2020-05-27
|
|
OXID eShop 6.3.4 - 'sorting' SQL Injection
|
1 |
WEB
|
VulnSpy
|
2020-05-27
|
|
Kuicms PHP EE 2.0 - Persistent Cross-Site Scripting
|
1 |
WEB
|
China Banking and Insurance Information Technology
|
2020-05-27
|
|
osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting
|
1 |
WEB
|
Matthew Aberegg
|
2020-05-27
|
|
osTicket 1.14.1 - 'Ticket Queue' Persistent Cross-Site Scripting
|
1 |
WEB
|
Matthew Aberegg
|
2020-05-27
|
|
LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting
|
1 |
WEB
|
Matthew Aberegg
|
2020-05-27
|
|
Online Marriage Registration System 1.0 - Persistent Cross-Site Scripting
|
2 |
WEB
|
that faceless coder
|
2020-05-26
|
|
WordPress Plugin Drag and Drop File Upload Contact Form 1.3.3.2 - Remote Code Execution
|
2 |
WEB
|
Austin Martin
|
2020-05-26
|
|
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
|
3 |
WEB
|
Photubias
|
2020-05-26
|
|
Joomla! Plugin XCloner Backup 3.5.3 - Local File Inclusion (Authenticated)
|
1 |
WEB
|
Mehmet Kelepçe
|
2020-05-26
|
|
Open-AudIT 3.3.0 - Reflective Cross-Site Scripting (Authenticated)
|
2 |
WEB
|
Kamaljeet Kumar
|
2020-05-26
|
|
OpenEMR 5.0.1 - Remote Code Execution (1)
|
4 |
WEB
|
Musyoka Ian
|
2020-05-25
|
|
Online Discussion Forum Site 1.0 - Remote Code Execution
|
2 |
WEB
|
Enesdex
|
2020-05-25
|
|
Victor CMS 1.0 - 'add_user' Persistent Cross-Site Scripting
|
2 |
WEB
|
Nitya Nand
|
2020-05-25
|
|
WordPress Plugin Form Maker 5.4.1 - 's' SQL Injection (Authenticated)
|
3 |
WEB
|
SunCSR
|
2020-05-22
|
|
Gym Management System 1.0 - Unauthenticated Remote Code Execution
|
3 |
WEB
|
boku
|
2020-05-22
|
|
Dolibarr 11.0.3 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Mehmet Kelepçe
|
2020-05-21
|
|
OpenEDX platform Ironwood 2.5 - Remote Code Execution
|
3 |
WEB
|
Daniel Monzón
|
2020-05-21
|
|
PHPFusion 9.03.50 - Persistent Cross-Site Scripting
|
3 |
WEB
|
coiffeur
|
2020-05-21
|
|
Composr CMS 10.0.30 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Manuel García Cárdenas
|
2020-05-21
|
|
forma.lms 5.6.40 - Cross-Site Request Forgery (Change Admin Email)
|
3 |
WEB
|
Daniel Ortiz
|
2020-05-20
|
|
CraftCMS 3 vCard Plugin 1.0.0 - Remote Code Execution
|
2 |
WEB
|
Wade Guest
|
2020-05-19
|
|
Victor CMS 1.0 - Authenticated Arbitrary File Upload
|
3 |
WEB
|
Kishan Lal Choudhary
|
2020-05-19
|
|
NukeViet VMS 4.4.00 - Cross-Site Request Forgery (Change Admin Password)
|
3 |
WEB
|
JEBARAJ
|
2020-05-19
|
|
Submitty 20.04.01 - Persistent Cross-Site Scripting
|
3 |
WEB
|
humblelad
|
2020-05-19
|
|
php-fusion 9.03.50 - 'ctype' SQL Injection
|
4 |
WEB
|
SunCSR
|
2020-05-19
|
|
qdPM 9.1 - 'cfg[app_app_name]' Persistent Cross-Site Scripting
|
3 |
WEB
|
Kishan Lal Choudhary
|
2020-05-19
|
|
Victor CMS 1.0 - 'cat_id' SQL Injection
|
4 |
WEB
|
Kishan Lal Choudhary
|
2020-05-19
|
|
Victor CMS 1.0 - 'comment_author' Persistent Cross-Site Scripting
|
3 |
WEB
|
Kishan Lal Choudhary
|
2020-05-18
|
|
Online Healthcare management system 1.0 - Authentication Bypass
|
3 |
WEB
|
BKpatron
|
2020-05-18
|
|
Online Healthcare Patient Record Management System 1.0 - Authentication Bypass
|
3 |
WEB
|
Daniel Monzón
|
2020-05-18
|
|
online Chatting System 1.0 - 'id' SQL Injection
|
3 |
WEB
|
BKpatron
|
2020-05-18
|
|
Monstra CMS 3.0.4 - Authenticated Arbitrary File Upload
|
3 |
WEB
|
Kishan Lal Choudhary
|
2020-05-18
|
|
forma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Daniel Ortiz
|
2020-05-18
|
|
Oracle Hospitality RES 3700 5.7 - Remote Code Execution
|
3 |
WEB
|
Walid Faour
|
2020-05-18
|
|
Online Examination System 1.0 - 'eid' SQL Injection
|
3 |
WEB
|
BKpatron
|
2020-05-18
|
|
WordPress Plugin Ajax Load More 5.3.1 - '#1' Authenticated SQL Injection
|
3 |
WEB
|
Nguyen Khang
|
2020-05-18
|
|
Mikrotik Router Monitoring System 1.2.3 - 'community' SQL Injection
|
2 |
WEB
|
jul10l1r4
|
2020-05-15
|
|
ManageEngine Service Desk 10.0 - Cross-Site Scripting
|
4 |
WEB
|
Felipe Molina
|
2020-05-15
|
|
vBulletin 5.6.1 - 'nodeId' SQL Injection
|
3 |
WEB
|
Photubias
|
2020-05-14
|
|
E-Commerce System 1.0 - Unauthenticated Remote Code Execution
|
3 |
WEB
|
SunCSR
|
2020-05-14
|
|
Netlink XPON 1GE WiFi V2801RGW - Remote Command Execution
|
2 |
WEB
|
Seecko Das
|
2020-05-14
|
|
Complaint Management System 1.0 - 'username' SQL Injection
|
3 |
WEB
|
Daniel Ortiz
|
2020-05-13
|
|
Sellacious eCommerce 4.6 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2020-05-13
|
|
Tryton 5.4 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2020-05-12
|
|
TylerTech Eagle 2018.3.11 - Remote Code Execution
|
3 |
WEB
|
Anthony Cole
|
2020-05-12
|
|
qdPM 9.1 - Arbitrary File Upload
|
2 |
WEB
|
Besim
|
2020-05-12
|
|
Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Dylan Garnaud
|
2020-05-12
|
|
CuteNews 2.1.2 - Authenticated Arbitrary File Upload
|
3 |
WEB
|
Nhat Ha
|
2020-05-12
|
|
WordPress Plugin ChopSlider 3.4 - 'id' SQL Injection
|
2 |
WEB
|
SunCSR
|
2020-05-12
|
|
Orchard Core RC1 - Persistent Cross-Site Scripting
|
2 |
WEB
|
SunCSR
|
2014-12-23
|
|
Phase Botnet - Blind SQL Injection
|
3 |
WEB
|
MalwareTech
|
2020-05-11
|
|
LibreNMS 1.46 - 'search' SQL Injection
|
2 |
WEB
|
Punt
|
2020-05-11
|
|
Complaint Management System 1.0 - Authentication Bypass
|
3 |
WEB
|
BKpatron
|
2020-05-11
|
|
Victor CMS 1.0 - 'post' SQL Injection
|
4 |
WEB
|
BKpatron
|
2020-05-11
|
|
OpenZ ERP 3.6.60 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Vulnerability-Lab
|
2020-05-11
|
|
WordPress Plugin Simple File List 4.2.2 - Remote Code Execution
|
2 |
WEB
|
coiffeur
|
2020-05-11
|
|
CuteNews 2.1.2 - Arbitrary File Deletion
|
4 |
WEB
|
Besim
|
2020-05-11
|
|
Sentrifugo CMS 3.2 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2020-05-11
|
|
Kartris 1.6 - Arbitrary File Upload
|
3 |
WEB
|
Nhat Ha
|
2020-05-11
|
|
Online AgroCulture Farm Management System 1.0 - 'uname' SQL Injection
|
4 |
WEB
|
Tarun Sehgal
|
2020-05-10
|
|
Pi-hole < 4.4 - Authenticated Remote Code Execution / Privileges Escalation
|
2 |
WEB
|
Nick Frichette
|
2020-05-10
|
|
Pi-hole < 4.4 - Authenticated Remote Code Execution
|
3 |
WEB
|
Nick Frichette
|
2020-05-07
|
|
Online AgroCulture Farm Management System 1.0 - 'pid' SQL Injection
|
3 |
WEB
|
BKpatron
|
2020-05-07
|
|
Pisay Online E-Learning System 1.0 - Remote Code Execution
|
4 |
WEB
|
boku
|
2020-05-07
|
|
Online Clothing Store 1.0 - Arbitrary File Upload
|
3 |
WEB
|
Sushant Kamble
|
2020-05-07
|
|
School File Management System 1.0 - 'username' SQL Injection
|
4 |
WEB
|
Tarun Sehgal
|
2020-05-07
|
|
Draytek VigorAP 1000C - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2020-05-07
|
|
Car Park Management System 1.0 - Authentication Bypass
|
3 |
WEB
|
Tarun Sehgal
|
2020-05-06
|
|
MPC Sharj 3.11.1 - Arbitrary File Download
|
3 |
WEB
|
SajjadBnd
|
2020-05-06
|
|
YesWiki cercopitheque 2020.04.18.1 - 'id' SQL Injection
|
5 |
WEB
|
coiffeur
|
2020-05-06
|
|
GitLab 12.9.0 - Arbitrary File Read
|
1 |
WEB
|
KouroshRZ
|
2020-05-06
|
|
webTareas 2.0.p8 - Arbitrary File Deletion
|
3 |
WEB
|
Besim
|
2020-05-06
|
|
Online Clothing Store 1.0 - 'username' SQL Injection
|
3 |
WEB
|
Sushant Kamble
|
2020-05-06
|
|
Booked Scheduler 2.7.7 - Authenticated Directory Traversal
|
2 |
WEB
|
Besim
|
2020-05-06
|
|
i-doit Open Source CMDB 1.14.1 - Arbitrary File Deletion
|
3 |
WEB
|
Besim
|
2020-05-06
|
|
Online Clothing Store 1.0 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Sushant Kamble
|
2020-05-05
|
|
NEC Electra Elite IPK II WebPro 01.03.01 - Session Enumeration
|
3 |
WEB
|
Cold z3ro
|
2020-05-05
|
|
SimplePHPGal 0.7 - Remote File Inclusion
|
2 |
WEB
|
h4shur
|
2020-05-05
|
|
PhreeBooks ERP 5.2.5 - Remote Command Execution
|
2 |
WEB
|
Besim
|
2020-05-05
|
|
BlogEngine 3.3 - 'syndication.axd' XML External Entity Injection
|
4 |
WEB
|
Daniel Martinez Adan
|
2020-05-05
|
|
webERP 4.15.1 - Unauthenticated Backup File Access
|
3 |
WEB
|
Besim
|
2020-05-05
|
|
Online Scheduling System 1.0 - 'username' SQL Injection
|
3 |
WEB
|
Saurav Shukla
|
2020-05-05
|
|
Fishing Reservation System 7.5 - 'uid' SQL Injection
|
2 |
WEB
|
Vulnerability-Lab
|
2020-05-04
|
|
addressbook 9.0.0.1 - 'id' SQL Injection
|
2 |
WEB
|
David Velazquez
|
2020-05-04
|
|
osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting
|
2 |
WEB
|
Mehmet Kelepçe
|
2020-05-04
|
|
BoltWire 6.03 - Local File Inclusion
|
4 |
WEB
|
Andrey Stoykov
|
2020-05-01
|
|
Online Scheduling System 1.0 - Authentication Bypass
|
3 |
WEB
|
boku
|
2020-05-01
|
|
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
|
2 |
WEB
|
Faiz Ahmed Zaidi
|
2020-05-01
|
|
HardDrive 2.1 for iOS - Arbitrary File Upload
|
3 |
WEB
|
Vulnerability-Lab
|
2020-05-01
|
|
Super Backup 2.0.5 for iOS - Directory Traversal
|
2 |
WEB
|
Vulnerability-Lab
|
2020-05-01
|
|
php-fusion 9.03.50 - Persistent Cross-Site Scripting
|
3 |
WEB
|
SunCSR
|
2020-05-01
|
|
Online Scheduling System 1.0 - Persistent Cross-Site Scripting
|
3 |
WEB
|
boku
|
2020-05-01
|
|
ChemInv 1.0 - Authenticated Persistent Cross-Site Scripting
|
2 |
WEB
|
boku
|
2020-04-29
|
|
hits script 1.0 - 'item_name' SQL Injection
|
2 |
WEB
|
SajjadBnd
|
2020-04-29
|
|
Easy Transfer 1.7 for iOS - Directory Traversal
|
2 |
WEB
|
Vulnerability-Lab
|
2020-04-29
|
|
School ERP Pro 1.0 - Arbitrary File Read
|
3 |
WEB
|
Besim
|
2020-04-29
|
|
Open-AudIT Professional 3.3.1 - Remote Code Execution
|
4 |
WEB
|
Askar
|
2020-04-28
|
|
School ERP Pro 1.0 - Remote Code Execution
|
2 |
WEB
|
Besim
|
2020-04-28
|
|
School ERP Pro 1.0 - 'es_messagesid' SQL Injection
|
3 |
WEB
|
Besim
|
2020-04-27
|
|
Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
Besim
|
2020-04-27
|
|
Online Course Registration 2.0 - Authentication Bypass
|
3 |
WEB
|
Daniel Monzón
|
2020-04-27
|
|
Netis E1+ V1.2.32533 - Unauthenticated WiFi Password Leak
|
4 |
WEB
|
Besim
|
2020-04-27
|
|
Online shopping system advanced 1.0 - 'p' SQL Injection
|
3 |
WEB
|
Majid kalantari
|
2020-04-27
|
|
Netis E1+ 1.2.32533 - Backdoor Account (root)
|
4 |
WEB
|
Besim
|
2020-04-27
|
|
PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
|
3 |
WEB
|
Besim
|
2020-04-24
|
|
Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
|
2 |
WEB
|
LiquidWorm
|
2020-04-24
|
|
Edimax EW-7438RPn 1.13 - Remote Code Execution
|
2 |
WEB
|
Besim
|
2020-04-24
|
|
EspoCRM 5.8.5 - Privilege Escalation
|
3 |
WEB
|
Besim
|
2020-04-23
|
|
Sky File 2.1.0 iOS - Directory Traversal
|
4 |
WEB
|
Vulnerability-Lab
|
2020-04-23
|
|
Library CMS Powerful Book Management System 2.2.0 - Session Fixation
|
3 |
WEB
|
Ismail Tasdelen
|
2020-04-23
|
|
Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)
|
4 |
WEB
|
Dhiraj Mishra
|
2020-04-23
|
|
Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
|
3 |
WEB
|
Besim
|
2020-04-23
|
|
Complaint Management System 4.2 - Authentication Bypass
|
2 |
WEB
|
Besim
|
2020-04-23
|
|
Complaint Management System 4.2 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Besim
|
2020-04-23
|
|
User Management System 2.0 - Authentication Bypass
|
3 |
WEB
|
Besim
|
2020-04-23
|
|
User Management System 2.0 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Besim
|
2020-04-22
|
|
Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2020-04-22
|
|
Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)
|
3 |
WEB
|
Besim
|
2020-04-22
|
|
Edimax EW-7438RPn - Information Disclosure (WiFi Password)
|
3 |
WEB
|
Besim
|
2020-04-21
|
|
P5 FNIP-8x16A FNIP-4xSH 1.0.20 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
LiquidWorm
|
2020-04-21
|
|
jizhi CMS 1.6.7 - Arbitrary File Download
|
3 |
WEB
|
jizhicms
|
2020-04-21
|
|
NSClient++ 0.5.2.35 - Authenticated Remote Code Execution
|
2 |
WEB
|
kindredsec
|
2020-04-21
|
|
IQrouter 3.3.1 Firmware - Remote Code Execution
|
2 |
WEB
|
drakylar
|
2020-04-21
|
|
CSZ CMS 1.2.7 - 'title' HTML Injection
|
4 |
WEB
|
Metin Yunus Kandemir
|
2020-04-21
|
|
PMB 5.6 - 'logid' SQL Injection
|
3 |
WEB
|
41-trk
|