Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2020-04-21   CSZ CMS 1.2.7 - Persistent Cross-Site Scripting 2 WEB Metin Yunus Kandemir
2020-04-20   Fork CMS 5.8.0 - Persistent Cross-Site Scripting 2 WEB Vulnerability-Lab
2020-04-20   Prestashop 1.7.6.4 - Cross-Site Request Forgery 2 WEB Sivanesh Ashok
2020-04-20   Centreon 19.10.5 - 'id' SQL Injection 3 WEB Basim Alabdullah
2020-04-17   TAO Open Source Assessment Platform 3.3.0 RC02 - HTML Injection 3 WEB Vulnerability-Lab
2020-04-17   Playable 9.18 iOS - Persistent Cross-Site Scripting 2 WEB Vulnerability-Lab
2020-04-15   Xeroneit Library Management System 3.0 - 'category' SQL Injection 3 WEB Sohel Yousef
2020-04-15   File Transfer iFamily 2.1 - Directory Traversal 3 WEB Vulnerability-Lab
2020-04-15   DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting 3 WEB Vulnerability Research Laboratory
2020-04-15   Macs Framework 1.14f CMS - Persistent Cross-Site Scripting 3 WEB Vulnerability-Lab
2020-04-15   SeedDMS 5.1.18 - Persistent Cross-Site Scripting 2 WEB Vulnerability-Lab
2020-04-15   Pinger 1.0 - Remote Code Execution 2 WEB Milad karimi
2020-04-15   SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting 2 WEB Vulnerability-Lab
2020-04-15   AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting 2 WEB Vulnerability-Lab
2020-04-14   Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution 2 WEB nu11secur1ty
2020-04-14   WSO2 3.1.0 - Persistent Cross-Site Scripting 2 WEB Raki Ben Hamouda
2020-04-14   Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution 1 WEB Wadeek
2020-04-13   MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection 1 WEB Aviv Beniash
2020-04-13   WordPress Plugin Media Library Assistant 2.81 - Local File Inclusion 2 WEB Daniel Monzón
2020-04-13   WSO2 3.1.0 - Arbitrary File Delete 2 WEB Raki Ben Hamouda
2020-04-13   Webtateas 2.0 - Arbitrary File Read 2 WEB China Banking and Insurance Information Technology
2020-04-13   TVT NVMS 1000 - Directory Traversal 2 WEB Mohin Paramasivam
2020-04-13   Huawei HG630 2 Router - Authentication Bypass 2 WEB Eslam Medhat
2020-04-10   Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal 2 WEB Basim Alabdullah
2020-04-10   WordPress Plugin Helpful 2.4.11 - SQL Injection 1 WEB numan türle
2020-04-08   Django 3.0 - Cross-Site Request Forgery Token Bypass 2 WEB Spad Security Group
2020-04-06   pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting 2 WEB Matthew Aberegg
2020-04-06   LimeSurvey 4.1.11 - 'File Manager' Path Traversal 3 WEB Matthew Aberegg
2020-04-06   Bolt CMS 3.7.0 - Authenticated Remote Code Execution 2 WEB r3m0t3nu11
2020-04-06   WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting 2 WEB Gal Weizman
2020-04-06   Vesta Control Panel 0.9.8-26 - Authenticated Remote Code Execution (Metasploit) 1 WEB Mehmet Ince
2020-04-06   LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting 2 WEB Matthew Aberegg
2020-04-03   Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution 1 WEB Basim Alabdullah
2020-04-02   PHP-Fusion 9.03.50 - 'panels.php' Remote Code Execution 1 WEB Unkn0wn
2020-03-31   Grandstream UCM6200 Series WebSocket 1.0.20.20 - 'user_password' SQL Injection 2 WEB Jacob Baines
2020-03-31   Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection 2 WEB Jacob Baines
2020-03-30   Zen Load Balancer 3.10.1 - Remote Code Execution 1 WEB Cody Sixteen
2020-03-30   Joomla! com_fabrik 3.9.11 - Directory Traversal 1 WEB qw3rTyTy
2020-03-27   rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution 2 WEB vikingfr
2020-03-27   Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal 1 WEB hongphukt
2020-03-27   ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin) 1 WEB Mustafa Emre Gül
2020-03-26   Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution 2 WEB Engin Demirbilek
2020-03-25   LeptonCMS 4.5.0 - Persistent Cross-Site Scripting 1 WEB SunCSR
2020-03-25   Joomla! Component GMapFP 3.30 - Arbitrary File Upload 1 WEB ThelastVvV
2020-03-24   UCM6202 1.0.18.13 - Remote Command Injection 1 WEB Jacob Baines
2020-03-24   WordPress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting 1 WEB Jinson Varghese Behanan
2020-03-24   UliCMS 2020.1 - Persistent Cross-Site Scripting 1 WEB SunCSR
2020-03-23   Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection 1 WEB qw3rTyTy
2020-03-23   rConfig 3.9.4 - 'search.crud.php' Remote Command Injection 1 WEB Matthew Aberegg
2020-03-23   FIBARO System Home Center 5.021 - Remote File Include 1 WEB LiquidWorm
2020-03-23   Wordpress Plugin PicUploader 1.0 - Remote File Upload 1 WEB Milad karimi
2020-03-20   Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin) 1 WEB Metin Yunus Kandemir
2020-03-18   Joomla! Component ACYMAILING 3.9.0 - Unauthenticated Arbitrary File Upload 1 WEB qw3rTyTy
2020-03-18   Netlink GPON Router 1.0.11 - Remote Code Execution 1 WEB shellord
2020-03-17   UADMIN Botnet 1.0 - 'link' SQL Injection 1 WEB n4pst3r
2020-03-16   PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution 1 WEB Antonio Cannito
2020-03-16   PHPKB Multi-Language 9 - Authenticated Directory Traversal 1 WEB Antonio Cannito
2020-03-16   PHPKB Multi-Language 9 - Authenticated Remote Code Execution 1 WEB Antonio Cannito
2020-03-16   MiladWorkShop VIP System 1.0 - 'lang' SQL Injection 1 WEB AYADI Mohamed
2020-03-16   Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin) 2 WEB Miguel Mendez Z
2020-03-10   Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution 2 WEB Andrea Cardaci
2020-03-13   WordPress Plugin Custom Searchable Data System - Unauthenticated Data M]odification 2 WEB Nawaf Alkeraithe
2020-03-13   Centos WebPanel 7 - 'term' SQL Injection 1 WEB Berke YILMAZ
2020-03-11   Horde Groupware Webmail Edition 5.2.22 - PHAR Loading 1 WEB Andrea Cardaci
2020-03-11   Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion 2 WEB Andrea Cardaci
2020-03-12   rConfig 3.9 - 'searchColumn' SQL Injection 2 WEB vikingfr
2020-03-12   rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution 1 WEB Engin Demirbilek
2020-03-12   HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin) 1 WEB Ismail Akıcı
2020-03-12   WordPress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection 2 WEB Daniel Monzón
2020-03-12   WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure 3 WEB RedTeam Pentesting GmbH
2020-03-12   Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection 2 WEB Milad karimi
2020-03-11   TeamCity Agent XML-RPC 10.0 - Remote Code Execution 2 WEB 1F98D
2020-03-11   Wing FTP Server - Authenticated CSRF (Delete Admin) 2 WEB Dhiraj Mishra
2020-03-11   PlaySMS 1.4.3 - Template Injection / Remote Code Execution 2 WEB Touhid M.Shaikh
2020-03-11   Joomla! 3.9.0 < 3.9.7 - CSV Injection 2 WEB i4bdullah
2020-03-11   WordPress Plugin Search Meter 2.13.2 - CSV injection 1 WEB Daniel Monzón
2020-03-10   Persian VIP Download Script 1.0 - 'active' SQL Injection 2 WEB Amir Hossein Vafifar
2020-03-10   YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting 2 WEB En_dust
2020-03-10   Sysaid 20.1.11 b26 - Remote Command Execution 1 WEB Ahmed Sherif
2020-03-09   Sentrifugo HRMS 3.2 - 'id' SQL Injection 1 WEB minhnb
2020-03-09   60CycleCMS - 'news.php' SQL Injection 2 WEB Unkn0wn
2019-12-12   ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization / Unauthenticated Remote 2 WEB mr_me
2020-03-04   UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read 2 WEB NgoAnhDuc
2020-03-03   RICOH Aficio SP 5210SF Printer - 'entryNameIn' HTML Injection 2 WEB Olga Villagran
2020-03-03   GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection 3 WEB emaragkos
2020-03-03   Alfresco 5.2.4 - Persistent Cross-Site Scripting 2 WEB Alexandre ZANNI
2020-03-03   RICOH Aficio SP 5200S Printer - 'entryNameIn' HTML Injection 1 WEB Paulina Girón
2020-03-02   Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit) 1 WEB Lucas Amorim
2020-03-02   Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload) 2 WEB Elber Tavares
2020-03-02   TP LINK TL-WR849N - Remote Code Execution 2 WEB Elber Tavares
2020-03-02   Wing FTP Server 6.2.5 - Privilege Escalation 1 WEB Cary Hooper
2020-03-02   TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware) 2 WEB Elber Tavares
2020-03-02   WordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User) 2 WEB Jinson Varghese Behanan
2020-03-02   Netis WF2419 2.2.36123 - Remote Code Execution 1 WEB Elias Issa
2020-03-02   Joplin Desktop 1.0.184 - Cross-Site Scripting 1 WEB Javier Olmedo
2020-02-28   qdPM < 9.1 - Remote Code Execution 2 WEB Tobin Shields
2020-02-03   Cacti 1.2.8 - Unauthenticated Remote Code Execution 2 WEB Askar
2020-02-03   Cacti 1.2.8 - Authenticated Remote Code Execution 2 WEB Askar
2020-02-20   Apache Tomcat - AJP 'Ghostcat File Read/Inclusion 2 WEB YDHCUI
2020-02-27   Comtrend VR-3033 - Command Injection 2 WEB Raki Ben Hamouda
2020-02-27   Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin) 1 WEB Meisam Monsef
2020-02-26   PhpIX 2012 Professional - 'id' SQL Injection 2 WEB indoushka
2020-02-25   Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass 2 WEB GeekHack
2020-02-25   WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass 2 WEB GeekHack
2020-02-24   Cacti 1.2.8 - Remote Code Execution 1 WEB Askar
2020-02-24   Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure 2 WEB Todor Donev
2020-02-24   DotNetNuke 9.5 - File Upload Restrictions Bypass 2 WEB Sajjad Pourali
2020-02-24   DotNetNuke 9.5 - Persistent Cross-Site Scripting 2 WEB Sajjad Pourali
2020-02-24   eLection 2.0 - 'id' SQL Injection 2 WEB J3rryBl4nks
2020-02-24   ManageEngine EventLog Analyzer 10.0 - Information Disclosure 2 WEB Scott Goodwin
2020-02-24   I6032B-P POE 2.0MP Outdoor Camera - Remote Configuration Disclosure 2 WEB Todor Donev
2020-02-24   ATutor 2.2.4 - 'id' SQL Injection 1 WEB Andrey Stoykov
2020-02-24   SecuSTATION SC-831 HD Camera - Remote Configuration Disclosure 1 WEB Todor Donev
2020-02-24   AMSS++ 4.7 - Backdoor Admin Account 2 WEB indoushka
2020-02-24   CandidATS 2.1.0 - Cross-Site Request Forgery (Add Admin) 2 WEB J3rryBl4nks
2020-02-24   SecuSTATION IPCAM-130 HD Camera - Remote Configuration Disclosure 2 WEB Todor Donev
2020-02-24   AMSS++ v 4.31 - 'id' SQL Injection 1 WEB indoushka
2020-02-24   Real Web Pentesting Tutorial Step by Step - [Persian] 2 WEB Meisam Monsef
2020-02-24   ESCAM QD-900 WIFI HD Camera - Remote Configuration Disclosure 2 WEB Todor Donev
2020-02-24   GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection 2 WEB emaragkos
2020-02-24   Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting 2 WEB Scott Goodwin
2020-02-20   Easy2Pilot 7 - Cross-Site Request Forgery (Add User) 2 WEB indoushka
2020-02-19   Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak 2 WEB byteGoblin
2020-02-19   DBPower C300 HD Camera - Remote Configuration Disclosure 2 WEB Todor Donev
2020-02-19   Virtual Freer 1.58 - Remote Command Execution 2 WEB SajjadBnd