2018-05-28
|
|
TP-Link TL-WR840N/TL-WR841N - Authenticaton Bypass
|
2 |
WEB
|
BlackFog Team
|
2018-05-27
|
|
Baby Names Search Engine 1.0 - 'a' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-27
|
|
My Directory 2.0 - SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
AkkuS
|
2018-05-27
|
|
ClipperCMS 1.3.3 - Cross-Site Scripting
|
2 |
WEB
|
Nathu Nandwani
|
2018-05-27
|
|
Listing Hub CMS 1.0 - SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-27
|
|
BookingWizz Booking System 5.5 - 'id' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-27
|
|
Lyrist - 'id' SQL Injection
|
2 |
WEB
|
Meisam Monsef
|
2018-05-27
|
|
Sharetronix CMS 3.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
|
2 |
WEB
|
Hesam Bazvand
|
2018-05-27
|
|
Ingenious School Management System - 'id' SQL Injection
|
1 |
WEB
|
Meisam Monsef
|
2018-05-27
|
|
WordPress Plugin Booking Calendar 3.0.0 - SQL Injection / Cross-Site Scripting
|
1 |
WEB
|
AkkuS
|
2018-05-26
|
|
easyLetters 1.0 - 'id' SQL Injection
|
1 |
WEB
|
AkkuS
|
2018-05-26
|
|
mySurvey 1.0 - 'id' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-26
|
|
EasyService Billing 1.0 - 'q' SQL Injection
|
1 |
WEB
|
Divya Jain
|
2018-05-26
|
|
EasyService Billing 1.0 - Cross-Site Scripting
|
1 |
WEB
|
Divya Jain
|
2018-05-26
|
|
EasyService Billing 1.0 - Cross-Site Request Forgery
|
1 |
WEB
|
Divya Jain
|
2018-05-26
|
|
Ajax Full Featured Calendar 2.0 - 'search' SQL Injection
|
1 |
WEB
|
AkkuS
|
2018-05-26
|
|
Employee Work Schedule 5.9 - 'cal_id' SQL Injection
|
1 |
WEB
|
AkkuS
|
2018-05-25
|
|
Oracle WebCenter FatWire Content Server < 7 - Improper Access Control
|
2 |
WEB
|
Sebastian Cornejo
|
2018-05-25
|
|
SAP Internet Transaction Server 6200.x - Session Fixation / Cross-Site Scripting
|
2 |
WEB
|
J. Carrillo Lencina
|
2018-05-25
|
|
MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Scripting
|
2 |
WEB
|
0xB9
|
2018-05-25
|
|
KomSeo Cart 1.3 - 'my_item_search' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-25
|
|
Oracle WebCenter Sites 11.1.1.8.0/12.2.1.x - Cross-Site Scripting
|
2 |
WEB
|
Richard Alviarez
|
2018-05-24
|
|
EU MRV Regulatory Complete Solution 1 - Authentication Bypass
|
2 |
WEB
|
Veyselxan
|
2018-05-24
|
|
Honeywell XL Web Controller - Cross-Site Scripting
|
1 |
WEB
|
t4rkd3vilz
|
2018-05-24
|
|
Timber 1.1 - Cross-Site Request Forgery
|
2 |
WEB
|
L0RD
|
2018-05-24
|
|
PaulNews 1.0 - 'keyword' SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
AkkuS
|
2018-05-24
|
|
ASP.NET jVideo Kit - 'query' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
WordPress Plugin Peugeot Music - Arbitrary File Upload
|
2 |
WEB
|
Mr.7z
|
2018-05-23
|
|
SKT LTE Wi-Fi SDT-CW3B1 - Unauthorized Admin Credential Change
|
2 |
WEB
|
Safak Aslan
|
2018-05-23
|
|
Honeywell Scada System - Information Disclosure
|
2 |
WEB
|
t4rkd3vilz
|
2018-05-23
|
|
Mcard Mobile Card Selling Platform 1 - SQL Injection
|
2 |
WEB
|
L0RD
|
2018-05-23
|
|
eWallet Online Payment Gateway 2 - Cross-Site Request Forgery
|
2 |
WEB
|
L0RD
|
2018-05-23
|
|
Wecodex Restaurant CMS 1.0 - 'Login' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
Wecodex Hotel CMS 1.0 - 'Admin Login' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
Library CMS 1.0 - SQL Injection
|
1 |
WEB
|
AkkuS
|
2018-05-23
|
|
School Management System CMS 1.0 - 'username' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
SAT CFDI 3.3 - SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
Wecodex Store Paypal 1.0 - SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
Shipping System CMS 1.0 - SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
GPSTracker 1.0 - 'id' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
Online Store System CMS 1.0 - SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
Gigs 2.0 - 'username' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
Mobile Card Selling Platform 1 - Cross-Site Request Forgery
|
1 |
WEB
|
L0RD
|
2018-05-23
|
|
PHP Dashboards 4.5 - SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
PHP Dashboards 4.5 - 'email' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
MySQL Blob Uploader 1.7 - 'home-filet-edit.php' SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
MySQL Blob Uploader 1.7 - 'home-file-edit.php' SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
MySQL Blob Uploader 1.7 - 'download.php' SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
MySQL Smart Reports 1.0 - 'id' SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
AkkuS
|
2018-05-23
|
|
EasyService Billing 1.0 - 'p1' SQL Injection
|
1 |
WEB
|
AkkuS
|
2018-05-23
|
|
EasyService Billing 1.0 - SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
AkkuS
|
2018-05-22
|
|
Easy File Uploader 1.7 - SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
AkkuS
|
2018-05-22
|
|
NewsBee CMS 1.4 - 'download.php' SQL Injection
|
2 |
WEB
|
AkkuS
|
2018-05-22
|
|
Feedy RSS News Ticker 2.0 - 'cat' SQL Injection
|
1 |
WEB
|
AkkuS
|
2018-05-22
|
|
NewsBee CMS 1.4 - 'home-text-edit.php' SQL Injection
|
1 |
WEB
|
AkkuS
|
2018-05-22
|
|
Auto Car 1.2 - 'car_title' SQL Injection / Cross-Site Scripting
|
1 |
WEB
|
L0RD
|
2018-05-22
|
|
NewsBee CMS 1.4 - 'home-text-edit.php' SQL Injection
|
1 |
WEB
|
AkkuS
|
2018-05-22
|
|
iSocial 1.2.0 - Cross-Site Scripting / Cross-Site Request Forgery
|
2 |
WEB
|
L0RD
|
2018-05-22
|
|
ERPnext 11 - Cross-Site Scripting
|
2 |
WEB
|
Veerababu Penugonda
|
2018-05-22
|
|
PaulPrinting CMS Printing 1.0 - SQL Injection
|
2 |
WEB
|
Mehmet Onder
|
2018-05-22
|
|
Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting
|
1 |
WEB
|
t4rkd3vilz
|
2018-05-22
|
|
WebSocket Live Chat - Cross-Site Scripting
|
1 |
WEB
|
Alireza Norkazemi
|
2018-05-22
|
|
Zechat 1.5 - SQL Injection / Cross-Site Request Forgery
|
2 |
WEB
|
L0RD
|
2018-05-22
|
|
Nordex N149/4.0-4.5 - SQL Injection
|
2 |
WEB
|
t4rkd3vilz
|
2018-05-21
|
|
Wchat PHP AJAX Chat Script 1.5 - Cross-Site Scripting
|
2 |
WEB
|
L0RD
|
2018-05-21
|
|
Model Agency Media House & Model Gallery 1.0 - Multiple Vulnerabilities
|
2 |
WEB
|
L0RD
|
2018-05-21
|
|
Merge PACS 7.0 - Cross-Site Request Forgery
|
2 |
WEB
|
Safak Aslan
|
2018-05-21
|
|
Auto Dealership & Vehicle Showroom WebSys 1.0 - Multiple Vulnerabilities
|
3 |
WEB
|
L0RD
|
2018-05-21
|
|
Schneider Electric PLCs - Cross-Site Request Forgery
|
2 |
WEB
|
t4rkd3vilz
|
2018-05-21
|
|
Teradek Slice 7.3.15 - Cross-Site Request Forgery
|
1 |
WEB
|
LiquidWorm
|
2018-05-21
|
|
Teradek Cube 7.3.6 - Cross-Site Request Forgery
|
1 |
WEB
|
LiquidWorm
|
2018-05-21
|
|
Teradek VidiU Pro 3.0.3 - Server-Side Request Forgery
|
1 |
WEB
|
LiquidWorm
|
2018-05-21
|
|
Teradek VidiU Pro 3.0.3 - Cross-Site Request Forgery
|
1 |
WEB
|
LiquidWorm
|
2018-05-21
|
|
GitBucket 4.23.1 - Remote Code Execution
|
1 |
WEB
|
Kacper Szurek
|
2018-05-21
|
|
Siemens SIMATIC S7-1200 CPU - Cross-Site Request Forgery
|
1 |
WEB
|
t4rkd3vilz
|
2018-05-21
|
|
ManageEngine Recovery Manager Plus 5.3 - Cross-Site Scripting
|
1 |
WEB
|
Ahmet Gurel
|
2018-05-21
|
|
Zenar Content Management System - Cross-Site Scripting
|
3 |
WEB
|
Berk Dusunur
|
2018-05-21
|
|
Flippy DamnFacts - Viral Fun Facts Sharing Script 1.1.0 - Cross-Site Scripting / Cross-Site Request
|
2 |
WEB
|
L0RD
|
2018-05-21
|
|
Flippy DamnFacts - Viral Fun Facts Sharing Script 1.1.0 - Cross-Site Scripting / Cross-Site Request
|
2 |
WEB
|
L0RD
|
2018-05-21
|
|
Private Message PHP Script 2.0 - Cross-Site Scripting
|
2 |
WEB
|
L0RD
|
2018-05-21
|
|
Superfood 1.0 - Multiple Vulnerabilities
|
2 |
WEB
|
L0RD
|
2018-05-20
|
|
Joomla! Component EkRishta 2.10 - Cross-Site Scripting / SQL Injection
|
2 |
WEB
|
Sina Kheirkhah
|
2018-05-20
|
|
D-Link DSL-3782 - Authentication Bypass
|
2 |
WEB
|
Giulio Comi
|
2018-05-18
|
|
SAP B2B / B2C CRM 2.x < 4.x - Local File Inclusion
|
2 |
WEB
|
Richard Alviarez
|
2018-05-18
|
|
Infinity Market Classified Ads Script 1.6.2 - Cross-Site Request Forgery
|
1 |
WEB
|
L0RD
|
2018-05-18
|
|
Cisco SA520W Security Appliance - Path Traversal
|
1 |
WEB
|
Nassim Asrir
|
2018-05-18
|
|
SAP NetWeaver Web Dynpro 6.4 < 7.5 - Information Disclosure
|
0 |
WEB
|
Richard Alviarez
|
2018-05-18
|
|
Monstra CMS < 3.0.4 - Cross-Site Scripting (2)
|
2 |
WEB
|
Berk Dusunur
|
2018-05-18
|
|
Healwire Online Pharmacy 3.0 - Cross-Site Scripting / Cross-Site Request Forgery
|
2 |
WEB
|
L0RD
|
2018-05-17
|
|
Powerlogic/Schneider Electric IONXXXX Series - Cross-Site Request Forgery
|
2 |
WEB
|
t4rkd3vilz
|
2018-05-17
|
|
SuperCom Online Shopping Ecommerce Cart 1 - Persistent Cross-Site scripting / Cross site request for
|
2 |
WEB
|
L0RD
|
2018-05-17
|
|
SuperCom Online Shopping Ecommerce Cart 1 - Persistent Cross-Site scripting / Cross site request for
|
2 |
WEB
|
L0RD
|
2018-05-17
|
|
Intelbras NCLOUD 300 1.0 - Authentication bypass
|
1 |
WEB
|
Pedro Aguiar
|
2018-05-17
|
|
NodAPS 4.0 - SQL injection / Cross-Site Request Forgery
|
2 |
WEB
|
L0RD
|
2018-05-17
|
|
NodAPS 4.0 - SQL injection / Cross-Site Request Forgery
|
2 |
WEB
|
L0RD
|
2018-05-16
|
|
RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross
|
1 |
WEB
|
SEC Consult
|
2018-05-16
|
|
RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross
|
1 |
WEB
|
SEC Consult
|
2018-05-16
|
|
WordPress Plugin Metronet Tag Manager 1.2.7 - Cross-Site Request Forgery
|
2 |
WEB
|
dxw
|
2018-05-16
|
|
totemomail Encryption Gateway 6.0.0 Build 371 - Cross-Site Request Forgery
|
0 |
WEB
|
Compass Security
|
2018-05-16
|
|
Horse Market Sell & Rent Portal Script 1.5.7 - Cross-Site Request Forgery
|
1 |
WEB
|
L0RD
|
2018-05-16
|
|
Multiplayer BlackJack Online Casino Game 2.5 - Cross-Site Scripting
|
1 |
WEB
|
L0RD
|
2018-05-16
|
|
Rockwell Scada System 27.011 - Cross-Site Scripting
|
1 |
WEB
|
t4rkd3vilz
|
2018-05-16
|
|
VirtueMart 3.1.14 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Mattia Furlani
|
2018-05-16
|
|
MyBB Admin Notes Plugin 1.1 - Cross-Site Request Forgery
|
2 |
WEB
|
0xB9
|
2018-05-03
|
|
JasperReports - (Authenticated) File Read
|
2 |
WEB
|
Hector Monsegur
|
2018-05-14
|
|
XATABoost 1.0.0 - SQL Injection
|
2 |
WEB
|
MgThuraMoeMyint
|
2018-05-13
|
|
WUZHI CMS 4.1.0 - 'tag[pinyin]' Cross-Site Scripting
|
2 |
WEB
|
jiguang
|
2018-05-13
|
|
WUZHI CMS 4.1.0 - 'form[qq_10]' Cross-Site Scripting
|
2 |
WEB
|
jiguang
|
2018-05-11
|
|
Open-AudIT Community 2.2.0 - Cross-Site Scripting
|
2 |
WEB
|
Tejesh Kolisetty
|
2018-05-11
|
|
Open-AudIT Professional - 2.1.1 - Cross-Site Scripting
|
2 |
WEB
|
Tejesh Kolisetty
|
2018-05-10
|
|
MyBB Latest Posts on Profile Plugin 1.1 - Cross-Site Scripting
|
1 |
WEB
|
0xB9
|
2018-05-10
|
|
ModbusPal 1.6b - XML External Entity Injection
|
2 |
WEB
|
Trent Gordon
|
2018-05-10
|
|
Fastweb FASTGate 0.00.47 - Cross-Site Request Forgery
|
2 |
WEB
|
Raffaele Sabato
|
2018-05-06
|
|
WordPress Plugin User Role Editor < 4.25 - Privilege Escalation
|
2 |
WEB
|
Tomislav Paskalev
|
2018-05-06
|
|
CSP MySQL User Manager 2.3.1 - Authentication Bypass
|
2 |
WEB
|
Youssef Mami
|
2018-05-04
|
|
IceWarp Mail Server < 11.1.1 - Directory Traversal
|
2 |
WEB
|
Trustwave's SpiderLabs
|
2018-05-04
|
|
WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting
|
2 |
WEB
|
B0UG
|
2014-01-14
|
|
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
|
2 |
WEB
|
Takeshi Terada
|
2018-03-27
|
|
DLINK DCS-5020L - Remote Code Execution (PoC)
|
2 |
WEB
|
Fidus InfoSecurity
|
2018-05-02
|
|
Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
|
2 |
WEB
|
Qian Wu_ Bo Wang_ Jiawang Zhang
|
2018-05-01
|
|
WordPress Plugin Responsive Cookie Consent 1.7 / 1.6 / 1.5 - (Authenticated) Persistent Cross-Site S
|
2 |
WEB
|
B0UG
|
2018-04-30
|
|
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
|
2 |
WEB
|
Jared Arave
|
2018-04-30
|
|
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
|
2 |
WEB
|
Jared Arave
|
2018-04-30
|
|
WordPress Plugin Form Maker 1.12.20 - CSV Injection
|
2 |
WEB
|
Sairam Jetty
|