2019-02-19
|
|
XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting
|
5 |
WEB
|
Rafael Pedrero
|
2019-02-19
|
|
eDirectory - SQL Injection
|
6 |
WEB
|
Efrén Díaz
|
2019-02-19
|
|
Zuz Music 2.1 - 'zuzconsole/___contact ' Persistent Cross-Site Scripting
|
4 |
WEB
|
Deyaa Muhammad
|
2019-02-19
|
|
Listing Hub CMS 1.0 - 'pages.php id' SQL Injection
|
4 |
WEB
|
Deyaa Muhammad
|
2019-02-19
|
|
Find a Place CMS Directory 1.5 - 'assets/external/data_2.php cate' SQL Injection
|
4 |
WEB
|
Deyaa Muhammad
|
2019-02-18
|
|
WordPress Plugin WooCommerce - GloBee (cryptocurrency) Payment Gateway 1.1.1 - Payment Bypass / Unau
|
4 |
WEB
|
GeekHack
|
2019-02-18
|
|
Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Upload
|
5 |
WEB
|
Dao Duy Hung
|
2019-02-18
|
|
Comodo Dome Firewall 2.7.0 - Cross-Site Scripting
|
6 |
WEB
|
Ozer Goker
|
2019-02-18
|
|
ArangoDB Community Edition 3.4.2-1 - Cross-Site Scripting
|
4 |
WEB
|
Ozer Goker
|
2019-02-18
|
|
Apache CouchDB 2.3.0 - Cross-Site Scripting
|
4 |
WEB
|
Ozer Goker
|
2019-02-18
|
|
Webiness Inventory 2.3 - 'ProductModel' Arbitrary File Upload
|
5 |
WEB
|
Mehmet EMIROGLU
|
2019-02-18
|
|
M/Monit 3.7.2 - Privilege Escalation
|
5 |
WEB
|
Dolev Farhi
|
2019-02-18
|
|
CMSsite 1.0 - 'post' SQL Injection
|
4 |
WEB
|
Mr Winst0n
|
2019-02-18
|
|
MISP 2.4.97 - SQL Command Execution via Command Injection in STIX Module
|
4 |
WEB
|
Tm9jdGlz
|
2019-02-18
|
|
Master IP CAM 01 3.3.4.2103 - Remote Command Execution
|
5 |
WEB
|
Raffaele Sabato
|
2019-02-18
|
|
qdPM 9.1 - 'search[keywords]' Cross-Site Scripting
|
4 |
WEB
|
Mehmet EMIROGLU
|
2019-02-18
|
|
qdPM 9.1 - 'type' Cross-Site Scripting
|
5 |
WEB
|
Mehmet EMIROGLU
|
2019-02-15
|
|
UniSharp Laravel File Manager 2.0.0-alpha7 - Arbitrary File Upload
|
4 |
WEB
|
Mohammad Danish
|
2019-02-15
|
|
qdPM 9.1 - 'search_by_extrafields[]' SQL Injection
|
4 |
WEB
|
Mehmet EMIROGLU
|
2019-02-15
|
|
Jinja2 2.10 - 'from_string' Server Side Template Injection
|
5 |
WEB
|
JameelNabbo
|
2019-02-15
|
|
MyBB Trash Bin Plugin 1.1.3 - Cross-Site Scripting / Cross-Site Request Forgery
|
3 |
WEB
|
0xB9
|
2019-02-15
|
|
MyBB Trash Bin Plugin 1.1.3 - Cross-Site Scripting / Cross-Site Request Forgery
|
5 |
WEB
|
0xB9
|
2019-02-14
|
|
LayerBB 1.1.2 - Cross-Site Request Forgery (Add Admin)
|
5 |
WEB
|
0xB9
|
2019-02-14
|
|
WordPress Plugin Booking Calendar 8.4.3 - (Authenticated) SQL Injection
|
5 |
WEB
|
B0UG
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'assets/edit/host.php?whid=5' Cross-Site Scripting
|
6 |
WEB
|
Mohammed Abdul Kareem
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'assets/add/dns.php' Cross-Site Scripting
|
5 |
WEB
|
Mohammed Abdul Kareem
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'category.php CatagoryName_ StakeHolder' Cross-Site Scripting
|
5 |
WEB
|
Mohammed Abdul Raheem
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'ssl-accounts.php username' Cross-Site Scripting
|
5 |
WEB
|
Mohammed Abdul Raheem
|
2019-02-14
|
|
DomainMOD 4.11.01 - 'ssl-provider-name' Cross-Site Scripting
|
5 |
WEB
|
Mohammed Abdul Raheem
|
2019-02-13
|
|
PilusCart 1.4.1 - 'send' SQL Injection
|
5 |
WEB
|
Mehmet EMIROGLU
|
2019-02-13
|
|
Rukovoditel Project Management CRM 2.4.1 - Cross-Site Scripting
|
6 |
WEB
|
Mehmet EMIROGLU
|
2019-02-12
|
|
LayerBB 1.1.2 - Cross-Site Scripting
|
5 |
WEB
|
0xB9
|
2019-02-12
|
|
BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution
|
5 |
WEB
|
Dustin Cobb
|
2019-02-12
|
|
Jenkins 2.150.2 - Remote Command Execution (Metasploit)
|
5 |
WEB
|
AkkuS
|
2019-02-12
|
|
OPNsense < 19.1.1 - Cross-Site Scripting
|
5 |
WEB
|
Ozer Goker
|
2019-02-11
|
|
Webiness Inventory 2.3 - 'email' SQL Injection
|
4 |
WEB
|
Mehmet EMIROGLU
|
2019-02-11
|
|
CentOS Web Panel 0.9.8.763 - Persistent Cross-Site Scripting
|
5 |
WEB
|
DKM
|
2019-02-11
|
|
VA MAX 8.3.4 - (Authenticated) Remote Code Execution
|
5 |
WEB
|
Cody Sixteen
|
2019-02-11
|
|
MyBB Bans List 1.0 - Cross-Site Scripting
|
6 |
WEB
|
0xB9
|
2019-02-11
|
|
IPFire 2.21 - Cross-Site Scripting
|
4 |
WEB
|
Ozer Goker
|
2019-02-11
|
|
Coship Wireless Router 4.0.0.x/5.0.0.x - WiFi Password Reset
|
5 |
WEB
|
Adithyan AK
|
2019-02-11
|
|
Smoothwall Express 3.1-SP4 - Cross-Site Scripting
|
4 |
WEB
|
Ozer Goker
|
2019-02-06
|
|
osCommerce 2.3.4.1 - 'reviews_id' SQL Injection
|
5 |
WEB
|
Mehmet EMIROGLU
|
2019-02-06
|
|
osCommerce 2.3.4.1 - 'products_id' SQL Injection
|
6 |
WEB
|
Mehmet EMIROGLU
|
2019-02-06
|
|
osCommerce 2.3.4.1 - 'currency' SQL Injection
|
6 |
WEB
|
Mehmet EMIROGLU
|
2019-02-05
|
|
OpenMRS Platform < 2.24.0 - Insecure Object Deserialization
|
6 |
WEB
|
Bishop Fox
|
2019-02-05
|
|
Zyxel VMG3312-B10B DSL-491HNU-B1B v2 Modem - Cross-Site Request Forgery
|
5 |
WEB
|
Yusuf Furkan
|
2019-02-05
|
|
devolo dLAN 550 duo+ Starter Kit - Remote Code Execution
|
6 |
WEB
|
sm
|
2019-02-05
|
|
devolo dLAN 550 duo+ Starter Kit - Cross-Site Request Forgery
|
4 |
WEB
|
sm
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure
|
5 |
WEB
|
LiquidWorm
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - Remote Code Execution
|
5 |
WEB
|
LiquidWorm
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
LiquidWorm
|
2019-02-05
|
|
BEWARD N100 H.264 VGA IP Camera M2.1.6 - RTSP Stream Disclosure
|
4 |
WEB
|
LiquidWorm
|
2019-02-04
|
|
pfSense 2.4.4-p1 - Cross-Site Scripting
|
5 |
WEB
|
Ozer Goker
|
2019-02-04
|
|
Nessus 8.2.1 - Cross-Site Scripting
|
4 |
WEB
|
Ozer Goker
|
2019-02-04
|
|
SuiteCRM 7.10.7 - 'record' SQL Injection
|
5 |
WEB
|
Mehmet EMIROGLU
|
2019-02-04
|
|
SuiteCRM 7.10.7 - 'parentTab' SQL Injection
|
4 |
WEB
|
Mehmet EMIROGLU
|
2019-02-04
|
|
ResourceSpace 8.6 - 'watched_searches.php' SQL Injection
|
4 |
WEB
|
dd_
|
2019-02-01
|
|
SureMDM < 2018-11 Patch - Local / Remote File Inclusion
|
4 |
WEB
|
Digital Interruption
|
2019-01-30
|
|
Rukovoditel Project Management CRM 2.4.1 - 'lists_id' SQL Injection
|
5 |
WEB
|
Mehmet EMIROGLU
|
2019-01-29
|
|
PDF Signer 3.0 - Server-Side Template Injection leading to Remote Command Execution (via Cross-Site
|
4 |
WEB
|
dd_
|
2019-01-28
|
|
ResourceSpace 8.6 - 'collection_edit.php' SQL Injection
|
3 |
WEB
|
dd_
|
2019-01-28
|
|
MyBB IP History Logs Plugin 1.0.2 - Cross-Site Scripting
|
4 |
WEB
|
0xB9
|
2019-01-28
|
|
Mess Management System 1.0 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-28
|
|
Teameyo Project Management System 1.0 - SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-28
|
|
Care2x 2.7 (HIS) Hospital Information System - Multiple SQL Injection
|
3 |
WEB
|
Carlos Avila
|
2019-01-28
|
|
Newsbull Haber Script 1.0.0 - 'search' SQL Injection
|
6 |
WEB
|
Mehmet EMIROGLU
|
2019-01-28
|
|
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
|
5 |
WEB
|
Bhushan B. Patil
|
2019-01-28
|
|
Cisco RV300 / RV320 - Information Disclosure
|
3 |
WEB
|
Harom Ramos
|
2019-01-28
|
|
CMSsite 1.0 - 'search' SQL Injection
|
5 |
WEB
|
Majid kalantari
|
2019-01-28
|
|
CMSsite 1.0 - 'cat_id' SQL Injection
|
4 |
WEB
|
Majid kalantari
|
2019-01-28
|
|
LogonBox Limited / Hypersocket Nervepoint Access Manager - (Unauthenticated) Insecure Direct Object
|
4 |
WEB
|
0v3rride
|
2019-01-28
|
|
AirTies Air5341 Modem 1.0.0.12 - Cross-Site Request Forgery
|
5 |
WEB
|
Ali Can Gönüllü
|
2019-01-28
|
|
WordPress Plugin Ad Manager WD 1.0.11 - Arbitrary File Download
|
4 |
WEB
|
41!kh4224rDz
|
2019-01-28
|
|
Rundeck Community Edition < 3.0.13 - Persistent Cross-Site Scripting
|
4 |
WEB
|
Ishaq Mohammed
|
2019-01-25
|
|
WordPress Plugin Wisechat 2.6.3 - Reverse Tabnabbing
|
5 |
WEB
|
MTK
|
2019-01-25
|
|
GreenCMS 2.x - Arbitrary File Download
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-25
|
|
GreenCMS 2.x - SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-25
|
|
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
|
4 |
WEB
|
RedTeam Pentesting
|
2019-01-24
|
|
Zyxel NBG-418N v2 Modem 1.00(AAXM.6)C0 - Cross-Site Request Forgery
|
4 |
WEB
|
Ali Can Gönüllü
|
2019-01-24
|
|
ImpressCMS 1.3.11 - 'bid' SQL Injection
|
4 |
WEB
|
Mehmet Onder
|
2019-01-24
|
|
Splunk Enterprise 7.2.3 - (Authenticated) Custom App Remote Code Execution
|
3 |
WEB
|
Lee Mazzoleni
|
2019-01-24
|
|
SirsiDynix e-Library 3.5.x - Cross-Site Scripting
|
4 |
WEB
|
AkkuS
|
2019-01-24
|
|
SimplePress CMS 1.0.7 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-24
|
|
Joomla! Component JHotelReservation 6.0.7 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-24
|
|
Joomla! Component J-CruisePortal 6.0.4 - SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component JMultipleHotelReservation 6.0.7 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component J-ClassifiedsManager 3.0.5 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component J-BusinessDirectory 4.9.7 - 'type' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component VMap 1.9.6 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vRestaurant 1.9.4 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vReview 1.9.11 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vAccount 2.0.2 - 'vid' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vWishlist 1.0.1 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vBizz 1.0.7 - Remote Code Execution
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Joomla! Component vBizz 1.0.7 - SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-23
|
|
Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation
|
4 |
WEB
|
Chris Lyne
|
2019-01-22
|
|
Joomla! Component Easy Shop 1.2.3 - Local File Inclusion
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
Adianti Framework 5.5.0 - SQL Injection
|
4 |
WEB
|
Joner de Mello Assolin
|
2019-01-21
|
|
PHP Uber-style GeoTracking 1.1 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
PHP Dashboards NEW 5.8 - Local File Inclusion
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
PHP Dashboards NEW 5.8 - 'dashID' SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
MoneyFlux 1.0 - 'id' SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
Reservic 1.0 - 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
Coman 1.0 - 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-21
|
|
Kepler Wallpaper Script 1.1 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-18
|
|
Pydio / AjaXplorer < 5.0.4 - (Unauthenticated) Arbitrary File Upload
|
4 |
WEB
|
_jazz______
|
2019-01-18
|
|
Joomla! Core 3.9.1 - Persistent Cross-Site Scripting in Global Configuration Textfilter Settings
|
4 |
WEB
|
Praveen Sutar
|
2019-01-18
|
|
phpTransformer 2016.9 - Directory Traversal
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-18
|
|
phpTransformer 2016.9 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-18
|
|
SeoToaster Ecommerce / CRM / CMS 3.0.0 - Local File Inclusion
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-17
|
|
Oracle Reports Developer Component 12.2.1.3 - Cross-site Scripting
|
4 |
WEB
|
Mohamed M.Fouad
|
2019-01-16
|
|
Blueimp's jQuery File Upload 9.22.0 - Arbitrary File Upload Exploit
|
4 |
WEB
|
Larry W. Cashdollar
|
2019-01-16
|
|
Coship Wireless Router 4.0.0.48 / 4.0.0.40 / 5.0.0.54 / 5.0.0.55 / 10.0.0.49 - Unauthenticated Admin
|
5 |
WEB
|
Adithyan AK
|
2019-01-16
|
|
GL-AR300M-Lite 2.27 - (Authenticated) Command Injection / Arbitrary File Download / Directory Traver
|
5 |
WEB
|
Pasquale Turi
|
2019-01-16
|
|
GL-AR300M-Lite 2.27 - (Authenticated) Command Injection / Arbitrary File Download / Directory Traver
|
2 |
WEB
|
Pasquale Turi
|
2019-01-16
|
|
ShoreTel / Mitel Connect ONSITE 19.49.5200.0 - Remote Code Execution
|
5 |
WEB
|
twosevenzero
|
2019-01-16
|
|
doorGets CMS 7.0 - Arbitrary File Download
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-16
|
|
Roxy Fileman 1.4.5 - Arbitrary File Download
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-16
|
|
Fortinet FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure
|
4 |
WEB
|
Julio Ureña
|
2019-01-15
|
|
ownDMS 4.7 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
AudioCode 400HD - Command Injection
|
4 |
WEB
|
Sysdream
|
2019-01-14
|
|
Portier Vision 4.4.4.2 / 4.4.4.6 - SQL Injection
|
4 |
WEB
|
SySS GmbH
|
2019-01-14
|
|
Bigcart - Ecommerce Multivendor System 1.0 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Umbraco CMS 7.12.4 - (Authenticated) Remote Code Execution
|
3 |
WEB
|
Gregory Draperi
|