2019-01-07
|
|
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 - Cross-Site Request Forgery
|
2 |
WEB
|
LiquidWorm
|
2019-01-07
|
|
Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data
|
2 |
WEB
|
Anthony Cole
|
2019-01-07
|
|
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
|
2 |
WEB
|
Pongtorn Angsuchotmetee_ Vittawat Masaree
|
2019-01-07
|
|
MyT Project Management 1.5.1 - 'Charge[group_total]' SQL Injection
|
2 |
WEB
|
Mehmet Onder
|
2019-01-07
|
|
WordPress Plugin UserPro < 4.9.21 - User Registration Privilege Escalation
|
2 |
WEB
|
Noman Riffat
|
2019-01-07
|
|
phpMoAdmin MongoDB GUI 1.1.5 - Cross-Site Request Forgery / Cross-Site Scripting
|
2 |
WEB
|
Ozer Goker
|
2019-01-07
|
|
phpMoAdmin MongoDB GUI 1.1.5 - Cross-Site Request Forgery / Cross-Site Scripting
|
1 |
WEB
|
Ozer Goker
|
2019-01-07
|
|
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Scripting
|
3 |
WEB
|
Kumar Saurav
|
2019-01-07
|
|
MyBB OUGC Awards Plugin 1.8.3 - Persistent Cross-Site Scripting
|
2 |
WEB
|
0xB9
|
2019-01-07
|
|
LayerBB 1.1.1 - Persistent Cross-Site Scripting
|
2 |
WEB
|
0xB9
|
2019-01-07
|
|
All in One Video Downloader 1.2 - (Authenticated) SQL Injection
|
0 |
WEB
|
Deyaa Muhammad
|
2019-01-07
|
|
Embed Video Scripts - Persistent Cross-Site Scripting
|
2 |
WEB
|
Deyaa Muhammad
|
2019-01-02
|
|
Frog CMS 0.9.5 - Cross-Site Scripting
|
2 |
WEB
|
WangDudu
|
2019-01-02
|
|
WordPress Plugin Adicon Server 1.2 - 'selectedPlace' SQL Injection
|
2 |
WEB
|
Kaimi
|
2019-01-02
|
|
Vtiger CRM 7.1.0 - Remote Code Execution
|
2 |
WEB
|
AkkuS
|
2018-12-27
|
|
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File Upload
|
1 |
WEB
|
Kaimi
|
2018-12-27
|
|
bludit Pages Editor 3.0.0 - Arbitrary File Upload
|
2 |
WEB
|
BouSalman
|
2018-12-27
|
|
WordPress Plugin Audio Record 1.0 - Arbitrary File Upload
|
2 |
WEB
|
Kaimi
|
2018-12-27
|
|
Craft CMS 3.0.25 - Cross-Site Scripting
|
2 |
WEB
|
Raif Berkay Dincel
|
2018-11-30
|
|
PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
|
2 |
WEB
|
Alex Leahu
|
2018-12-15
|
|
phpMyAdmin 4.8.4 - 'AllowArbitraryServer' Arbitrary File Read
|
2 |
WEB
|
VulnSpy
|
2018-12-24
|
|
FrontAccounting 2.4.5 - 'SubmitUser' SQL Injection
|
2 |
WEB
|
Sainadh Jamalpur
|
2018-12-24
|
|
WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
linfeng
|
2018-12-24
|
|
WSTMart 2.0.8 - Cross-Site Scripting
|
1 |
WEB
|
linfeng
|
2018-12-21
|
|
ZeusCart 4.0 - Cross-Site Request Forgery (Deactivate Customer Accounts)
|
2 |
WEB
|
mqt
|
2018-12-19
|
|
IBM Operational Decision Manager 8.x - XML External Entity Injection
|
2 |
WEB
|
Mohamed M.Fouad
|
2018-12-19
|
|
Yeswiki Cercopitheque - 'id' SQL Injection
|
2 |
WEB
|
Mickael BROUTY
|
2018-12-19
|
|
Bolt CMS < 3.6.2 - Cross-Site Scripting
|
2 |
WEB
|
Raif Berkay Dincel
|
2018-12-19
|
|
Integria IMS 5.0.83 - Cross-Site Request Forgery
|
1 |
WEB
|
Javier Olmedo
|
2018-12-19
|
|
Integria IMS 5.0.83 - 'search_string' Cross-Site Scripting
|
2 |
WEB
|
Javier Olmedo
|
2018-12-19
|
|
Rukovoditel Project Management CRM 2.3.1 - Remote Code Execution (Metasploit)
|
2 |
WEB
|
AkkuS
|
2018-12-19
|
|
Hotel Booking Script 3.4 - Cross-Site Request Forgery (Change Admin Password)
|
2 |
WEB
|
Sainadh Jamalpur
|
2018-12-18
|
|
SDL Web Content Manager 8.5.0 - XML External Entity Injection
|
0 |
WEB
|
Ahmed Elhady Mohamed
|
2018-12-14
|
|
Double Your Bitcoin Script Automatic - Authentication Bypass
|
1 |
WEB
|
Veyselxan
|
2018-12-14
|
|
Facebook And Google Reviews System For Businesses 1.1 - Remote Code Execution
|
1 |
WEB
|
Ihsan Sencan
|
2018-12-14
|
|
Facebook And Google Reviews System For Businesses 1.1 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-12-14
|
|
Facebook And Google Reviews System For Businesses - Cross-Site Request Forgery (Change Admin Passwor
|
1 |
WEB
|
Veyselxan
|
2018-12-14
|
|
Huawei Router HG532e - Command Execution
|
2 |
WEB
|
Rebellion
|
2018-12-14
|
|
Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2)
|
2 |
WEB
|
alt3kx
|
2018-12-14
|
|
Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure
|
2 |
WEB
|
alt3kx
|
2018-12-14
|
|
Responsive FileManager 9.13.4 - Multiple Vulnerabilities
|
2 |
WEB
|
Fariskhi Vidyan
|
2018-12-11
|
|
Adobe ColdFusion 2018 - Arbitrary File Upload
|
2 |
WEB
|
Vahagn Vardanyan
|
2018-12-11
|
|
ThinkPHP 5.0.23/5.1.31 - Remote Code Execution
|
3 |
WEB
|
VulnSpy
|
2018-12-11
|
|
WordPress Plugin AutoSuggest 0.24 - 'wpas_keys' SQL Injection
|
2 |
WEB
|
Kaimi
|
2018-12-11
|
|
HotelDruid 2.3.0 - 'id_utente_mod' SQL Injection
|
2 |
WEB
|
Sainadh Jamalpur
|
2018-12-11
|
|
Apache OFBiz 16.11.05 - Cross-Site Scripting
|
1 |
WEB
|
DKM
|
2014-02-17
|
|
IceWarp Mail Server 11.0.0.0 - Cross-Site Scripting
|
1 |
WEB
|
Usman Saeed
|
2017-05-05
|
|
Sitecore CMS 8.2 - Cross-Site Scripting / Arbitrary File Disclosure
|
1 |
WEB
|
Usman Saeed
|
2018-12-11
|
|
ZTE ZXHN H168N - Improper Access Restrictions
|
1 |
WEB
|
Usman Saeed
|
2018-12-11
|
|
Huawei B315s-22 - Information Leak
|
1 |
WEB
|
Usman Saeed
|
2018-12-11
|
|
TP-Link wireless router Archer C1200 - Cross-Site Scripting
|
1 |
WEB
|
Usman Saeed
|
2018-12-11
|
|
PrinterOn Enterprise 4.1.4 - Arbitrary File Deletion
|
1 |
WEB
|
bzyo
|
2018-12-11
|
|
DomainMOD 4.11.01 - Cross-Site Scripting
|
1 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-11
|
|
PrestaShop 1.6.x/1.7.x - Remote Code Execution
|
1 |
WEB
|
Fariskhi Vidyan
|
2018-12-11
|
|
Alumni Tracer SMS Notification - SQL Injection / Cross-Site Request Forgery
|
1 |
WEB
|
Ihsan Sencan
|
2018-12-11
|
|
Alumni Tracer SMS Notification - SQL Injection / Cross-Site Request Forgery
|
3 |
WEB
|
Ihsan Sencan
|
2018-12-11
|
|
Tourism Website Blog - Remote Code Execution / SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-12-09
|
|
DomainMOD 4.11.01 - 'DisplayName' Cross-Site Scripting
|
2 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-09
|
|
Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting
|
2 |
WEB
|
Gustavo Sorondo
|
2018-12-09
|
|
i-doit CMDB 1.11.2 - Remote Code Execution
|
2 |
WEB
|
AkkuS
|
2018-12-05
|
|
HasanMWB 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2018-12-04
|
|
FreshRSS 1.11.1 - Cross-Site Scripting
|
1 |
WEB
|
Netsparker
|
2018-12-04
|
|
DomainMOD 4.11.01 - Registrar Cross-Site Scripting
|
2 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-04
|
|
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection
|
2 |
WEB
|
Artem Metla
|
2018-12-04
|
|
DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting
|
2 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-04
|
|
DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting
|
2 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-04
|
|
Dolibarr ERP/CRM 8.0.3 - Cross-Site Scripting
|
2 |
WEB
|
AkkuS
|
2018-12-04
|
|
KeyBase Botnet 1.5 - SQL Injection
|
2 |
WEB
|
n4pst3r
|
2018-12-04
|
|
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
|
2 |
WEB
|
hyp3rlinx
|
2018-12-04
|
|
DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting
|
2 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-04
|
|
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
|
3 |
WEB
|
Luca.Chiou
|
2018-12-03
|
|
WordPress Plugin Advanced-Custom-Fields 5.7.7 - Cross-Site Scripting
|
2 |
WEB
|
Loading Kura Kura
|
2018-12-03
|
|
Apache Superset < 0.23 - Remote Code Execution
|
1 |
WEB
|
David May
|
2018-12-03
|
|
PHP Server Monitor 3.3.1 - Cross-Site Request Forgery
|
2 |
WEB
|
Javier Olmedo
|
2018-12-03
|
|
Joomla! Component JE Photo Gallery 1.1 - 'categoryid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-12-03
|
|
PaloAlto Networks Expedition Migration Tool 1.0.106 - Information Disclosure
|
2 |
WEB
|
ParagonSec
|
2018-12-03
|
|
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting
|
1 |
WEB
|
Luca.Chiou
|
2018-12-03
|
|
Fleetco Fleet Maintenance Management 1.2 - Remote Code Execution
|
2 |
WEB
|
AkkuS
|
2018-11-30
|
|
Synaccess netBooter NP-02x/NP-08x 6.8 - Authentication Bypass
|
1 |
WEB
|
LiquidWorm
|
2018-11-30
|
|
Schneider Electric PLC - Session Calculation Authentication Bypass
|
1 |
WEB
|
Photubias
|
2018-11-26
|
|
Zyxel VMG1312-B10D 5.13AAXA.8 - Directory Traversal
|
2 |
WEB
|
numan türle
|
2018-11-26
|
|
No-Cms 1.0 - 'order_by' SQL Injection
|
2 |
WEB
|
Loading Kura Kura
|
2018-11-26
|
|
Ticketly 1.0 - 'kind_id' SQL Injection
|
2 |
WEB
|
Javier Olmedo
|
2018-11-26
|
|
WordPress Plugin Easy Testimonials 3.2 - Cross-Site Scripting
|
2 |
WEB
|
En_dust
|
2018-11-26
|
|
Ricoh myPrint 2.9.2.4 - Hard-Coded Credentials
|
2 |
WEB
|
Hodorsec
|
2018-11-21
|
|
WebOfisi E-Ticaret V4 - 'urun' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-11-21
|
|
WordPress Theme CherryFramework 3.1.4 - Backup File Download
|
2 |
WEB
|
b1p0l4r
|
2018-11-21
|
|
Ticketly 1.0 - 'name' SQL Injection
|
2 |
WEB
|
Javier Olmedo
|
2018-11-21
|
|
Synaccess netBooter NP-0801DU 7.4 - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
LiquidWorm
|
2018-11-20
|
|
Ticketly 1.0 - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
Javier Olmedo
|
2018-11-16
|
|
DomainMOD 4.11.01 - 'raid' Cross-Site Scripting
|
2 |
WEB
|
Dawood Ansar
|
2018-11-16
|
|
Helpdezk 1.1.1 - Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-16
|
|
Warranty Tracking System 11.06.3 - 'txtCustomerCode' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-15
|
|
WordPress Plugin Ninja Forms 3.3.17 - Cross-Site Scripting
|
2 |
WEB
|
MTK
|
2018-11-15
|
|
PHP Mass Mail 1.0 - Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-15
|
|
2-Plan Team 1.0.4 - Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-15
|
|
Simple E-Document 1.31 - 'username' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-15
|
|
Kordil EDMS 2.2.60rc3 - Arbitrary File Upload
|
3 |
WEB
|
Ihsan Sencan
|
2018-11-15
|
|
Meneame English Pligg 5.8 - 'search' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-11-15
|
|
EverSync 0.5 - Arbitrary File Download
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-15
|
|
Galaxy Forces MMORPG 0.5.8 - 'type' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-11-15
|
|
Net-Billetterie 2.9 - 'login' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-11-15
|
|
BitZoom 1.0 - 'rollno' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-15
|
|
PHP-Proxy 5.1.0 - Local File Inclusion
|
2 |
WEB
|
Ameer Pornillos
|
2018-11-15
|
|
Precurio Intranet Portal 2.0 - Cross-Site Request Forgery (Add Admin)
|
0 |
WEB
|
Ihsan Sencan
|
2018-11-14
|
|
DoceboLMS 1.2 - SQL Injection / Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-14
|
|
Electricks eCommerce 1.0 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Nawaf Alkeraithe
|
2018-11-14
|
|
Pedidos 1.0 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-11-14
|
|
Rmedia SMS 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-14
|
|
Advanced Comment System 1.0 - SQL Injection
|
2 |
WEB
|
Rafael Pedrero
|
2018-11-14
|
|
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
|
2 |
WEB
|
KoreLogic
|
2018-11-14
|
|
EdTv 2 - 'id' SQL Injection
|
0 |
WEB
|
Ihsan Sencan
|
2018-11-14
|
|
Electricks eCommerce 1.0 - Cross-Site Request Forgery (Change Admin Password)
|
1 |
WEB
|
Nawaf Alkeraithe
|
2018-11-14
|
|
Helpdezk 1.1.1 - 'query' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-11-14
|
|
iServiceOnline 1.0 - 'r' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-13
|
|
SIPve 0.0.2-R19 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-13
|
|
Webiness Inventory 2.3 - 'order' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-13
|
|
Webiness Inventory 2.3 - Arbitrary File Upload / Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-13
|
|
Maitra Mail Tracking System 1.7.2 - SQL Injection / Database File Download
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-13
|
|
Alive Parish 2.0.4 - SQL Injection / Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-13
|
|
ClipperCMS 1.3.3 - Cross-Site Request Forgery (File Upload)
|
2 |
WEB
|
Ameer Pornillos
|
2018-11-13
|
|
Silurus Classifieds Script 2.0 - 'wcategory' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-13
|
|
Gumbo CMS 0.99 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-13
|
|
ABC ERP 0.6.4 - Cross-Site Request Forgery (Update Admin)
|
2 |
WEB
|
Ihsan Sencan
|
2018-11-13
|
|
Easyndexer 1.0 - Arbitrary File Download
|
2 |
WEB
|
Ihsan Sencan
|