2017-04-05
|
|
Apple WebKit 10.0.2(12602.3.12.0.1) - 'disconnectSubframes' Universal Cross-Site Scripting
|
75 |
WEB
|
Google Security Research
|
2017-04-05
|
|
Apple Webkit - Universal Cross-Site Scripting by Accessing a Named Property from an Unloaded Window
|
159 |
WEB
|
Google Security Research
|
2017-04-05
|
|
Apple Webkit - 'JSCallbackData' Universal Cross-Site Scripting
|
183 |
WEB
|
Google Security Research
|
2017-04-05
|
|
Apple WebKit 10.0.2(12602.3.12.0.1) - 'Frame::setDocument (1)' Universal Cross-Site Scripting
|
177 |
WEB
|
Google Security Research
|
2017-04-05
|
|
Splunk Enterprise - Information Disclosure
|
142 |
WEB
|
hyp3rlinx
|
2017-03-30
|
|
EyesOfNetwork (EON) 5.1 - SQL Injection
|
190 |
WEB
|
Dany Bach
|
2017-03-21
|
|
D-Link DGS-1510 - Multiple Vulnerabilities
|
106 |
WEB
|
Varang Amin
|
2017-03-20
|
|
Wordpress Plugin Membership Simplified 1.58 - Arbitrary File Download
|
146 |
WEB
|
The Martian
|
2017-03-20
|
|
Microsoft Internet Information Services Cross Site Scripting
|
103 |
WEB
|
David Fernandez
|
2017-03-16
|
|
GitHub Enterprise 2.8.0 < 2.8.6 - Remote Code Execution
|
125 |
WEB
|
iblue
|
2017-03-15
|
|
Microsoft Edge Fetch API Arbitrary Header Setting
|
188 |
WEB
|
Securify B.V.
|
2017-03-13
|
|
e107 <= 2.1.4 - 'keyword' Blind SQL Injection
|
209 |
WEB
|
StAkeR
|
2017-03-13
|
|
WatchGuard XTMv 11.12 Build 516911 - User Management Cross-Site Request Forgery
|
220 |
WEB
|
KoreLogic
|
2017-03-10
|
|
FTP Voyager Scheduler 16.2.0 - Cross-Site Request Forgery
|
317 |
WEB
|
hyp3rlinx
|
2017-03-10
|
|
ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Remote Code Execution
|
270 |
WEB
|
Bruno Bierbaumer
|
2017-03-10
|
|
Drupal 7.x Module Services - Remote Code Execution
|
302 |
WEB
|
Charles Fol
|
2017-03-09
|
|
Navetti PricePoint 4.6.0.0 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
|
174 |
WEB
|
SEC Consult
|
2017-03-08
|
|
Western Digital My Cloud Command Injection
|
300 |
WEB
|
Remco Vermeulen
|
2017-03-07
|
|
Deluge Web UI 1.3.13 - Cross-Site Request Forgery
|
211 |
WEB
|
Kyle Neideck
|
2017-03-07
|
|
WordPress Multiple Plugins - Arbitrary File Upload
|
294 |
WEB
|
The Martian
|
2017-03-06
|
|
pfSense 2.3.2 Cross Site Request Forgery / Cross Site Scripting
|
194 |
WEB
|
Yann CAM
|
2017-03-06
|
|
WordPress Username Enumeration
|
261 |
WEB
|
Dctor
|
2017-03-01
|
|
NETGEAR DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery
|
188 |
WEB
|
SivertPL
|
2017-03-01
|
|
Blizard BB 1.7 (privtmsg) MD5 Hash Retrieve Blind sql injection Exploit
|
331 |
WEB
|
StAkeR
|
2017-02-28
|
|
Grails PDF Plugin 0.6 - XML External Entity Injection
|
227 |
WEB
|
Charles Fol
|
2017-02-28
|
|
NETGEAR DGN2200v1/v2/v3/v4 - 'dnslookup.cgi' Remote Command Execution
|
202 |
WEB
|
SivertPL
|
2017-02-27
|
|
Apple WebKit 10.0.2 - 'Frame::setDocument' Universal Cross-Site Scripting
|
151 |
WEB
|
Google Security Research
|
2017-02-27
|
|
Apple WebKit 10.0.2 - Cross-Origin or Sandboxed IFRAME Pop-up Blocker Bypass
|
218 |
WEB
|
Google Security Research
|
2017-02-27
|
|
Apple WebKit 10.0.2 - 'FrameLoader::clear' Universal Cross-Site Scripting
|
203 |
WEB
|
Google Security Research
|
2017-02-23
|
|
Teradici Management Console 2.2.0 - Privilege Escalation
|
349 |
WEB
|
hantwister
|
2017-02-22
|
|
AlienVault OSSIM/USM <= 5.3.1 - Remote Code Execution (Metasploit)
|
124 |
WEB
|
Mehmet Ince
|
2017-02-22
|
|
Sonicwall 8.1.0.2-14sv - 'viewcert.cgi' Remote Command Injection (Metasploit)
|
192 |
WEB
|
xort
|
2017-02-22
|
|
Sonicwall 8.1.0.2-14sv - 'extensionsettings.cgi' Remote Command Injection (Metasploit)
|
159 |
WEB
|
xort
|
2017-02-22
|
|
Sophos Web Appliance 4.2.1.3 - DiagnosticTools Remote Command Injection (Metasploit)
|
168 |
WEB
|
xort
|
2017-02-22
|
|
Sophos Web Appliance 4.2.1.3 - block/unblock Remote Command Injection (Metasploit)
|
212 |
WEB
|
xort
|
2017-02-20
|
|
NETGEAR DGN2200v1/v2/v3/v4 - 'ping.cgi' Remote Command Execution
|
218 |
WEB
|
SivertPL
|
2017-02-20
|
|
TI Online Examination System 2.0 Admin Password Changer Exploit
|
244 |
WEB
|
StAkeR
|
2017-02-17
|
|
dotCMS 3.6.1 - Blind Boolean SQL Injection
|
238 |
WEB
|
Ben Nott
|
2017-02-16
|
|
Geutebruck 5.02024 G-Cam/EFD-2250 - Remote Command Execution (Metasploit)
|
165 |
WEB
|
Davy Douhine
|
2017-02-14
|
|
PHP Marketplace Script - SQL Injection
|
199 |
WEB
|
Th3GundY
|
2017-02-10
|
|
WordPress wp-json Content Injection
|
248 |
WEB
|
Larry W. Cashdollar
|
2017-02-09
|
|
POSNIC 1.03 Shell Upload Exploit
|
149 |
WEB
|
Rony Das
|
2017-02-06
|
|
Alstrasoft Template Seller Pro 3.25e - 'tempid' Parameter SQL Injection
|
90 |
WEB
|
Ihsan Sencan
|
2017-02-03
|
|
WordPress 4.7.0/4.7.1 - Unauthenticated Content Injection (Ruby)
|
334 |
WEB
|
Harsh Jaiswal
|
2017-02-03
|
|
WordPress 4.7.0/4.7.1 - Unauthenticated Content Injection (Python)
|
216 |
WEB
|
leonjza
|
2017-02-03
|
|
Multiple Netgear Routers - Password Disclosure
|
198 |
WEB
|
Trustwave's SpiderLabs
|
2017-02-03
|
|
HelpDeskZ < 1.0.2 - Authenticated SQL Injection / Unauthorized File Download
|
197 |
WEB
|
Mariusz Poplawski
|
2017-02-03
|
|
Joomla! < 3.6.4 - Admin TakeOver
|
317 |
WEB
|
Charles Fol
|
2017-02-03
|
|
Joomla! < 2.5.2 - Admin Creation
|
89 |
WEB
|
Charles Fol
|
2017-01-23
|
|
PageKit 1.0.10 - Password Reset
|
96 |
WEB
|
Saurabh Banawar
|
2017-01-22
|
|
Pirelli DRG A115 v3 ADSL Router - Unauthenticated DNS Change
|
183 |
WEB
|
Todor Donev
|
2017-01-22
|
|
Tenda ADSL2/2+ Modem D820R - Unauthenticated DNS Change
|
281 |
WEB
|
Todor Donev
|
2017-01-18
|
|
BoZoN 2.4 - Remote Code Execution
|
242 |
WEB
|
hyp3rlinx
|
2017-01-18
|
|
dirLIST 0.3.0 - Arbitrary File Upload
|
210 |
WEB
|
hyp3rlinx
|
2017-01-18
|
|
WordPress WooCommerce Direct Download Local File Inclusion
|
225 |
WEB
|
Diego Celdran Morell
|
2017-01-17
|
|
Tenda ADSL2/2+ Modem D840R - Unauthenticated DNS Change
|
226 |
WEB
|
Todor Donev
|
2017-01-17
|
|
Pirelli DRG A115 ADSL Router - Unauthenticated DNS Change
|
219 |
WEB
|
Todor Donev
|
2017-01-13
|
|
iTechscripts Freelancer Script 5.11 - 'sk' Parameter SQL Injection
|
280 |
WEB
|
v3n0m
|
2017-01-11
|
|
Freepbx < 2.11.1.5 - Remote Code Execution
|
203 |
WEB
|
inj3ctor3
|
2017-01-04
|
|
PHPMailer Sendmail Argument Injection
|
187 |
WEB
|
Spencer McIntyre
|
2017-01-03
|
|
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - (AIO) 'PwnScri
|
153 |
WEB
|
Dawid Golunski
|
2017-01-03
|
|
Xfinity Gateway (Technicolor DPC3941T) - Cross-Site Request Forgery
|
203 |
WEB
|
Ayushman Dutta
|
2017-01-03
|
|
Zend Framework / zend-mail < 2.4.11 - Remote Code Execution
|
217 |
WEB
|
Dawid Golunski
|
2016-12-30
|
|
PHPMailer < 5.2.18 - Remote Code Execution (Python)
|
458 |
WEB
|
anarc0der
|
2016-12-29
|
|
SwiftMailer < 5.4.5-DEV - Remote Code Execution
|
102 |
WEB
|
Dawid Golunski
|
2016-12-29
|
|
PHPMailer < 5.2.18 - Remote Code Execution (PHP)
|
207 |
WEB
|
Dawid Golunski
|
2016-12-29
|
|
PHPMailer < 5.2.20 - Remote Code Execution
|
110 |
WEB
|
Dawid Golunski
|
2016-12-27
|
|
PHPMailer 5.2.17 - Remote Code Execution
|
97 |
WEB
|
Dawid Golunski
|
2016-12-26
|
|
Apache mod_session_crypto - Padding Oracle
|
108 |
WEB
|
RedTeam Pentesting GmbH
|
2016-12-20
|
|
ntop-ng 2.5.160805 - Username Enumeration
|
189 |
WEB
|
Dolev Farhi
|
2016-12-13
|
|
ARG-W4 ADSL Router - Multiple Vulnerabilities
|
169 |
WEB
|
Persian Hack Team
|
2016-12-12
|
|
Splunk Enterprise 6.4.3 - Server-Side Request Forgery
|
137 |
WEB
|
Security-Assessment.com
|
2016-12-02
|
|
MS Edge CMarkup::EnsureDeleteCFState Use-After-Free
|
185 |
WEB
|
SkyLined
|
2016-11-30
|
|
Google Chrome Accessibility blink::Node Corruption
|
119 |
WEB
|
SkyLined
|
2016-11-28
|
|
Osticket 1.9.14 - 'X-Forwarded-For' Cross-Site Scripting
|
180 |
WEB
|
Joaquin Ramirez Martinez
|
2016-11-24
|
|
Chrome Blink SpeechRecognitionController Use-After-Free
|
83 |
WEB
|
SkyLined
|
2016-11-18
|
|
Microsoft Internet Explorer 8 Javascript RegExpBase::FBadHeader Use-After-Free
|
132 |
WEB
|
SkyLined
|
2016-11-16
|
|
phpWebAdmin 1.0 SQL Injection
|
153 |
WEB
|
N_A
|
2016-11-15
|
|
Boonex Dolphin 7.3.2 - Authentication Bypass / Remote Code Execution
|
163 |
WEB
|
0x4148
|
2016-11-14
|
|
Schoolhos CMS 2.29 - Remote Code Execution / SQL Injection
|
204 |
WEB
|
0x4148
|
2016-11-14
|
|
InvoicePlane 1.4.8 - Password Reset
|
213 |
WEB
|
feedersec
|
2016-11-11
|
|
e107 CMS 2.1.2 - Privilege Escalation
|
155 |
WEB
|
Kacper Szurek
|
2016-11-10
|
|
Adobe Connect 9.5.7 - Cross-Site Scripting
|
76 |
WEB
|
Vulnerability-Lab
|
2016-11-04
|
|
SweetRice 1.5.1 - Arbitrary File Download
|
183 |
WEB
|
Ehsan Hosseini
|
2016-11-04
|
|
Mini Notice Board 1.1 SQL Injection
|
134 |
WEB
|
N_A
|
2016-11-01
|
|
ASP Gateway 1.0.0 Database Disclosure
|
100 |
WEB
|
indoushka
|
2016-11-01
|
|
Angelo Emlak Scripti 1.0 Database Disclosure
|
85 |
WEB
|
indoushka
|
2016-10-31
|
|
InfraPower PPS-02-S Q213V1 - Local File Disclosure
|
104 |
WEB
|
LiquidWorm
|
2016-10-26
|
|
EC-CUBE 2.12.6 - Server-Side Request Forgery
|
160 |
WEB
|
Wadeek
|
2016-10-25
|
|
Event Calendar PHP 1.5 Cross Site Request Forgery
|
97 |
WEB
|
Ehsan Hosseini
|
2016-10-25
|
|
WordPress Userpro Remote File Upload
|
145 |
WEB
|
T3rm!nat0r5
|
2016-10-24
|
|
Zenbership 107 - Multiple Vulnerabilities
|
194 |
WEB
|
Zenbership
|
2016-10-24
|
|
FreePBX 10.13.66 - Remote Command Execution / Privilege Escalation
|
208 |
WEB
|
Christopher Davis
|
2016-10-19
|
|
Cgiemail 1.6 - Source Code Disclosure
|
220 |
WEB
|
Finbar Crago
|
2016-10-19
|
|
Pluck CMS 4.7.3 - Cross-Site Request Forgery (Add Page)
|
208 |
WEB
|
Ahsan Tahir
|
2016-10-17
|
|
YouTube Automated CMS 1.0.7 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
|
438 |
WEB
|
Arbin Godar
|
2016-10-17
|
|
Simple Forum PHP 2.4 - Cross-Site Request Forgery (Edit Options)
|
125 |
WEB
|
Ehsan Hosseini
|
2016-10-13
|
|
ApPHP MicroCMS 3.9.5 - (Add Admin) Cross-Site Request Forgery
|
145 |
WEB
|
Besim
|
2016-10-12
|
|
ApPHP MicroBlog 1.0.2 - Cross-Site Request Forgery (Add New Author)
|
94 |
WEB
|
Besim
|
2016-10-12
|
|
phpEnter 4.2.7 - Cross-Site Request Forgery (Add New Post)
|
105 |
WEB
|
Besim
|
2016-10-12
|
|
BirdBlog 1.4.0 - Cross-Site Request Forgery (Add New Post)
|
109 |
WEB
|
Besim
|
2016-10-12
|
|
Spacemarc News - Cross-Site Request Forgery (Add New Post)
|
69 |
WEB
|
Besim
|
2016-10-08
|
|
Witbe - Remote Code Execution
|
124 |
WEB
|
BeLmar
|
2016-09-27
|
|
VenShop System 2010 Database Disclosure
|
195 |
WEB
|
indoushka
|
2016-09-23
|
|
Kerio Control Unified Threat Management 9.1.0 build 1087, 9.1.1 build 1324 - Multiple Vulnerabilitie
|
137 |
WEB
|
SEC Consult
|
2016-09-21
|
|
VegaDNS 0.13.2 - Remote Command Injection
|
133 |
WEB
|
Wireghoul
|
2016-09-20
|
|
ZineBasic 1.1 - Arbitrary File Disclosure
|
108 |
WEB
|
bd0rk
|
2016-09-18
|
|
AnoBBS 1.0.1 - Remote File Inclusion
|
99 |
WEB
|
bd0rk
|
2016-09-14
|
|
wdCalendar 2 - SQL Injection
|
189 |
WEB
|
Alfonso Castillo Angel
|
2016-09-14
|
|
Cherry Music 0.35.1 - Arbitrary File Disclosure
|
201 |
WEB
|
feedersec
|
2016-09-12
|
|
Vodafone Mobile Wifi - Reset Admin Password
|
270 |
WEB
|
Daniele Linguaglossa
|
2016-09-09
|
|
Zabbix 2.0 - 3.0.3 - SQL Injection
|
137 |
WEB
|
Zzzians
|
2016-09-08
|
|
Adobe ColdFusion < 11 Update 10 - XML External Entity Injection
|
252 |
WEB
|
Dawid Golunski
|
2016-09-05
|
|
Belkin F9K1122v1 1.00.30 - Buffer Overflow (via Cross-Site Request Forgery)
|
210 |
WEB
|
b1ack0wl
|
2016-09-05
|
|
Easy File Sharing Web Server 7.2 SEH Buffer Overflow
|
171 |
WEB
|
Iran Cyber Security Group
|
2016-09-01
|
|
CactuShop 7 Database Disclosure
|
171 |
WEB
|
indoushka
|
2016-08-31
|
|
Arabportal 2.x RCE Vulnerability
|
77 |
WEB
|
Team Uruk
|
2016-08-30
|
|
HelpDeskZ 1.0.2 - Unauthenticated Shell Upload
|
227 |
WEB
|
Lars Morgenroth
|
2016-08-29
|
|
Prestashop VtermSlideShow Module Arbitrary File Upload Exploit
|
135 |
WEB
|
PentesterDesk
|
2016-08-29
|
|
Prestashop Attributewizardpro Module Arbitrary File Upload Exploit
|
132 |
WEB
|
PentesterDesk
|
2016-08-29
|
|
Prestashop Multi Modules Arbitrary File Upload Exploit
|
218 |
WEB
|
PentesterDesk
|
2016-08-23
|
|
WordPress 4.5.3 - Directory Traversal / Denial of Service
|
196 |
WEB
|
Yorick Koster
|
2016-08-23
|
|
VideoIQ Camera - Local File Disclosure
|
138 |
WEB
|
Yakir Wizman
|
2016-08-23
|
|
MESSOA IP Cameras (Multiple Models) - Unauthenticated Password Change
|
81 |
WEB
|
Todor Donev
|
2016-08-23
|
|
ZYCOO IP Phone System - Remote Command Execution
|
103 |
WEB
|
0x4148
|