2020-10-23
|
|
Online Library Management System 1.0 - Arbitrary File Upload
|
3 |
WEB
|
Jyotsna Adhana
|
2020-10-21
|
|
Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
|
4 |
WEB
|
Maximilian Barz
|
2020-10-21
|
|
Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
|
4 |
WEB
|
Adeeb Shah
|
2020-10-21
|
|
Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scripting
|
3 |
WEB
|
Adeeb Shah
|
2020-10-21
|
|
Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scripting
|
4 |
WEB
|
Adeeb Shah
|
2020-10-21
|
|
GOautodial 4.0 - Authenticated Shell Upload
|
4 |
WEB
|
Balzabu
|
2020-10-21
|
|
School Faculty Scheduling System 1.0 - Authentication Bypass POC
|
4 |
WEB
|
Jyotsna Adhana
|
2020-10-21
|
|
School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
|
4 |
WEB
|
Jyotsna Adhana
|
2020-10-21
|
|
Hrsale 2.0.0 - Local File Inclusion
|
4 |
WEB
|
Sosecure
|
2020-10-20
|
|
WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting (Authenticated)
|
4 |
WEB
|
n1x_
|
2020-10-20
|
|
WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection
|
3 |
WEB
|
Jonatas Fil
|
2020-10-20
|
|
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
|
4 |
WEB
|
Jonatas Fil
|
2020-10-20
|
|
Mobile Shop System v1.0 - SQL Injection Authentication Bypass
|
4 |
WEB
|
Moaaz Taha
|
2020-10-20
|
|
RiteCMS 2.2.1 - Remote Code Execution (Authenticated)
|
4 |
WEB
|
H0j3n
|
2020-10-20
|
|
User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS
|
4 |
WEB
|
yusufmalikul
|
2020-10-20
|
|
WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload
|
4 |
WEB
|
Net-Hunter
|
2020-10-20
|
|
Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated)
|
4 |
WEB
|
nag0mez
|
2020-10-20
|
|
Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
|
3 |
WEB
|
Rahul Ramkumar
|
2020-10-20
|
|
Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Courses Content Disclosure
|
4 |
WEB
|
redtimmysec
|
2020-10-20
|
|
Loan Management System 1.0 - Multiple Cross Site Scripting (Stored)
|
3 |
WEB
|
Akıner Kısa
|
2020-10-20
|
|
Comtrend AR-5387un router - Persistent XSS (Authenticated)
|
4 |
WEB
|
OscarAkaElvis
|
2020-10-19
|
|
Textpattern CMS 4.6.2 - Cross-site Request Forgery
|
4 |
WEB
|
Alperen Ergel
|
2020-10-19
|
|
Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
|
4 |
WEB
|
Rodolfo Tavares
|
2020-10-19
|
|
Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
|
3 |
WEB
|
Kokn3t
|
2020-10-19
|
|
Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
|
4 |
WEB
|
Daniel Morris
|
2020-10-19
|
|
HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
|
4 |
WEB
|
Alexei Kojenov
|
2020-10-19
|
|
HiSilicon Video Encoders - Full admin access via backdoor password
|
3 |
WEB
|
Alexei Kojenov
|
2020-10-19
|
|
HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware
|
4 |
WEB
|
Alexei Kojenov
|
2020-10-19
|
|
HiSilicon Video Encoders - RCE via unauthenticated command injection
|
3 |
WEB
|
Alexei Kojenov
|
2020-10-19
|
|
HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal
|
4 |
WEB
|
Alexei Kojenov
|
2020-10-19
|
|
Online Job Portal 1.0 - Cross Site Scripting (Stored)
|
4 |
WEB
|
Akıner Kısa
|
2020-10-19
|
|
Online Discussion Forum Site 1.0 - XSS in Messaging System
|
5 |
WEB
|
j5oh
|
2020-10-19
|
|
Online Student's Management System 1.0 - Remote Code Execution (Authenticated)
|
4 |
WEB
|
Akıner Kısa
|
2020-10-19
|
|
Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection
|
4 |
WEB
|
Matthew Aberegg
|
2020-10-19
|
|
Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection
|
4 |
WEB
|
Matthew Aberegg
|
2020-10-19
|
|
Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting
|
4 |
WEB
|
Matthew Aberegg
|
2020-10-19
|
|
Tourism Management System 1.0 - Arbitrary File Upload
|
3 |
WEB
|
Ankita Pal
|
2020-10-16
|
|
CS-Cart 1.3.3 - authenticated RCE
|
3 |
WEB
|
0xmmnbassel
|
2020-10-16
|
|
CS-Cart 1.3.3 - 'classes_dir' LFI
|
3 |
WEB
|
0xmmnbassel
|
2020-10-16
|
|
Seat Reservation System 1.0 - Unauthenticated SQL Injection
|
3 |
WEB
|
Rahul Ramkumar
|
2020-10-16
|
|
Hotel Management System 1.0 - Remote Code Execution (Authenticated)
|
3 |
WEB
|
Aporlorxl23
|
2020-10-16
|
|
Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated)
|
3 |
WEB
|
Rahul Ramkumar
|
2020-10-16
|
|
aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated)
|
2 |
WEB
|
Ünsal Furkan Harani
|
2020-10-16
|
|
Restaurant Reservation System 1.0 - 'date' SQL Injection (Authenticated)
|
2 |
WEB
|
b1nary
|
2020-10-16
|
|
Company Visitor Management System (CVMS) 1.0 - Authentication Bypass
|
1 |
WEB
|
Oğuz Türkgenç
|
2020-10-16
|
|
Alumni Management System 1.0 - Authentication Bypass
|
2 |
WEB
|
Ankita Pal
|
2020-10-16
|
|
Employee Management System 1.0 - Authentication Bypass
|
2 |
WEB
|
Ankita Pal
|
2020-10-16
|
|
Employee Management System 1.0 - Cross Site Scripting (Stored)
|
2 |
WEB
|
Ankita Pal
|
2020-10-15
|
|
Zoo Management System 1.0 - Authentication Bypass
|
3 |
WEB
|
Jyotsna Adhana
|
2020-10-15
|
|
Simple Grocery Store Sales And Inventory System 1.0 - Authentication Bypass
|
4 |
WEB
|
Saurav Shukla
|
2020-10-15
|
|
rConfig 3.9.5 - Remote Code Execution (Unauthenticated)
|
5 |
WEB
|
Daniel Monzón
|
2020-10-15
|
|
Vehicle Parking Management System 1.0 - Authentication Bypass
|
3 |
WEB
|
BKpatron
|
2020-10-14
|
|
NodeBB Forum 1.12.2-1.14.2 - Account Takeover
|
3 |
WEB
|
Muhammed Eren Uygun
|
2020-07-23
|
|
TimeClock Software 1.01 0 - (Authenticated) Time-Based SQL Injection
|
2 |
WEB
|
François Bibeau
|
2020-10-13
|
|
berliCRM 1.0.24 - 'src_record' SQL Injection
|
4 |
WEB
|
Ahmet Ümit BAYRAM
|
2020-10-12
|
|
Cisco ASA and FTD 9.6.4.42 - Path Traversal
|
3 |
WEB
|
3ndG4me
|
2020-10-12
|
|
Online Students Management System 1.0 - 'username' SQL Injections
|
3 |
WEB
|
George Tsimpidas
|
2020-10-12
|
|
Liman 0.7 - Cross-Site Request Forgery (Change Password)
|
3 |
WEB
|
George Tsimpidas
|
2020-10-12
|
|
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Unauthenticated)
|
2 |
WEB
|
bzyo
|
2020-10-12
|
|
Small CRM 2.0 - 'email' SQL Injection
|
3 |
WEB
|
Ahmet Ümit BAYRAM
|
2020-10-09
|
|
openMAINT 1.1-2.4.2 - Arbitrary File Upload
|
2 |
WEB
|
mrb3n
|
2020-10-09
|
|
DynPG 4.9.1 - Persistent Cross-Site Scripting (Authenticated)
|
3 |
WEB
|
Enes Özeser
|
2020-10-09
|
|
Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
|
3 |
WEB
|
Ataberk YAVUZER
|
2020-10-08
|
|
D-Link DSR-250N 3.12 - Denial of Service (PoC)
|
2 |
WEB
|
RedTeam Pentesting GmbH
|
2020-10-08
|
|
SEO Panel 4.6.0 - Remote Code Execution (1)
|
3 |
WEB
|
Kiko Andreu
|
2020-10-07
|
|
Textpattern CMS 4.6.2 - 'body' Persistent Cross-Site Scripting
|
4 |
WEB
|
Alperen Ergel
|
2020-10-06
|
|
EasyPMS 1.0.0 - Authentication Bypass
|
4 |
WEB
|
Jok3r
|
2020-10-06
|
|
Karel IP Phone IP1211 Web Management Panel - Directory Traversal
|
4 |
WEB
|
berat isler
|
2020-10-05
|
|
SpamTitan 7.07 - Unauthenticated Remote Code Execution
|
5 |
WEB
|
Felipe Molina
|
2020-10-02
|
|
Photo Share Website 1.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Augkim
|
2020-10-02
|
|
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated)
|
4 |
WEB
|
bzyo
|
2020-10-01
|
|
Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting
|
5 |
WEB
|
Alperen Ergel
|
2020-10-01
|
|
CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)
|
6 |
WEB
|
Roel van Beurden
|
2020-10-01
|
|
GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting (Authenticated)
|
4 |
WEB
|
Roel van Beurden
|
2020-10-01
|
|
WebsiteBaker 2.12.2 - 'display_name' SQL Injection (authenticated)
|
5 |
WEB
|
Roel van Beurden
|
2020-10-01
|
|
MonoCMS Blog 1.0 - Arbitrary File Deletion (Authenticated)
|
5 |
WEB
|
Shahrukh Iqbal Mirza
|
2020-10-01
|
|
SpinetiX Fusion Digital Signage 3.4.8 - Username Enumeration
|
4 |
WEB
|
LiquidWorm
|
2020-10-01
|
|
SpinetiX Fusion Digital Signage 3.4.8 - Cross-Site Request Forgery (Add Admin)
|
5 |
WEB
|
LiquidWorm
|
2020-10-01
|
|
SpinetiX Fusion Digital Signage 3.4.8 - Database Backup Disclosure
|
5 |
WEB
|
LiquidWorm
|
2020-10-01
|
|
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - File Delete Path Traversal
|
4 |
WEB
|
LiquidWorm
|
2020-10-01
|
|
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - Server-Side Request Forgery (Unauthenticat
|
4 |
WEB
|
LiquidWorm
|
2020-09-29
|
|
WebsiteBaker 2.12.2 - Remote Code Execution
|
3 |
WEB
|
Enesdex
|
2020-09-28
|
|
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
|
3 |
WEB
|
Ademar Nowasky Junior
|
2020-09-28
|
|
Mida eFramework 2.8.9 - Remote Code Execution
|
3 |
WEB
|
elbae
|
2020-09-25
|
|
B-swiss 3 Digital Signage System 3.6.5 - Database Disclosure
|
4 |
WEB
|
LiquidWorm
|
2020-09-25
|
|
B-swiss 3 Digital Signage System 3.6.5 - Cross-Site Request Forgery (Add Maintenance Admin)
|
4 |
WEB
|
LiquidWorm
|
2020-09-25
|
|
Anchor CMS 0.12.7 - Persistent Cross-Site Scripting (Authenticated)
|
5 |
WEB
|
Sinem Şahin
|
2020-09-25
|
|
BigTree CMS 4.4.10 - Remote Code Execution
|
5 |
WEB
|
SunCSR
|
2020-09-24
|
|
Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Rahul Ramkumar
|
2020-09-24
|
|
Simple Online Food Ordering System 1.0 - 'id' SQL Injection (Unauthenticated)
|
4 |
WEB
|
Aporlorxl23
|
2020-09-23
|
|
Online Food Ordering System 1.0 - Remote Code Execution
|
4 |
WEB
|
Eren Şimşek
|
2020-09-22
|
|
Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Alperen Ergel
|
2020-09-22
|
|
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
|
4 |
WEB
|
Milad Fadavvi
|
2020-09-21
|
|
B-swiss 3 Digital Signage System 3.6.5 - Remote Code Execution
|
5 |
WEB
|
LiquidWorm
|
2020-09-21
|
|
Mida eFramework 2.9.0 - Back Door Access
|
4 |
WEB
|
elbae
|
2020-09-21
|
|
Seat Reservation System 1.0 - 'id' SQL Injection
|
3 |
WEB
|
Augkim
|
2020-09-21
|
|
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
|
3 |
WEB
|
Noth
|
2020-09-21
|
|
Online Shop Project 1.0 - 'p' SQL Injection
|
4 |
WEB
|
Augkim
|
2020-09-18
|
|
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
|
4 |
WEB
|
Nikolas Geiselman
|
2020-09-18
|
|
SpamTitan 7.07 - Remote Code Execution (Authenticated)
|
4 |
WEB
|
Felipe Molina
|
2020-09-16
|
|
Piwigo 2.10.1 - Cross Site Scripting
|
3 |
WEB
|
Iridium
|
2020-09-15
|
|
Tailor MS 1.0 - Reflected Cross-Site Scripting
|
4 |
WEB
|
boku
|
2020-09-15
|
|
ThinkAdmin 6 - Arbitrarily File Read
|
5 |
WEB
|
Hzllaga
|
2020-09-14
|
|
Joomla! paGO Commerce 2.5.9.0 - SQL Injection (Authenticated)
|
4 |
WEB
|
Mehmet Kelepçe
|
2020-09-14
|
|
RAD SecFlow-1v SF_0290_2.3.01.26 - Cross-Site Request Forgery (Reboot)
|
3 |
WEB
|
Jonatan Schor
|
2020-09-14
|
|
RAD SecFlow-1v SF_0290_2.3.01.26 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Jonatan Schor
|
2020-09-11
|
|
Tea LaTex 1.0 - Remote Code Execution (Unauthenticated)
|
4 |
WEB
|
nepska
|
2020-09-11
|
|
VTENEXT 19 CE - Remote Code Execution
|
2 |
WEB
|
Marco Ruela
|
2020-09-10
|
|
ZTE Router F602W - Captcha Bypass
|
3 |
WEB
|
Hritik Vijay
|
2020-09-10
|
|
CuteNews 2.1.2 - Remote Code Execution
|
3 |
WEB
|
Musyoka Ian
|
2020-09-10
|
|
Tiandy IPC and NVR 9.12.7 - Credential Disclosure
|
3 |
WEB
|
zb3
|
2020-09-09
|
|
Scopia XT Desktop 8.3.915.4 - Cross-Site Request Forgery (change admin password)
|
4 |
WEB
|
V1n1v131r4
|
2020-09-09
|
|
Tailor Management System - 'id' SQL Injection
|
2 |
WEB
|
Mosaaed
|
2020-09-07
|
|
ManageEngine Applications Manager 14700 - Remote Code Execution (Authenticated)
|
2 |
WEB
|
Hodorsec
|
2020-09-07
|
|
grocy 2.7.1 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Mufaddal Masalawala
|
2020-09-07
|
|
Cabot 0.11.12 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Abhiram V
|
2020-09-03
|
|
SiteMagic CMS 4.4.2 - Arbitrary File Upload (Authenticated)
|
3 |
WEB
|
V1n1v131r4
|
2020-09-03
|
|
Daily Tracker System 1.0 - Authentication Bypass
|
3 |
WEB
|
Adeeb Shah
|
2020-09-03
|
|
BloodX CMS 1.0 - Authentication Bypass
|
3 |
WEB
|
BKpatron
|
2020-09-03
|
|
Savsoft Quiz Enterprise Version 5.5 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Hemant Patidar
|
2020-09-02
|
|
Rukovoditel 2.7.1 - Remote Code Execution (2) (Authenticated)
|
4 |
WEB
|
danyx07
|
2020-09-02
|
|
Stock Management System 1.0 - Cross-Site Request Forgery (Change Username)
|
3 |
WEB
|
boku
|
2020-09-01
|
|
moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)
|
3 |
WEB
|
Abdulkadir Kaya
|
2020-09-01
|
|
Mara CMS 7.5 - Remote Code Execution (Authenticated)
|
5 |
WEB
|
0blio_
|
2020-08-31
|
|
CMS Made Simple 2.2.14 - Arbitrary File Upload (Authenticated)
|
3 |
WEB
|
Luis Noriega
|