2014-08-29
|
|
XRMS - Blind SQL Injection and Command Execution
|
108 |
WEB
|
Benjamin Harris
|
2014-08-29
|
|
PhpWiki - Remote Command Execution
|
51 |
WEB
|
Benjamin Harris
|
2014-08-29
|
|
ActualAnalyzer Lite 2.81 - Unauthenticated Command Execution
|
72 |
WEB
|
Benjamin Harris
|
2014-08-29
|
|
Plogger 1.0-RC1 - Authenticated Arbitrary File Upload
|
73 |
WEB
|
b0z
|
2014-08-20
|
|
HybridAuth install.php PHP Code Execution
|
78 |
WEB
|
Pichaya Morimoto
|
2014-08-14
|
|
WordPress Disqus 2.7.5 CSRF / Cross Site Scripting Vulnerabilities
|
111 |
WEB
|
Nik Cubrilovic
|
2014-08-13
|
|
CS-Cart 4.2.0 Session Hijacking
|
62 |
WEB
|
Nik Cubrilovic
|
2014-08-04
|
|
TigerCom iFolder+ v1.2 iOS - Multiple Vulnerabilities
|
90 |
WEB
|
Vulnerability-Lab
|
2014-07-31
|
|
D-Link AP 3200 Multiple Vulnerabilities
|
96 |
WEB
|
pws
|
2014-07-31
|
|
SkaDate Lite 2.0 - Remote Code Execution Exploit
|
182 |
WEB
|
LiquidWorm
|
2014-07-29
|
|
Oxwall 1.7.0 - Remote Code Execution Exploit
|
134 |
WEB
|
LiquidWorm
|
2014-07-29
|
|
Oxwall 1.7.0 - Multiple CSRF And HTML Injection Vulnerabilities
|
86 |
WEB
|
LiquidWorm
|
2014-07-28
|
|
Pligg 2.0.1 - Multiple Vulnerabilities
|
78 |
WEB
|
BlackHawk
|
2014-07-25
|
|
NETGEAR DGN2200 1.0.0.29_1.7.29_HotS - Password Disclosure vulnerability
|
85 |
WEB
|
Dolev Farhi
|
2014-07-22
|
|
vBulletin 5.1.2 SQL Injection
|
85 |
WEB
|
Nytro
|
2014-07-22
|
|
MTS MBlaze Ultra Wi-Fi / ZTE AC3633 - Multiple Vulnerabilities
|
70 |
WEB
|
Ajin Abraham
|
2014-07-16
|
|
Wordpress WPTouch Authenticated File Upload
|
60 |
WEB
|
Marc-Alexandre Montpas
|
2014-07-09
|
|
Yokogawa CS3000 BKFSim_vhfd.exe Buffer Overflow
|
103 |
WEB
|
Redsadic
|
2014-07-09
|
|
Wordpress Theme ProjectTheme Shell Upload Vulnerability
|
115 |
WEB
|
Aloulou
|
2014-07-09
|
|
Wordpress Theme PricerrTheme Shell Upload Vulnerability
|
121 |
WEB
|
Aloulou
|
2014-07-08
|
|
Netgear WNR1000v3 - Password Recovery Credential Disclosure Vulnerability
|
139 |
WEB
|
c1ph04
|
2014-07-01
|
|
IBM Algorithmics RICOS Disclosure / XSS / CSRF
|
140 |
WEB
|
F. Lukavsky
|
2014-07-01
|
|
Horde Framework Unserialize PHP Code Execution
|
73 |
WEB
|
Akra Macha
|
2014-06-30
|
|
WordPress wp-crm Plugin Arbitrary File Upload Vulnerability
|
306 |
WEB
|
brunox
|
2014-06-27
|
|
Python CGIHTTPServer File Disclosure / Code Execution
|
228 |
WEB
|
Jens Liebchen
|
2014-06-25
|
|
WordPress image-symlinks Plugin Arbitrary File Upload Vulnerability
|
149 |
WEB
|
brunox
|
2014-06-25
|
|
Cogent DataHub Command Injection
|
105 |
WEB
|
juan vazquez
|
2014-06-24
|
|
Supermicro IPMI/BMC Cleartext Password Scanner
|
207 |
WEB
|
1N3
|
2014-06-23
|
|
D-link DSL-2760U-E1 - Persistent XSS
|
75 |
WEB
|
Yuval tisf Nativ
|
2014-06-20
|
|
AlienVault OSSIM av-centerd Command Injection
|
55 |
WEB
|
temp66
|
2014-06-19
|
|
Ericom AccessNow Server Buffer Overflow
|
90 |
WEB
|
temp66
|
2014-06-16
|
|
ZeroCMS 1.0 - zero_transact_user.php, Handling Privilege Escalation
|
147 |
WEB
|
Tiago Carvalho
|
2014-06-13
|
|
Plesk 10.4.4 / 11.0.9 XXE Injection
|
78 |
WEB
|
z00
|
2014-06-10
|
|
Xornic Contact Us Form CAPTCHA Bypass / XSS
|
96 |
WEB
|
Scott Arciszewski
|
2014-06-09
|
|
Madness Pro <= 1.14 - SQL Injection
|
71 |
WEB
|
bwall
|
2014-06-09
|
|
Madness Pro <= 1.14 - Persistent XSS
|
92 |
WEB
|
bwall
|
2014-05-22
|
|
SPIP - CMS < 3.0.9 / 2.1.22 / 2.0.23 - Privilege Escalation
|
79 |
WEB
|
Gregory DRAPERI
|
2014-05-20
|
|
UPS Web/SNMP-Manager CS121 Login Bypass
|
78 |
WEB
|
jkmac
|
2014-05-20
|
|
SafeNet Sentinel Protection Server 7.0 - 7.4 and Sentinel Keys Server 1.0.3 - 1.0.4 Directory Traver
|
69 |
WEB
|
Matt Schmidt
|
2014-05-20
|
|
HP Release Control Authenticated XXE
|
90 |
WEB
|
Brandon Perry
|
2014-05-16
|
|
ElasticSearch Remote Code Execution
|
71 |
WEB
|
Jeff Geiger
|
2014-05-14
|
|
WordPress Formidable Forms Remote Code Execution
|
85 |
WEB
|
Manish Tanwar
|
2014-05-14
|
|
AlienVault OSSIM 4.6.1 - Authenticated SQL Injection
|
103 |
WEB
|
Chris Hebert
|
2014-05-09
|
|
F5 iControl Remote Command Execution Vulnerability
|
68 |
WEB
|
Brandon Perry
|
2014-05-04
|
|
HP Laser Jet - JavaScript Persistent XSS via PJL Directory Traversal
|
74 |
WEB
|
@0x00string
|
2014-04-25
|
|
Bonefire v.0.7.1 - Reinstall Admin Account Exploit
|
60 |
WEB
|
Mehmet Ince
|
2014-04-23
|
|
No-CMS 0.6.6 rev 1 - Admin Account Hijacking / RCE Exploit via Static Encryption Key
|
174 |
WEB
|
Mehmet Ince
|
2014-04-23
|
|
Sixnet Sixview 2.4.1 - Web Console Directory Traversal
|
59 |
WEB
|
daniel svartman
|
2014-04-22
|
|
Comtrend CT 5361T Cross Site Request Forgery / Cross Site Scripting
|
84 |
WEB
|
TUNISIAN CYBER
|
2014-04-22
|
|
ATSEngine credential disclosure vulnerability
|
53 |
WEB
|
Xylitol
|
2014-04-21
|
|
CU3ER 1.24 Cross Site Scripting / Content Spoofing
|
69 |
WEB
|
MustLive
|
2014-04-16
|
|
NETGEAR N600 WIRELESS DUAL BAND WNDR3400 - Multiple Vulnerabilities
|
75 |
WEB
|
Santhosh Kumar
|
2014-04-15
|
|
Madss Software Solution SQL Injection
|
121 |
WEB
|
Ashiyane Digital Security Team
|
2014-04-14
|
|
Plex Media Server 0.9.9.10 CSRF / Disclosure
|
171 |
WEB
|
S. Viehbock
|
2014-04-14
|
|
eScan Web Management Console Command Injection
|
64 |
WEB
|
juan vazquez
|
2014-04-10
|
|
Sophos Web Protection Appliance Command Execution
|
59 |
WEB
|
Brandon Perry
|
2014-04-10
|
|
RunCMS 1.6.1 - 'pm.class.php' Multiple SQL Injection Vulnerabilities
|
112 |
WEB
|
The:Paradox
|
2014-04-09
|
|
Vtiger Install Unauthenticated Remote Command Execution
|
39 |
WEB
|
Jonathan Borgeaud
|
2014-04-08
|
|
PHPFox 3.7.5 Authorization Bypass
|
91 |
WEB
|
Wesley Henrique Leite
|
2014-04-04
|
|
Kyocera FS5250 Cross Site Scripting
|
58 |
WEB
|
Jeff Sergeant
|
2014-04-04
|
|
Kloxo-MR 6.5.0 - CSRF Vulnerability
|
91 |
WEB
|
Necmettin COSKUN
|
2014-04-04
|
|
Kloxo 6.1.18 Stable - CSRF Vulnerability
|
74 |
WEB
|
Necmettin COSKUN
|
2014-04-03
|
|
iShare Your Moving Library 1.0 iOS - Multiple Vulnerabilities
|
43 |
WEB
|
Vulnerability-Lab
|
2014-04-03
|
|
ICOMM 610 Wireless Modem - CSRF Vulnerability
|
95 |
WEB
|
Blessen Thomas
|
2014-04-01
|
|
AlienVault 4.5.0 SQL Injection
|
79 |
WEB
|
Brandon Perry
|
2014-04-01
|
|
EMC Cloud Tiering Appliance v10.0 Unauthenticated XXE Arbitrary File Read
|
182 |
WEB
|
Brandon Perry
|
2014-03-31
|
|
WordPress Business Intelligence 1.0.6 Shell Upload
|
99 |
WEB
|
Manish Tanwar
|
2014-03-27
|
|
IBM Tealeaf CX 8.8 - Remote OS Command Injection
|
55 |
WEB
|
drone
|
2014-03-26
|
|
qEngine CMS 6.0.0 - Multiple Vulnerabilities
|
76 |
WEB
|
LiquidWorm
|
2014-03-26
|
|
Kemana Directory 1.5.6 (qvc_init()) Cookie Poisoning CAPTCHA Bypass Exploit
|
73 |
WEB
|
LiquidWorm
|
2014-03-26
|
|
Kemana Directory 1.5.6 Database Backup Disclosure Exploit
|
87 |
WEB
|
LiquidWorm
|
2014-03-26
|
|
Cart Engine 3.0.0 Database Backup Disclosure Exploit
|
76 |
WEB
|
LiquidWorm
|
2014-03-18
|
|
osCmax 2.5.X Cross-Site Request Forgery (Add Admin) Vulnerability
|
72 |
WEB
|
TUNISIAN CYBER
|
2014-03-17
|
|
OpenSupports v2.x AuthBypass/CSRF Vulnerabilities
|
69 |
WEB
|
TUNISIAN CYBER
|
2014-03-11
|
|
Herpes Net 3.0 SQL Injection
|
82 |
WEB
|
bwall
|
2014-03-06
|
|
Ganib 2.3 SQL Injection
|
86 |
WEB
|
drone
|
2014-02-14
|
|
Dexter CasinoLoader SQL Injection
|
98 |
WEB
|
bwall
|
2014-02-11
|
|
ZTE ZXV10 W300 Hardcoded Credentials
|
105 |
WEB
|
Cesar Neira
|
2014-02-11
|
|
WordPress Kidoo Shell Upload
|
86 |
WEB
|
TUNISIAN CYBER
|
2014-01-21
|
|
WordPress Global Flash Galleries File Upload
|
75 |
WEB
|
Ashiyane Digital Security Team
|
2014-01-20
|
|
bloofoxCMS 0.5.0 CSRF / PHP Code Injection
|
147 |
WEB
|
AtT4CKxT3rR0r1ST
|
2014-01-17
|
|
SmarterMail 11.x Cross Site Scripting
|
154 |
WEB
|
Saeed reza Zamanian
|
2014-01-09
|
|
Eyou Mail System Remote Code Execution
|
66 |
WEB
|
conqu3r.zeng
|
2014-01-08
|
|
Command School Student Management System 1.06.01 SQL Injection / CSRF / XSS
|
81 |
WEB
|
AtT4CKxT3rR0r1ST
|
2014-01-08
|
|
vTiger CRM SOAP AddEmailAttachment Arbitrary File Upload
|
83 |
WEB
|
EgiX
|
2014-01-07
|
|
Seagate BlackArmor NAS sg2000-2000.1331 - Multiple Persistent Cross Site Scripting Vulnerabilities
|
77 |
WEB
|
Jeroen - IT Nerdbox
|
2014-01-07
|
|
Seagate BlackArmor NAS sg2000-2000.1331 - Cross Site Request Forgery
|
62 |
WEB
|
Jeroen - IT Nerdbox
|
2014-01-07
|
|
Seagate BlackArmor NAS sg2000-2000.1331 - Remote Command Execution
|
193 |
WEB
|
Jeroen - IT Nerdbox
|
2014-01-07
|
|
Seagate BlackArmor - Root Exploit
|
104 |
WEB
|
Jeroen - IT Nerdbox
|
2013-12-31
|
|
PhotoStore 4.0.7. Shell Upload
|
76 |
WEB
|
Gabby
|
2013-12-24
|
|
Synology DiskStation Manager SLICEUPLOAD Remote Command Execution
|
68 |
WEB
|
Markus Wulftange
|
2013-12-24
|
|
OpenSIS 'modname' PHP Code Execution
|
84 |
WEB
|
EgiX
|
2013-12-24
|
|
Zimbra Collaboration Server LFI
|
105 |
WEB
|
rubina119
|
2013-12-24
|
|
Song Exporter 2.1.1 RS Local File Inclusion
|
60 |
WEB
|
Benjamin Kunz Mejri
|
2013-12-24
|
|
WordPress Persuasion Theme File Download / Deletion
|
72 |
WEB
|
Interference Security
|
2013-12-23
|
|
USP Secure Entry Server URL Redirection
|
55 |
WEB
|
Alexandre Herzog
|
2013-12-18
|
|
iScripts Support Desk 4.1 SQL Injection
|
138 |
WEB
|
i-Hmx
|
2013-12-18
|
|
Traidnt Upload 3 Add Administrator
|
71 |
WEB
|
i-Hmx
|
2013-12-16
|
|
PHP openssl_x509_parse() Memory Corruption
|
119 |
WEB
|
Stefan Esser
|
2013-12-16
|
|
iScripts AutoHoster PHP Code Injection
|
69 |
WEB
|
i-Hmx
|
2013-12-11
|
|
vBulletin index.php/ajax/api/reputation/vote nodeid Parameter SQL Injection
|
80 |
WEB
|
Orestis Kourides
|
2013-12-09
|
|
Up.Time Monitoring Station post2file.php Arbitrary File Upload
|
83 |
WEB
|
Denis Andzakovic
|
2013-12-09
|
|
Eaton Network Shutdown Module 3.21 PHP Code Injection
|
77 |
WEB
|
Filip Waeytens
|
2013-12-06
|
|
Joomla Hotornot2 Shell Upload
|
94 |
WEB
|
DevilScreaM
|
2013-12-05
|
|
Kaseya uploadImage Arbitrary File Upload
|
93 |
WEB
|
Thomas Hibbert
|
2013-12-03
|
|
WordPress OptimizePress Theme File Upload
|
91 |
WEB
|
Mekanismen
|
2013-12-02
|
|
Joomla JMultimedia Command Execution
|
90 |
WEB
|
Deepankar Arora
|
2013-11-29
|
|
Kimai 0.9.2 db_restore.php SQL Injection
|
73 |
WEB
|
drone
|
2013-11-26
|
|
LimeSurvey 2.00+ (build 131107) - Multiple Vulnerabilities
|
88 |
WEB
|
LiquidWorm
|
2013-11-11
|
|
RASPcalendar 1.01 SQL Injection
|
62 |
WEB
|
Hackeri-AL
|
2013-11-01
|
|
Joomla Joomleague Shell Upload
|
84 |
WEB
|
wantexz
|
2013-11-01
|
|
Unicorn WB-3300NR Cross Site Request Forgery
|
83 |
WEB
|
absane
|
2013-10-31
|
|
ProcessMaker Open Source Authenticated PHP Code Execution
|
67 |
WEB
|
Brendan Coles
|
2013-10-28
|
|
WordPress GeoPlaces 4.x Shell Upload
|
66 |
WEB
|
DevilScreaM
|
2013-10-28
|
|
WebCollab 3.30 HTTP Response Splitting
|
76 |
WEB
|
Manuel Garcia Cardenas
|
2013-10-24
|
|
Joomla Component com_maianmedia Remote Code Execution
|
97 |
WEB
|
indexphp
|
2013-10-23
|
|
Apache Shindig 2.5.0 XXE Injection
|
73 |
WEB
|
Kousuke Ebihara
|
2013-10-21
|
|
Bluetooth U 1.2.0 Directory Traversal
|
71 |
WEB
|
Benjamin Kunz Mejri
|
2013-10-21
|
|
WebTester 5.x Command Execution
|
63 |
WEB
|
Brendan Coles
|
2013-10-18
|
|
Oracle Portal Demo Organization Chart PL/SQL Injection
|
113 |
WEB
|
Manuel Garcia Cardenas
|
2013-10-18
|
|
Level One Enterprise Access Points Password Disclosure
|
72 |
WEB
|
Richard Weinberger
|
2013-10-15
|
|
Zabbix 2.0.8 SQL Injection / Remote Code Execution
|
93 |
WEB
|
Lincoln
|
2013-10-08
|
|
WordPress Woopra Remote Code Execution
|
97 |
WEB
|
wantexz
|
2013-10-08
|
|
WordPress Slimstat Ex Code Execution
|
65 |
WEB
|
wantexz
|
2013-10-08
|
|
WordPress SEO Watcher Remote Code Execution
|
78 |
WEB
|
wantexz
|