2018-08-03
|
|
Seq 4.2.476 Authentication Bypass
|
132 |
WEB
|
Daniel Chactoura
|
2018-08-03
|
|
CoSoSys Endpoint Protector 4.5.0.1 - Authenticated Remote Root Command Injection
|
96 |
WEB
|
0x09AL
|
2018-08-01
|
|
SonicWall Global Management System XMLRPC
|
128 |
WEB
|
Michael Flanders
|
2018-08-01
|
|
Vtiger CRM 6.3.0 Authenticated Logo Upload Remote Command Execution
|
151 |
WEB
|
Touhid M.Shaikh
|
2018-07-31
|
|
H2 Database 1.4.197 Information Disclosure
|
138 |
WEB
|
owodelta
|
2018-07-25
|
|
Cisco Adaptive Security Appliance Path Traversal
|
152 |
WEB
|
Angelo Ruwantha
|
2018-07-25
|
|
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
|
110 |
WEB
|
Mehmet Ince
|
2018-07-25
|
|
Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
|
137 |
WEB
|
Nathu Nandwani
|
2018-07-25
|
|
Davolink DVW 3200 Router - Password Disclosure
|
113 |
WEB
|
Ankit Anubhav
|
2018-07-20
|
|
CMS Made Simple 2.2.5 Authenticated Remote Command Execution
|
152 |
WEB
|
Jacob Robles
|
2018-07-19
|
|
PrestaShop < 1.6.1.19 - AES CBC Privilege Escalation Exploit
|
109 |
WEB
|
Charles Fol
|
2018-07-19
|
|
PrestaShop < 1.6.1.19 - BlowFish ECD Privilege Escalation Exploit
|
139 |
WEB
|
Charles Fol
|
2018-07-19
|
|
Modx Revolution Remote Code Execution
|
105 |
WEB
|
Vitalii Rudnykh
|
2018-07-17
|
|
QNAP Q'Center change_passwd Command Execution
|
117 |
WEB
|
Brendan Coles
|
2018-07-13
|
|
Apache CouchDB Arbitrary Command Execution
|
117 |
WEB
|
Green-m
|
2018-07-13
|
|
phpMyAdmin Authenticated Remote Code Execution
|
196 |
WEB
|
Jacob Robles
|
2018-07-12
|
|
Instagram Clone Script 2.0 Cross Site Scripting
|
126 |
WEB
|
Borna Nematzadeh
|
2018-07-11
|
|
Monstra CMS Authenticated Arbitrary File Upload
|
179 |
WEB
|
Touhid M.Shaikh
|
2018-07-11
|
|
D-Link DIR601 2.02 - Credential Disclosure
|
141 |
WEB
|
Richard Rogerson
|
2018-07-11
|
|
Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code Execution
|
164 |
WEB
|
bobsecq
|
2018-07-11
|
|
Gitea 1.4.0 - Remote Code Execution
|
117 |
WEB
|
Kacper Szurek
|
2018-07-09
|
|
GitList 0.6.0 Argument Injection
|
132 |
WEB
|
Shelby Pace
|
2018-07-05
|
|
CMS Made Simple 2.2.5 - Remote Code Execution
|
210 |
WEB
|
Mustafa Hasan
|
2018-07-03
|
|
VMware NSX SD-WAN Edge < 3.1.2 - Command Injection
|
147 |
WEB
|
ParagonSec
|
2018-07-03
|
|
Geutebruck 5.02024 G-Cam/EFD-2250 - 'simple_loglistjs.cgi' Remote Command Execution (Metasploit)
|
108 |
WEB
|
RandoriSec
|
2018-06-29
|
|
Cisco Adaptive Security Appliance - Path Traversal
|
151 |
WEB
|
Yassine Aboukir
|
2018-06-28
|
|
HPE VAN SDN 2.7.18.0503 - Remote Root
|
112 |
WEB
|
KoreLogic
|
2018-06-28
|
|
IPConfigure Orchid VMS 2.0.5 - Directory Traversal Information Disclosure (Metasploit)
|
108 |
WEB
|
Sanjiv Kawa
|
2018-06-28
|
|
Apache CouchDB < 2.1.0 - Remote Code Execution
|
123 |
WEB
|
Cody Zacharias
|
2018-06-28
|
|
TP-Link TL-WA850RE - Remote Command Execution
|
128 |
WEB
|
yoresongo
|
2018-06-11
|
|
userSpice 4.3.24 - Username Enumeration
|
158 |
WEB
|
Dolev Farhi
|
2018-06-11
|
|
userSpice 4.3.24 - 'X-Forwarded-For' Cross-Site Scripting
|
107 |
WEB
|
Dolev Farhi
|
2018-06-11
|
|
XiongMai uc-httpd 1.0.0 - Buffer Overflow
|
187 |
WEB
|
Andrew Watson
|
2018-06-11
|
|
Monstra CMS < 3.0.4 - Cross-Site Scripting
|
141 |
WEB
|
DEEPIN2
|
2018-06-11
|
|
Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email)
|
158 |
WEB
|
Kl3_GMjq6
|
2018-06-11
|
|
Pagekit < 1.0.13 - Cross-Site Scripting Code Generator
|
141 |
WEB
|
DEEPIN2
|
2018-05-28
|
|
SAP Internet Transaction Server 6200.x - Session Fixation / Cross-Site Scripting
|
127 |
WEB
|
J. Carrillo Lencina
|
2018-05-22
|
|
GitBucket 4.23.1 - Remote Code Execution
|
114 |
WEB
|
Kacper Szurek
|
2018-05-18
|
|
Intelbras NCLOUD 300 1.0 - Authentication bypass
|
140 |
WEB
|
Pedro Aguiar
|
2018-05-10
|
|
Mantis manage_proj_page PHP Code Execution
|
150 |
WEB
|
Lars Sorenson
|
2018-05-08
|
|
Palo Alto Networks readSessionVarsFromFile() Session Corruption
|
142 |
WEB
|
hdm
|
2018-05-08
|
|
PlaySMS import.php Code Execution
|
124 |
WEB
|
Touhid M.Shaikh
|
2018-05-08
|
|
PlaySMS sendfromfile.php Code Execution
|
125 |
WEB
|
DarkS3curity
|
2018-05-07
|
|
WordPress Plugin User Role Editor < 4.25 - Privilege Escalation
|
167 |
WEB
|
Tomislav Paskalev
|
2018-05-07
|
|
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
|
199 |
WEB
|
Takeshi Terada
|
2018-05-03
|
|
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
|
141 |
WEB
|
Jared Arave
|
2018-05-03
|
|
Drupal < 7.58 - 'Drupalgeddon3' Authenticated Remote Code
|
182 |
WEB
|
SixP4ck3r
|
2018-05-03
|
|
osCommerce Installer Unauthenticated Code Execution
|
124 |
WEB
|
Daniel Teixeira
|
2018-04-27
|
|
GitList 0.6 - Unauthenticated Remote Code Execution
|
127 |
WEB
|
Kacper Szurek
|
2018-04-27
|
|
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
|
103 |
WEB
|
Sven Fassbender
|
2018-04-25
|
|
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
|
140 |
WEB
|
Berk Cem Göksel
|
2018-04-25
|
|
Interspire Email Marketer < 6.1.6 - Remote Admin Authentication Bypass
|
142 |
WEB
|
devcoinfet
|
2018-04-24
|
|
Apache CouchDB 1.7.0 and 2.x before 2.1.1 - Remote Privilege Escalation
|
99 |
WEB
|
Sebastián Castro
|
2018-04-19
|
|
Lutron Quantum 2.0 - 3.2.243 - Information Disclosure
|
130 |
WEB
|
SadFud
|
2018-04-16
|
|
MikroTik 6.41.4 - FTP daemon Denial of Service PoC
|
136 |
WEB
|
FarazPajohan
|
2018-04-16
|
|
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution
|
176 |
WEB
|
Hans Topo
|
2018-04-16
|
|
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)
|
176 |
WEB
|
Vitalii Rudnykh
|
2018-04-10
|
|
CyberArk Password Vault Web Access < 9.9.5 / < 9.10 / 10.1 - Remote Code Execution
|
94 |
WEB
|
RedTeam Pentesting
|
2018-04-04
|
|
ProcessMaker Plugin Code Execution
|
114 |
WEB
|
Brendan Coles
|
2018-04-04
|
|
DuckDuckGo 4.2.0 WebRTC Private IP Leakage
|
139 |
WEB
|
Brendan Coles
|
2018-04-02
|
|
Vtiger CRM 6.3.0 - Authenticated Arbitrary File Upload (Metasploit)
|
141 |
WEB
|
Touhid M.Shaikh
|
2018-04-02
|
|
osCommerce 2.3.4.1 - Remote Code Execution
|
145 |
WEB
|
Simon Scannell
|
2018-04-02
|
|
Homematic CCU2 2.29.23 - Remote Command Execution
|
146 |
WEB
|
Gregor Kopf
|
2018-04-02
|
|
Homematic CCU2 2.29.23 - Arbitrary File Write
|
160 |
WEB
|
Gregor Kopf
|
2018-03-30
|
|
Joomla Component Fields - SQLi Remote Code Execution (Metasploit)
|
181 |
WEB
|
luisco100
|
2018-03-30
|
|
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session)
|
135 |
WEB
|
Stefan Horst
|
2018-03-30
|
|
Square 9 GlobalForms 6.2.x Blind SQL Injection
|
131 |
WEB
|
Darrell Damstedt
|
2018-03-29
|
|
TwonkyMedia Server 7.0.11-8.5 - Directory Traversal
|
134 |
WEB
|
Sven Fassbender
|
2018-03-27
|
|
ClipBucket beats_uploader Unauthenticated Arbitrary File Upload
|
103 |
WEB
|
Touhid M.Shaikh
|
2018-03-26
|
|
XenForo 2 - CSS Loader Denial of Service
|
133 |
WEB
|
LockedByte
|
2018-03-26
|
|
TL-WR720N 150Mbps Wireless N Router - Cross-Site Request Forgery
|
146 |
WEB
|
Mans van Someren
|
2018-03-26
|
|
Hikvision IP Camera versions 5.2.0 - 5.3.9 (Builds 140721 - 170109) - Access Control Bypass
|
307 |
WEB
|
Matamorphosis
|
2018-03-22
|
|
Cisco node-jos < 0.11.0 - Re-sign Tokens
|
157 |
WEB
|
zioBlack
|
2018-03-21
|
|
Intelbras Telefone IP TIP200 LITE - Local File Disclosure
|
123 |
WEB
|
anhax0r
|
2018-03-16
|
|
Spring Data REST < 2.6.9 (Ingalls SR9), 3.0.1 (Kay SR1) - PATCH Request Remote Code Execution
|
185 |
WEB
|
Antonio Francesco Sardella
|
2018-03-13
|
|
Advantech WebAccess < 8.3 - Directory Traversal / Remote Code Execution
|
132 |
WEB
|
Chris Lyne
|
2018-03-13
|
|
ManageEngine Applications Manager 13.5 - Remote Code Execution (Metasploit)
|
118 |
WEB
|
Mehmet Ince
|
2018-03-07
|
|
Bravo Tejari Web Portal Cross Site Scripting
|
118 |
WEB
|
Arvind V.
|
2018-02-28
|
|
Concrete5 < 8.3.0 - Username / Comments Enumeration
|
171 |
WEB
|
Chapman Schleiss
|
2018-02-26
|
|
AsusWRT LAN Unauthenticated Remote Code Execution
|
158 |
WEB
|
Pedro Ribeiro
|
2018-02-26
|
|
UserSpice 4.3 - Blind SQL Injection
|
179 |
WEB
|
Dolev Farhi
|
2018-02-07
|
|
Hava Tahmin 1.0 Database Disclosure
|
151 |
WEB
|
indoushka
|
2018-02-07
|
|
Hazir Site 2.2 Database Disclosure
|
179 |
WEB
|
indoushka
|
2018-02-07
|
|
Gateway 1.0 Database Disclosure
|
160 |
WEB
|
indoushka
|
2018-02-07
|
|
iPortalx Portal Scripti Database Disclosure
|
171 |
WEB
|
indoushka
|
2018-02-06
|
|
Online Voting System - Authentication Bypass
|
196 |
WEB
|
Giulio Comi
|
2018-02-05
|
|
Oracle Hospitality Simphony (MICROS) 2.7 < 2.9 - Directory Traversal
|
155 |
WEB
|
Dmitry Chastuhin
|
2018-01-31
|
|
BMC BladeLogic RSCD Agent 8.3.00.64 - Windows Users Disclosure
|
177 |
WEB
|
Paul Taylor
|
2018-01-30
|
|
Advantech WebAccess < 8.3 - SQL Injection
|
147 |
WEB
|
Chris Lyne
|
2018-01-29
|
|
Asus Router Cross Site Script / Authentication Bypass
|
157 |
WEB
|
4TT4CK3R
|
2018-01-29
|
|
ASUS DSL-N14U B1 Router 1.1.2.3_345 - Change Administrator Password
|
159 |
WEB
|
Víctor Calvo
|
2018-01-24
|
|
Kaltura Remote PHP Code Execution
|
148 |
WEB
|
Robin Verton
|
2018-01-24
|
|
GoAhead Web Server LD_PRELOAD Arbitrary Module Load
|
161 |
WEB
|
h00die
|
2018-01-24
|
|
Photography CMS 1.0 - Cross-Site Request Forgery (Add Admin)
|
145 |
WEB
|
Ihsan Sencan
|
2018-01-22
|
|
Simple ASC CMS 1.2 Database Disclosure
|
134 |
WEB
|
indoushka
|
2018-01-22
|
|
PHPFreeChat 1.7 - Denial of Service
|
129 |
WEB
|
A. Pakbaz
|
2018-01-19
|
|
Primefaces 5.x - Remote Code Execution (Metasploit)
|
201 |
WEB
|
Bjoern Schuette
|
2018-01-16
|
|
Adminer 4.3.1 - Server-Side Request Forgery
|
160 |
WEB
|
hyp3rlinx
|
2018-01-16
|
|
pfSense < 2.1.4 - 'status_rrd_graph_img.php' Command Injection
|
129 |
WEB
|
absolomb
|
2018-01-12
|
|
D-Link Routers 110/412/615/815 < 1.03 - 'service.cgi' Arbitrary Code Execution
|
156 |
WEB
|
Cr0n1c
|
2018-01-12
|
|
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
|
131 |
WEB
|
Vahagn Vardanyan
|
2018-01-11
|
|
Samsung SRN-1670D Web Viewer 1.0.0.193 Arbitrary File Read / Upload
|
131 |
WEB
|
Algeria
|
2018-01-11
|
|
phpCollab 2.5.1 Unauthenticated File Upload
|
133 |
WEB
|
Nick Marcoccio
|
2018-01-10
|
|
Synology Photostation 6.7.2-3429 - Remote Code Execution (Metasploit)
|
164 |
WEB
|
James Bercegay
|
2018-01-09
|
|
FiberHome LM53Q1 - Multiple Vulnerabilities
|
144 |
WEB
|
Ibad Shah
|
2018-01-05
|
|
D-Link DNS-320L 'mydlinkBRionyg' Backdoor
|
138 |
WEB
|
James Bercegay
|
2018-01-05
|
|
Western Digital WDMyCloud 'mydlinkBRionyg' Backdoor
|
129 |
WEB
|
James Bercegay
|
2018-01-04
|
|
Linksys WVBR0-25 User-Agent Command Execution
|
123 |
WEB
|
HeadlessZeke
|
2018-01-02
|
|
Huawei Router HG532 - Arbitrary Command Execution
|
161 |
WEB
|
anonymous
|
2017-12-28
|
|
DotNetNuke DreamSlider 01.01.02 - Arbitrary File Download
|
123 |
WEB
|
Glafkos Charalambous
|
2017-12-27
|
|
Sendroid < 6.5.0 - SQL Injection
|
130 |
WEB
|
Onwuka Gideon
|
2017-12-21
|
|
Ability Mail Server 3.3.2 - Cross-Site Scripting
|
86 |
WEB
|
Aloyce J. Makalanga
|
2017-12-19
|
|
Linksys WVBR0 - 'User-Agent' Remote Command Injection
|
119 |
WEB
|
nixawk
|
2017-12-18
|
|
ITGuard-Manager 0.0.0.1 - Remote Code Execution
|
117 |
WEB
|
Nassim Asrir
|
2017-12-18
|
|
Western Digital MyCloud multi_uploadify File Upload
|
108 |
WEB
|
Zenofex
|
2017-12-14
|
|
Microsoft Office DDE Payload Delivery
|
316 |
WEB
|
mumbai
|
2017-12-14
|
|
Dup Scout Enterprise 10.0.18 Buffer Overflow
|
329 |
WEB
|
Chris Higgins
|
2017-12-14
|
|
pfSense 2.4.1 CSRF Error Page Clickjacking
|
387 |
WEB
|
Yorick Koster
|
2017-12-06
|
|
WinduCMS 3.1 - Local File Disclosure
|
249 |
WEB
|
Maciek Krupa
|
2017-12-04
|
|
Artica Web Proxy 3.06 - Remote Code Execution
|
207 |
WEB
|
hyp3rlinx
|
2017-12-04
|
|
MistServer 2.12 - Cross-Site Scripting
|
199 |
WEB
|
hyp3rlinx
|
2017-12-04
|
|
WinduCMS 3.1 Local File Disclosure
|
187 |
WEB
|
Maciej Krupa
|
2017-11-30
|
|
osCommerce 2.3.4.1 - Arbitrary File Upload
|
237 |
WEB
|
Simon Scannell
|
2017-11-29
|
|
Synology StorageManager 5.2 - Remote Root Command Execution
|
232 |
WEB
|
SecuriTeam
|
2017-11-20
|
|
phpMyFAQ 2.9.9 Code Injection
|
370 |
WEB
|
tomplixsee
|