26
|
|
Eibiz i-Media Server Digital Signage 3.8.0 - Directory Traversal
|
1 |
WEB
|
LiquidWorm
|
2020-08-26
|
|
Ericom Access Server x64 9.2.0 - Server-Side Request Forgery
|
2 |
WEB
|
hyp3rlinx
|
2020-08-24
|
|
Eibiz i-Media Server Digital Signage 3.8.0 - Configuration Disclosure
|
2 |
WEB
|
LiquidWorm
|
2020-08-24
|
|
Eibiz i-Media Server Digital Signage 3.8.0 - Authentication Bypass
|
2 |
WEB
|
LiquidWorm
|
2020-08-24
|
|
LimeSurvey 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
|
2 |
WEB
|
Matthew Aberegg
|
2017-07-24
|
|
vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit)
|
1 |
WEB
|
Metasploit
|
2020-08-21
|
|
Seowon SlC 130 Router - Remote Code Execution
|
2 |
WEB
|
maj0rmil4d
|
2020-08-21
|
|
Complaint Management System 1.0 - 'cid' SQL Injection
|
1 |
WEB
|
Mohamed Elobeid
|
2020-08-20
|
|
PNPSCADA 2.200816204020 - 'interf' SQL Injection (Authenticated)
|
2 |
WEB
|
İsmail ERKEK
|
2020-08-20
|
|
ElkarBackup 1.3.3 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Enes Özeser
|
2020-08-19
|
|
Ruijie Networks Switch eWeb S29_RGOS 11.4 - Directory Traversal
|
2 |
WEB
|
Tuygun
|
2020-08-18
|
|
Savsoft Quiz 5 - Stored Cross-Site Scripting
|
1 |
WEB
|
Mayur Parmar
|
2020-08-18
|
|
Pharmacy Medical Store and Sale Point 1.0 - 'catid' SQL Injection
|
2 |
WEB
|
Moaaz Taha
|
2020-08-17
|
|
QiHang Media Web Digital Signage 3.0.9 - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
LiquidWorm
|
2020-08-17
|
|
QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Disclosure
|
2 |
WEB
|
LiquidWorm
|
2020-08-17
|
|
QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Deletion
|
3 |
WEB
|
LiquidWorm
|
2020-08-17
|
|
QiHang Media Web Digital Signage 3.0.9 - Cleartext Credential Disclosure
|
2 |
WEB
|
LiquidWorm
|
2020-08-17
|
|
Microsoft SharePoint Server 2019 - Remote Code Execution
|
2 |
WEB
|
West Shepherd
|
2020-08-17
|
|
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
|
1 |
WEB
|
Alexandre ZANNI
|
2020-08-13
|
|
GetSimple CMS Plugin Multi User 1.8.2 - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
boku
|
2020-08-13
|
|
Artica Proxy 4.3.0 - Authentication Bypass
|
1 |
WEB
|
Dan Duffy
|
2020-08-12
|
|
vBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
|
1 |
WEB
|
zenofex
|
2020-08-12
|
|
CMS Made Simple 2.2.14 - Authenticated Arbitrary File Upload
|
1 |
WEB
|
Roel van Beurden
|
2020-08-11
|
|
Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated)
|
1 |
WEB
|
Roel van Beurden
|
2020-08-10
|
|
ManageEngine ADSelfService Build prior to 6003 - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
Bhadresh Patel
|
2020-08-10
|
|
Warehouse Inventory System 1.0 - Cross-Site Request Forgery (Change Admin Password)
|
2 |
WEB
|
boku
|
2020-08-07
|
|
Daily Expenses Management System 1.0 - 'item' SQL Injection
|
2 |
WEB
|
screetsec
|
2020-08-07
|
|
All-Dynamics Digital Signage System 2.0.2 - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
LiquidWorm
|
2020-08-06
|
|
Victor CMS 1.0 - 'Search' SQL Injection
|
1 |
WEB
|
screetsec
|
2020-08-05
|
|
Stock Management System 1.0 - Authentication Bypass
|
2 |
WEB
|
Adeeb Shah
|
2020-08-04
|
|
Daily Expenses Management System 1.0 - 'username' SQL Injection
|
2 |
WEB
|
Daniel Ortiz
|