2019-11-12
|
|
eMerge E3 1.00-06 - Privilege Escalation
|
3 |
WEB
|
LiquidWorm
|
2019-11-12
|
|
eMerge E3 1.00-06 - Unauthenticated Directory Traversal
|
3 |
WEB
|
LiquidWorm
|
2019-11-12
|
|
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
|
3 |
WEB
|
LiquidWorm
|
2019-11-12
|
|
Adrenalin Core HCM 5.4.0 - 'prntDDLCntrlName' Reflected Cross-Site Scripting
|
2 |
WEB
|
Cy83rl0gger
|
2019-11-12
|
|
Prima FlexAir Access Control 2.3.38 - Remote Code Execution
|
2 |
WEB
|
LiquidWorm
|
2019-11-12
|
|
Adrenalin Core HCM 5.4.0 - 'strAction' Reflected Cross-Site Scripting
|
3 |
WEB
|
Cy83rl0gger
|
2019-11-08
|
|
Nextcloud 17 - Cross-Site Request Forgery
|
3 |
WEB
|
Ozer Goker
|
2019-11-08
|
|
Adive Framework 2.0.7 - Privilege Escalation
|
3 |
WEB
|
Pablo Santiago
|
2019-11-08
|
|
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
|
3 |
WEB
|
vesche
|
2019-11-06
|
|
Smartwares HOME easy 1.0.9 - Database Backup Information Disclosure
|
3 |
WEB
|
LiquidWorm
|
2019-11-06
|
|
Smartwares HOME easy 1.0.9 - Client-Side Authentication Bypass
|
3 |
WEB
|
LiquidWorm
|
2019-11-05
|
|
SD.NET RIM 4.7.3c - 'idtyp' SQL Injection
|
2 |
WEB
|
Fabian Mosch_ Nick Theisinger
|
2019-11-05
|
|
html5_snmp 1.11 - 'Router_ID' SQL Injection
|
3 |
WEB
|
cakes
|
2019-11-05
|
|
html5_snmp 1.11 - 'Remark' Persistent Cross-Site Scripting
|
3 |
WEB
|
cakes
|
2019-11-05
|
|
rimbalinux AhadPOS 1.11 - 'alamatCustomer' SQL Injection
|
2 |
WEB
|
cakes
|
2019-11-05
|
|
thrsrossi Millhouse-Project 1.414 - 'content' Persistent Cross-Site Scripting
|
4 |
WEB
|
cakes
|
2019-11-05
|
|
thejshen Globitek CMS 1.4 - 'id' SQL Injection
|
3 |
WEB
|
cakes
|
2019-11-01
|
|
Apache Solr 8.2.0 - Remote Code Execution
|
2 |
WEB
|
@l3x_wong
|
2019-11-01
|
|
ownCloud 10.3.0 stable - Cross-Site Request Forgery
|
2 |
WEB
|
Ozer Goker
|
2019-11-01
|
|
TheJshen contentManagementSystem 1.04 - 'id' SQL Injection
|
3 |
WEB
|
cakes
|
2019-10-31
|
|
WordPress Plugin Google Review Slider 6.1 - 'tid' SQL Injection
|
3 |
WEB
|
Princy Edward
|
2019-10-30
|
|
iSeeQ Hybrid DVR WH-H4 2.0.0.P - (get_jpeg) Stream Disclosure
|
3 |
WEB
|
LiquidWorm
|
2019-10-30
|
|
Citrix StoreFront Server 7.15 - XML External Entity Injection
|
3 |
WEB
|
Vahagn Vardanyan
|
2019-10-30
|
|
Ajenti 2.1.31 - Remote Code Exection (Metasploit)
|
3 |
WEB
|
Onur ER
|
2019-10-29
|
|
WordPress Core 5.2.4 - Cross-Origin Resource Sharing
|
3 |
WEB
|
Milad Khoshdel
|
2019-10-29
|
|
rConfig 3.9.2 - Remote Code Execution
|
3 |
WEB
|
Askar
|
2019-10-28
|
|
PHP-FPM + Nginx - Remote Code Execution
|
3 |
WEB
|
Emil Lerner
|
2019-10-28
|
|
delpino73 Blue-Smiley-Organizer 1.32 - 'datetime' SQL Injection
|
3 |
WEB
|
cakes
|
2019-10-28
|
|
waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'description' Cross-Site Scripting
|
3 |
WEB
|
cakes
|
2019-10-28
|
|
Part-DB 0.4 - Authentication Bypass
|
2 |
WEB
|
Marvoloo
|
2019-10-28
|
|
waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 - 'start' SQL Injection
|
2 |
WEB
|
cakes
|
2019-10-28
|
|
Intelbras Router WRN150 1.0.18 - Cross-Site Request Forgery
|
2 |
WEB
|
Prof. Joas Antonio
|
2019-10-25
|
|
ClonOs WEB UI 19.09 - Improper Access Control
|
2 |
WEB
|
İbrahim Hakan Şeker
|
2019-10-24
|
|
AUO SunVeillance Monitoring System 1.1.9e - 'MailAdd' SQL Injection
|
2 |
WEB
|
Luca.Chiou
|
2019-10-24
|
|
AUO SunVeillance Monitoring System 1.1.9e - Incorrect Access Control
|
1 |
WEB
|
Luca.Chiou
|
2019-10-24
|
|
WordPress Plugin Sliced Invoices 3.8.2 - 'post' SQL Injection
|
2 |
WEB
|
Lucian Ioan Nitescu
|
2019-10-23
|
|
Joomla! 3.4.6 - Remote Code Execution (Metasploit)
|
2 |
WEB
|
Alessandro Groppo
|
2019-10-23
|
|
Rocket.Chat 2.1.0 - Cross-Site Scripting
|
3 |
WEB
|
3H34N
|
2019-10-18
|
|
Joomla! 3.4.6 - Remote Code Execution
|
3 |
WEB
|
Alessandro Groppo
|
2019-10-17
|
|
Restaurant Management System 1.0 - Remote Code Execution
|
3 |
WEB
|
Ibad Shah
|
2019-10-17
|
|
WordPress Plugin Popup Builder 3.49 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Unk9vvN
|
2019-10-17
|
|
WordPress Plugin Soliloquy Lite 2.5.6 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Unk9vvN
|
2019-10-17
|
|
WordPress Plugin FooGallery 1.8.12 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Unk9vvN
|
2019-10-16
|
|
Accounts Accounting 7.02 - Persistent Cross-Site Scripting
|
5 |
WEB
|
Debashis Pal
|
2019-10-15
|
|
Bolt CMS 3.6.10 - Cross-Site Request Forgery
|
4 |
WEB
|
r3m0t3nu11
|
2019-10-14
|
|
Kirona-DRS 5.5.3.5 - Information Disclosure
|
5 |
WEB
|
Ramikan
|
2019-10-14
|
|
Ajenti 2.1.31 - Remote Code Execution
|
4 |
WEB
|
Jeremy Brown
|
2019-10-14
|
|
Express Invoice 7.12 - 'Customer' Persistent Cross-Site Scripting
|
4 |
WEB
|
Debashis Pal
|
2019-10-11
|
|
WordPress Plugin Arforms 3.7.1 - Directory Traversal
|
5 |
WEB
|
Ahmad Almorabea
|
2019-10-11
|
|
Intelbras Router WRN150 1.0.18 - Persistent Cross-Site Scripting
|
5 |
WEB
|
Prof. Joas Antonio
|
2019-10-10
|
|
TP-Link TL-WR1043ND 2 - Authentication Bypass
|
4 |
WEB
|
Uriel Kosayev
|
2019-10-10
|
|
SMA Solar Technology AG Sunny WebBox device - 1.6 - Cross-Site Request Forgery
|
5 |
WEB
|
Borja Merino
|
2019-10-07
|
|
vBulletin 5.0 < 5.5.4 - 'updateAvatar' Authenticated Remote Code Execution
|
4 |
WEB
|
EgiX
|
2019-10-08
|
|
Zabbix 4.4 - Authentication Bypass
|
3 |
WEB
|
Todor Donev
|
2019-10-07
|
|
IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload
|
3 |
WEB
|
Jakub Palaczynski
|
2019-10-07
|
|
Subrion 4.2.1 - 'Email' Persistant Cross-Site Scripting
|
4 |
WEB
|
Creatigon
|
2019-10-07
|
|
Zabbix 4.2 - Authentication Bypass
|
4 |
WEB
|
Milad Khoshdel
|
2019-10-07
|
|
Joomla! 3.4.6 - 'configuration.php' Remote Code Execution
|
5 |
WEB
|
Alessandro Groppo
|
2019-10-03
|
|
PHP 7.0 < 7.3 (Unix) - 'gc' disable_functions Bypass
|
4 |
WEB
|
mm0r1
|
2019-10-04
|
|
LabCollector 5.423 - SQL Injection
|
4 |
WEB
|
Carlos Avila
|
2019-10-03
|
|
AnchorCMS < 0.12.3a - Information Disclosure
|
6 |
WEB
|
Tijme Gommers
|
2019-10-03
|
|
mintinstall 7.9.9 - Code Execution
|
5 |
WEB
|
İbrahim Hakan Şeker
|
2019-10-02
|
|
Detrix EDMS 1.2.3.1505 - SQL Injection
|
3 |
WEB
|
Burov Konstantin
|
2019-10-01
|
|
DotNetNuke 9.3.2 - Cross-Site Scripting
|
6 |
WEB
|
Semen Alexandrovich Lyhin
|
2019-10-01
|
|
DotNetNuke < 9.4.0 - Cross-Site Scripting
|
4 |
WEB
|
MaYaSeVeN
|
2019-09-23
|
|
vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution
|
4 |
WEB
|
anonymous
|
2019-09-28
|
|
PHP 7.1 < 7.3 - 'json serializer' disable_functions Bypass
|
4 |
WEB
|
mm0r1
|
2019-09-30
|
|
WordPress Plugin ARforms 3.7.1 - Arbitrary File Deletion
|
4 |
WEB
|
Ahmad Almorabea
|
2019-09-30
|
|
TheSystem 1.0 - Command Injection
|
5 |
WEB
|
Sadik Cetin
|
2019-09-30
|
|
thesystem 1.0 - Cross-Site Scripting
|
5 |
WEB
|
Anıl Baran Yelken
|
2019-09-30
|
|
phpIPAM 1.4 - SQL Injection
|
4 |
WEB
|
Kevin Kirsche
|
2019-09-30
|
|
vBulletin 5.x - Remote Command Execution (Metasploit)
|
4 |
WEB
|
r00tpgp
|
2019-09-27
|
|
WordPress Theme Zoner Real Estate - 4.1.1 Persistent Cross-Site Scripting
|
4 |
WEB
|
m0ze
|
2019-09-27
|
|
V-SOL GPON/EPON OLT Platform 2.03 - Remote Privilege Escalation
|
5 |
WEB
|
LiquidWorm
|
2019-09-27
|
|
V-SOL GPON/EPON OLT Platform 2.03 - Cross-Site Request Forgery
|
5 |
WEB
|
LiquidWorm
|
2019-09-27
|
|
V-SOL GPON/EPON OLT Platform 2.03 - Unauthenticated Configuration Download
|
4 |
WEB
|
LiquidWorm
|
2019-09-27
|
|
thesystem App 1.0 - 'username' SQL Injection
|
4 |
WEB
|
Anıl Baran Yelken
|
2019-09-27
|
|
thesystem App 1.0 - Persistent Cross-Site Scripting
|
4 |
WEB
|
İsmail Güngör
|
2019-09-27
|
|
thesystem App 1.0 - 'server_name' SQL Injection
|
4 |
WEB
|
Sadik Cetin
|
2019-09-27
|
|
InoERP 0.7.2 - Persistent Cross-Site Scripting
|
3 |
WEB
|
strider
|
2019-09-26
|
|
citecodecrashers Pic-A-Point 1.1 - 'Consignment' SQL Injection
|
4 |
WEB
|
cakes
|
2019-09-26
|
|
inoERP 4.15 - 'download' SQL Injection
|
4 |
WEB
|
Semen Alexandrovich Lyhin
|
2019-09-26
|
|
all-in-one-seo-pack 3.2.7 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Unk9vvN
|
2019-09-26
|
|
Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting
|
5 |
WEB
|
Unk9vvN
|
2019-09-26
|
|
Chamillo LMS 1.11.8 - Arbitrary File Upload
|
4 |
WEB
|
Sohel Yousef
|
2019-09-25
|
|
YzmCMS 5.3 - 'Host' Header Injection
|
4 |
WEB
|
Debashis Pal
|
2019-09-25
|
|
NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution
|
4 |
WEB
|
Semen Alexandrovich Lyhin
|
2019-09-25
|
|
WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting
|
5 |
WEB
|
strider
|
2019-09-25
|
|
Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting
|
4 |
WEB
|
Davide Cioccia
|
2019-09-24
|
|
Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
|
5 |
WEB
|
Nassim Asrir
|
2019-09-23
|
|
Gila CMS < 1.11.1 - Local File Inclusion
|
5 |
WEB
|
Sainadh Jamalpur
|
2019-09-20
|
|
LayerBB < 1.1.4 - Cross-Site Request Forgery
|
4 |
WEB
|
0xB9
|
2019-09-19
|
|
GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting
|
4 |
WEB
|
cakes
|
2019-09-19
|
|
DIGIT CENTRIS 4 ERP - 'datum1' SQL Injection
|
4 |
WEB
|
n1x_
|
2019-09-19
|
|
Western Digital My Book World II NAS 1.02.12 - Authentication Bypass / Command Execution
|
4 |
WEB
|
Noman Riffat
|
2019-09-18
|
|
Hospital-Management 1.26 - 'fname' SQL Injection
|
3 |
WEB
|
cakes
|
2019-09-16
|
|
CollegeManagementSystem-CMS 1.3 - 'batch' SQL Injection
|
3 |
WEB
|
cakes
|
2019-09-16
|
|
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
|
5 |
WEB
|
Pankaj Kumar Thakur
|
2019-09-16
|
|
NetGain EM Plus 10.1.68 - Remote Command Execution
|
4 |
WEB
|
azams
|
2019-09-14
|
|
College-Management-System 1.2 - Authentication Bypass
|
4 |
WEB
|
cakes
|
2019-09-14
|
|
Ticket-Booking 1.4 - Authentication Bypass
|
4 |
WEB
|
cakes
|
2019-09-13
|
|
LimeSurvey 3.17.13 - Cross-Site Scripting
|
4 |
WEB
|
SEC Consult
|
2019-09-13
|
|
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
|
4 |
WEB
|
Manuel García Cárdenas
|
2019-09-13
|
|
Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
|
5 |
WEB
|
Metin Yunus Kandemir
|
2019-09-11
|
|
eWON Flexy - Authentication Bypass
|
5 |
WEB
|
Photubias
|
2019-09-11
|
|
AVCON6 systems management platform - OGNL Remote Command Execution
|
6 |
WEB
|
Nassim Asrir
|
2019-09-10
|
|
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2)
|
4 |
WEB
|
MTK
|
2019-09-10
|
|
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting
|
4 |
WEB
|
MTK
|
2019-09-10
|
|
WordPress Plugin Photo Gallery 1.5.34 - SQL Injection
|
3 |
WEB
|
MTK
|
2019-09-09
|
|
Dolibarr ERP-CRM 10.0.1 - SQL Injection
|
3 |
WEB
|
Metin Yunus Kandemir
|
2019-09-09
|
|
WordPress Plugin Sell Downloads 1.0.86 - Cross-Site Scripting
|
5 |
WEB
|
Mr Winst0n
|
2019-09-09
|
|
Rifatron Intelligent Digital Security System - 'animate.cgi' Stream Disclosure
|
4 |
WEB
|
LiquidWorm
|
2019-09-09
|
|
Online Appointment - SQL Injection
|
5 |
WEB
|
mohammad zaheri
|
2019-09-09
|
|
Enigma NMS 65.0.0 - SQL Injection
|
4 |
WEB
|
xerubus
|
2019-09-09
|
|
Enigma NMS 65.0.0 - OS Command Injection
|
4 |
WEB
|
xerubus
|
2019-09-09
|
|
Enigma NMS 65.0.0 - Cross-Site Request Forgery
|
5 |
WEB
|
xerubus
|
2019-09-09
|
|
Dolibarr ERP-CRM 10.0.1 - 'elemid' SQL Injection
|
4 |
WEB
|
Metin Yunus Kandemir
|
2019-09-09
|
|
WordPress Core 5.2.3 - Cross-Site Host Modification
|
4 |
WEB
|
Todor Donev
|
2019-09-06
|
|
Publisure Hybrid - Multiple Vulnerabilities
|
4 |
WEB
|
Jean-Marie Bourbon
|
2019-09-06
|
|
Inventory Webapp - 'itemquery' SQL injection
|
4 |
WEB
|
mohammad zaheri
|
2019-09-04
|
|
DASAN Zhone ZNID GPON 2426A EU - Multiple Cross-Site Scripting
|
4 |
WEB
|
Adam Ziaja
|
2019-09-04
|
|
WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting
|
4 |
WEB
|
MgThuraMoeMyint
|
2019-09-03
|
|
FileThingie 2.5.7 - Arbitrary File Upload
|
4 |
WEB
|
cakes
|
2019-09-02
|
|
Craft CMS 2.7.9/3.2.5 - Information Disclosure
|
5 |
WEB
|
Mohammed Abdul Raheem
|
2019-09-02
|
|
Wolters Kluwer TeamMate 3.1 - Cross-Site Request Forgery
|
5 |
WEB
|
Bhadresh Patel
|