2020-02-18
|
|
WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Ultra Security Team
|
2020-02-17
|
|
LabVantage 8.3 - Information Disclosure
|
2 |
WEB
|
Joel Aviad Ossi
|
2020-02-17
|
|
SOPlanning 1.45 - 'users' SQL Injection
|
2 |
WEB
|
J3rryBl4nks
|
2020-02-17
|
|
WordPress Plugin WOOF Products Filter for WooCommerce 1.2.3 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Shahab.ra.9
|
2020-02-17
|
|
SOPlanning 1.45 - Cross-Site Request Forgery (Add User)
|
1 |
WEB
|
J3rryBl4nks
|
2020-02-17
|
|
WordPress Theme Fruitful 3.8 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Ultra Security Team
|
2020-02-17
|
|
Ice HRM 26.2.0 - Cross-Site Request Forgery (Add User)
|
1 |
WEB
|
J3rryBl4nks
|
2020-02-17
|
|
Avaya Aura Communication Manager 5.2 - Remote Code Execution
|
1 |
WEB
|
Sarang Tumne
|
2020-02-17
|
|
WordPress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Jinson Varghese Behanan
|
2020-02-17
|
|
SOPlanning 1.45 - 'by' SQL Injection
|
1 |
WEB
|
J3rryBl4nks
|
2020-02-14
|
|
phpMyChat Plus 1.98 - 'pmc_username' SQL Injection
|
2 |
WEB
|
J3rryBl4nks
|
2020-02-13
|
|
WordPress Plugin ultimate-member 2.1.3 - Local File Inclusion
|
3 |
WEB
|
Mehran Feizi
|
2020-02-13
|
|
PANDORAFMS 7.0 - Authenticated Remote Code Execution
|
1 |
WEB
|
Engin Demirbilek
|
2020-02-13
|
|
WordPress Plugin contact-form-7 5.1.6 - Remote File Upload
|
2 |
WEB
|
Mehran Feizi
|
2020-02-13
|
|
WordPress Plugin Wordfence.7.4.5 - Local File Disclosure
|
1 |
WEB
|
Mehran Feizi
|
2020-02-13
|
|
WordPress Plugin tutor.1.5.3 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Mehran Feizi
|
2020-02-13
|
|
WordPress Plugin Tutor.1.5.3 - Local File Inclusion
|
1 |
WEB
|
Mehran Feizi
|
2020-02-11
|
|
WordPress Plugin InfiniteWP - Client Authentication Bypass (Metasploit)
|
1 |
WEB
|
Metasploit
|
2020-02-11
|
|
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Sayak Naskar
|
2020-02-11
|
|
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
|
1 |
WEB
|
Luca.Chiou
|
2020-02-10
|
|
WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scripting
|
2 |
WEB
|
Jinson Varghese Behanan
|
2020-02-10
|
|
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
|
1 |
WEB
|
Prasenjit Kanti Paul
|
2020-02-07
|
|
Google Invisible RECAPTCHA 3 - Spoof Bypass
|
1 |
WEB
|
Matamorphosis
|
2020-02-07
|
|
ExpertGPS 6.38 - XML External Entity Injection
|
2 |
WEB
|
Trent Gordon
|
2020-02-07
|
|
EyesOfNetwork 5.3 - Remote Code Execution
|
2 |
WEB
|
Clément Billac
|
2020-02-07
|
|
PackWeb Formap E-learning 1.0 - 'NumCours' SQL Injection
|
2 |
WEB
|
Amel BOUZIANE-LEBLOND
|
2020-02-07
|
|
VehicleWorkshop 1.0 - 'bookingid' SQL Injection
|
1 |
WEB
|
Mehran Feizi
|
2020-02-07
|
|
QuickDate 1.3.2 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2020-02-06
|
|
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
|
1 |
WEB
|
mr_me
|
2020-02-06
|
|
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
|
2 |
WEB
|
mr_me
|
2020-02-06
|
|
Cisco Data Center Network Manager 11.2 - Remote Code Execution
|
2 |
WEB
|
mr_me
|
2020-02-06
|
|
Ecommerce Systempay 1.0 - Production KEY Brute Force
|
3 |
WEB
|
live3
|
2020-02-06
|
|
Online Job Portal 1.0 - Cross Site Request Forgery (Add User)
|
2 |
WEB
|
Ihsan Sencan
|
2020-02-06
|
|
Online Job Portal 1.0 - Remote Code Execution
|
3 |
WEB
|
Ihsan Sencan
|
2020-02-06
|
|
Online Job Portal 1.0 - 'user_email' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2020-02-05
|
|
AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
|
2 |
WEB
|
Ihsan Sencan
|
2020-02-05
|
|
Verodin Director Web Console 3.5.4.0 - Remote Authenticated Password Disclosure (PoC)
|
2 |
WEB
|
nxkennedy
|
2020-02-05
|
|
Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
|
1 |
WEB
|
nxkennedy
|
2020-02-05
|
|
Wago PFC200 - Authenticated Remote Code Execution (Metasploit)
|
0 |
WEB
|
0x483d
|
2020-02-05
|
|
AVideo Platform 8.1 - Information Disclosure (User Enumeration)
|
2 |
WEB
|
Ihsan Sencan
|
2020-02-04
|
|
F-Secure Internet Gatekeeper 5.40 - Heap Overflow (PoC)
|
2 |
WEB
|
Kevin Joensen
|
2020-02-04
|
|
Centreon 19.10.5 - 'Pollers' Remote Command Execution (Metasploit)
|
1 |
WEB
|
mekhalleh
|
2020-02-03
|
|
School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
|
1 |
WEB
|
J3rryBl4nks
|
2020-02-03
|
|
Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
|
2 |
WEB
|
Cosmin Craciun
|
2020-02-03
|
|
Jira 8.3.4 - Information Disclosure (Username Enumeration)
|
2 |
WEB
|
Mufeed VH
|
2020-02-03
|
|
phpList 3.5.0 - Authentication Bypass
|
1 |
WEB
|
Suvadip Kar
|
2020-02-03
|
|
IceWarp WebMail 11.4.4.1 - Reflective Cross-Site Scripting
|
2 |
WEB
|
Lutfu Mert Ceylan
|
2020-01-31
|
|
FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)
|
2 |
WEB
|
Ismail Tasdelen
|
2020-01-31
|
|
Lotus Core CMS 1.0.1 - Local File Inclusion
|
2 |
WEB
|
Daniel Monzón
|
2020-01-30
|
|
rConfig 3.9.3 - Authenticated Remote Code Execution
|
1 |
WEB
|
vikingfr
|
2020-01-29
|
|
Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
|
1 |
WEB
|
LiquidWorm
|
2020-01-29
|
|
Centreon 19.10.5 - 'centreontrapd' Remote Command Execution
|
2 |
WEB
|
Fabien AUNAY
|
2020-01-29
|
|
Centreon 19.10.5 - 'Pollers' Remote Command Execution
|
2 |
WEB
|
Omri Baso
|
2020-01-29
|
|
Satellian 1.12 - Remote Code Execution
|
1 |
WEB
|
Xh4H
|
2020-01-29
|
|
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
|
1 |
WEB
|
J3rryBl4nks
|
2020-01-29
|
|
Liferay CE Portal 6.0.2 - Remote Command Execution
|
2 |
WEB
|
Berk Dusunur
|
2020-01-29
|
|
Kibana 6.6.1 - CSV Injection
|
2 |
WEB
|
Aamir Rehman
|
2020-01-28
|
|
Centreon 19.10.5 - Remote Command Execution
|
2 |
WEB
|
Fabien AUNAY
|
2020-01-28
|
|
Centreon 19.10.5 - Database Credentials Disclosure
|
2 |
WEB
|
Fabien AUNAY
|
2020-01-28
|
|
Octeth Oempro 4.8 - 'CampaignID' SQL Injection
|
2 |
WEB
|
Bruno de Barros Bulle
|
2020-01-28
|
|
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
|
2 |
WEB
|
Sarthak Saini
|
2020-01-24
|
|
Genexis Platinum-4410 2.1 - Authentication Bypass
|
1 |
WEB
|
Husinul Sanub
|
2020-01-24
|
|
OLK Web Store 2020 - Cross-Site Request Forgery
|
2 |
WEB
|
Joel Aviad Ossi
|
2020-01-24
|
|
Webtareas 2.0 - 'id' SQL Injection
|
1 |
WEB
|
Greg.Priest
|
2020-01-24
|
|
TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
|
1 |
WEB
|
PCEumel
|
2020-01-23
|
|
qdPM 9.1 - Remote Code Execution
|
1 |
WEB
|
Rishal Dwivedi
|
2020-01-22
|
|
Citrix XenMobile Server 10.8 - XML External Entity Injection
|
1 |
WEB
|
Jonas Lejon
|
2020-01-21
|
|
ManageEngine Network Configuration Manager 12.2 - 'apiKey' SQL Injection
|
1 |
WEB
|
Ertebat Gostar Co
|
2020-01-20
|
|
Centreon 19.04 - Authenticated Remote Code Execution (Metasploit)
|
2 |
WEB
|
TheCyberGeek
|
2020-01-20
|
|
Adive Framework 2.0.8 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Sarthak Saini
|
2020-01-17
|
|
WordPress Plugin Time Capsule 1.21.16 - Authentication Bypass
|
1 |
WEB
|
B. Canavate
|
2020-01-17
|
|
WordPress Plugin InfiniteWP Client 1.9.4.5 - Authentication Bypass
|
1 |
WEB
|
Raphael Karger
|
2020-01-16
|
|
Rukovoditel Project Management CRM 2.5.2 - 'filters' SQL Injection
|
1 |
WEB
|
Fatih Çelik
|
2020-01-16
|
|
Rukovoditel Project Management CRM 2.5.2 - 'entities_id' SQL Injection
|
1 |
WEB
|
Fatih Çelik
|
2020-01-16
|
|
Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal
|
2 |
WEB
|
Dhiraj Mishra
|
2020-01-16
|
|
Online Book Store 1.0 - Arbitrary File Upload
|
2 |
WEB
|
Or4nG.M4N
|
2020-01-16
|
|
Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting
|
2 |
WEB
|
Ai Ho
|
2020-01-16
|
|
Rukovoditel Project Management CRM 2.5.2 - 'reports_id' SQL Injection
|
2 |
WEB
|
Fatih Çelik
|
2020-01-16
|
|
WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting
|
2 |
WEB
|
V1n1v131r4
|
2020-01-15
|
|
Huawei HG255 - Directory Traversal (Metasploit)
|
3 |
WEB
|
Ismail Tasdelen
|
2020-01-15
|
|
Online Book Store 1.0 - 'bookisbn' SQL Injection
|
1 |
WEB
|
Ertebat Gostar Co
|
2020-01-14
|
|
IBM RICOH 6400 Printer - HTML Injection
|
2 |
WEB
|
Ismail Tasdelen
|
2020-01-14
|
|
IBM RICOH InfoPrint 6500 Printer - HTML Injection
|
1 |
WEB
|
Ismail Tasdelen
|
2020-01-13
|
|
Digi AnywhereUSB 14 - Reflective Cross-Site Scripting
|
3 |
WEB
|
Raspina Net Pars Group
|
2020-01-13
|
|
Citrix Application Delivery Controller and Gateway 10.5 - Remote Code Execution (Metasploit)
|
2 |
WEB
|
mekhalleh
|
2020-01-13
|
|
Chevereto 3.13.4 Core - Remote Code Execution
|
2 |
WEB
|
Jinny Ramsmark
|
2020-01-11
|
|
Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution
|
2 |
WEB
|
TrustedSec
|
2020-01-11
|
|
Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution (PoC)
|
2 |
WEB
|
Project Zero India
|
2020-01-10
|
|
ASTPP 4.0.1 VoIP Billing - Database Backup Download
|
2 |
WEB
|
Fabien AUNAY
|
2020-01-10
|
|
PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution
|
3 |
WEB
|
.:UND3R:.
|
2020-01-10
|
|
Pandora 7.0NG - Remote Code Execution
|
1 |
WEB
|
Askar
|
2020-01-09
|
|
Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
|
1 |
WEB
|
james
|
2019-12-31
|
|
Sony Playstation 4 (PS4) < 6.72 - WebKit Code Execution (PoC)
|
1 |
WEB
|
TJ Corley
|
2020-01-08
|
|
Tomcat proprietaryEvaluate 9.0.0.M1 - Sandbox Escape
|
2 |
WEB
|
hantwister
|
2020-01-08
|
|
Online Book Store 1.0 - Unauthenticated Remote Code Execution
|
2 |
WEB
|
Tib3rius
|
2020-01-08
|
|
Codoforum 4.8.3 - 'input_txt' Persistent Cross-Site Scripting
|
2 |
WEB
|
Vyshnav nk
|
2020-01-07
|
|
Complaint Management System 4.0 - Remote Code Execution
|
1 |
WEB
|
Metin Yunus Kandemir
|
2020-01-07
|
|
piSignage 2.6.4 - Directory Traversal
|
1 |
WEB
|
JunYeong Ko
|
2020-01-07
|
|
Job Portal 1.0 - Remote Code Execution
|
1 |
WEB
|
Tib3rius
|
2019-12-24
|
|
Django < 3.0 < 2.2 < 1.11 - Account Hijack
|
1 |
WEB
|
Ryuji Tsutsui
|
2020-01-06
|
|
Codoforum 4.8.3 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Prasanth
|
2020-01-06
|
|
Voyager 1.3.0 - Directory Traversal
|
3 |
WEB
|
NgoAnhDuc
|
2020-01-06
|
|
Small CRM 2.0 - Authentication Bypass
|
2 |
WEB
|
FULLSHADE
|
2020-01-06
|
|
elaniin CMS 1.0 - Authentication Bypass
|
2 |
WEB
|
riamloo
|
2020-01-06
|
|
Hostel Management System 2.0 - 'id' SQL Injection
|
2 |
WEB
|
FULLSHADE
|
2020-01-06
|
|
Subrion CMS 4.0.5 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
Ismail Tasdelen
|
2020-01-06
|
|
IBM RICOH Infoprint 1532 Printer - Persistent Cross-Site Scripting
|
2 |
WEB
|
Ismail Tasdelen
|
2020-01-06
|
|
Complaint Management System 4.0 - 'cid' SQL injection
|
2 |
WEB
|
FULLSHADE
|
2020-01-06
|
|
Dairy Farm Shop Management System 1.0 - 'username' SQL Injection
|
1 |
WEB
|
Chris Inzinga
|
2020-01-03
|
|
Karakuzu ERP Management Web 5.7.0 - 'k_adi_duz' SQL Injection
|
2 |
WEB
|
Hakan TAŞKÖPRÜ
|
2020-01-03
|
|
Online Course Registration 2.0 - Remote Code Execution
|
1 |
WEB
|
Metin Yunus Kandemir
|
2020-01-02
|
|
BloodX 1.0 - Authentication Bypass
|
2 |
WEB
|
riamloo
|
2020-01-02
|
|
Hospital Management System 4.0 - Persistent Cross-Site Scripting
|
2 |
WEB
|
FULLSHADE
|
2020-01-02
|
|
Hospital Management System 4.0 - 'searchdata' SQL Injection
|
2 |
WEB
|
FULLSHADE
|
2020-01-01
|
|
Hospital Management System 4.0 - Authentication Bypass
|
2 |
WEB
|
Metin Yunus Kandemir
|
2020-01-01
|
|
IBM InfoPrint 4247-Z03 Impact Matrix Printer - Directory Traversal
|
1 |
WEB
|
Raif Berkay Dincel
|
2020-01-01
|
|
Shopping Portal ProVersion 3.0 - Authentication Bypass
|
2 |
WEB
|
Metin Yunus Kandemir
|
2019-12-31
|
|
WordPress Plugin Ultimate Addons for Beaver Builder 1.2.4.1 - Authentication Bypass
|
1 |
WEB
|
Raphael Karger
|
2019-12-30
|
|
Heatmiser Netmonitor 3.03 - HTML Injection
|
1 |
WEB
|
Ismail Tasdelen
|
2019-12-30
|
|
RICOH Web Image Monitor 1.09 - HTML Injection
|
1 |
WEB
|
Ismail Tasdelen
|
2019-12-30
|
|
RICOH SP 4510SF Printer - HTML Injection
|
1 |
WEB
|
Ismail Tasdelen
|
2019-12-30
|
|
MyDomoAtHome REST API Domoticz ISS Gateway 0.2.40 - Information Disclosure
|
1 |
WEB
|
LiquidWorm
|
2019-12-30
|
|
Heatmiser Netmonitor 3.03 - Hardcoded Credentials
|
2 |
WEB
|
Ismail Tasdelen
|
2019-12-30
|
|
AVE DOMINAplus 1.10.x - Authentication Bypass
|
2 |
WEB
|
LiquidWorm
|
2019-12-30
|
|
AVE DOMINAplus 1.10.x - Cross-Site Request Forgery (enable/disable alarm)
|
2 |
WEB
|
LiquidWorm
|