2016-12-27
|
|
PHPMailer 5.2.17 - Remote Code Execution
|
104 |
WEB
|
Dawid Golunski
|
2016-12-26
|
|
Apache mod_session_crypto - Padding Oracle
|
114 |
WEB
|
RedTeam Pentesting GmbH
|
2016-12-20
|
|
ntop-ng 2.5.160805 - Username Enumeration
|
193 |
WEB
|
Dolev Farhi
|
2016-12-13
|
|
ARG-W4 ADSL Router - Multiple Vulnerabilities
|
175 |
WEB
|
Persian Hack Team
|
2016-12-12
|
|
Splunk Enterprise 6.4.3 - Server-Side Request Forgery
|
142 |
WEB
|
Security-Assessment.com
|
2016-12-02
|
|
MS Edge CMarkup::EnsureDeleteCFState Use-After-Free
|
191 |
WEB
|
SkyLined
|
2016-11-30
|
|
Google Chrome Accessibility blink::Node Corruption
|
125 |
WEB
|
SkyLined
|
2016-11-28
|
|
Osticket 1.9.14 - 'X-Forwarded-For' Cross-Site Scripting
|
186 |
WEB
|
Joaquin Ramirez Martinez
|
2016-11-24
|
|
Chrome Blink SpeechRecognitionController Use-After-Free
|
88 |
WEB
|
SkyLined
|
2016-11-18
|
|
Microsoft Internet Explorer 8 Javascript RegExpBase::FBadHeader Use-After-Free
|
139 |
WEB
|
SkyLined
|
2016-11-16
|
|
phpWebAdmin 1.0 SQL Injection
|
158 |
WEB
|
N_A
|
2016-11-15
|
|
Boonex Dolphin 7.3.2 - Authentication Bypass / Remote Code Execution
|
167 |
WEB
|
0x4148
|
2016-11-14
|
|
Schoolhos CMS 2.29 - Remote Code Execution / SQL Injection
|
208 |
WEB
|
0x4148
|
2016-11-14
|
|
InvoicePlane 1.4.8 - Password Reset
|
220 |
WEB
|
feedersec
|
2016-11-11
|
|
e107 CMS 2.1.2 - Privilege Escalation
|
161 |
WEB
|
Kacper Szurek
|
2016-11-10
|
|
Adobe Connect 9.5.7 - Cross-Site Scripting
|
81 |
WEB
|
Vulnerability-Lab
|
2016-11-04
|
|
SweetRice 1.5.1 - Arbitrary File Download
|
190 |
WEB
|
Ehsan Hosseini
|
2016-11-04
|
|
Mini Notice Board 1.1 SQL Injection
|
140 |
WEB
|
N_A
|
2016-11-01
|
|
ASP Gateway 1.0.0 Database Disclosure
|
104 |
WEB
|
indoushka
|
2016-11-01
|
|
Angelo Emlak Scripti 1.0 Database Disclosure
|
90 |
WEB
|
indoushka
|
2016-10-31
|
|
InfraPower PPS-02-S Q213V1 - Local File Disclosure
|
110 |
WEB
|
LiquidWorm
|
2016-10-26
|
|
EC-CUBE 2.12.6 - Server-Side Request Forgery
|
166 |
WEB
|
Wadeek
|
2016-10-25
|
|
Event Calendar PHP 1.5 Cross Site Request Forgery
|
102 |
WEB
|
Ehsan Hosseini
|
2016-10-25
|
|
WordPress Userpro Remote File Upload
|
151 |
WEB
|
T3rm!nat0r5
|
2016-10-24
|
|
Zenbership 107 - Multiple Vulnerabilities
|
200 |
WEB
|
Zenbership
|
2016-10-24
|
|
FreePBX 10.13.66 - Remote Command Execution / Privilege Escalation
|
215 |
WEB
|
Christopher Davis
|
2016-10-19
|
|
Cgiemail 1.6 - Source Code Disclosure
|
224 |
WEB
|
Finbar Crago
|
2016-10-19
|
|
Pluck CMS 4.7.3 - Cross-Site Request Forgery (Add Page)
|
214 |
WEB
|
Ahsan Tahir
|
2016-10-17
|
|
YouTube Automated CMS 1.0.7 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
|
442 |
WEB
|
Arbin Godar
|
2016-10-17
|
|
Simple Forum PHP 2.4 - Cross-Site Request Forgery (Edit Options)
|
130 |
WEB
|
Ehsan Hosseini
|
2016-10-13
|
|
ApPHP MicroCMS 3.9.5 - (Add Admin) Cross-Site Request Forgery
|
151 |
WEB
|
Besim
|
2016-10-12
|
|
ApPHP MicroBlog 1.0.2 - Cross-Site Request Forgery (Add New Author)
|
100 |
WEB
|
Besim
|
2016-10-12
|
|
phpEnter 4.2.7 - Cross-Site Request Forgery (Add New Post)
|
110 |
WEB
|
Besim
|
2016-10-12
|
|
BirdBlog 1.4.0 - Cross-Site Request Forgery (Add New Post)
|
114 |
WEB
|
Besim
|
2016-10-12
|
|
Spacemarc News - Cross-Site Request Forgery (Add New Post)
|
75 |
WEB
|
Besim
|
2016-10-08
|
|
Witbe - Remote Code Execution
|
129 |
WEB
|
BeLmar
|
2016-09-27
|
|
VenShop System 2010 Database Disclosure
|
199 |
WEB
|
indoushka
|
2016-09-23
|
|
Kerio Control Unified Threat Management 9.1.0 build 1087, 9.1.1 build 1324 - Multiple Vulnerabilitie
|
143 |
WEB
|
SEC Consult
|
2016-09-21
|
|
VegaDNS 0.13.2 - Remote Command Injection
|
139 |
WEB
|
Wireghoul
|
2016-09-20
|
|
ZineBasic 1.1 - Arbitrary File Disclosure
|
114 |
WEB
|
bd0rk
|
2016-09-18
|
|
AnoBBS 1.0.1 - Remote File Inclusion
|
103 |
WEB
|
bd0rk
|
2016-09-14
|
|
wdCalendar 2 - SQL Injection
|
196 |
WEB
|
Alfonso Castillo Angel
|
2016-09-14
|
|
Cherry Music 0.35.1 - Arbitrary File Disclosure
|
207 |
WEB
|
feedersec
|
2016-09-12
|
|
Vodafone Mobile Wifi - Reset Admin Password
|
276 |
WEB
|
Daniele Linguaglossa
|
2016-09-09
|
|
Zabbix 2.0 - 3.0.3 - SQL Injection
|
143 |
WEB
|
Zzzians
|
2016-09-08
|
|
Adobe ColdFusion < 11 Update 10 - XML External Entity Injection
|
260 |
WEB
|
Dawid Golunski
|
2016-09-05
|
|
Belkin F9K1122v1 1.00.30 - Buffer Overflow (via Cross-Site Request Forgery)
|
215 |
WEB
|
b1ack0wl
|
2016-09-05
|
|
Easy File Sharing Web Server 7.2 SEH Buffer Overflow
|
178 |
WEB
|
Iran Cyber Security Group
|
2016-09-01
|
|
CactuShop 7 Database Disclosure
|
176 |
WEB
|
indoushka
|
2016-08-31
|
|
Arabportal 2.x RCE Vulnerability
|
84 |
WEB
|
Team Uruk
|
2016-08-30
|
|
HelpDeskZ 1.0.2 - Unauthenticated Shell Upload
|
234 |
WEB
|
Lars Morgenroth
|
2016-08-29
|
|
Prestashop VtermSlideShow Module Arbitrary File Upload Exploit
|
140 |
WEB
|
PentesterDesk
|
2016-08-29
|
|
Prestashop Attributewizardpro Module Arbitrary File Upload Exploit
|
140 |
WEB
|
PentesterDesk
|
2016-08-29
|
|
Prestashop Multi Modules Arbitrary File Upload Exploit
|
225 |
WEB
|
PentesterDesk
|
2016-08-23
|
|
WordPress 4.5.3 - Directory Traversal / Denial of Service
|
202 |
WEB
|
Yorick Koster
|
2016-08-23
|
|
VideoIQ Camera - Local File Disclosure
|
144 |
WEB
|
Yakir Wizman
|
2016-08-23
|
|
MESSOA IP Cameras (Multiple Models) - Unauthenticated Password Change
|
88 |
WEB
|
Todor Donev
|
2016-08-23
|
|
ZYCOO IP Phone System - Remote Command Execution
|
108 |
WEB
|
0x4148
|
2016-08-19
|
|
SIEMENS IP Camera CCMW1025 x.2.2.1798 - Remote Admin Credentials Change
|
117 |
WEB
|
Todor Donev
|
2016-08-11
|
|
EyeLock nano NXT 3.5 - Remote Root Exploit
|
216 |
WEB
|
LiquidWorm
|
2016-08-11
|
|
EyeLock nano NXT 3.5 - Local File Disclosure
|
76 |
WEB
|
LiquidWorm
|
2016-08-11
|
|
vBulletin 5.2.2 - Preauth Server Side Request Forgery (SSRF)
|
339 |
WEB
|
Dawid Golunski
|
2016-08-11
|
|
Nagios Network Analyzer 2.2.1 - Multiple CSRF
|
186 |
WEB
|
hyp3rlinx
|
2016-08-09
|
|
NUUO NVRmini 2 3.0.8 - (Add Admin) CSRF
|
326 |
WEB
|
LiquidWorm
|
2016-08-09
|
|
NUUO NVRmini 2 3.0.8 - Remote Root Exploit
|
343 |
WEB
|
LiquidWorm
|
2016-08-09
|
|
PhpMyAdmin 4.6.2 - Post-Auth Remote Code Execution
|
126 |
WEB
|
iamsecurity
|
2016-07-27
|
|
PHP File Vault 0.9 - Directory Traversal
|
99 |
WEB
|
N_A
|
2016-07-27
|
|
Bellini/Supercook Wi-Fi Yumi SC200 - Multiple Vulnerabilities
|
94 |
WEB
|
James McLean
|
2016-07-27
|
|
Technicolor TC7200 Modem/Router STD6.02.11 - Multiple Vulnerabilities
|
158 |
WEB
|
Gergely Eberhardt
|
2016-07-27
|
|
Ubee EVW3226 Modem/Router 1.0.20 - Multiple Vulnerabilities
|
79 |
WEB
|
Gergely Eberhardt
|
2016-07-27
|
|
PHP gettext (gettext.php) 1.0.12 - Unauthenticated Code Execution
|
74 |
WEB
|
kmkz
|
2016-07-27
|
|
Drupal CODER Module 2.5 - Remote Command Execution (Metasploit)
|
69 |
WEB
|
Mehmet Ince
|
2016-07-22
|
|
Technicolor TC7200 Modem / Router Session Management / Fixed Password
|
162 |
WEB
|
Gergely Eberhardt
|
2016-07-22
|
|
Cisco EPC3925 UPC Modem / Router Default Passphrase
|
139 |
WEB
|
Gergely Eberhardt
|
2016-07-21
|
|
WordPress Video Player Plugin 1.5.16 - SQL Injection
|
123 |
WEB
|
David Vaartjes
|
2016-07-21
|
|
Wowza Streaming Engine 4.5.0 - Multiple XSS
|
115 |
WEB
|
LiquidWorm
|
2016-07-21
|
|
Wowza Streaming Engine 4.5.0 - Add Advanced Admin CSRF
|
101 |
WEB
|
LiquidWorm
|
2016-07-21
|
|
Wowza Streaming Engine 4.5.0 - Remote Privilege Escalation
|
89 |
WEB
|
LiquidWorm
|
2016-07-19
|
|
vBulletin 4.x - SQLi in breadcrumbs via xmlrpc API (Post-Auth)
|
95 |
WEB
|
tintinweb
|
2016-07-19
|
|
vBulletin 5.x/4.x - Persistent XSS in AdminCP/ApiLog via xmlrpc API (Post-Auth)
|
73 |
WEB
|
tintinweb
|
2016-07-13
|
|
Prestashop vtermslidesshow module Arbitrary File Upload Exploit
|
316 |
WEB
|
PentesterDesk
|
2016-07-12
|
|
Belkin Router AC1200 Firmware 1.00.27 - Authentication Bypass
|
104 |
WEB
|
Gregory Smiley
|
2016-07-11
|
|
CyberPower Systems PowerPanel 3.1.2 - XXE Out-Of-Band Data Retrieval
|
212 |
WEB
|
LiquidWorm
|
2016-07-11
|
|
php Real Estate Script 3 - Arbitrary File Disclosure
|
66 |
WEB
|
Meisam Monsef
|
2016-07-11
|
|
WordPress WP-DownloadManager Plugin 1.68.1 - Arbitrary File Upload Vulnerability
|
227 |
WEB
|
Mojtaba MobhaM
|
2016-07-07
|
|
PrinceXML Wrapper Class Command Injection
|
213 |
WEB
|
Brandon Perry
|
2016-07-06
|
|
Nagios XI Chained Remote Code Execution
|
213 |
WEB
|
wvu
|
2016-07-05
|
|
WordPress Real3D FlipBook Plugin - Multiple Vulnerabilities
|
143 |
WEB
|
Mukarram Khalid
|
2016-07-01
|
|
Ubiquiti Administration Portal - CSRF to Remote Command Execution
|
102 |
WEB
|
KoreLogic
|
2016-07-01
|
|
WordPress Ultimate Membership Pro Plugin 3.3 - SQL Injection
|
147 |
WEB
|
wp0Day
|
2016-07-01
|
|
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
|
103 |
WEB
|
hyp3rlinx
|
2016-06-29
|
|
Prestashop Attribute Wizard Pro module Arbitrary File Upload Exploit
|
722 |
WEB
|
PentesterDesk
|
2016-06-28
|
|
Untangle NGFW 12.1.0 Beta execEvil() Command Injection
|
193 |
WEB
|
Matt Bush
|
2016-06-28
|
|
Ruby HTTP Header Injection
|
111 |
WEB
|
rootredrain
|
2016-06-28
|
|
MyLittleForum 2.3.5 - PHP Command Injection
|
80 |
WEB
|
hyp3rlinx
|
2016-06-23
|
|
Prestashop modules Arbitrary File Upload Vulnerability
|
820 |
WEB
|
PentesterDesk Team
|
2016-06-21
|
|
Airia - Webshell Upload Exploit
|
118 |
WEB
|
HaHwul
|
2016-06-21
|
|
Airia - (Add Content) CSRF
|
106 |
WEB
|
HaHwul
|
2016-06-21
|
|
WordPress Ultimate Product Catalog Plugin 3.8.1 - Privilege Escalation Exploit
|
113 |
WEB
|
Joaquin Ramirez Martinez
|
2016-06-21
|
|
WordPress Premium SEO Pack 1.9.1.3 wp_options Overwrite
|
96 |
WEB
|
wp0Day.com
|
2016-06-20
|
|
Skype For Business 2013 User Enumeration
|
72 |
WEB
|
nyxgeek
|
2016-06-20
|
|
Microsoft Internet Explorer 11 Garbage Collector Attribute Type Confusion
|
78 |
WEB
|
SkyLined
|
2016-06-20
|
|
phpATM 1.32 - Remote Command Execution (Shell Upload) on Windows Servers
|
93 |
WEB
|
Paolo Massenio
|
2016-06-20
|
|
WordPress Gravity Forms Plugin 1.8.19 - Arbitrary File Upload
|
327 |
WEB
|
Abk Khan
|
2016-06-16
|
|
PHPLive 4.4.8 - 4.5.4 - Password Recovery SQL Injection
|
108 |
WEB
|
Tiago Carvalho
|
2016-06-15
|
|
WordPress Social Stream Plugin 1.5.15 - wp_options Overwrite
|
115 |
WEB
|
wp0Day.com
|
2016-06-14
|
|
Viart Shopping Cart 5.0 CSRF / Shell Upload
|
200 |
WEB
|
Ali Ghanbari
|
2016-06-14
|
|
Zabbix 2.2 - 3.0.3 - RCE with API JSON-RPC
|
150 |
WEB
|
Alexander Gurin
|
2016-06-12
|
|
Mobiketa 1.0 - CSRF Add Admin Exploit
|
75 |
WEB
|
Murat Yilmazlar
|
2016-06-12
|
|
Dell OpenManage Server Administrator 8.3 - XML External Entity Exploit
|
264 |
WEB
|
hantwister
|
2016-06-08
|
|
Apache Continuum 1.4.2 Command Injection / Cross Site Scripting
|
85 |
WEB
|
David Shanahan
|
2016-06-07
|
|
WordPress Uncode Theme 1.3.1 - Arbitrary File Upload
|
170 |
WEB
|
wp0Day.com
|
2016-06-07
|
|
WordPress Newspaper Theme 6.7.1 - Privilege Escalation
|
181 |
WEB
|
wp0Day.com
|
2016-06-07
|
|
WordPress WP PRO Advertising System Plugin 4.6.18 - SQL Injection
|
212 |
WEB
|
wp0Day.com
|
2016-06-07
|
|
WordPress Creative Multi-Purpose Theme 9.1.3 - Stored XSS
|
227 |
WEB
|
wp0Day.com
|
2016-06-01
|
|
FlatPress 1.0.3 - CSRF Arbitrary File Upload
|
283 |
WEB
|
LiquidWorm
|
2016-05-30
|
|
WordPress Ninja Forms Unauthenticated File Upload
|
142 |
WEB
|
Rob Carr
|
2016-05-30
|
|
Linknat VOS3000/VOS2009 SQL Injection Exploit
|
268 |
WEB
|
Osama Khalid
|
2016-05-24
|
|
Job Script by Scubez - Remote Code Execution
|
114 |
WEB
|
Bikramaditya Guha
|
2016-05-19
|
|
Magento < 2.0.6 - Unauthenticated Arbitrary Unserialize -> Arbitrary Write File
|
185 |
WEB
|
agix
|
2016-05-17
|
|
TP-Link SC2020n Authenticated Telnet Injection
|
110 |
WEB
|
Nicholas Starke
|
2016-05-17
|
|
Meteocontrol WEB’log - Admin Password Disclosure
|
102 |
WEB
|
Karn Ganeshen
|
2016-05-17
|
|
eXtplorer 2.1.9 - Archive Path Traversal
|
176 |
WEB
|
hyp3rlinx
|
2016-05-17
|
|
Web interface for DNSmasq / Mikrotik - SQL Injection
|
273 |
WEB
|
hyp3rlinx
|
2016-05-06
|
|
ImageMagick < 6.9.3-9 - Multiple Vulnerabilities
|
241 |
WEB
|
Nikolay Ermishkin
|