2020-08-04
|
|
Pi-hole 4.3.2 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
Luis Vacacas
|
2020-07-30
|
|
Online Shopping Alphaware 1.0 - Authentication Bypass
|
1 |
WEB
|
Ahmed Abbas
|
2020-07-29
|
|
Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Jinson Varghese Behanan
|
2020-07-29
|
|
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
|
2 |
WEB
|
0xmmnbassel
|
2020-07-28
|
|
Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
|
2 |
WEB
|
0xmmnbassel
|
2020-07-27
|
|
eGroupWare 1.14 - 'spellchecker.php' Remote Command Execution
|
1 |
WEB
|
Berk KIRAS
|
2020-07-26
|
|
Rails 5.0.1 - Remote Code Execution
|
1 |
WEB
|
Lucas Amorim
|
2020-07-26
|
|
Virtual Airlines Manager 2.6.2 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Peter Blue
|
2020-07-26
|
|
pfSense 2.4.4-p3 - Cross-Site Request Forgery
|
2 |
WEB
|
ghost_fh
|
2020-07-26
|
|
Socket.io-file 2.0.31 - Arbitrary File Upload
|
3 |
WEB
|
Cr0wTom
|
2020-07-26
|
|
Sickbeard 0.1 - Cross-Site Request Forgery (Disable Authentication)
|
2 |
WEB
|
bdrake
|
2020-07-26
|
|
F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
|
2 |
WEB
|
Carlos E. Vieira
|
2020-07-26
|
|
Webtareas 2.1p - Arbitrary File Upload (Authenticated)
|
2 |
WEB
|
AppleBois
|
2020-07-26
|
|
Bio Star 2.8.2 - Local File Inclusion
|
1 |
WEB
|
SITE Team
|
2020-07-26
|
|
PandoraFMS 7.0 NG 746 - Persistent Cross-Site Scripting
|
2 |
WEB
|
AppleBois
|
2020-07-26
|
|
Koken CMS 0.22.24 - Arbitrary File Upload (Authenticated)
|
2 |
WEB
|
V1n1v131r4
|
2020-07-26
|
|
elaniin CMS - Authentication Bypass
|
3 |
WEB
|
BKpatron
|
2020-07-26
|
|
Online Course Registration 1.0 - Unauthenticated Remote Code Execution
|
2 |
WEB
|
boku
|
2020-07-26
|
|
LibreHealth 2.0.0 - Authenticated Remote Code Execution
|
1 |
WEB
|
boku
|
2020-07-26
|
|
Bludit 3.9.2 - Directory Traversal
|
2 |
WEB
|
James Green
|
2020-07-26
|
|
PandoraFMS NG747 7.0 - 'filename' Persistent Cross-Site Scripting
|
2 |
WEB
|
Emre ÖVÜNÇ
|
2020-07-26
|
|
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injection (Unauthenticated)
|
2 |
WEB
|
KBA@SOGETI_ESEC
|
2020-07-26
|
|
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File Download
|
2 |
WEB
|
KBA@SOGETI_ESEC
|
2020-07-26
|
|
UBICOD Medivision Digital Signage 1.5.1 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
LiquidWorm
|
2020-07-26
|
|
INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
|
3 |
WEB
|
Patrick Hener
|
2020-07-26
|
|
ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
|
1 |
WEB
|
aldorm
|
2020-07-26
|
|
GOautodial 4.0 - Persistent Cross-Site Scripting (Authenticated)
|
2 |
WEB
|
Balzabu
|
2020-07-23
|
|
UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass
|
1 |
WEB
|
LiquidWorm
|
2020-07-22
|
|
Sophos VPN Web Panel 2020 - Denial of Service (Poc)
|
2 |
WEB
|
Berk KIRAS
|
2020-07-22
|
|
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
|
2 |
WEB
|
Vlad Vector
|
2020-07-22
|
|
Docsify.js 4.11.4 - Reflective Cross-Site Scripting
|
1 |
WEB
|
Amin Sharifi
|
2020-07-17
|
|
CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
|
1 |
WEB
|
Noth
|
2020-07-16
|
|
Wing FTP Server 6.3.8 - Remote Code Execution (Authenticated)
|
1 |
WEB
|
V1n1v131r4
|
2020-07-15
|
|
Infor Storefront B2B 1.0 - 'usr_name' SQL Injection
|
2 |
WEB
|
ratboy
|
2020-07-15
|
|
Online Farm Management System 0.1.0 - Persistent Cross-Site Scripting
|
2 |
WEB
|
KeopssGroup0day_Inc
|
2020-07-15
|
|
Web Based Online Hotel Booking System 0.1.0 - Authentication Bypass
|
1 |
WEB
|
KeopssGroup0day_Inc
|
2020-07-15
|
|
Online Polling System 1.0 - Authentication Bypass
|
1 |
WEB
|
AppleBois
|
2020-07-15
|
|
Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
|
2 |
WEB
|
Mehmet Kelepçe
|
2020-07-15
|
|
Zyxel Armor X1 WAP6806 - Directory Traversal
|
2 |
WEB
|
Rajivarnan R
|
2020-07-15
|
|
SuperMicro IPMI WebInterface 03.40 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
Metin Yunus Kandemir
|
2020-07-14
|
|
Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 - Remote Code Execution (Metas
|
2 |
WEB
|
Mehmet Ince
|
2020-07-14
|
|
BSA Radar 1.6.7234.24750 - Local File Inclusion
|
0 |
WEB
|
William Summerhill
|
2020-07-13
|
|
Park Ticketing Management System 1.0 - Authentication Bypass
|
1 |
WEB
|
gh1mau
|
2020-07-13
|
|
Park Ticketing Management System 1.0 - 'viewid' SQL Injection
|
2 |
WEB
|
gh1mau
|
2020-07-10
|
|
Barangay Management System 1.0 - Authentication Bypass
|
1 |
WEB
|
BKpatron
|
2020-07-10
|
|
HelloWeb 2.0 - Arbitrary File Download
|
1 |
WEB
|
bRpsd
|
2020-07-09
|
|
Savsoft Quiz 5 - Persistent Cross-Site Scripting
|
1 |
WEB
|
th3d1gger
|
2020-07-09
|
|
Wordpress Plugin Powie's WHOIS Domain Check 0.9.31 - Persistent Cross-Site Scripting
|
1 |
WEB
|
mqt
|
2020-07-07
|
|
PHP 7.4 FFI - 'disable_functions' Bypass
|
1 |
WEB
|
hunter gregal
|
2020-07-07
|
|
Exhibitor Web UI 1.7.1 - Remote Code Execution
|
1 |
WEB
|
Logan Sanderson
|
2020-07-08
|
|
BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
|
1 |
WEB
|
William Summerhill
|
2020-07-08
|
|
SuperMicro IPMI 03.40 - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
Metin Yunus Kandemir
|
2020-07-07
|
|
BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
|
2 |
WEB
|
William Summerhill
|
2020-07-07
|
|
Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
|
1 |
WEB
|
Mehmet Kelepçe
|
2020-07-07
|
|
Online Shopping Portal 3.1 - 'email' SQL Injection
|
1 |
WEB
|
gh1mau
|
2020-07-07
|
|
Sickbeard 0.1 - Remote Command Injection
|
1 |
WEB
|
bdrake
|
2020-07-05
|
|
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6
|
2 |
WEB
|
Budi Khoirudin
|
2020-07-06
|
|
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6
|
2 |
WEB
|
Critical Start
|
2020-07-06
|
|
Nagios XI 5.6.12 - 'export-rrd.php' Remote Code Execution
|
2 |
WEB
|
Basim Alabdullah
|
2020-07-06
|
|
RSA IG&L Aveksa 7.1.1 - Remote Code Execution
|
3 |
WEB
|
Jakub Palaczynski
|
2020-07-06
|
|
RiteCMS 2.2.1 - Authenticated Remote Code Execution
|
2 |
WEB
|
Enes Özeser
|
2020-07-06
|
|
File Management System 1.1 - Persistent Cross-Site Scripting
|
1 |
WEB
|
KeopssGroup0day_Inc
|
2020-07-02
|
|
OCS Inventory NG 2.7 - Remote Code Execution
|
3 |
WEB
|
Askar
|
2020-07-02
|
|
ZenTao Pro 8.8.2 - Command Injection
|
1 |
WEB
|
Daniel Monzón
|
2020-07-01
|
|
Online Shopping Portal 3.1 - Authentication Bypass
|
2 |
WEB
|
Ümit Yalçın
|
2020-07-01
|
|
PHP-Fusion 9.03.60 - PHP Object Injection
|
2 |
WEB
|
coiffeur
|
2020-07-01
|
|
e-learning Php Script 0.1.0 - 'search' SQL Injection
|
1 |
WEB
|
KeopssGroup0day_Inc
|
2020-06-30
|
|
Reside Property Management 3.0 - 'profile' SQL Injection
|
1 |
WEB
|
Behzad Khalifeh
|
2020-06-30
|
|
Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scripting
|
2 |
WEB
|
Anushree Priyadarshini
|
2020-06-26
|
|
OpenEMR 5.0.1 - 'controller' Remote Code Execution
|
1 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-25
|
|
FHEM 6.0 - Local File Inclusion
|
2 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-24
|
|
BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting
|
1 |
WEB
|
William Summerhill
|
2020-06-23
|
|
Online Student Enrollment System 1.0 - Cross-Site Request Forgery (Add Student)
|
2 |
WEB
|
BKpatron
|
2020-06-23
|
|
Responsive Online Blog 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Eren Şimşek
|
2020-06-22
|
|
Eaton Intelligent Power Manager 1.6 - Directory Traversal
|
2 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-22
|
|
WebPort 1.19.1 - 'setup' Reflected Cross-Site Scripting
|
2 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-22
|
|
WebPort 1.19.1 - Reflected Cross-Site Scripting
|
1 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-22
|
|
Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload
|
2 |
WEB
|
BKpatron
|
2020-06-22
|
|
Odoo 12.0 - Local File Inclusion
|
2 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-22
|
|
Student Enrollment 1.0 - Unauthenticated Remote Code Execution
|
2 |
WEB
|
Enesdex
|
2020-06-22
|
|
FileRun 2019.05.21 - Reflected Cross-Site Scripting
|
2 |
WEB
|
Emre ÖVÜNÇ
|
2020-06-18
|
|
Beauty Parlour Management System 1.0 - Authentication Bypass
|
2 |
WEB
|
Prof. Kailas PATIL
|
2020-06-17
|
|
OpenCTI 3.3.1 - Directory Traversal
|
1 |
WEB
|
Raif Berkay Dincel
|
2020-06-17
|
|
College-Management-System-Php 1.0 - Authentication Bypass
|
1 |
WEB
|
BLAY ABU SAFIAN
|
2020-06-16
|
|
Gila CMS 1.11.8 - 'query' SQL Injection
|
1 |
WEB
|
BillyV4
|
2020-06-15
|
|
Netgear R7000 Router - Remote Code Execution
|
2 |
WEB
|
grimm-co
|
2020-06-12
|
|
Sysax MultiServer 6.90 - Reflected Cross Site Scripting
|
1 |
WEB
|
Luca Epifanio
|
2020-06-12
|
|
Avaya IP Office 11 - Password Disclosure
|
2 |
WEB
|
hyp3rlinx
|
2020-06-12
|
|
SmarterMail 16 - Arbitrary File Upload
|
1 |
WEB
|
vvhack.org
|
2020-06-10
|
|
Virtual Airlines Manager 2.6.2 - 'id' SQL Injection
|
1 |
WEB
|
Mosaaed
|
2020-06-10
|
|
Joomla! J2 Store 3.3.11 - 'filter_order_Dir' Authenticated SQL Injection
|
1 |
WEB
|
Mehmet Kelepçe
|
2020-06-10
|
|
Sistem Informasi Pengumuman Kelulusan Online 1.0 - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
Extinction
|
2020-06-09
|
|
Bludit 3.9.12 - Directory Traversal
|
2 |
WEB
|
Luis Vacacas
|
2020-06-09
|
|
Virtual Airlines Manager 2.6.2 - 'airport' SQL Injection
|
2 |
WEB
|
Kostadin Tonev
|
2020-06-08
|
|
Virtual Airlines Manager 2.6.2 - 'notam' SQL Injection
|
1 |
WEB
|
Pankaj Kumar Thakur
|
2020-06-08
|
|
Kyocera Printer d-COPIA253MF - Directory Traversal (PoC)
|
1 |
WEB
|
Hakan Eren ŞAN
|
2020-06-05
|
|
Online-Exam-System 2015 - 'feedback' SQL Injection
|
1 |
WEB
|
Gus Ralph
|
2020-06-05
|
|
Online Course Registration 1.0 - Authentication Bypass
|
2 |
WEB
|
BKpatron
|
2020-06-04
|
|
Cayin Digital Signage System xPost 2.5 - Remote Command Injection
|
1 |
WEB
|
LiquidWorm
|
2020-06-04
|
|
Cayin Signage Media Player 3.0 - Remote Command Injection (root)
|
2 |
WEB
|
LiquidWorm
|
2020-06-04
|
|
Secure Computing SnapGear Management Console SG560 3.1.5 - Arbitrary File Read
|
1 |
WEB
|
LiquidWorm
|
2020-06-04
|
|
SnapGear Management Console SG560 3.1.5 - Cross-Site Request Forgery (Add Super User)
|
1 |
WEB
|
LiquidWorm
|
2020-06-04
|
|
Cayin Content Management Server 11.0 - Remote Command Injection (root)
|
1 |
WEB
|
LiquidWorm
|
2020-06-04
|
|
Online Marriage Registration System 1.0 - Remote Code Execution (1)
|
2 |
WEB
|
Enesdex
|
2020-06-04
|
|
D-Link DIR-615 T1 20.10 - CAPTCHA Bypass
|
1 |
WEB
|
huzaifa hussain
|
2020-06-04
|
|
Navigate CMS 2.8.7 - Authenticated Directory Traversal
|
1 |
WEB
|
Gus Ralph
|
2020-06-04
|
|
VMWAre vCloud Director 9.7.0.15498291 - Remote Code Execution
|
1 |
WEB
|
Tomas Melicher
|
2020-06-04
|
|
Navigate CMS 2.8.7 - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
Gus Ralph
|
2020-06-04
|
|
Clinic Management System 1.0 - Authenticated Arbitrary File Upload
|
1 |
WEB
|
BKpatron
|
2020-06-04
|
|
Oriol Espinal CMS 1.0 - 'id' SQL Injection
|
1 |
WEB
|
TSAR
|
2020-06-04
|
|
Navigate CMS 2.8.7 - ''sidx' SQL Injection (Authenticated)
|
1 |
WEB
|
Gus Ralph
|
2020-06-04
|
|
Clinic Management System 1.0 - Unauthenticated Remote Code Execution
|
2 |
WEB
|
BKpatron
|
2020-06-04
|
|
Hostel Management System 2.0 - 'id' SQL Injection (Unauthenticated)
|
1 |
WEB
|
Enesdex
|
2020-06-04
|
|
AirControl 1.4.2 - PreAuth Remote Code Execution
|
2 |
WEB
|
0xd0ff9
|
2020-06-02
|
|
OpenCart 3.0.3.2 - Stored Cross Site Scripting (Authenticated)
|
3 |
WEB
|
Kailash Bohara
|
2020-06-02
|
|
Clinic Management System 1.0 - Authentication Bypass
|
1 |
WEB
|
BKpatron
|
2020-06-01
|
|
QuickBox Pro 2.1.8 - Authenticated Remote Code Execution
|
1 |
WEB
|
s1gh
|
2020-06-01
|
|
VMware vCenter Server 6.7 - Authentication Bypass
|
1 |
WEB
|
Photubias
|
2020-06-01
|
|
WordPress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
|
1 |
WEB
|
Raphael Karger
|
2020-05-29
|
|
Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass
|
0 |
WEB
|
Halis Duraki
|
2020-05-29
|
|
WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete User)
|
1 |
WEB
|
UnD3sc0n0c1d0
|
2020-05-28
|
|
QNAP QTS and Photo Station 6.0.3 - Remote Command Execution
|
1 |
WEB
|
Th3GundY
|
2020-05-28
|
|
EyouCMS 1.4.6 - Persistent Cross-Site Scripting
|
1 |
WEB
|
China Banking and Insurance Information Technology
|
2020-05-28
|
|
Online-Exam-System 2015 - 'fid' SQL Injection
|
1 |
WEB
|
Berk Dusunur
|
2020-05-28
|
|
NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection
|
1 |
WEB
|
Berk Dusunur
|