2019-06-25
|
|
AZADMIN CMS 1.0 - SQL Injection
|
4 |
WEB
|
felipe andrian
|
2019-06-25
|
|
Fortinet FCM-MB40 - Cross-Site Request Forgery / Remote Command Execution
|
4 |
WEB
|
XORcat
|
2019-06-24
|
|
GrandNode 4.40 - Path Traversal / Arbitrary File Download
|
5 |
WEB
|
Corey Robinson
|
2019-06-24
|
|
SeedDMS < 5.1.11 - 'out.GroupMgr.php' Cross-Site Scripting
|
3 |
WEB
|
Nimit Jain
|
2019-06-24
|
|
SeedDMS < 5.1.11 - 'out.UsrMgr.php' Cross-Site Scripting
|
4 |
WEB
|
Nimit Jain
|
2019-06-24
|
|
SeedDMS versions < 5.1.11 - Remote Command Execution
|
4 |
WEB
|
Nimit Jain
|
2019-06-24
|
|
dotProject 2.1.9 - SQL Injection
|
4 |
WEB
|
Metin Yunus Kandemir
|
2019-06-20
|
|
BlogEngine.NET 3.3.6/3.3.7 - XML External Entity Injection
|
4 |
WEB
|
Aaron Bishop
|
2019-06-20
|
|
WebERP 4.15 - SQL injection
|
4 |
WEB
|
Semen Alexandrovich Lyhin
|
2019-06-19
|
|
BlogEngine.NET 3.3.6/3.3.7 - 'theme Cookie' Directory Traversal / Remote Code Execution
|
4 |
WEB
|
Aaron Bishop
|
2019-06-19
|
|
BlogEngine.NET 3.3.6/3.3.7 - 'dirPath' Directory Traversal / Remote Code Execution
|
4 |
WEB
|
Aaron Bishop
|
2019-06-18
|
|
Sahi pro 8.x - Cross-Site Scripting
|
3 |
WEB
|
Goutham Madhwaraj
|
2019-06-18
|
|
Sahi pro 8.x - SQL Injection
|
4 |
WEB
|
Goutham Madhwaraj
|
2019-06-18
|
|
Sahi pro 7.x/8.x - Directory Traversal
|
4 |
WEB
|
Goutham Madhwaraj
|
2019-06-17
|
|
Spring Security OAuth - Open Redirector
|
5 |
WEB
|
Riemann
|
2019-06-17
|
|
CleverDog Smart Camera DOG-2W / DOG-2W-V4 - Multiple Vulnerabilities
|
3 |
WEB
|
Alex Akinbi
|
2019-06-17
|
|
RedwoodHQ 2.5.5 - Authentication Bypass
|
4 |
WEB
|
EthicalHCOP
|
2019-06-13
|
|
Sitecore 8.x - Deserialization Remote Code Execution
|
3 |
WEB
|
Jarad Kopf
|
2019-06-12
|
|
FusionPBX 4.4.3 - Remote Command Execution
|
3 |
WEB
|
Dustin Cobb
|
2019-06-11
|
|
Liferay Portal 7.1 CE GA=3 / SimpleCaptcha API - Cross-Site Scripting
|
3 |
WEB
|
Valerio Brussani
|
2019-06-11
|
|
phpMyAdmin 4.8 - Cross-Site Request Forgery
|
3 |
WEB
|
Riemann
|
2019-06-11
|
|
WordPress Plugin Insert or Embed Articulate Content into WordPress - Remote Code Execution
|
3 |
WEB
|
xulchibalraa
|
2019-06-10
|
|
UliCMS 2019.1 'Spitting Lama' - Persistent Cross-Site Scripting
|
3 |
WEB
|
Unk9vvN
|
2019-06-06
|
|
Supra Smart Cloud TV - 'openLiveURL()' Remote File Inclusion
|
3 |
WEB
|
Dhiraj Mishra
|
2019-06-05
|
|
Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery
|
3 |
WEB
|
k8gege
|
2019-06-05
|
|
Zimbra < 8.8.11 - XML External Entity Injection / Server-Side Request Forgery
|
3 |
WEB
|
k8gege
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'PurchaseRequest.do' Cross-Site Scripting
|
2 |
WEB
|
Vingroup
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SearchN.do' Cross-Site Scripting
|
3 |
WEB
|
Vingroup
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SolutionSearch.do' Cross-Site Scripting
|
3 |
WEB
|
Vingroup
|
2019-06-04
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - 'SiteLookup.do' Cross-Site Scripting
|
2 |
WEB
|
Vingroup
|
2019-06-04
|
|
IceWarp 10.4.4 - Local File Inclusion
|
3 |
WEB
|
JameelNabbo
|
2019-06-03
|
|
WordPress Plugin Form Maker 1.13.3 - SQL Injection
|
2 |
WEB
|
Daniele Scanu
|
2019-06-03
|
|
AUO Solar Data Recorder < 1.3.0 - Incorrect Access Control
|
3 |
WEB
|
Luca.Chiou
|
2019-06-03
|
|
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
|
3 |
WEB
|
SlidingWindow
|
2019-05-29
|
|
pfSense 2.4.4-p3 (ACME Package 0.59_14) - Persistent Cross-Site Scripting
|
2 |
WEB
|
Chi Tran
|
2019-05-28
|
|
Phraseanet < 4.0.7 - Cross-Site Scripting
|
2 |
WEB
|
Krzysztof Szulski
|
2019-05-27
|
|
Deltek Maconomy 2.2.5 - Local File Inclusion
|
4 |
WEB
|
JameelNabbo
|
2019-05-23
|
|
Nagios XI 5.6.1 - SQL injection
|
2 |
WEB
|
JameelNabbo
|
2019-05-22
|
|
Horde Webmail 5.2.22 - Multiple Vulnerabilities
|
2 |
WEB
|
InfinitumIT
|
2019-05-22
|
|
Carel pCOWeb < B1.2.1 - Credentials Disclosure
|
2 |
WEB
|
Luca.Chiou
|
2019-05-22
|
|
Carel pCOWeb < B1.2.1 - Cross-Site Scripting
|
3 |
WEB
|
Luca.Chiou
|
2019-05-22
|
|
AUO Solar Data Recorder < 1.3.0 - 'addr' Cross-Site Scripting
|
2 |
WEB
|
Luca.Chiou
|
2019-05-22
|
|
Zoho ManageEngine ServiceDesk Plus 9.3 - Cross-Site Scripting
|
2 |
WEB
|
Vingroup
|
2019-05-22
|
|
Zoho ManageEngine ServiceDesk Plus < 10.5 - Improper Access Restrictions
|
3 |
WEB
|
Vingroup
|
2019-05-21
|
|
Brocade Network Advisor 14.4.1 - Unauthenticated Remote Code Execution
|
3 |
WEB
|
Jakub Palaczynski
|
2019-05-21
|
|
WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities
|
3 |
WEB
|
Simone Quatrini
|
2019-05-21
|
|
Oracle CTI Web Service - 'EBS_ASSET_HISTORY_OPERATIONS' XML Entity Injection
|
3 |
WEB
|
omurugur
|
2019-05-21
|
|
TP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting
|
3 |
WEB
|
purnendu ghosh
|
2019-05-21
|
|
Moodle Jmol Filter 6.1 - Directory Traversal / Cross-Site Scripting
|
3 |
WEB
|
Dionach Ltd
|
2019-05-21
|
|
Moodle Jmol Filter 6.1 - Directory Traversal / Cross-Site Scripting
|
2 |
WEB
|
Dionach Ltd
|
2019-05-20
|
|
eLabFTW 1.8.5 - Arbitrary File Upload / Remote Code Execution
|
2 |
WEB
|
liquidsky
|
2019-05-17
|
|
Interspire Email Marketer 6.20 - 'surveys_submit.php' Remote Code Execution
|
2 |
WEB
|
numan türle
|
2019-05-16
|
|
DeepSound 1.0.4 - SQL Injection
|
3 |
WEB
|
Mehmet EMIROGLU
|
2019-05-15
|
|
Legrand BTicino Driver Manager F454 1.0.51 - Cross-Site Request Forgery / Cross-Site Scripting
|
3 |
WEB
|
LiquidWorm
|
2019-05-15
|
|
Legrand BTicino Driver Manager F454 1.0.51 - Cross-Site Request Forgery / Cross-Site Scripting
|
3 |
WEB
|
LiquidWorm
|
2019-05-15
|
|
CommSy 8.6.5 - SQL injection
|
3 |
WEB
|
Jens Regel
|
2019-05-14
|
|
PasteShr 1.6 - Multiple SQL Injection
|
3 |
WEB
|
Mehmet EMIROGLU
|
2019-05-14
|
|
Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Comm
|
3 |
WEB
|
Julien Ahrens
|
2019-05-14
|
|
D-Link DWL-2600AP - Multiple OS Command Injection
|
3 |
WEB
|
Raki Ben Hamouda
|
2019-05-14
|
|
Sales ERP 8.1 - Multiple SQL Injection
|
3 |
WEB
|
Mehmet EMIROGLU
|
2019-05-13
|
|
OpenProject 5.0.0 - 8.3.1 - SQL Injection
|
3 |
WEB
|
SEC Consult
|
2019-05-13
|
|
XOOPS 2.5.9 - SQL Injection
|
3 |
WEB
|
felipe andrian
|
2019-05-13
|
|
SOCA Access Control System 180612 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
LiquidWorm
|
2019-05-13
|
|
SOCA Access Control System 180612 - SQL Injection
|
3 |
WEB
|
LiquidWorm
|
2019-05-13
|
|
SOCA Access Control System 180612 - Information Disclosure
|
3 |
WEB
|
LiquidWorm
|
2019-05-10
|
|
CyberArk Enterprise Password Vault 10.7 - XML External Entity Injection
|
3 |
WEB
|
Marcelo Toran
|
2019-05-10
|
|
RICOH SP 4520DN Printer - HTML Injection
|
4 |
WEB
|
Ismail Tasdelen
|
2019-05-10
|
|
RICOH SP 4510DN Printer - HTML Injection
|
4 |
WEB
|
Ismail Tasdelen
|
2019-05-10
|
|
dotCMS 5.1.1 - HTML Injection
|
4 |
WEB
|
Ismail Tasdelen
|
2019-05-10
|
|
Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
|
4 |
WEB
|
Alexandre Basquin
|
2019-05-09
|
|
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting
|
4 |
WEB
|
Ibrahim Raafat
|
2019-05-08
|
|
NetNumber Titan ENUM/DNS/NP 7.9.1 - Path Traversal / Authorization Bypass
|
4 |
WEB
|
MobileNetworkSecurity
|
2019-05-07
|
|
Prinect Archive System 2015 Release 2.6 - Cross-Site Scripting
|
4 |
WEB
|
alt3kx
|
2019-05-06
|
|
microASP (Portal+) CMS - 'pagina.phtml?explode_tree' SQL Injection
|
3 |
WEB
|
felipe andrian
|
2019-05-06
|
|
PHPads 2.0 - 'click.php3?bannerID' SQL Injection
|
4 |
WEB
|
felipe andrian
|
2019-05-06
|
|
ReadyAPI 2.5.0 / 2.6.0 - Remote Code Execution
|
4 |
WEB
|
Gilson Camelo
|
2019-05-03
|
|
WordPress Plugin Social Warfare < 3.5.3 - Remote Code Execution
|
4 |
WEB
|
hash3liZer
|
2019-05-03
|
|
Zotonic < 0.47.0 mod_admin - Cross-Site Scripting
|
3 |
WEB
|
Ramòn Janssen
|
2019-05-03
|
|
Instagram Auto Follow - Authentication Bypass
|
4 |
WEB
|
Veyselxan
|
2019-05-03
|
|
Crestron AM/Barco wePresent WiPG/Extron ShareLink/Teq AV IT/SHARP PN-L703WA/Optoma WPS-Pro/Blackbox
|
4 |
WEB
|
Jacob Baines
|
2019-05-01
|
|
CentOS Web Panel 0.9.8.793 (Free) / v0.9.8.753 (Pro) / 0.9.8.807 (Pro) - Domain Field (Add DNS Zone)
|
3 |
WEB
|
DKM
|
2019-04-30
|
|
Oracle Weblogic 10.3.6.0.0 / 12.1.3.0.0 - Remote Code Execution
|
3 |
WEB
|
Avinash Kumar Thapa
|
2019-04-30
|
|
Agent Tesla Botnet - Information Disclosure
|
2 |
WEB
|
n4pst3r
|
2019-04-30
|
|
Hyvikk Fleet Manager - Shell Upload
|
2 |
WEB
|
saxgy1331
|
2019-04-30
|
|
Joomla! Component JiFile 2.3.1 - Arbitrary File Download
|
3 |
WEB
|
Mr Winst0n
|
2019-04-30
|
|
Domoticz 4.10577 - Unauthenticated Remote Command Execution
|
2 |
WEB
|
Fabio Carretto
|
2019-04-30
|
|
Spring Cloud Config 2.1.x - Path Traversal (Metasploit)
|
2 |
WEB
|
Dhiraj Mishra
|
2019-04-30
|
|
Spring Cloud Config 2.1.x - Path Traversal (Metasploit)
|
3 |
WEB
|
Dhiraj Mishra
|
2019-04-30
|
|
HumHub 1.3.12 - Cross-Site Scripting
|
3 |
WEB
|
Kağan EĞLENCE
|
2019-04-30
|
|
Intelbras IWR 3000N 1.5.0 - Cross-Site Request Forgery
|
3 |
WEB
|
Social Engineering Neo
|
2019-04-30
|
|
Joomla! Component ARI Quiz 3.7.4 - SQL Injection
|
2 |
WEB
|
Mr Winst0n
|
2019-04-30
|
|
Veeam ONE Reporter 9.5.0.3201 - Persistent Cross-site Scripting (Add/Edit Widget)
|
3 |
WEB
|
Seyed Sadegh Khatami
|
2019-04-30
|
|
Veeam ONE Reporter 9.5.0.3201 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Seyed Sadegh Khatami
|
2019-04-30
|
|
Veeam ONE Reporter 9.5.0.3201 - Multiple Cross-Site Request Forgery
|
3 |
WEB
|
Seyed Sadegh Khatami
|
2019-04-30
|
|
Netgear DGN2200 / DGND3700 - Admin Password Disclosure
|
3 |
WEB
|
Social Engineering Neo
|
2019-04-26
|
|
Apache Pluto 3.0.0 / 3.0.1 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Dhiraj Mishra
|
2019-04-25
|
|
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
|
3 |
WEB
|
AkkuS
|
2019-04-25
|
|
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
|
3 |
WEB
|
AkkuS
|
2019-04-25
|
|
JioFi 4G M2S 1.0.2 - 'mask' Cross-Site Scripting
|
3 |
WEB
|
Vikas Chaudhary
|
2019-04-22
|
|
UliCMS 2019.2 / 2019.1 - Multiple Cross-Site Scripting
|
3 |
WEB
|
Kağan EĞLENCE
|
2019-04-22
|
|
Msvod 10 - Cross-Site Request Forgery (Change User Information)
|
3 |
WEB
|
ax8
|
2019-04-22
|
|
74CMS 5.0.1 - Cross-Site Request Forgery (Add New Admin User)
|
3 |
WEB
|
ax8
|
2019-04-22
|
|
WordPress Plugin Contact Form Builder 1.0.67 - Cross-Site Request Forgery / Local File Inclusion
|
3 |
WEB
|
Panagiotis Vagenas
|
2019-04-22
|
|
WordPress Plugin Contact Form Builder 1.0.67 - Cross-Site Request Forgery / Local File Inclusion
|
3 |
WEB
|
Panagiotis Vagenas
|
2019-04-19
|
|
Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Ent
|
1 |
WEB
|
Vahagn Vardanyan
|
2019-04-19
|
|
Oracle Business Intelligence 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - Directory Traversal
|
3 |
WEB
|
Vahagn Vardanyan
|
2019-04-16
|
|
Joomla! Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion
|
3 |
WEB
|
Haboob Team
|
2019-04-16
|
|
Zyxel ZyWall 310 / ZyWall 110 / USG1900 / ATP500 / USG40 - Login Page Cross-Site Scripting
|
3 |
WEB
|
Aaron Bishop
|
2019-04-15
|
|
DirectAdmin 1.561 - Multiple Vulnerabilities
|
3 |
WEB
|
InfinitumIT
|
2019-04-12
|
|
ATutor < 2.2.4 - 'file_manager' Remote Code Execution (Metasploit)
|
3 |
WEB
|
AkkuS
|
2019-04-10
|
|
D-Link DI-524 V2.06RU - Multiple Cross-Site Scripting
|
3 |
WEB
|
Semen Alexandrovich Lyhin
|
2019-04-10
|
|
Dell KACE Systems Management Appliance (K1000) 6.4.120756 - Unauthenticated Remote Code Execution
|
3 |
WEB
|
Julien Ahrens
|
2019-04-09
|
|
Ashop Shopping Cart Software - 'bannedcustomers.php?blacklistitemid' SQL Injection
|
2 |
WEB
|
Doğukan Karaciğer
|
2019-04-08
|
|
ManageEngine ServiceDesk Plus 9.3 - User Enumeration
|
3 |
WEB
|
Operat0r
|
2019-04-08
|
|
WordPress Plugin Limit Login Attempts Reloaded 2.7.4 - Login Limit Bypass
|
3 |
WEB
|
isdampe
|
2019-04-08
|
|
Tradebox CryptoCurrency - 'symbol' SQL Injection
|
3 |
WEB
|
Abdullah Çelebi
|
2019-04-08
|
|
CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) - Cross-Site Scripting
|
3 |
WEB
|
DKM
|
2019-04-08
|
|
SaLICru -SLC-20-cube3(5) - HTML Injection
|
3 |
WEB
|
Ramikan
|
2019-04-08
|
|
ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities
|
3 |
WEB
|
Ramikan
|
2019-04-08
|
|
Bolt CMS 3.6.6 - Cross-Site Request Forgery / Remote Code Execution
|
3 |
WEB
|
FelipeGaspar
|
2019-04-08
|
|
Jobgator - 'experience' SQL Injection
|
3 |
WEB
|
Ahmet Ümit BAYRAM
|
2019-04-05
|
|
WordPress Plugin Contact Form Maker 1.13.1 - Cross-Site Request Forgery
|
3 |
WEB
|
Peyman Forouzan
|
2019-04-05
|
|
Manage Engine ServiceDesk Plus 10.0 - Privilege Escalation
|
2 |
WEB
|
Ata Hakçıl_ Melih Kaan Yıldız
|
2019-04-04
|
|
FreeSMS 2.1.2 - SQL Injection (Authentication Bypass)
|
3 |
WEB
|
Yilmaz Degirmenci
|
2019-04-03
|
|
PhreeBooks ERP 5.2.3 - Arbitrary File Upload
|
3 |
WEB
|
Abdullah Çelebi
|