2018-07-17
|
|
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway - File Manipulation
|
2 |
WEB
|
LiquidWorm
|
2018-07-17
|
|
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway - Configuration Download
|
3 |
WEB
|
LiquidWorm
|
2018-07-17
|
|
Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway - Cross-Site Request Forgery
|
3 |
WEB
|
LiquidWorm
|
2018-07-16
|
|
WordPress Plugin Job Manager 4.1.0 - Cross-Site Scripting
|
3 |
WEB
|
Berk Dusunur
|
2018-07-16
|
|
VelotiSmart WiFi B-380 Camera - Directory Traversal
|
3 |
WEB
|
Miguel Mendez Z
|
2018-07-16
|
|
Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection
|
5 |
WEB
|
alt3kx
|
2018-07-13
|
|
Grundig Smart Inter@ctive 3.0 - Cross-Site Request Forgery
|
3 |
WEB
|
t4rkd3vilz
|
2018-07-13
|
|
Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload
|
2 |
WEB
|
Safak Aslan
|
2018-07-13
|
|
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
|
2 |
WEB
|
SEC Consult
|
2018-07-13
|
|
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
|
2 |
WEB
|
Core Security
|
2018-07-13
|
|
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
|
2 |
WEB
|
SEC Consult
|
2018-07-11
|
|
Dicoogle PACS 2.5.0 - Directory Traversal
|
3 |
WEB
|
Carlos Avila
|
2018-07-11
|
|
Instagram-Clone Script 2.0 - Cross-Site Scripting
|
3 |
WEB
|
L0RD
|
2018-07-10
|
|
D-Link DIR601 2.02 - Credential Disclosure
|
2 |
WEB
|
Thomas Zuk
|
2018-07-10
|
|
Elektronischer Leitz-Ordner 10 - SQL Injection
|
3 |
WEB
|
Jens Regel
|
2018-07-07
|
|
Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code Execution
|
3 |
WEB
|
bobsecq
|
2018-07-10
|
|
WolfSight CMS 3.2 - SQL Injection
|
3 |
WEB
|
Berk Dusunur
|
2018-07-04
|
|
Gitea 1.4.0 - Remote Code Execution
|
3 |
WEB
|
Kacper Szurek
|
2018-07-09
|
|
Umbraco CMS SeoChecker Plugin 1.9.2 - Cross-Site Scripting
|
3 |
WEB
|
Ahmed Elhady Mohamed
|
2018-07-06
|
|
Airties AIR5444TT - Cross-Site Scripting
|
3 |
WEB
|
Raif Berkay Dincel
|
2018-07-05
|
|
ADB Broadband Gateways / Routers - Authorization Bypass
|
3 |
WEB
|
SEC Consult
|
2018-07-05
|
|
SoftExpert Excellence Suite 2.0 - 'cddocument' SQL Injection
|
3 |
WEB
|
Seren PORSUK
|
2018-07-04
|
|
ShopNx - Arbitrary File Upload
|
3 |
WEB
|
L0RD
|
2018-07-04
|
|
Online Trade - Information Disclosure
|
3 |
WEB
|
L0RD
|
2018-07-04
|
|
CMS Made Simple 2.2.5 - (Authenticated) Remote Code Execution
|
3 |
WEB
|
Mustafa Hasan
|
2018-07-04
|
|
ManageEngine Exchange Reporter Plus < Build 5311 - Remote Code Execution
|
3 |
WEB
|
Kacper Szurek
|
2018-07-03
|
|
ntop-ng < 3.4.180617 - Authentication Bypass
|
2 |
WEB
|
Ioannis Profetis
|
2018-07-02
|
|
Dolibarr ERP/CRM < 7.0.3 - PHP Code Injection
|
3 |
WEB
|
om3rcitak
|
2018-07-02
|
|
DAMICMS 6.0.0 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
bay0net
|
2018-07-02
|
|
VMware NSX SD-WAN Edge < 3.1.2 - Command Injection
|
3 |
WEB
|
ParagonSec
|
2018-07-02
|
|
Geutebruck 5.02024 G-Cam/EFD-2250 - 'simple_loglistjs.cgi' Remote Command Execution (Metasploit)
|
5 |
WEB
|
RandoriSec
|
2018-06-28
|
|
Cisco Adaptive Security Appliance - Path Traversal
|
2 |
WEB
|
Yassine Aboukir
|
2018-06-28
|
|
DIGISOL DG-HR3400 Wireless Router - Cross-Site Scripting
|
3 |
WEB
|
Adipta Basu
|
2018-06-28
|
|
hycus CMS 1.0.4 - Authentication Bypass
|
2 |
WEB
|
Berk Dusunur
|
2018-06-28
|
|
HongCMS 3.0.0 - (Authenticated) SQL Injection
|
2 |
WEB
|
Hzllaga
|
2018-06-28
|
|
BEESCMS 4.0 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
bay0net
|
2018-06-27
|
|
HPE VAN SDN 2.7.18.0503 - Remote Root
|
2 |
WEB
|
KoreLogic
|
2018-06-27
|
|
WordPress Core < 4.9.6 - (Authenticated) Arbitrary File Deletion
|
2 |
WEB
|
VulnSpy
|
2018-06-26
|
|
Liferay Portal < 7.0.4 - Server-Side Request Forgery
|
2 |
WEB
|
Mehmet Ince
|
2018-06-25
|
|
WordPress Plugin iThemes Security < 7.0.3 - SQL Injection
|
2 |
WEB
|
Çlirim Emini
|
2018-06-25
|
|
WordPress Plugin Comments Import & Export < 2.0.4 - CSV Injection
|
2 |
WEB
|
Bhushan B. Patil
|
2018-06-25
|
|
Intex Router N-150 - Arbitrary File Upload
|
2 |
WEB
|
Samrat Das
|
2018-06-25
|
|
Ecessa ShieldLink SL175EHQ < 10.7.4 - Cross-Site Request Forgery (Add Superuser)
|
2 |
WEB
|
LiquidWorm
|
2018-06-25
|
|
AsusWRT RT-AC750GF - Cross-Site Request Forgery (Change Admin Password)
|
3 |
WEB
|
Wadeek
|
2018-06-25
|
|
Ecessa WANWorx WVR-30 < 10.7.4 - Cross-Site Request Forgery (Add Superuser)
|
2 |
WEB
|
LiquidWorm
|
2018-06-25
|
|
DIGISOL DG-BR4000NG - Cross-Site Scripting
|
2 |
WEB
|
Adipta Basu
|
2018-06-25
|
|
Intex Router N-150 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
Samrat Das
|
2018-06-25
|
|
Ecessa Edge EV150 10.7.4 - Cross-Site Request Forgery (Add Superuser)
|
1 |
WEB
|
LiquidWorm
|
2018-06-25
|
|
WordPress Plugin Advanced Order Export For WooCommerce < 1.5.4 - CSV Injection
|
3 |
WEB
|
Bhushan B. Patil
|
2018-06-22
|
|
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (2)
|
3 |
WEB
|
VulnSpy
|
2018-06-22
|
|
phpLDAPadmin 1.2.2 - 'server_id' LDAP Injection (Username)
|
3 |
WEB
|
Berk Dusunur
|
2018-06-21
|
|
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (1)
|
3 |
WEB
|
ChaMd5
|
2018-06-22
|
|
GreenCMS 2.3.0603 - Information Disclosure
|
3 |
WEB
|
vr_system
|
2018-06-21
|
|
LFCMS 3.7.0 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
bay0net
|
2018-06-21
|
|
LFCMS 3.7.0 - Cross-Site Request Forgery (Add User)
|
3 |
WEB
|
bay0net
|
2018-06-20
|
|
VideoInsight WebClient 5 - SQL Injection
|
3 |
WEB
|
vosec
|
2018-06-20
|
|
IPConfigure Orchid VMS 2.0.5 - Directory Traversal / Information Disclosure (Metasploit)
|
2 |
WEB
|
Nettitude
|
2018-06-20
|
|
IPConfigure Orchid VMS 2.0.5 - Directory Traversal / Information Disclosure (Metasploit)
|
2 |
WEB
|
Nettitude
|
2018-06-20
|
|
Apache CouchDB < 2.1.0 - Remote Code Execution
|
2 |
WEB
|
Cody Zacharias
|
2018-06-20
|
|
TP-Link TL-WA850RE - Remote Command Execution
|
2 |
WEB
|
yoresongo
|
2018-06-20
|
|
NewMark CMS 2.1 - 'sec_id' SQL Injection
|
2 |
WEB
|
Berk Dusunur
|
2018-06-20
|
|
MaDDash 2.0.2 - Directory Listing
|
2 |
WEB
|
ManhNho
|
2018-06-20
|
|
Mirasys DVMS Workstation 5.12.6 - Path Traversal
|
2 |
WEB
|
Onvio
|
2018-06-18
|
|
Redatam Web Server < 7 - Directory Traversal
|
3 |
WEB
|
Berk Dusunur
|
2018-06-18
|
|
RabbitMQ Web Management < 3.7.6 - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
Dolev Farhi
|
2018-06-18
|
|
Joomla! Component Jomres 9.11.2 - Cross-Site Request Forgery (Add User)
|
4 |
WEB
|
L0RD
|
2018-06-15
|
|
Dimofinf CMS 3.0.0 - Cross-Site Scripting
|
3 |
WEB
|
Renzi
|
2018-06-15
|
|
OEcms 3.1 - Cross-Site Scripting
|
3 |
WEB
|
Renzi
|
2018-06-14
|
|
Joomla! Component Ek Rishta 2.10 - SQL Injection
|
4 |
WEB
|
Guilherme Assmann
|
2018-06-13
|
|
Redaxo CMS Mediapool Addon < 5.5.1 - Arbitrary File Upload
|
3 |
WEB
|
h0n1gsp3cht
|
2018-06-13
|
|
MACCMS 10 - Cross-Site Request Forgery (Add User)
|
4 |
WEB
|
bay0net
|
2018-06-12
|
|
WordPress Plugin Ultimate Form Builder Lite < 1.3.7 - SQL Injection
|
3 |
WEB
|
defensecode
|
2018-06-12
|
|
WordPress Plugin Google Map < 4.0.4 - SQL Injection
|
2 |
WEB
|
defensecode
|
2018-06-12
|
|
Canon PrintMe EFI - Cross-Site Scripting
|
3 |
WEB
|
Huy Kha
|
2018-06-12
|
|
OX App Suite 7.8.4 - Multiple Vulnerabilities
|
1 |
WEB
|
Open-Xchange
|
2018-06-12
|
|
OX App Suite 7.8.4 - Multiple Vulnerabilities
|
2 |
WEB
|
Open-Xchange
|
2018-06-11
|
|
Siaberry 1.2.2 - Command Injection
|
3 |
WEB
|
Space Duck
|
2018-06-12
|
|
Joomla! Component EkRishta 2.10 - 'username' SQL Injection
|
2 |
WEB
|
L0RD
|
2018-06-11
|
|
Schools Alert Management Script - Arbitrary File Read
|
2 |
WEB
|
M3@Pandas
|
2018-06-11
|
|
Schools Alert Management Script - 'get_sec.php' SQL Injection
|
3 |
WEB
|
M3@Pandas
|
2018-06-11
|
|
userSpice 4.3.24 - Username Enumeration
|
2 |
WEB
|
Dolev Farhi
|
2018-06-11
|
|
userSpice 4.3.24 - 'X-Forwarded-For' Cross-Site Scripting
|
2 |
WEB
|
Dolev Farhi
|
2018-06-11
|
|
Schools Alert Management Script - Arbitrary File Deletion
|
2 |
WEB
|
M3@Pandas
|
2018-06-11
|
|
Joomla! Component EkRishta 2.10 - 'cid' SQL Injection
|
2 |
WEB
|
41!kh4224rDz
|
2018-06-11
|
|
Event Manager Admin panel - 'events_new.php' SQL injection
|
2 |
WEB
|
telahdihapus
|
2018-06-11
|
|
WordPress Plugin Pie Register < 3.0.9 - Blind SQL Injection
|
2 |
WEB
|
Manuel García Cárdenas
|
2018-06-11
|
|
Schools Alert Management Script - SQL Injection
|
2 |
WEB
|
M3@Pandas
|
2018-06-08
|
|
Splunk < 7.0.1 - Information Disclosure
|
3 |
WEB
|
KoF2002
|
2018-06-08
|
|
XiongMai uc-httpd 1.0.0 - Buffer Overflow
|
2 |
WEB
|
Andrew Watson
|
2018-06-07
|
|
Monstra CMS < 3.0.4 - Cross-Site Scripting (1)
|
3 |
WEB
|
DEEPIN2
|
2018-06-07
|
|
WordPress Plugin Contact Form Maker 1.12.20 - SQL Injection
|
3 |
WEB
|
defensecode
|
2018-06-07
|
|
WordPress Plugin Form Maker 1.12.24 - SQL Injection
|
2 |
WEB
|
defensecode
|
2018-06-07
|
|
WampServer 3.0.6 - Cross-Site Request Forgery
|
3 |
WEB
|
L0RD
|
2018-06-05
|
|
Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email)
|
3 |
WEB
|
Kl3_GMjq6
|
2018-06-04
|
|
Brother HL Series Printers 1.15 - Cross-Site Scripting
|
4 |
WEB
|
Huy Kha
|
2018-06-05
|
|
Pagekit < 1.0.13 - Cross-Site Scripting Code Generator
|
2 |
WEB
|
DEEPIN2
|
2018-06-05
|
|
MyBB Recent Threads Plugin 1.0 - Cross-Site Scripting
|
4 |
WEB
|
0xB9
|
2018-06-04
|
|
EMS Master Calendar < 8.0.0.20180520 - Cross-Site Scripting
|
2 |
WEB
|
Chris Barretto
|
2018-06-04
|
|
SearchBlox 8.6.7 - XML External Entity Injection
|
2 |
WEB
|
Ahmet Gurel
|
2018-06-03
|
|
GreenCMS 2.3.0603 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
xichao
|
2018-06-03
|
|
GreenCMS 2.3.0603 - Cross-Site Request Forgery / Remote Code Execution
|
1 |
WEB
|
xichao
|
2018-06-03
|
|
Smartshop 1 - Cross-Site Request Forgery
|
1 |
WEB
|
L0RD
|
2018-06-03
|
|
Smartshop 1 - 'id' SQL Injection
|
2 |
WEB
|
L0RD
|
2018-05-31
|
|
Grid Pro Big Data 1.0 - SQL Injection
|
4 |
WEB
|
Kağan Çapar
|
2018-05-31
|
|
CSV Import & Export 1.1.0 - SQL Injection / Cross-Site Scripting
|
3 |
WEB
|
Kağan Çapar
|
2018-05-31
|
|
PHP Dashboards NEW 5.5 - 'email' SQL Injection
|
4 |
WEB
|
Kağan Çapar
|
2018-05-31
|
|
New STAR 2.1 - SQL Injection / Cross-Site Scripting
|
1 |
WEB
|
Kağan Çapar
|
2018-05-31
|
|
TAC Xenta 511/911 - Directory Traversal
|
3 |
WEB
|
Marek Cybul
|
2018-05-30
|
|
Dolibarr ERP/CRM 7.0.0 - (Authenticated) SQL Injection
|
3 |
WEB
|
Sysdream
|
2018-05-30
|
|
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
|
2 |
WEB
|
Amine Taouirsa
|
2018-05-30
|
|
Yosoro 1.0.4 - Remote Code Execution
|
3 |
WEB
|
Carlo Pelliccioni
|
2018-05-30
|
|
SearchBlox 8.6.6 - Cross-Site Request Forgery
|
2 |
WEB
|
Ahmet Gurel
|
2018-05-29
|
|
Facebook Clone Script 1.0.5 - Cross-Site Request Forgery
|
3 |
WEB
|
L0RD
|
2018-05-29
|
|
Facebook Clone Script 1.0.5 - 'search' SQL Injection
|
2 |
WEB
|
L0RD
|
2018-05-29
|
|
MyBB ChangUonDyU Plugin 1.0.2 - Cross-Site Scripting
|
4 |
WEB
|
0xB9
|
2018-05-29
|
|
NUUO NVRmini2 / NVRsolo - Arbitrary File Upload
|
3 |
WEB
|
M3@Pandas
|
2018-05-29
|
|
Sitemakin SLAC 1.0 - 'my_item_search' SQL Injection
|
3 |
WEB
|
Divya Jain
|
2018-05-29
|
|
IssueTrak 7.0 - SQL Injection
|
4 |
WEB
|
Chris Anastasio
|
2018-05-28
|
|
wityCMS 0.6.1 - Cross-Site Scripting
|
3 |
WEB
|
Nathu Nandwani
|
2018-05-28
|
|
Joomla! Component JoomOCShop 1.0 - Cross-Site Request Forgery
|
3 |
WEB
|
L0RD
|
2018-05-28
|
|
Joomla! Component jCart for OpenCart 2.3.0.2 - Cross-Site Request Forgery
|
3 |
WEB
|
L0RD
|
2018-05-28
|
|
Joomla! Component Full Social 1.1.0 - 'search_query' SQL Injection
|
3 |
WEB
|
L0RD
|
2018-05-28
|
|
WordPress Plugin Events Calendar - SQL Injection
|
3 |
WEB
|
AkkuS
|
2018-05-28
|
|
DomainMod 4.09.03 - 'sslpaid' Cross-Site Scripting
|
3 |
WEB
|
longer
|
2018-05-28
|
|
DomainMod 4.09.03 - 'oid' Cross-Site Scripting
|
2 |
WEB
|
longer
|