Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2018-04-30   Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit) 1 WEB SixP4ck3r
2018-04-30   Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit) 2 WEB SixP4ck3r
2018-04-26   Frog CMS 0.9.5 - Persistent Cross-Site Scripting 2 WEB Wenming Jiang
2018-04-26   TP-Link Technologies TL-WA850RE Wi-Fi Range Extender - Remote Reboot 2 WEB Wadeek
2018-04-26   GitList 0.6 - Remote Code Execution 2 WEB Kacper Szurek
2018-04-26   MyBB Threads to Link Plugin 1.3 - Cross-Site Scripting 1 WEB 0xB9
2018-04-26   October CMS User Plugin 1.4.5 - Persistent Cross-Site Scripting 1 WEB 0xB9
2018-04-26   SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response 1 WEB Sven Fassbender
2018-04-26   WordPress Plugin WP with Spritz 1.0 - Remote File Inclusion 0 WEB Wadeek
2018-04-26   Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution 1 WEB Alessio Sergi
2018-04-25   Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC) 1 WEB Blaklis
2018-04-25   HRSALE The Ultimate HRM 1.0.2 - Local File Inclusion 1 WEB 8bitsec
2018-04-25   HRSALE The Ultimate HRM 1.0.2 - (Authenticated) Cross-Site Scripting 1 WEB 8bitsec
2018-04-25   HRSALE The Ultimate HRM 1.0.2 - 'award_id' SQL Injection 1 WEB 8bitsec
2018-04-25   HRSALE The Ultimate HRM 1.0.2 - CSV Injection 0 WEB 8bitsec
2018-04-25   Blog Master Pro 1.0 - CSV Injection 0 WEB 8bitsec
2018-04-25   Shopy Point of Sale 1.0 - CSV Injection 1 WEB 8bitsec
2018-04-24   WSO2 Carbon / WSO2 Dashboard Server 5.3.0 - Persistent Cross-Site Scripting 1 WEB SEC Consult
2018-04-24   WordPress Plugin Woo Import Export 1.0 - Arbitrary File Deletion 2 WEB Lenon Leite
2018-04-24   Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure 1 WEB Berk Cem Göksel
2018-04-24   Interspire Email Marketer < 6.1.6 - Remote Admin Authentication Bypass 2 WEB devcoinfet
2018-04-24   Monstra CMS 3.0.4 - Arbitrary Folder Deletion 3 WEB Wenming Jiang
2018-04-24   Open-AudIT 2.1 - CSV Macro Injection 2 WEB Sureshbabu Narvaneni
2018-04-24   WUZHI CMS 4.1.0 - Cross-Site Request Forgery 2 WEB jiguang
2018-04-24   UK Cookie Consent - Persistent Cross-Site Scripting 1 WEB B0UG
2018-04-23   Monstra cms 3.0.4 - Persitent Cross-Site Scripting 1 WEB Wenming Jiang
2018-04-23   Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure 2 WEB Larry W. Cashdollar
2018-04-23   Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation 1 WEB r4wd3r
2018-04-23   Ncomputing vSpace Pro 10/11 - Directory Traversal 1 WEB Javier Bernardo
2018-04-23   phpMyAdmin 4.8.0 < 4.8.0-1 - Cross-Site Request Forgery 1 WEB revengsh
2018-04-20   Cobub Razor 0.8.0 - Physical Path Leakage 1 WEB Kyhvedn
2018-04-18   Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities 1 WEB bzyo
2018-04-18   Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities 1 WEB bzyo
2018-04-18   Joomla! Component JS Jobs 1.2.0 - Cross-Site Request Forgery 1 WEB Sureshbabu Narvaneni
2018-04-18   WordPress Plugin Caldera Forms 1.5.9.1 - Cross-Site Scripting 1 WEB Federico Scalco
2018-04-18   Lutron Quantum 2.0 - 3.2.243 - Information Disclosure 1 WEB SadFud
2018-04-18   Kodi 17.6 - Persistent Cross-Site Scripting 1 WEB Manuel García Cárdenas
2018-04-18   Match Clone Script 1.0.4 - Cross-Site Scripting 1 WEB ManhNho
2018-04-18   Rvsitebuilder CMS - Database Backup Download 2 WEB Hesam Bazvand
2018-04-18   MySQL Squid Access Report 2.1.4 - SQL Injection / Cross-Site Scripting 2 WEB Keerati T.
2018-04-18   MySQL Squid Access Report 2.1.4 - SQL Injection / Cross-Site Scripting 2 WEB Keerati T.
2018-04-17   Joomla! Component jDownloads 3.2.58 - Cross Site Scripting 1 WEB Sureshbabu Narvaneni
2018-04-16   Sophos Cyberoam UTM CR25iNG - 10.6.3 MR-5 - Direct Object Reference 1 WEB Frogy
2018-04-16   Cobub Razor 0.8.0 - SQL injection 2 WEB Kyhvedn
2018-04-13   Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution 1 WEB Hans Topo & g0tmi1k
2018-04-13   Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC) 2 WEB Vitalii Rudnykh
2018-04-12   Joomla! Convert Forms version 2.0.3 - Formula Injection (CSV Injection) 2 WEB Sairam Jetty
2018-04-10   WordPress Plugin File Upload 4.3.3 - Stored Cross-Site Scripting (PoC) 2 WEB ManhNho
2018-04-10   WordPress Plugin File Upload 4.3.2 - Stored Cross-Site Scripting 1 WEB ManhNho
2018-04-10   Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Contr 2 WEB SlidingWindow
2018-04-10   WUZHI CMS 4.1.0 - Cross-Site Request Forgery (Add User) 2 WEB taoge
2018-04-10   WUZHI CMS 4.1.0 - Cross-Site Request Forgery (Add Admin) 1 WEB taoge
2018-04-10   WordPress Plugin Activity Log 2.4.0 - Stored Cross-Site Scripting 1 WEB Stefan Broeder
2018-04-10   iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting 0 WEB ManhNho
2018-04-09   WordPress Plugin Google Drive 2.2 - Remote Code Execution 1 WEB Lenon Leite
2018-04-09   iScripts SonicBB 1.0 - Reflected Cross-Site Scripting (PoC) 1 WEB ManhNho
2018-04-09   WooCommerce CSV-Importer-Plugin 3.3.6 - Remote Code Execution 2 WEB Lenon Leite
2018-04-09   Buddypress Xprofile Custom Fields Type 2.6.3 - Remote Code Execution 2 WEB Lenon Leite
2018-04-09   KYOCERA Net Admin 3.4 - Cross-Site Request Forgery (Add Admin) 2 WEB LiquidWorm
2018-04-09   KYOCERA Multi-Set Template Editor 3.4 - Out-Of-Band XML External Entity Injection 1 WEB LiquidWorm
2018-04-09   CyberArk Password Vault Web Access < 9.9.5 / < 9.10 / 10.1 - Remote Code Execution 1 WEB RedTeam Pentesting
2018-04-09   WordPress Plugin Simple Fields 0.2 - 0.3.5 - Local/Remote File Inclusion / Remote Code Execution 2 WEB Graeme Robinson
2018-04-09   Yahei PHP Prober 0.4.7 - Cross-Site Scripting 1 WEB ManhNho
2018-04-09   WolfCMS 0.8.3.1 - Open Redirection 1 WEB Sureshbabu Narvaneni
2018-04-09   MyBB Plugin Recent Threads On Index - Cross-Site Scripting 1 WEB Perileos
2018-04-09   Cobub Razor 0.7.2 - Add New Superuser Account 2 WEB ppb
2018-04-09   WolfCMS 0.8.3.1 - Cross-Site Request Forgery 2 WEB Sureshbabu Narvaneni
2018-04-09   WordPress Plugin Background Takeover < 4.1.4 - Directory Traversal 1 WEB Colette Chamberland
2018-04-06   Cobub Razor 0.7.2 - Cross-Site Request Forgery 2 WEB ppb
2018-04-06   DotNetNuke DNNarticle Module 11 - Directory Traversal 2 WEB Esmaeil Rahimian
2018-04-06   FiberHome VDSL2 Modem HG 150-UB - Authentication Bypass 2 WEB Noman Riffat
2018-04-05   WordPress Plugin Activity Log 2.4.0 - Cross-Site Scripting 1 WEB Stefan Broeder
2018-04-05   GetSimple CMS 3.3.13 - Cross-Site Scripting 1 WEB Sureshbabu Narvaneni
2018-04-05   Z-Blog 1.5.1.1740 - Full Path Disclosure 1 WEB zzw
2018-04-05   Z-Blog 1.5.1.1740 - Cross-Site Scripting 2 WEB zzw
2018-04-05   YzmCMS 3.6 - Cross-Site Scripting 2 WEB zzw
2018-04-05   WebRTC - Private IP Leakage (Metasploit) 2 WEB Dhiraj Mishra
2018-04-05   Joomla! Component JS Jobs 1.2.0 - Cross-Site Scripting 2 WEB Sureshbabu Narvaneni
2018-04-05   MyBB Plugin Downloads 2.0.3 - Cross-Site Scripting 2 WEB 0xB9
2018-04-04   ProcessMaker - Plugin Upload (Metasploit) 2 WEB Metasploit
2018-04-02   Secutech RiS-11/RiS-22/RiS-33 - Remote DNS Change 2 WEB Todor Donev
2018-04-02   OpenCMS 10.5.3 - Cross-Site Scripting 1 WEB Sureshbabu Narvaneni
2018-04-02   OpenCMS 10.5.3 - Cross-Site Request Forgery 2 WEB Sureshbabu Narvaneni
2018-04-02   LifeSize ClearSea 3.1.4 - Directory Traversal 2 WEB rsp3ar
2018-04-02   DLink DIR-601 - Admin Password Disclosure 2 WEB Kevin Randall
2018-04-02   VideoFlow Digital Video Protection (DVP) 2.10 - Hard-Coded Credentials 2 WEB LiquidWorm
2018-04-02   VideoFlow Digital Video Protection (DVP) 2.10 - Directory Traversal 2 WEB LiquidWorm
2018-04-02   WampServer 3.1.2 - Cross-Site Request Forgery 1 WEB Vipin Chaudhary
2018-04-02   WampServer 3.1.1 - Cross-Site Scripting / Cross-Site Request Forgery 2 WEB Vipin Chaudhary
2018-04-02   Frog CMS 0.9.5 - Cross-Site Request Forgery (Add User) 2 WEB Samrat Das
2018-03-30   Tenda FH303/A300 Firmware v5.07.68_EN - Remote DNS Change 1 WEB Todor Donev
2018-03-30   Tenda W3002R/A302/w309r Wireless Router v5.07.64_en - Remote DNS Change (PoC) 1 WEB Todor Donev
2018-03-30   Vtiger CRM 6.3.0 - (Authenticated) Arbitrary File Upload (Metasploit) 2 WEB Touhid M.Shaikh
2018-03-30   D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router - Authentication Bypass 3 WEB Gem George
2018-03-30   Tenda W316R Wireless Router 5.07.50 - Remote DNS Change 2 WEB Todor Donev
2018-03-30   osCommerce 2.3.4.1 - Remote Code Execution 0 WEB Simon Scannell
2018-03-30   Tenda W308R v2 Wireless Router 5.07.48 - (Cookie Session) Remote DNS Change 1 WEB Todor Donev
2018-03-30   WordPress Plugin WP Security Audit Log 3.1.1 - Sensitive Information Disclosure 2 WEB Colette Chamberland
2018-03-30   Joomla! Component AcySMS 3.5.0 - CSV Macro Injection 2 WEB Sureshbabu Narvaneni
2018-03-30   Joomla! Component Acymailing Starter 5.9.5 - CSV Macro Injection 2 WEB Sureshbabu Narvaneni
2018-03-30   Homematic CCU2 2.29.23 - Remote Command Execution 1 WEB Patrick Muench and Gregor Kopf
2018-03-30   WordPress Plugin Contact Form 7 to Database Extension 2.10.32 - CSV Injection 1 WEB Stefan Broeder
2018-03-30   WordPress Plugin Relevanssi 4.0.4 - Reflected Cross-Site Scripting 1 WEB Stefan Broeder
2018-03-30   MiniCMS 1.10 - Cross-Site Request Forgery 1 WEB zixian
2018-03-30   Homematic CCU2 2.29.23 - Arbitrary File Write 1 WEB Patrick Muench and Gregor Kopf
2018-03-30   Open-AuditIT Professional 2.1 - Cross-Site Request Forgery 2 WEB Nilesh Sapariya
2018-03-29   Joomla! Component Fields - SQLi Remote Code Execution (Metasploit) 2 WEB Metasploit
2018-03-29   Joomla! Component Fields - SQLi Remote Code Execution (Metasploit) 1 WEB Metasploit
2014-11-03   Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session) 2 WEB Stefan Horst
2018-03-28   Open-AuditIT Professional 2.1 - Cross-Site Scripting 1 WEB Nilesh Sapariya
2018-03-28   Tenda N11 Wireless Router 5.07.43_en_NEX01 - Remote DNS Change 0 WEB Todor Donev
2018-03-28   Microsoft Windows Remote Assistance - XML External Entity Injection 0 WEB Nabeel Ahmed
2018-03-28   TwonkyMedia Server 7.0.11-8.5 - Persistent Cross-Site Scripting 0 WEB Sven Fassbender
2018-03-28   TwonkyMedia Server 7.0.11-8.5 - Directory Traversal 0 WEB Sven Fassbender
2018-03-27   ClipBucket - 'beats_uploader' Arbitrary File Upload (Metasploit) 0 WEB Metasploit
2018-03-27   ClipBucket - 'beats_uploader' Arbitrary File Upload (Metasploit) 1 WEB Metasploit
2018-03-26   Laravel Log Viewer < 0.13.0 - Local File Download 2 WEB Haboob Team
2018-03-23   WordPress Plugin Site Editor 1.1.1 - Local File Inclusion 3 WEB Nicolas Buzy-Debat
2018-03-23   MyBB Plugin Last User's Threads in Profile Plugin 1.2 - Persistent Cross-Site Scripting 2 WEB 0xB9
2018-03-23   TL-WR720N 150Mbps Wireless N Router - Cross-Site Request Forgery 2 WEB Mans van Someren
2018-03-23   Hikvision IP Camera versions 5.2.0 - 5.3.9 (Builds 140721 < 170109) - Access Control Bypass 2 WEB Matamorphosis
2018-03-20   Cisco node-jos < 0.11.0 - Re-sign Tokens 2 WEB zioBlack
2018-03-20   Coship RT3052 Wireless Router - Persistent Cross-Site Scripting 2 WEB Sayan Chatterjee
2018-03-20   Vehicle Sales Management System - Multiple Vulnerabilities 2 WEB Sing
2018-03-20   Intelbras Telefone IP TIP200 LITE - Local File Disclosure 1 WEB anhax0r