Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2019-06-25   AZADMIN CMS 1.0 - SQL Injection 4 WEB felipe andrian
2019-06-25   Fortinet FCM-MB40 - Cross-Site Request Forgery / Remote Command Execution 4 WEB XORcat
2019-06-24   GrandNode 4.40 - Path Traversal / Arbitrary File Download 5 WEB Corey Robinson
2019-06-24   SeedDMS < 5.1.11 - 'out.GroupMgr.php' Cross-Site Scripting 3 WEB Nimit Jain
2019-06-24   SeedDMS < 5.1.11 - 'out.UsrMgr.php' Cross-Site Scripting 4 WEB Nimit Jain
2019-06-24   SeedDMS versions < 5.1.11 - Remote Command Execution 4 WEB Nimit Jain
2019-06-24   dotProject 2.1.9 - SQL Injection 4 WEB Metin Yunus Kandemir
2019-06-20   BlogEngine.NET 3.3.6/3.3.7 - XML External Entity Injection 4 WEB Aaron Bishop
2019-06-20   WebERP 4.15 - SQL injection 4 WEB Semen Alexandrovich Lyhin
2019-06-19   BlogEngine.NET 3.3.6/3.3.7 - 'theme Cookie' Directory Traversal / Remote Code Execution 4 WEB Aaron Bishop
2019-06-19   BlogEngine.NET 3.3.6/3.3.7 - 'dirPath' Directory Traversal / Remote Code Execution 4 WEB Aaron Bishop
2019-06-18   Sahi pro 8.x - Cross-Site Scripting 3 WEB Goutham Madhwaraj
2019-06-18   Sahi pro 8.x - SQL Injection 4 WEB Goutham Madhwaraj
2019-06-18   Sahi pro 7.x/8.x - Directory Traversal 4 WEB Goutham Madhwaraj
2019-06-17   Spring Security OAuth - Open Redirector 5 WEB Riemann
2019-06-17   CleverDog Smart Camera DOG-2W / DOG-2W-V4 - Multiple Vulnerabilities 3 WEB Alex Akinbi
2019-06-17   RedwoodHQ 2.5.5 - Authentication Bypass 4 WEB EthicalHCOP
2019-06-13   Sitecore 8.x - Deserialization Remote Code Execution 3 WEB Jarad Kopf
2019-06-12   FusionPBX 4.4.3 - Remote Command Execution 3 WEB Dustin Cobb
2019-06-11   Liferay Portal 7.1 CE GA=3 / SimpleCaptcha API - Cross-Site Scripting 3 WEB Valerio Brussani
2019-06-11   phpMyAdmin 4.8 - Cross-Site Request Forgery 3 WEB Riemann
2019-06-11   WordPress Plugin Insert or Embed Articulate Content into WordPress - Remote Code Execution 3 WEB xulchibalraa
2019-06-10   UliCMS 2019.1 'Spitting Lama' - Persistent Cross-Site Scripting 3 WEB Unk9vvN
2019-06-06   Supra Smart Cloud TV - 'openLiveURL()' Remote File Inclusion 3 WEB Dhiraj Mishra
2019-06-05   Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery 3 WEB k8gege
2019-06-05   Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery 3 WEB k8gege
2019-06-04   Zoho ManageEngine ServiceDesk Plus 9.3 - 'PurchaseRequest.do' Cross-Site Scripting 2 WEB Vingroup
2019-06-04   Zoho ManageEngine ServiceDesk Plus 9.3 - 'SearchN.do' Cross-Site Scripting 3 WEB Vingroup
2019-06-04   Zoho ManageEngine ServiceDesk Plus 9.3 - 'SolutionSearch.do' Cross-Site Scripting 3 WEB Vingroup
2019-06-04   Zoho ManageEngine ServiceDesk Plus 9.3 - 'SiteLookup.do' Cross-Site Scripting 2 WEB Vingroup
2019-06-04   IceWarp 10.4.4 - Local File Inclusion 3 WEB JameelNabbo
2019-06-03   WordPress Plugin Form Maker 1.13.3 - SQL Injection 2 WEB Daniele Scanu
2019-06-03   AUO Solar Data Recorder < 1.3.0 - Incorrect Access Control 3 WEB Luca.Chiou
2019-06-03   KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities 3 WEB SlidingWindow
2019-05-29   pfSense 2.4.4-p3 (ACME Package 0.59_14) - Persistent Cross-Site Scripting 2 WEB Chi Tran
2019-05-28   Phraseanet < 4.0.7 - Cross-Site Scripting 2 WEB Krzysztof Szulski
2019-05-27   Deltek Maconomy 2.2.5 - Local File Inclusion 4 WEB JameelNabbo
2019-05-23   Nagios XI 5.6.1 - SQL injection 2 WEB JameelNabbo
2019-05-22   Horde Webmail 5.2.22 - Multiple Vulnerabilities 2 WEB InfinitumIT
2019-05-22   Carel pCOWeb < B1.2.1 - Credentials Disclosure 2 WEB Luca.Chiou
2019-05-22   Carel pCOWeb < B1.2.1 - Cross-Site Scripting 3 WEB Luca.Chiou
2019-05-22   AUO Solar Data Recorder < 1.3.0 - 'addr' Cross-Site Scripting 2 WEB Luca.Chiou
2019-05-22   Zoho ManageEngine ServiceDesk Plus 9.3 - Cross-Site Scripting 2 WEB Vingroup
2019-05-22   Zoho ManageEngine ServiceDesk Plus < 10.5 - Improper Access Restrictions 3 WEB Vingroup
2019-05-21   Brocade Network Advisor 14.4.1 - Unauthenticated Remote Code Execution 3 WEB Jakub Palaczynski
2019-05-21   WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities 3 WEB Simone Quatrini
2019-05-21   Oracle CTI Web Service - 'EBS_ASSET_HISTORY_OPERATIONS' XML Entity Injection 3 WEB omurugur
2019-05-21   TP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting 3 WEB purnendu ghosh
2019-05-21   Moodle Jmol Filter 6.1 - Directory Traversal / Cross-Site Scripting 3 WEB Dionach Ltd
2019-05-21   Moodle Jmol Filter 6.1 - Directory Traversal / Cross-Site Scripting 2 WEB Dionach Ltd
2019-05-20   eLabFTW 1.8.5 - Arbitrary File Upload / Remote Code Execution 2 WEB liquidsky
2019-05-17   Interspire Email Marketer 6.20 - 'surveys_submit.php' Remote Code Execution 2 WEB numan türle
2019-05-16   DeepSound 1.0.4 - SQL Injection 3 WEB Mehmet EMIROGLU
2019-05-15   Legrand BTicino Driver Manager F454 1.0.51 - Cross-Site Request Forgery / Cross-Site Scripting 3 WEB LiquidWorm
2019-05-15   Legrand BTicino Driver Manager F454 1.0.51 - Cross-Site Request Forgery / Cross-Site Scripting 3 WEB LiquidWorm
2019-05-15   CommSy 8.6.5 - SQL injection 3 WEB Jens Regel
2019-05-14   PasteShr 1.6 - Multiple SQL Injection 3 WEB Mehmet EMIROGLU
2019-05-14   Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Comm 3 WEB Julien Ahrens
2019-05-14   D-Link DWL-2600AP - Multiple OS Command Injection 3 WEB Raki Ben Hamouda
2019-05-14   Sales ERP 8.1 - Multiple SQL Injection 3 WEB Mehmet EMIROGLU
2019-05-13   OpenProject 5.0.0 - 8.3.1 - SQL Injection 3 WEB SEC Consult
2019-05-13   XOOPS 2.5.9 - SQL Injection 3 WEB felipe andrian
2019-05-13   SOCA Access Control System 180612 - Cross-Site Request Forgery (Add Admin) 3 WEB LiquidWorm
2019-05-13   SOCA Access Control System 180612 - SQL Injection 3 WEB LiquidWorm
2019-05-13   SOCA Access Control System 180612 - Information Disclosure 3 WEB LiquidWorm
2019-05-10   CyberArk Enterprise Password Vault 10.7 - XML External Entity Injection 3 WEB Marcelo Toran
2019-05-10   RICOH SP 4520DN Printer - HTML Injection 4 WEB Ismail Tasdelen
2019-05-10   RICOH SP 4510DN Printer - HTML Injection 4 WEB Ismail Tasdelen
2019-05-10   dotCMS 5.1.1 - HTML Injection 4 WEB Ismail Tasdelen
2019-05-10   Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery 4 WEB Alexandre Basquin
2019-05-09   Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting 4 WEB Ibrahim Raafat
2019-05-08   NetNumber Titan ENUM/DNS/NP 7.9.1 - Path Traversal / Authorization Bypass 4 WEB MobileNetworkSecurity
2019-05-07   Prinect Archive System 2015 Release 2.6 - Cross-Site Scripting 4 WEB alt3kx
2019-05-06   microASP (Portal+) CMS - 'pagina.phtml?explode_tree' SQL Injection 3 WEB felipe andrian
2019-05-06   PHPads 2.0 - 'click.php3?bannerID' SQL Injection 4 WEB felipe andrian
2019-05-06   ReadyAPI 2.5.0 / 2.6.0 - Remote Code Execution 4 WEB Gilson Camelo
2019-05-03   WordPress Plugin Social Warfare < 3.5.3 - Remote Code Execution 4 WEB hash3liZer
2019-05-03   Zotonic < 0.47.0 mod_admin - Cross-Site Scripting 3 WEB Ramòn Janssen
2019-05-03   Instagram Auto Follow - Authentication Bypass 4 WEB Veyselxan
2019-05-03   Crestron AM/Barco wePresent WiPG/Extron ShareLink/Teq AV IT/SHARP PN-L703WA/Optoma WPS-Pro/Blackbox 4 WEB Jacob Baines
2019-05-01   CentOS Web Panel 0.9.8.793 (Free) / v0.9.8.753 (Pro) / 0.9.8.807 (Pro) - Domain Field (Add DNS Zone) 3 WEB DKM
2019-04-30   Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 - Remote Code Execution 3 WEB Avinash Kumar Thapa
2019-04-30   Agent Tesla Botnet - Information Disclosure 2 WEB n4pst3r
2019-04-30   Hyvikk Fleet Manager - Shell Upload 2 WEB saxgy1331
2019-04-30   Joomla! Component JiFile 2.3.1 - Arbitrary File Download 3 WEB Mr Winst0n
2019-04-30   Domoticz 4.10577 - Unauthenticated Remote Command Execution 2 WEB Fabio Carretto
2019-04-30   Spring Cloud Config 2.1.x - Path Traversal (Metasploit) 2 WEB Dhiraj Mishra
2019-04-30   Spring Cloud Config 2.1.x - Path Traversal (Metasploit) 3 WEB Dhiraj Mishra
2019-04-30   HumHub 1.3.12 - Cross-Site Scripting 3 WEB Kağan EĞLENCE
2019-04-30   Intelbras IWR 3000N 1.5.0 - Cross-Site Request Forgery 3 WEB Social Engineering Neo
2019-04-30   Joomla! Component ARI Quiz 3.7.4 - SQL Injection 2 WEB Mr Winst0n
2019-04-30   Veeam ONE Reporter 9.5.0.3201 - Persistent Cross-site Scripting (Add/Edit Widget) 3 WEB Seyed Sadegh Khatami
2019-04-30   Veeam ONE Reporter 9.5.0.3201 - Persistent Cross-Site Scripting 3 WEB Seyed Sadegh Khatami
2019-04-30   Veeam ONE Reporter 9.5.0.3201 - Multiple Cross-Site Request Forgery 3 WEB Seyed Sadegh Khatami
2019-04-30   Netgear DGN2200 / DGND3700 - Admin Password Disclosure 3 WEB Social Engineering Neo
2019-04-26   Apache Pluto 3.0.0 / 3.0.1 - Persistent Cross-Site Scripting 3 WEB Dhiraj Mishra
2019-04-25   osTicket 1.11 - Cross-Site Scripting / Local File Inclusion 3 WEB AkkuS
2019-04-25   osTicket 1.11 - Cross-Site Scripting / Local File Inclusion 3 WEB AkkuS
2019-04-25   JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting 3 WEB Vikas Chaudhary
2019-04-22   UliCMS 2019.2 / 2019.1 - Multiple Cross-Site Scripting 3 WEB Kağan EĞLENCE
2019-04-22   Msvod 10 - Cross-Site Request Forgery (Change User Information) 3 WEB ax8
2019-04-22   74CMS 5.0.1 - Cross-Site Request Forgery (Add New Admin User) 3 WEB ax8
2019-04-22   WordPress Plugin Contact Form Builder 1.0.67 - Cross-Site Request Forgery / Local File Inclusion 3 WEB Panagiotis Vagenas
2019-04-22   WordPress Plugin Contact Form Builder 1.0.67 - Cross-Site Request Forgery / Local File Inclusion 3 WEB Panagiotis Vagenas
2019-04-19   Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Ent 1 WEB Vahagn Vardanyan
2019-04-19   Oracle Business Intelligence 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - Directory Traversal 3 WEB Vahagn Vardanyan
2019-04-16   Joomla! Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion 3 WEB Haboob Team
2019-04-16   Zyxel ZyWall 310 / ZyWall 110 / USG1900 / ATP500 / USG40 - Login Page Cross-Site Scripting 3 WEB Aaron Bishop
2019-04-15   DirectAdmin 1.561 - Multiple Vulnerabilities 3 WEB InfinitumIT
2019-04-12   ATutor < 2.2.4 - 'file_manager' Remote Code Execution (Metasploit) 3 WEB AkkuS
2019-04-10   D-Link DI-524 V2.06RU - Multiple Cross-Site Scripting 3 WEB Semen Alexandrovich Lyhin
2019-04-10   Dell KACE Systems Management Appliance (K1000) 6.4.120756 - Unauthenticated Remote Code Execution 3 WEB Julien Ahrens
2019-04-09   Ashop Shopping Cart Software - 'bannedcustomers.php?blacklistitemid' SQL Injection 2 WEB Doğukan Karaciğer
2019-04-08   ManageEngine ServiceDesk Plus 9.3 - User Enumeration 3 WEB Operat0r
2019-04-08   WordPress Plugin Limit Login Attempts Reloaded 2.7.4 - Login Limit Bypass 3 WEB isdampe
2019-04-08   Tradebox CryptoCurrency - 'symbol' SQL Injection 3 WEB Abdullah Çelebi
2019-04-08   CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) - Cross-Site Scripting 3 WEB DKM
2019-04-08   SaLICru -SLC-20-cube3(5) - HTML Injection 3 WEB Ramikan
2019-04-08   ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities 3 WEB Ramikan
2019-04-08   Bolt CMS 3.6.6 - Cross-Site Request Forgery / Remote Code Execution 3 WEB FelipeGaspar
2019-04-08   Jobgator - 'experience' SQL Injection 3 WEB Ahmet Ümit BAYRAM
2019-04-05   WordPress Plugin Contact Form Maker 1.13.1 - Cross-Site Request Forgery 3 WEB Peyman Forouzan
2019-04-05   Manage Engine ServiceDesk Plus 10.0 - Privilege Escalation 2 WEB Ata Hakçıl_ Melih Kaan Yıldız
2019-04-04   FreeSMS 2.1.2 - SQL Injection (Authentication Bypass) 3 WEB Yilmaz Degirmenci
2019-04-03   PhreeBooks ERP 5.2.3 - Arbitrary File Upload 3 WEB Abdullah Çelebi