2019-02-11
|
|
Coship Wireless Router 4.0.0.x/5.0.0.x - WiFi Password Reset
|
2 |
WEB
|
Adithyan AK
|
2019-02-11
|
|
Smoothwall Express 3.1-SP4 - Cross-Site Scripting
|
2 |
WEB
|
Ozer Goker
|
2019-02-06
|
|
osCommerce 2.3.4.1 - 'reviews_id' SQL Injection
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-02-06
|
|
osCommerce 2.3.4.1 - 'products_id' SQL Injection
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-02-06
|
|
osCommerce 2.3.4.1 - 'currency' SQL Injection
|
3 |
WEB
|
Mehmet EMIROGLU
|
2019-02-05
|
|
OpenMRS Platform < 2.24.0 - Insecure Object Deserialization
|
2 |
WEB
|
Bishop Fox
|
2019-02-05
|
|
Zyxel VMG3312-B10B DSL-491HNU-B1B v2 Modem - Cross-Site Request Forgery
|
2 |
WEB
|
Yusuf Furkan
|
2019-02-05
|
|
devolo dLAN 550 duo+ Starter Kit - Remote Code Execution
|
2 |
WEB
|
sm
|
2019-02-05
|
|
devolo dLAN 550 duo+ Starter Kit - Cross-Site Request Forgery
|
1 |
WEB
|
sm
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure
|
2 |
WEB
|
LiquidWorm
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - Remote Code Execution
|
3 |
WEB
|
LiquidWorm
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
LiquidWorm
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - RTSP Stream Disclosure
|
1 |
WEB
|
LiquidWorm
|
2019-02-04
|
|
pfSense 2.4.4-p1 - Cross-Site Scripting
|
1 |
WEB
|
Ozer Goker
|
2019-02-04
|
|
Nessus 8.2.1 - Cross-Site Scripting
|
1 |
WEB
|
Ozer Goker
|
2019-02-04
|
|
SuiteCRM 7.10.7 - 'record' SQL Injection
|
1 |
WEB
|
Mehmet EMIROGLU
|
2019-02-04
|
|
SuiteCRM 7.10.7 - 'parentTab' SQL Injection
|
1 |
WEB
|
Mehmet EMIROGLU
|
2019-02-04
|
|
ResourceSpace 8.6 - 'watched_searches.php' SQL Injection
|
1 |
WEB
|
dd_
|
2019-02-01
|
|
SureMDM < 2018-11 Patch - Local / Remote File Inclusion
|
2 |
WEB
|
Digital Interruption
|
2019-01-30
|
|
Rukovoditel Project Management CRM 2.4.1 - 'lists_id' SQL Injection
|
3 |
WEB
|
Mehmet EMIROGLU
|
2019-01-29
|
|
PDF Signer 3.0 - Server-Side Template Injection leading to Remote Command Execution (via Cross-Site
|
2 |
WEB
|
dd_
|
2019-01-28
|
|
ResourceSpace 8.6 - 'collection_edit.php' SQL Injection
|
1 |
WEB
|
dd_
|
2019-01-28
|
|
MyBB IP History Logs Plugin 1.0.2 - Cross-Site Scripting
|
3 |
WEB
|
0xB9
|
2019-01-28
|
|
Mess Management System 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-28
|
|
Teameyo Project Management System 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-28
|
|
Care2x 2.7 (HIS) Hospital Information System - Multiple SQL Injection
|
2 |
WEB
|
Carlos Avila
|
2019-01-28
|
|
Newsbull Haber Script 1.0.0 - 'search' SQL Injection
|
2 |
WEB
|
Mehmet EMIROGLU
|
2019-01-28
|
|
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
|
1 |
WEB
|
Bhushan B. Patil
|
2019-01-28
|
|
Cisco RV300 / RV320 - Information Disclosure
|
1 |
WEB
|
Harom Ramos
|
2019-01-28
|
|
CMSsite 1.0 - 'search' SQL Injection
|
2 |
WEB
|
Majid kalantari
|
2019-01-28
|
|
CMSsite 1.0 - 'cat_id' SQL Injection
|
3 |
WEB
|
Majid kalantari
|
2019-01-28
|
|
LogonBox Limited / Hypersocket Nervepoint Access Manager - (Unauthenticated) Insecure Direct Object
|
3 |
WEB
|
0v3rride
|
2019-01-28
|
|
AirTies Air5341 Modem 1.0.0.12 - Cross-Site Request Forgery
|
2 |
WEB
|
Ali Can Gönüllü
|
2019-01-28
|
|
WordPress Plugin Ad Manager WD 1.0.11 - Arbitrary File Download
|
0 |
WEB
|
41!kh4224rDz
|
2019-01-28
|
|
Rundeck Community Edition < 3.0.13 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Ishaq Mohammed
|
2019-01-25
|
|
WordPress Plugin Wisechat 2.6.3 - Reverse Tabnabbing
|
2 |
WEB
|
MTK
|
2019-01-25
|
|
GreenCMS 2.x - Arbitrary File Download
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-25
|
|
GreenCMS 2.x - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-25
|
|
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
|
2 |
WEB
|
RedTeam Pentesting
|
2019-01-24
|
|
Zyxel NBG-418N v2 Modem 1.00(AAXM.6)C0 - Cross-Site Request Forgery
|
2 |
WEB
|
Ali Can Gönüllü
|
2019-01-24
|
|
ImpressCMS 1.3.11 - 'bid' SQL Injection
|
2 |
WEB
|
Mehmet Onder
|
2019-01-24
|
|
Splunk Enterprise 7.2.3 - (Authenticated) Custom App Remote Code Execution
|
1 |
WEB
|
Lee Mazzoleni
|
2019-01-24
|
|
SirsiDynix e-Library 3.5.x - Cross-Site Scripting
|
1 |
WEB
|
AkkuS
|
2019-01-24
|
|
SimplePress CMS 1.0.7 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-24
|
|
Joomla! Component JHotelReservation 6.0.7 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-24
|
|
Joomla! Component J-CruisePortal 6.0.4 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component JMultipleHotelReservation 6.0.7 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component J-ClassifiedsManager 3.0.5 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component J-BusinessDirectory 4.9.7 - 'type' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component VMap 1.9.6 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vRestaurant 1.9.4 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vReview 1.9.11 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vAccount 2.0.2 - 'vid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vWishlist 1.0.1 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vBizz 1.0.7 - Remote Code Execution
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vBizz 1.0.7 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation
|
2 |
WEB
|
Chris Lyne
|
2019-01-22
|
|
Joomla! Component Easy Shop 1.2.3 - Local File Inclusion
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
Adianti Framework 5.5.0 - SQL Injection
|
2 |
WEB
|
Joner de Mello Assolin
|
2019-01-21
|
|
PHP Uber-style GeoTracking 1.1 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
PHP Dashboards NEW 5.8 - Local File Inclusion
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
PHP Dashboards NEW 5.8 - 'dashID' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
MoneyFlux 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
Reservic 1.0 - 'id' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
Coman 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
Kepler Wallpaper Script 1.1 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-18
|
|
Pydio / AjaXplorer < 5.0.4 - (Unauthenticated) Arbitrary File Upload
|
2 |
WEB
|
_jazz______
|
2019-01-18
|
|
Joomla! Core 3.9.1 - Persistent Cross-Site Scripting in Global Configuration Textfilter Settings
|
2 |
WEB
|
Praveen Sutar
|
2019-01-18
|
|
phpTransformer 2016.9 - Directory Traversal
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-18
|
|
phpTransformer 2016.9 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-18
|
|
SeoToaster Ecommerce / CRM / CMS 3.0.0 - Local File Inclusion
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-17
|
|
Oracle Reports Developer Component 12.2.1.3 - Cross-site Scripting
|
2 |
WEB
|
Mohamed M.Fouad
|
2019-01-16
|
|
Blueimp's jQuery File Upload 9.22.0 - Arbitrary File Upload Exploit
|
3 |
WEB
|
Larry W. Cashdollar
|
2019-01-16
|
|
Coship Wireless Router 4.0.0.48 / 4.0.0.40 / 5.0.0.54 / 5.0.0.55 / 10.0.0.49 - Unauthenticated Admin
|
2 |
WEB
|
Adithyan AK
|
2019-01-16
|
|
GL-AR300M-Lite 2.27 - (Authenticated) Command Injection / Arbitrary File Download / Directory Traver
|
2 |
WEB
|
Pasquale Turi
|
2019-01-16
|
|
GL-AR300M-Lite 2.27 - (Authenticated) Command Injection / Arbitrary File Download / Directory Traver
|
1 |
WEB
|
Pasquale Turi
|
2019-01-16
|
|
ShoreTel / Mitel Connect ONSITE 19.49.5200.0 - Remote Code Execution
|
2 |
WEB
|
twosevenzero
|
2019-01-16
|
|
doorGets CMS 7.0 - Arbitrary File Download
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-16
|
|
Roxy Fileman 1.4.5 - Arbitrary File Download
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-16
|
|
Fortinet FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure
|
1 |
WEB
|
Julio Ureña
|
2019-01-15
|
|
ownDMS 4.7 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
AudioCode 400HD - Command Injection
|
2 |
WEB
|
Sysdream
|
2019-01-14
|
|
Portier Vision 4.4.4.2 / 4.4.4.6 - SQL Injection
|
1 |
WEB
|
SySS GmbH
|
2019-01-14
|
|
Bigcart - Ecommerce Multivendor System 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Umbraco CMS 7.12.4 - (Authenticated) Remote Code Execution
|
1 |
WEB
|
Gregory Draperi
|
2019-01-14
|
|
Job Portal Platform 1.0 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Real Estate Custom Script 2.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
ThinkPHP 5.X - Remote Command Execution
|
2 |
WEB
|
vr_system
|
2019-01-14
|
|
Hucart CMS 5.7.4 - Cross-Site Request Forgery (Add Administrator Account)
|
2 |
WEB
|
AllenChen
|
2019-01-14
|
|
HealthNode Hospital Management System 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Lenovo R2105 - Cross-Site Request Forgery (Command Execution)
|
1 |
WEB
|
Nathu Nandwani
|
2019-01-14
|
|
Cleanto 5.0 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Find a Place CMS Directory 1.5 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Craigs Classified Ads CMS Theme 1.0.2 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Live Call Support Widget 1.5 - Remote Code Execution / SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Live Call Support Widget 1.5 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Twilio WEB To Fax Machine System Application 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Modern POS 1.3 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Modern POS 1.3 - Arbitrary File Download
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Horde Imp - 'imap_open' Remote Command Execution
|
1 |
WEB
|
Paolo Serracino_ Pietro Minniti_ Damiano Proietti
|
2019-01-14
|
|
i-doit CMDB 1.12 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
i-doit CMDB 1.12 - Arbitrary File Download
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Across DR-810 ROM-0 - Backup File Disclosure
|
2 |
WEB
|
SajjadBnd
|
2019-01-11
|
|
Joomla! Component JoomCRM 1.1.1 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-11
|
|
Joomla! Component JoomProject 1.1.3.2 - Information Disclosure
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-11
|
|
Adapt Inventory Management System 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
OpenSource ERP 6.3.1. - SQL Injection
|
2 |
WEB
|
Emre ÖVÜNÇ
|
2019-01-10
|
|
eBrigade ERP 4.5 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
Event Locations 1.0.1 - 'id' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
Event Calendar 3.7.4 - 'id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
MLMPro 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
Architectural 1.0 - 'email' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
Shield CMS 2.2 - 'email' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
doitX 1.0 - 'search' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
Matrix MLM Script 1.0 - Information Disclosure
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
eBrigade ERP 4.5 - Arbitrary File Download
|
2 |
WEB
|
AkkuS
|
2019-01-10
|
|
PEAR Archive_Tar < 1.4.4 - PHP Object Injection
|
3 |
WEB
|
Fariskhi Vidyan
|
2019-01-09
|
|
BlogEngine 3.3 - XML External Entity Injection
|
2 |
WEB
|
Netsparker
|
2019-01-09
|
|
ZTE MF65 BD_HDV6MF65V1.0.0B05 - Cross-Site Scripting
|
1 |
WEB
|
Nathu Nandwani
|
2019-01-09
|
|
Heatmiser Wifi Thermostat 1.7 - Cross-Site Request Forgery (Update Admin)
|
2 |
WEB
|
SajjadBnd
|
2017-03-02
|
|
MDwiki < 0.6.2 - Cross-Site Scripting
|
2 |
WEB
|
evi1m0
|
2019-01-08
|
|
Dolibarr ERP-CRM 8.0.4 - 'rowid' SQL Injection
|
1 |
WEB
|
Mehmet Onder
|
2019-01-08
|
|
CF Image Hosting Script 1.6.5 - (Delete all Pictures) Privilege Escalation
|
2 |
WEB
|
David Tavarez
|
2019-01-07
|
|
Huawei E5330 21.210.09.00.158 - Cross-Site Request Forgery (Send SMS)
|
2 |
WEB
|
Nathu Nandwani
|
2019-01-07
|
|
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 - JS/HTML Code Injection
|
2 |
WEB
|
LiquidWorm
|