2018-03-27
|
|
ClipBucket beats_uploader Unauthenticated Arbitrary File Upload
|
109 |
WEB
|
Touhid M.Shaikh
|
2018-03-26
|
|
XenForo 2 - CSS Loader Denial of Service
|
138 |
WEB
|
LockedByte
|
2018-03-26
|
|
TL-WR720N 150Mbps Wireless N Router - Cross-Site Request Forgery
|
151 |
WEB
|
Mans van Someren
|
2018-03-26
|
|
Hikvision IP Camera versions 5.2.0 - 5.3.9 (Builds 140721 - 170109) - Access Control Bypass
|
313 |
WEB
|
Matamorphosis
|
2018-03-22
|
|
Cisco node-jos < 0.11.0 - Re-sign Tokens
|
163 |
WEB
|
zioBlack
|
2018-03-21
|
|
Intelbras Telefone IP TIP200 LITE - Local File Disclosure
|
128 |
WEB
|
anhax0r
|
2018-03-16
|
|
Spring Data REST < 2.6.9 (Ingalls SR9), 3.0.1 (Kay SR1) - PATCH Request Remote Code Execution
|
190 |
WEB
|
Antonio Francesco Sardella
|
2018-03-13
|
|
Advantech WebAccess < 8.3 - Directory Traversal / Remote Code Execution
|
136 |
WEB
|
Chris Lyne
|
2018-03-13
|
|
ManageEngine Applications Manager 13.5 - Remote Code Execution (Metasploit)
|
123 |
WEB
|
Mehmet Ince
|
2018-03-07
|
|
Bravo Tejari Web Portal Cross Site Scripting
|
123 |
WEB
|
Arvind V.
|
2018-02-28
|
|
Concrete5 < 8.3.0 - Username / Comments Enumeration
|
174 |
WEB
|
Chapman Schleiss
|
2018-02-26
|
|
AsusWRT LAN Unauthenticated Remote Code Execution
|
163 |
WEB
|
Pedro Ribeiro
|
2018-02-26
|
|
UserSpice 4.3 - Blind SQL Injection
|
182 |
WEB
|
Dolev Farhi
|
2018-02-07
|
|
Hava Tahmin 1.0 Database Disclosure
|
156 |
WEB
|
indoushka
|
2018-02-07
|
|
Hazir Site 2.2 Database Disclosure
|
184 |
WEB
|
indoushka
|
2018-02-07
|
|
Gateway 1.0 Database Disclosure
|
164 |
WEB
|
indoushka
|
2018-02-07
|
|
iPortalx Portal Scripti Database Disclosure
|
177 |
WEB
|
indoushka
|
2018-02-06
|
|
Online Voting System - Authentication Bypass
|
201 |
WEB
|
Giulio Comi
|
2018-02-05
|
|
Oracle Hospitality Simphony (MICROS) 2.7 < 2.9 - Directory Traversal
|
161 |
WEB
|
Dmitry Chastuhin
|
2018-01-31
|
|
BMC BladeLogic RSCD Agent 8.3.00.64 - Windows Users Disclosure
|
183 |
WEB
|
Paul Taylor
|
2018-01-30
|
|
Advantech WebAccess < 8.3 - SQL Injection
|
150 |
WEB
|
Chris Lyne
|
2018-01-29
|
|
Asus Router Cross Site Script / Authentication Bypass
|
162 |
WEB
|
4TT4CK3R
|
2018-01-29
|
|
ASUS DSL-N14U B1 Router 1.1.2.3_345 - Change Administrator Password
|
165 |
WEB
|
Víctor Calvo
|
2018-01-24
|
|
Kaltura Remote PHP Code Execution
|
153 |
WEB
|
Robin Verton
|
2018-01-24
|
|
GoAhead Web Server LD_PRELOAD Arbitrary Module Load
|
166 |
WEB
|
h00die
|
2018-01-24
|
|
Photography CMS 1.0 - Cross-Site Request Forgery (Add Admin)
|
150 |
WEB
|
Ihsan Sencan
|
2018-01-22
|
|
Simple ASC CMS 1.2 Database Disclosure
|
138 |
WEB
|
indoushka
|
2018-01-22
|
|
PHPFreeChat 1.7 - Denial of Service
|
135 |
WEB
|
A. Pakbaz
|
2018-01-19
|
|
Primefaces 5.x - Remote Code Execution (Metasploit)
|
207 |
WEB
|
Bjoern Schuette
|
2018-01-16
|
|
Adminer 4.3.1 - Server-Side Request Forgery
|
165 |
WEB
|
hyp3rlinx
|
2018-01-16
|
|
pfSense < 2.1.4 - 'status_rrd_graph_img.php' Command Injection
|
135 |
WEB
|
absolomb
|
2018-01-12
|
|
D-Link Routers 110/412/615/815 < 1.03 - 'service.cgi' Arbitrary Code Execution
|
161 |
WEB
|
Cr0n1c
|
2018-01-12
|
|
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
|
136 |
WEB
|
Vahagn Vardanyan
|
2018-01-11
|
|
Samsung SRN-1670D Web Viewer 1.0.0.193 Arbitrary File Read / Upload
|
137 |
WEB
|
Algeria
|
2018-01-11
|
|
phpCollab 2.5.1 Unauthenticated File Upload
|
142 |
WEB
|
Nick Marcoccio
|
2018-01-10
|
|
Synology Photostation 6.7.2-3429 - Remote Code Execution (Metasploit)
|
166 |
WEB
|
James Bercegay
|
2018-01-09
|
|
FiberHome LM53Q1 - Multiple Vulnerabilities
|
149 |
WEB
|
Ibad Shah
|
2018-01-05
|
|
D-Link DNS-320L 'mydlinkBRionyg' Backdoor
|
143 |
WEB
|
James Bercegay
|
2018-01-05
|
|
Western Digital WDMyCloud 'mydlinkBRionyg' Backdoor
|
134 |
WEB
|
James Bercegay
|
2018-01-04
|
|
Linksys WVBR0-25 User-Agent Command Execution
|
127 |
WEB
|
HeadlessZeke
|
2018-01-02
|
|
Huawei Router HG532 - Arbitrary Command Execution
|
167 |
WEB
|
anonymous
|
2017-12-28
|
|
DotNetNuke DreamSlider 01.01.02 - Arbitrary File Download
|
128 |
WEB
|
Glafkos Charalambous
|
2017-12-27
|
|
Sendroid < 6.5.0 - SQL Injection
|
135 |
WEB
|
Onwuka Gideon
|
2017-12-21
|
|
Ability Mail Server 3.3.2 - Cross-Site Scripting
|
92 |
WEB
|
Aloyce J. Makalanga
|
2017-12-19
|
|
Linksys WVBR0 - 'User-Agent' Remote Command Injection
|
126 |
WEB
|
nixawk
|
2017-12-18
|
|
ITGuard-Manager 0.0.0.1 - Remote Code Execution
|
121 |
WEB
|
Nassim Asrir
|
2017-12-18
|
|
Western Digital MyCloud multi_uploadify File Upload
|
112 |
WEB
|
Zenofex
|
2017-12-14
|
|
Microsoft Office DDE Payload Delivery
|
321 |
WEB
|
mumbai
|
2017-12-14
|
|
Dup Scout Enterprise 10.0.18 Buffer Overflow
|
334 |
WEB
|
Chris Higgins
|
2017-12-14
|
|
pfSense 2.4.1 CSRF Error Page Clickjacking
|
392 |
WEB
|
Yorick Koster
|
2017-12-06
|
|
WinduCMS 3.1 - Local File Disclosure
|
254 |
WEB
|
Maciek Krupa
|
2017-12-04
|
|
Artica Web Proxy 3.06 - Remote Code Execution
|
212 |
WEB
|
hyp3rlinx
|
2017-12-04
|
|
MistServer 2.12 - Cross-Site Scripting
|
204 |
WEB
|
hyp3rlinx
|
2017-12-04
|
|
WinduCMS 3.1 Local File Disclosure
|
192 |
WEB
|
Maciej Krupa
|
2017-11-30
|
|
osCommerce 2.3.4.1 - Arbitrary File Upload
|
242 |
WEB
|
Simon Scannell
|
2017-11-29
|
|
Synology StorageManager 5.2 - Remote Root Command Execution
|
237 |
WEB
|
SecuriTeam
|
2017-11-20
|
|
phpMyFAQ 2.9.9 Code Injection
|
375 |
WEB
|
tomplixsee
|
2017-11-15
|
|
Allworx Server Manager 6x / 6x12 / 48x Cross Site Scripting
|
142 |
WEB
|
LiquidWorm
|
2017-11-14
|
|
Web Viewer 1.0.0.193 (Samsung SRN-1670D) - Unrestricted File Upload
|
387 |
WEB
|
Omar Mezrag
|
2017-11-09
|
|
Geutebrueck GCore GCoreServer.exe Buffer Overflow
|
198 |
WEB
|
Luca Cappiello
|
2017-11-09
|
|
Mako Server 2.5 Command Injection
|
143 |
WEB
|
Steven Patterson
|
2017-11-06
|
|
WordPress WP Mobile Detector 3.5 Shell Upload
|
196 |
WEB
|
h00die
|
2017-11-06
|
|
Oracle PeopleSoft Enterprise PeopleTools < 8.55 - Remote Code Execution Via Blind XML External Entit
|
152 |
WEB
|
Charles Fol
|
2017-10-31
|
|
Oracle Java SE - Web Start jnlp XML External Entity Processing Information Disclosure
|
222 |
WEB
|
mr_me
|
2017-10-26
|
|
PHPMailer 5.2.21 Local File Disclosure
|
147 |
WEB
|
Maciej Krupa
|
2017-10-24
|
|
Kaltura < 13.1.0 - Remote Code Execution
|
156 |
WEB
|
Robin Verton
|
2017-10-23
|
|
TP-Link WR940N Remote Code Execution
|
172 |
WEB
|
Tim Carrington
|
2017-10-23
|
|
Check_MK 1.2.8p25 - Information Disclosure
|
154 |
WEB
|
Julien Ahrens
|
2017-10-17
|
|
Webmin 1.850 SSRF / CSRF / Cross Site Scripting
|
169 |
WEB
|
hyp3rlinx
|
2017-10-13
|
|
Tomcat JSP Upload Bypass Remote Code Execution
|
287 |
WEB
|
peewpw
|
2017-10-12
|
|
Trend Micro InterScan Messaging Security (Virtual Appliance) - Remote Code Execution (Metasploit)
|
137 |
WEB
|
Mehmet Ince
|
2017-10-10
|
|
ERS Data System 1.8.1 Java Deserialization
|
124 |
WEB
|
West Shepherd
|
2017-10-10
|
|
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execu
|
269 |
WEB
|
intx0x80
|
2017-10-10
|
|
ClipBucket 2.8.3 - Remote Code Execution
|
128 |
WEB
|
Meisam Monsef
|
2017-10-10
|
|
FileRun < 2017.09.18 - SQL Injection
|
152 |
WEB
|
SPARC
|
2017-09-28
|
|
Fibaro Home Center 2 - Remote Command Execution / Privilege Escalation
|
127 |
WEB
|
forsec
|
2017-09-26
|
|
FLIR Systems FLIR Thermal Camera F/FC/PT/D Multiple Information Disclosures
|
143 |
WEB
|
LiquidWorm
|
2017-09-26
|
|
FLIR Systems FLIR Thermal Camera PT-Series (PT-334 200562) - Root Remote Code Execution
|
123 |
WEB
|
LiquidWorm
|
2017-09-25
|
|
Cash Back Comparison Script 1.0 - SQL Injection
|
129 |
WEB
|
Ihsan Sencan
|
2017-09-25
|
|
DenyAll WAF < 6.3.0 - Remote Code Execution (Metasploit)
|
132 |
WEB
|
Mehmet Ince
|
2017-09-22
|
|
Stock Photo Selling 1.0 - SQL Injection
|
143 |
WEB
|
Ihsan Sencan
|
2017-09-21
|
|
Disk Pulse Enterprise 9.9.16 GET Buffer Overflow
|
120 |
WEB
|
Chance Johnson
|
2017-09-19
|
|
Apache - HTTP OPTIONS Memory Leak
|
174 |
WEB
|
Hanno Bock
|
2017-09-19
|
|
DigiAffiliate 1.4 - Cross-Site Request Forgery (Update Admin)
|
134 |
WEB
|
Ihsan Sencan
|
2017-09-19
|
|
Digileave 1.2 - Cross-Site Request Forgery (Update Admin)
|
138 |
WEB
|
Ihsan Sencan
|
2017-09-19
|
|
Digirez 3.4 - Cross-Site Request Forgery (Update Admin)
|
136 |
WEB
|
Ihsan Sencan
|
2017-09-18
|
|
D-Link DIR8xx Routers - Local Firmware Upload
|
233 |
WEB
|
embedi
|
2017-09-18
|
|
D-Link DIR8xx Routers - Root Remote Code Execution
|
158 |
WEB
|
embedi
|
2017-09-18
|
|
D-Link DIR8xx Routers - Leak Credentials
|
137 |
WEB
|
embedi
|
2017-09-11
|
|
Nimble Professional 1.0 - Cross-Site Request Forgery (Update Admin)
|
148 |
WEB
|
Ihsan Sencan
|
2017-09-11
|
|
Topsites Script 1.0 - Cross-Site Request Forgery / PHP Code Injection
|
128 |
WEB
|
Ihsan Sencan
|
2017-08-31
|
|
Invoice Manager 3.1 - Cross-Site Request Forgery (Add Admin)
|
252 |
WEB
|
Ali BawazeEer
|
2017-08-24
|
|
Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution
|
145 |
WEB
|
LiquidWorm
|
2017-08-11
|
|
DALIM SOFTWARE ES Core 5.0 Build 7184.1 User Enumeration
|
157 |
WEB
|
LiquidWorm
|
2017-08-09
|
|
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
|
124 |
WEB
|
Kacper Szurek
|
2017-08-02
|
|
Advantech SUSIAccess <= 3.0 - 'RecoveryMgmt' File Upload
|
137 |
WEB
|
James Fitts
|
2017-08-02
|
|
Advantech SUSIAccess <= 3.0 - Directory Traversal / Information Disclosure (Metasploit)
|
119 |
WEB
|
James Fitts
|
2017-07-31
|
|
GitHub Enterprise < 2.8.7 - Remote Code Execution
|
132 |
WEB
|
orange
|
2017-07-27
|
|
WebKit JSC - 'JSObject::putInlineSlow and JSValue::putToPrimitive' Universal Cross-Site Scripting
|
104 |
WEB
|
Google Security Research
|
2017-07-25
|
|
ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit)
|
209 |
WEB
|
Kacper Szurek
|
2017-07-21
|
|
Netscaler SD-WAN 9.1.2.26.561201 - Command Injection (Metasploit)
|
149 |
WEB
|
xort
|
2017-07-21
|
|
Sonicwall < 8.1.0.2-14sv - 'sitecustomization.cgi' Command Injection (Metasploit)
|
130 |
WEB
|
xort
|
2017-07-21
|
|
Sonicwall < 8.1.0.6-21sv - 'gencsr.cgi' Command Injection (Metasploit)
|
119 |
WEB
|
xort
|
2017-07-19
|
|
Easy File Sharing Web Server 7.2 Buffer Overflow
|
156 |
WEB
|
N_A
|
2017-07-18
|
|
Barracuda Load Balancer Firmware <= 6.0.1.006 - Remote Command Injection (Metasploit)
|
153 |
WEB
|
xort
|
2017-07-18
|
|
Sophos Web Appliance 4.3.0.2 - 'trafficType' Remote Command Injection (Metasploit)
|
132 |
WEB
|
xort
|
2017-07-17
|
|
WDTV Live SMP 2.03.20 - Remote Password Reset
|
197 |
WEB
|
Sw1tCh
|
2017-07-17
|
|
Apache Struts 2.3.x Showcase - Remote Code Execution (PoC)
|
298 |
WEB
|
Vex Woo
|
2017-07-13
|
|
RaidenHTTPD 2.0.44 User-Agent Cross Site Scripting
|
114 |
WEB
|
sultan albalawi
|
2017-07-12
|
|
NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection
|
175 |
WEB
|
Paul Taylor
|
2017-07-03
|
|
Humax HG100R 2.0.6 - Backup File Download
|
202 |
WEB
|
gambler
|
2017-06-29
|
|
Easy File Sharing Web Server 7.2 - Unrestricted File Upload
|
249 |
WEB
|
Chako
|
2017-06-26
|
|
Easy File Sharing HTTP Server 7.2 POST Buffer Overflow
|
81 |
WEB
|
Marco Rivoli
|
2017-06-26
|
|
Symantec Messaging Gateway Remote Code Execution
|
132 |
WEB
|
Mehmet Ince
|
2017-06-26
|
|
Netgear DGN2200 dnslookup.cgi Command Injection
|
106 |
WEB
|
thecarterb
|
2017-06-22
|
|
PHPMailer < 5.2.20 with Exim MTA - Remote Code Execution
|
155 |
WEB
|
phackt_ul
|
2017-06-20
|
|
D-Link ADSL DSL-2640B SEA_1.01 Unauthenticated Remote DNS Changer
|
287 |
WEB
|
Todor Donev
|
2017-06-20
|
|
D-Link DSL-2640B - Unauthenticated Remote DNS Change
|
122 |
WEB
|
Todor Donev
|
2017-06-20
|
|
D-Link DSL-2640U - Unauthenticated DNS Change
|
185 |
WEB
|
Todor Donev
|
2017-06-20
|
|
Beetel BCM96338 Router - Unauthenticated DNS Change
|
203 |
WEB
|
Todor Donev
|
2017-06-20
|
|
UTstarcom WA3002G4 - Unauthenticated DNS Change
|
140 |
WEB
|
Todor Donev
|
2017-06-20
|
|
iBall Baton iB-WRA150N - Unauthenticated DNS Change
|
183 |
WEB
|
Todor Donev
|
2017-06-16
|
|
Aerohive HiveOS 5.1r5 < 6.1r5 - Remote Code Execution
|
235 |
WEB
|
Ike-Clinton
|
2017-06-14
|
|
MyBB 1.8.12 Stored XSS / File Enumeration
|
223 |
WEB
|
MLT
|
2017-06-13
|
|
EFS Easy Chat Server 3.1 - Password Reset
|
292 |
WEB
|
Aitezaz Mohsin
|