2019-01-14
|
|
Job Portal Platform 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Real Estate Custom Script 2.0 - SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
ThinkPHP 5.X - Remote Command Execution
|
3 |
WEB
|
vr_system
|
2019-01-14
|
|
Hucart CMS 5.7.4 - Cross-Site Request Forgery (Add Administrator Account)
|
4 |
WEB
|
AllenChen
|
2019-01-14
|
|
HealthNode Hospital Management System 1.0 - SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Lenovo R2105 - Cross-Site Request Forgery (Command Execution)
|
4 |
WEB
|
Nathu Nandwani
|
2019-01-14
|
|
Cleanto 5.0 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Find a Place CMS Directory 1.5 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Craigs Classified Ads CMS Theme 1.0.2 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Live Call Support Widget 1.5 - Remote Code Execution / SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Live Call Support Widget 1.5 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Twilio WEB To Fax Machine System Application 1.0 - SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Modern POS 1.3 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Modern POS 1.3 - Arbitrary File Download
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Horde Imp - 'imap_open' Remote Command Execution
|
3 |
WEB
|
Paolo Serracino_ Pietro Minniti_ Damiano Proietti
|
2019-01-14
|
|
i-doit CMDB 1.12 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
i-doit CMDB 1.12 - Arbitrary File Download
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-14
|
|
Across DR-810 ROM-0 - Backup File Disclosure
|
5 |
WEB
|
SajjadBnd
|
2019-01-11
|
|
Joomla! Component JoomCRM 1.1.1 - SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-11
|
|
Joomla! Component JoomProject 1.1.3.2 - Information Disclosure
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-11
|
|
Adapt Inventory Management System 1.0 - SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
OpenSource ERP 6.3.1. - SQL Injection
|
6 |
WEB
|
Emre ÖVÜNÇ
|
2019-01-10
|
|
eBrigade ERP 4.5 - SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
Event Locations 1.0.1 - 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
Event Calendar 3.7.4 - 'id' SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
MLMPro 1.0 - SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
Architectural 1.0 - 'email' SQL Injection
|
6 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
Shield CMS 2.2 - 'email' SQL Injection
|
5 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
doitX 1.0 - 'search' SQL Injection
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
Matrix MLM Script 1.0 - Information Disclosure
|
4 |
WEB
|
Ihsan Sencan
|
2019-01-10
|
|
eBrigade ERP 4.5 - Arbitrary File Download
|
4 |
WEB
|
AkkuS
|
2019-01-10
|
|
PEAR Archive_Tar < 1.4.4 - PHP Object Injection
|
4 |
WEB
|
Fariskhi Vidyan
|
2019-01-09
|
|
BlogEngine 3.3 - XML External Entity Injection
|
4 |
WEB
|
Netsparker
|
2019-01-09
|
|
ZTE MF65 BD_HDV6MF65V1.0.0B05 - Cross-Site Scripting
|
3 |
WEB
|
Nathu Nandwani
|
2019-01-09
|
|
Heatmiser Wifi Thermostat 1.7 - Cross-Site Request Forgery (Update Admin)
|
4 |
WEB
|
SajjadBnd
|
2017-03-02
|
|
MDwiki < 0.6.2 - Cross-Site Scripting
|
2 |
WEB
|
evi1m0
|
2019-01-08
|
|
Dolibarr ERP-CRM 8.0.4 - 'rowid' SQL Injection
|
3 |
WEB
|
Mehmet Onder
|
2019-01-08
|
|
CF Image Hosting Script 1.6.5 - (Delete all Pictures) Privilege Escalation
|
4 |
WEB
|
David Tavarez
|
2019-01-07
|
|
Huawei E5330 21.210.09.00.158 - Cross-Site Request Forgery (Send SMS)
|
4 |
WEB
|
Nathu Nandwani
|
2019-01-07
|
|
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 - JS/HTML Code Injection
|
4 |
WEB
|
LiquidWorm
|
2019-01-07
|
|
Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 - Cross-Site Request Forgery
|
5 |
WEB
|
LiquidWorm
|
2019-01-07
|
|
Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data
|
3 |
WEB
|
Anthony Cole
|
2019-01-07
|
|
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
|
5 |
WEB
|
Pongtorn Angsuchotmetee_ Vittawat Masaree
|
2019-01-07
|
|
MyT Project Management 1.5.1 - 'Charge[group_total]' SQL Injection
|
4 |
WEB
|
Mehmet Onder
|
2019-01-07
|
|
WordPress Plugin UserPro < 4.9.21 - User Registration Privilege Escalation
|
5 |
WEB
|
Noman Riffat
|
2019-01-07
|
|
phpMoAdmin MongoDB GUI 1.1.5 - Cross-Site Request Forgery / Cross-Site Scripting
|
4 |
WEB
|
Ozer Goker
|
2019-01-07
|
|
phpMoAdmin MongoDB GUI 1.1.5 - Cross-Site Request Forgery / Cross-Site Scripting
|
3 |
WEB
|
Ozer Goker
|
2019-01-07
|
|
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Scripting
|
4 |
WEB
|
Kumar Saurav
|
2019-01-07
|
|
MyBB OUGC Awards Plugin 1.8.3 - Persistent Cross-Site Scripting
|
4 |
WEB
|
0xB9
|
2019-01-07
|
|
LayerBB 1.1.1 - Persistent Cross-Site Scripting
|
5 |
WEB
|
0xB9
|
2019-01-07
|
|
All in One Video Downloader 1.2 - (Authenticated) SQL Injection
|
3 |
WEB
|
Deyaa Muhammad
|
2019-01-07
|
|
Embed Video Scripts - Persistent Cross-Site Scripting
|
3 |
WEB
|
Deyaa Muhammad
|
2019-01-02
|
|
Frog CMS 0.9.5 - Cross-Site Scripting
|
3 |
WEB
|
WangDudu
|
2019-01-02
|
|
WordPress Plugin Adicon Server 1.2 - 'selectedPlace' SQL Injection
|
3 |
WEB
|
Kaimi
|
2019-01-02
|
|
Vtiger CRM 7.1.0 - Remote Code Execution
|
3 |
WEB
|
AkkuS
|
2018-12-27
|
|
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 - Arbitrary File Upload
|
2 |
WEB
|
Kaimi
|
2018-12-27
|
|
bludit Pages Editor 3.0.0 - Arbitrary File Upload
|
3 |
WEB
|
BouSalman
|
2018-12-27
|
|
WordPress Plugin Audio Record 1.0 - Arbitrary File Upload
|
2 |
WEB
|
Kaimi
|
2018-12-27
|
|
Craft CMS 3.0.25 - Cross-Site Scripting
|
2 |
WEB
|
Raif Berkay Dincel
|
2018-11-30
|
|
PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
|
3 |
WEB
|
Alex Leahu
|
2018-12-15
|
|
phpMyAdmin 4.8.4 - 'AllowArbitraryServer' Arbitrary File Read
|
3 |
WEB
|
VulnSpy
|
2018-12-24
|
|
FrontAccounting 2.4.5 - 'SubmitUser' SQL Injection
|
3 |
WEB
|
Sainadh Jamalpur
|
2018-12-24
|
|
WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
linfeng
|
2018-12-24
|
|
WSTMart 2.0.8 - Cross-Site Scripting
|
2 |
WEB
|
linfeng
|
2018-12-21
|
|
ZeusCart 4.0 - Cross-Site Request Forgery (Deactivate Customer Accounts)
|
3 |
WEB
|
mqt
|
2018-12-19
|
|
IBM Operational Decision Manager 8.x - XML External Entity Injection
|
3 |
WEB
|
Mohamed M.Fouad
|
2018-12-19
|
|
Yeswiki Cercopitheque - 'id' SQL Injection
|
3 |
WEB
|
Mickael BROUTY
|
2018-12-19
|
|
Bolt CMS < 3.6.2 - Cross-Site Scripting
|
3 |
WEB
|
Raif Berkay Dincel
|
2018-12-19
|
|
Integria IMS 5.0.83 - Cross-Site Request Forgery
|
3 |
WEB
|
Javier Olmedo
|
2018-12-19
|
|
Integria IMS 5.0.83 - 'search_string' Cross-Site Scripting
|
3 |
WEB
|
Javier Olmedo
|
2018-12-19
|
|
Rukovoditel Project Management CRM 2.3.1 - Remote Code Execution (Metasploit)
|
3 |
WEB
|
AkkuS
|
2018-12-19
|
|
Hotel Booking Script 3.4 - Cross-Site Request Forgery (Change Admin Password)
|
3 |
WEB
|
Sainadh Jamalpur
|
2018-12-18
|
|
SDL Web Content Manager 8.5.0 - XML External Entity Injection
|
2 |
WEB
|
Ahmed Elhady Mohamed
|
2018-12-14
|
|
Double Your Bitcoin Script Automatic - Authentication Bypass
|
3 |
WEB
|
Veyselxan
|
2018-12-14
|
|
Facebook And Google Reviews System For Businesses 1.1 - Remote Code Execution
|
3 |
WEB
|
Ihsan Sencan
|
2018-12-14
|
|
Facebook And Google Reviews System For Businesses 1.1 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2018-12-14
|
|
Facebook And Google Reviews System For Businesses - Cross-Site Request Forgery (Change Admin Passwor
|
2 |
WEB
|
Veyselxan
|
2018-12-14
|
|
Huawei Router HG532e - Command Execution
|
3 |
WEB
|
Rebellion
|
2018-12-14
|
|
Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2)
|
3 |
WEB
|
alt3kx
|
2018-12-14
|
|
Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure
|
3 |
WEB
|
alt3kx
|
2018-12-14
|
|
Responsive FileManager 9.13.4 - Multiple Vulnerabilities
|
3 |
WEB
|
Fariskhi Vidyan
|
2018-12-11
|
|
Adobe ColdFusion 2018 - Arbitrary File Upload
|
3 |
WEB
|
Vahagn Vardanyan
|
2018-12-11
|
|
ThinkPHP 5.0.23/5.1.31 - Remote Code Execution
|
4 |
WEB
|
VulnSpy
|
2018-12-11
|
|
WordPress Plugin AutoSuggest 0.24 - 'wpas_keys' SQL Injection
|
3 |
WEB
|
Kaimi
|
2018-12-11
|
|
HotelDruid 2.3.0 - 'id_utente_mod' SQL Injection
|
3 |
WEB
|
Sainadh Jamalpur
|
2018-12-11
|
|
Apache OFBiz 16.11.05 - Cross-Site Scripting
|
3 |
WEB
|
DKM
|
2014-02-17
|
|
IceWarp Mail Server 11.0.0.0 - Cross-Site Scripting
|
3 |
WEB
|
Usman Saeed
|
2017-05-05
|
|
Sitecore CMS 8.2 - Cross-Site Scripting / Arbitrary File Disclosure
|
3 |
WEB
|
Usman Saeed
|
2018-12-11
|
|
ZTE ZXHN H168N - Improper Access Restrictions
|
3 |
WEB
|
Usman Saeed
|
2018-12-11
|
|
Huawei B315s-22 - Information Leak
|
3 |
WEB
|
Usman Saeed
|
2018-12-11
|
|
TP-Link wireless router Archer C1200 - Cross-Site Scripting
|
3 |
WEB
|
Usman Saeed
|
2018-12-11
|
|
PrinterOn Enterprise 4.1.4 - Arbitrary File Deletion
|
3 |
WEB
|
bzyo
|
2018-12-11
|
|
DomainMOD 4.11.01 - Cross-Site Scripting
|
3 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-11
|
|
PrestaShop 1.6.x/1.7.x - Remote Code Execution
|
3 |
WEB
|
Fariskhi Vidyan
|
2018-12-11
|
|
Alumni Tracer SMS Notification - SQL Injection / Cross-Site Request Forgery
|
3 |
WEB
|
Ihsan Sencan
|
2018-12-11
|
|
Alumni Tracer SMS Notification - SQL Injection / Cross-Site Request Forgery
|
4 |
WEB
|
Ihsan Sencan
|
2018-12-11
|
|
Tourism Website Blog - Remote Code Execution / SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2018-12-09
|
|
DomainMOD 4.11.01 - 'DisplayName' Cross-Site Scripting
|
3 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-09
|
|
Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting
|
3 |
WEB
|
Gustavo Sorondo
|
2018-12-09
|
|
i-doit CMDB 1.11.2 - Remote Code Execution
|
3 |
WEB
|
AkkuS
|
2018-12-05
|
|
HasanMWB 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2018-12-04
|
|
FreshRSS 1.11.1 - Cross-Site Scripting
|
3 |
WEB
|
Netsparker
|
2018-12-04
|
|
DomainMOD 4.11.01 - Registrar Cross-Site Scripting
|
3 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-04
|
|
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection
|
3 |
WEB
|
Artem Metla
|
2018-12-04
|
|
DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting
|
3 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-04
|
|
DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting
|
3 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-04
|
|
Dolibarr ERP/CRM 8.0.3 - Cross-Site Scripting
|
3 |
WEB
|
AkkuS
|
2018-12-04
|
|
KeyBase Botnet 1.5 - SQL Injection
|
3 |
WEB
|
n4pst3r
|
2018-12-04
|
|
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
|
3 |
WEB
|
hyp3rlinx
|
2018-12-04
|
|
DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting
|
3 |
WEB
|
Mohammed Abdul Raheem
|
2018-12-04
|
|
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
|
3 |
WEB
|
Luca.Chiou
|
2018-12-03
|
|
WordPress Plugin Advanced-Custom-Fields 5.7.7 - Cross-Site Scripting
|
2 |
WEB
|
Loading Kura Kura
|
2018-12-03
|
|
Apache Superset < 0.23 - Remote Code Execution
|
2 |
WEB
|
David May
|
2018-12-03
|
|
PHP Server Monitor 3.3.1 - Cross-Site Request Forgery
|
2 |
WEB
|
Javier Olmedo
|
2018-12-03
|
|
Joomla! Component JE Photo Gallery 1.1 - 'categoryid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-12-03
|
|
PaloAlto Networks Expedition Migration Tool 1.0.106 - Information Disclosure
|
2 |
WEB
|
ParagonSec
|
2018-12-03
|
|
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Cross-Site Scripting
|
3 |
WEB
|
Luca.Chiou
|
2018-12-03
|
|
Fleetco Fleet Maintenance Management 1.2 - Remote Code Execution
|
2 |
WEB
|
AkkuS
|
2018-11-30
|
|
Synaccess netBooter NP-02x/NP-08x 6.8 - Authentication Bypass
|
2 |
WEB
|
LiquidWorm
|
2018-11-30
|
|
Schneider Electric PLC - Session Calculation Authentication Bypass
|
2 |
WEB
|
Photubias
|
2018-11-26
|
|
Zyxel VMG1312-B10D 5.13AAXA.8 - Directory Traversal
|
3 |
WEB
|
numan türle
|
2018-11-26
|
|
No-Cms 1.0 - 'order_by' SQL Injection
|
3 |
WEB
|
Loading Kura Kura
|
2018-11-26
|
|
Ticketly 1.0 - 'kind_id' SQL Injection
|
3 |
WEB
|
Javier Olmedo
|
2018-11-26
|
|
WordPress Plugin Easy Testimonials 3.2 - Cross-Site Scripting
|
2 |
WEB
|
En_dust
|
2018-11-26
|
|
Ricoh myPrint 2.9.2.4 - Hard-Coded Credentials
|
3 |
WEB
|
Hodorsec
|