2020-08-31
|
|
Fuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated)
|
4 |
WEB
|
c0mpu7er
|
2020-08-31
|
|
Mara CMS 7.5 - Reflective Cross-Site Scripting
|
3 |
WEB
|
George Tsimpidas
|
2020-08-31
|
|
Online Book Store 1.0 - 'id' SQL Injection
|
3 |
WEB
|
Moaaz Taha
|
2020-08-28
|
|
Eibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation
|
4 |
WEB
|
LiquidWorm
|
2020-08-28
|
|
SymphonyCMS 3.0.0 - Persistent Cross-Site Scripting
|
3 |
WEB
|
SunCSR
|
2020-08-28
|
|
Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Jinson Varghese Behanan
|
2020-08-28
|
|
Online Shopping Alphaware 1.0 - 'id' SQL Injection
|
3 |
WEB
|
Moaaz Taha
|
2020-08-27
|
|
Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
|
2 |
WEB
|
SunCSR Team
|
2020-08-27
|
|
Mida eFramework 2.9.0 - Remote Code Execution
|
3 |
WEB
|
elbae
|
2020-08-26
|
|
Eibiz i-Media Server Digital Signage 3.8.0 - Directory Traversal
|
2 |
WEB
|
LiquidWorm
|
2020-08-26
|
|
Ericom Access Server x64 9.2.0 - Server-Side Request Forgery
|
3 |
WEB
|
hyp3rlinx
|
2020-08-24
|
|
Eibiz i-Media Server Digital Signage 3.8.0 - Configuration Disclosure
|
4 |
WEB
|
LiquidWorm
|
2020-08-24
|
|
Eibiz i-Media Server Digital Signage 3.8.0 - Authentication Bypass
|
3 |
WEB
|
LiquidWorm
|
2020-08-24
|
|
LimeSurvey 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
|
4 |
WEB
|
Matthew Aberegg
|
2017-07-24
|
|
vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit)
|
5 |
WEB
|
Metasploit
|
2020-08-21
|
|
Seowon SlC 130 Router - Remote Code Execution
|
5 |
WEB
|
maj0rmil4d
|
2020-08-21
|
|
Complaint Management System 1.0 - 'cid' SQL Injection
|
2 |
WEB
|
Mohamed Elobeid
|
2020-08-20
|
|
PNPSCADA 2.200816204020 - 'interf' SQL Injection (Authenticated)
|
3 |
WEB
|
İsmail ERKEK
|
2020-08-20
|
|
ElkarBackup 1.3.3 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Enes Özeser
|
2020-08-19
|
|
Ruijie Networks Switch eWeb S29_RGOS 11.4 - Directory Traversal
|
3 |
WEB
|
Tuygun
|
2020-08-18
|
|
Savsoft Quiz 5 - Stored Cross-Site Scripting
|
3 |
WEB
|
Mayur Parmar
|
2020-08-18
|
|
Pharmacy Medical Store and Sale Point 1.0 - 'catid' SQL Injection
|
3 |
WEB
|
Moaaz Taha
|
2020-08-17
|
|
QiHang Media Web Digital Signage 3.0.9 - Remote Code Execution (Unauthenticated)
|
4 |
WEB
|
LiquidWorm
|
2020-08-17
|
|
QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Disclosure
|
3 |
WEB
|
LiquidWorm
|
2020-08-17
|
|
QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Deletion
|
3 |
WEB
|
LiquidWorm
|
2020-08-17
|
|
QiHang Media Web Digital Signage 3.0.9 - Cleartext Credential Disclosure
|
5 |
WEB
|
LiquidWorm
|
2020-08-17
|
|
Microsoft SharePoint Server 2019 - Remote Code Execution
|
4 |
WEB
|
West Shepherd
|
2020-08-17
|
|
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
|
4 |
WEB
|
Alexandre ZANNI
|
2020-08-13
|
|
GetSimple CMS Plugin Multi User 1.8.2 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
boku
|
2020-08-13
|
|
Artica Proxy 4.3.0 - Authentication Bypass
|
3 |
WEB
|
Dan Duffy
|
2020-08-12
|
|
vBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
|
4 |
WEB
|
zenofex
|
2020-08-12
|
|
CMS Made Simple 2.2.14 - Authenticated Arbitrary File Upload
|
4 |
WEB
|
Roel van Beurden
|
2020-08-11
|
|
Fuel CMS 1.4.7 - 'col' SQL Injection (Authenticated)
|
3 |
WEB
|
Roel van Beurden
|
2020-08-10
|
|
ManageEngine ADSelfService Build prior to 6003 - Remote Code Execution (Unauthenticated)
|
4 |
WEB
|
Bhadresh Patel
|
2020-08-10
|
|
Warehouse Inventory System 1.0 - Cross-Site Request Forgery (Change Admin Password)
|
5 |
WEB
|
boku
|
2020-08-07
|
|
Daily Expenses Management System 1.0 - 'item' SQL Injection
|
4 |
WEB
|
screetsec
|
2020-08-07
|
|
All-Dynamics Digital Signage System 2.0.2 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
LiquidWorm
|
2020-08-06
|
|
Victor CMS 1.0 - 'Search' SQL Injection
|
3 |
WEB
|
screetsec
|
2020-08-05
|
|
Stock Management System 1.0 - Authentication Bypass
|
3 |
WEB
|
Adeeb Shah
|
2020-08-04
|
|
Daily Expenses Management System 1.0 - 'username' SQL Injection
|
4 |
WEB
|
Daniel Ortiz
|
2020-08-04
|
|
Pi-hole 4.3.2 - Remote Code Execution (Authenticated)
|
4 |
WEB
|
Luis Vacacas
|
2020-07-30
|
|
Online Shopping Alphaware 1.0 - Authentication Bypass
|
3 |
WEB
|
Ahmed Abbas
|
2020-07-29
|
|
Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Jinson Varghese Behanan
|
2020-07-29
|
|
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
|
4 |
WEB
|
0xmmnbassel
|
2020-07-28
|
|
Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
|
4 |
WEB
|
0xmmnbassel
|
2020-07-27
|
|
eGroupWare 1.14 - 'spellchecker.php' Remote Command Execution
|
4 |
WEB
|
Berk KIRAS
|
2020-07-26
|
|
Rails 5.0.1 - Remote Code Execution
|
4 |
WEB
|
Lucas Amorim
|
2020-07-26
|
|
Virtual Airlines Manager 2.6.2 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Peter Blue
|
2020-07-26
|
|
pfSense 2.4.4-p3 - Cross-Site Request Forgery
|
4 |
WEB
|
ghost_fh
|
2020-07-26
|
|
Socket.io-file 2.0.31 - Arbitrary File Upload
|
5 |
WEB
|
Cr0wTom
|
2020-07-26
|
|
Sickbeard 0.1 - Cross-Site Request Forgery (Disable Authentication)
|
5 |
WEB
|
bdrake
|
2020-07-26
|
|
F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
|
4 |
WEB
|
Carlos E. Vieira
|
2020-07-26
|
|
Webtareas 2.1p - Arbitrary File Upload (Authenticated)
|
3 |
WEB
|
AppleBois
|
2020-07-26
|
|
Bio Star 2.8.2 - Local File Inclusion
|
4 |
WEB
|
SITE Team
|
2020-07-26
|
|
PandoraFMS 7.0 NG 746 - Persistent Cross-Site Scripting
|
3 |
WEB
|
AppleBois
|
2020-07-26
|
|
Koken CMS 0.22.24 - Arbitrary File Upload (Authenticated)
|
3 |
WEB
|
V1n1v131r4
|
2020-07-26
|
|
elaniin CMS - Authentication Bypass
|
5 |
WEB
|
BKpatron
|
2020-07-26
|
|
Online Course Registration 1.0 - Unauthenticated Remote Code Execution
|
4 |
WEB
|
boku
|
2020-07-26
|
|
LibreHealth 2.0.0 - Authenticated Remote Code Execution
|
4 |
WEB
|
boku
|
2020-07-26
|
|
Bludit 3.9.2 - Directory Traversal
|
5 |
WEB
|
James Green
|
2020-07-26
|
|
PandoraFMS NG747 7.0 - 'filename' Persistent Cross-Site Scripting
|
5 |
WEB
|
Emre ÖVÜNÇ
|
2020-07-26
|
|
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injection (Unauthenticated)
|
5 |
WEB
|
KBA@SOGETI_ESEC
|
2020-07-26
|
|
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File Download
|
5 |
WEB
|
KBA@SOGETI_ESEC
|
2020-07-26
|
|
UBICOD Medivision Digital Signage 1.5.1 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
LiquidWorm
|
2020-07-26
|
|
INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
|
3 |
WEB
|
Patrick Hener
|
2020-07-26
|
|
ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
|
3 |
WEB
|
aldorm
|
2020-07-26
|
|
GOautodial 4.0 - Persistent Cross-Site Scripting (Authenticated)
|
2 |
WEB
|
Balzabu
|
2020-07-23
|
|
UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass
|
2 |
WEB
|
LiquidWorm
|
2020-07-22
|
|
Sophos VPN Web Panel 2020 - Denial of Service (Poc)
|
3 |
WEB
|
Berk KIRAS
|
2020-07-22
|
|
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
|
3 |
WEB
|
Vlad Vector
|
2020-07-22
|
|
Docsify.js 4.11.4 - Reflective Cross-Site Scripting
|
2 |
WEB
|
Amin Sharifi
|
2020-07-17
|
|
CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
|
2 |
WEB
|
Noth
|
2020-07-16
|
|
Wing FTP Server 6.3.8 - Remote Code Execution (Authenticated)
|
3 |
WEB
|
V1n1v131r4
|
2020-07-15
|
|
Infor Storefront B2B 1.0 - 'usr_name' SQL Injection
|
3 |
WEB
|
ratboy
|
2020-07-15
|
|
Online Farm Management System 0.1.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
KeopssGroup0day_Inc
|
2020-07-15
|
|
Web Based Online Hotel Booking System 0.1.0 - Authentication Bypass
|
2 |
WEB
|
KeopssGroup0day_Inc
|
2020-07-15
|
|
Online Polling System 1.0 - Authentication Bypass
|
2 |
WEB
|
AppleBois
|
2020-07-15
|
|
Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
|
3 |
WEB
|
Mehmet Kelepçe
|
2020-07-15
|
|
Zyxel Armor X1 WAP6806 - Directory Traversal
|
3 |
WEB
|
Rajivarnan R
|
2020-07-15
|
|
SuperMicro IPMI WebInterface 03.40 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
Metin Yunus Kandemir
|
2020-07-14
|
|
Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 - Remote Code Execution (Metas
|
4 |
WEB
|
Mehmet Ince
|
2020-07-14
|
|
BSA Radar 1.6.7234.24750 - Local File Inclusion
|
5 |
WEB
|
William Summerhill
|
2020-07-13
|
|
Park Ticketing Management System 1.0 - Authentication Bypass
|
4 |
WEB
|
gh1mau
|
2020-07-13
|
|
Park Ticketing Management System 1.0 - 'viewid' SQL Injection
|
4 |
WEB
|
gh1mau
|
2020-07-10
|
|
Barangay Management System 1.0 - Authentication Bypass
|
5 |
WEB
|
BKpatron
|
2020-07-10
|
|
HelloWeb 2.0 - Arbitrary File Download
|
6 |
WEB
|
bRpsd
|
2020-07-09
|
|
Savsoft Quiz 5 - Persistent Cross-Site Scripting
|
6 |
WEB
|
th3d1gger
|
2020-07-09
|
|
Wordpress Plugin Powie's WHOIS Domain Check 0.9.31 - Persistent Cross-Site Scripting
|
4 |
WEB
|
mqt
|
2020-07-07
|
|
PHP 7.4 FFI - 'disable_functions' Bypass
|
5 |
WEB
|
hunter gregal
|
2020-07-07
|
|
Exhibitor Web UI 1.7.1 - Remote Code Execution
|
4 |
WEB
|
Logan Sanderson
|
2020-07-08
|
|
BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
|
4 |
WEB
|
William Summerhill
|
2020-07-08
|
|
SuperMicro IPMI 03.40 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
Metin Yunus Kandemir
|
2020-07-07
|
|
BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
|
4 |
WEB
|
William Summerhill
|
2020-07-07
|
|
Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
|
3 |
WEB
|
Mehmet Kelepçe
|
2020-07-07
|
|
Online Shopping Portal 3.1 - 'email' SQL Injection
|
4 |
WEB
|
gh1mau
|
2020-07-07
|
|
Sickbeard 0.1 - Remote Command Injection
|
4 |
WEB
|
bdrake
|
2020-07-05
|
|
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6
|
5 |
WEB
|
Budi Khoirudin
|
2020-07-06
|
|
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6
|
4 |
WEB
|
Critical Start
|
2020-07-06
|
|
Nagios XI 5.6.12 - 'export-rrd.php' Remote Code Execution
|
4 |
WEB
|
Basim Alabdullah
|
2020-07-06
|
|
RSA IG&L Aveksa 7.1.1 - Remote Code Execution
|
5 |
WEB
|
Jakub Palaczynski
|
2020-07-06
|
|
RiteCMS 2.2.1 - Authenticated Remote Code Execution
|
5 |
WEB
|
Enes Özeser
|
2020-07-06
|
|
File Management System 1.1 - Persistent Cross-Site Scripting
|
5 |
WEB
|
KeopssGroup0day_Inc
|
2020-07-02
|
|
OCS Inventory NG 2.7 - Remote Code Execution
|
4 |
WEB
|
Askar
|
2020-07-02
|
|
ZenTao Pro 8.8.2 - Command Injection
|
3 |
WEB
|
Daniel Monzón
|
2020-07-01
|
|
Online Shopping Portal 3.1 - Authentication Bypass
|
5 |
WEB
|
Ümit Yalçın
|
2020-07-01
|
|
PHP-Fusion 9.03.60 - PHP Object Injection
|
3 |
WEB
|
coiffeur
|
2020-07-01
|
|
e-learning Php Script 0.1.0 - 'search' SQL Injection
|
3 |
WEB
|
KeopssGroup0day_Inc
|
2020-06-30
|
|
Reside Property Management 3.0 - 'profile' SQL Injection
|
3 |
WEB
|
Behzad Khalifeh
|
2020-06-30
|
|
Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scripting
|
3 |
WEB
|
Anushree Priyadarshini
|
2020-06-26
|
|
OpenEMR 5.0.1 - 'controller' Remote Code Execution
|
2 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-25
|
|
FHEM 6.0 - Local File Inclusion
|
5 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-24
|
|
BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting
|
4 |
WEB
|
William Summerhill
|
2020-06-23
|
|
Online Student Enrollment System 1.0 - Cross-Site Request Forgery (Add Student)
|
4 |
WEB
|
BKpatron
|
2020-06-23
|
|
Responsive Online Blog 1.0 - 'id' SQL Injection
|
7 |
WEB
|
Eren Şimşek
|
2020-06-22
|
|
Eaton Intelligent Power Manager 1.6 - Directory Traversal
|
6 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-22
|
|
WebPort 1.19.1 - 'setup' Reflected Cross-Site Scripting
|
5 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-22
|
|
WebPort 1.19.1 - Reflected Cross-Site Scripting
|
5 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-22
|
|
Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload
|
4 |
WEB
|
BKpatron
|
2020-06-22
|
|
Odoo 12.0 - Local File Inclusion
|
5 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-22
|
|
Student Enrollment 1.0 - Unauthenticated Remote Code Execution
|
4 |
WEB
|
Enesdex
|
2020-06-22
|
|
FileRun 2019.05.21 - Reflected Cross-Site Scripting
|
5 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-18
|
|
Beauty Parlour Management System 1.0 - Authentication Bypass
|
5 |
WEB
|
Prof. Kailas PATIL
|
2020-06-17
|
|
OpenCTI 3.3.1 - Directory Traversal
|
4 |
WEB
|
Raif Berkay Dincel
|
2020-06-17
|
|
College-Management-System-Php 1.0 - Authentication Bypass
|
5 |
WEB
|
BLAY ABU SAFIAN
|
2020-06-16
|
|
Gila CMS 1.11.8 - 'query' SQL Injection
|
4 |
WEB
|
BillyV4
|