2018-03-16
|
|
Contec Smart Home 4.15 - Unauthorized Password Reset
|
2 |
WEB
|
Z3ro0ne
|
2018-03-15
|
|
Spring Data REST < 2.6.9 (Ingalls SR9) / 3.0.1 (Kay SR1) - PATCH Request Remote Code Execution
|
2 |
WEB
|
Antonio Francesco Sardella
|
2018-03-15
|
|
WordPress Plugin Duplicator 1.2.32 - Cross-Site Scripting
|
2 |
WEB
|
Stefan Broeder
|
2018-03-13
|
|
Tuleap 9.17.99.189 - Blind SQL Injection
|
2 |
WEB
|
Cristiano Maruti
|
2018-03-13
|
|
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
|
1 |
WEB
|
SEC Consult
|
2018-03-12
|
|
ACL Analytics 11.X - 13.0.0.579 - Arbitrary Code Execution
|
2 |
WEB
|
Clutchisback1
|
2018-03-12
|
|
Advantech WebAccess < 8.3 - Directory Traversal / Remote Code Execution
|
2 |
WEB
|
Chris Lyne
|
2018-03-12
|
|
TextPattern 4.6.2 - 'qty' SQL Injection
|
1 |
WEB
|
Manuel García Cárdenas
|
2018-03-12
|
|
Prisma Industriale Checkweigher PrismaWEB 1.21 - Hard-Coded Credentials
|
1 |
WEB
|
LiquidWorm
|
2018-03-12
|
|
ManageEngine Applications Manager 13.5 - Remote Code Execution (Metasploit)
|
1 |
WEB
|
Mehmet Ince
|
2018-03-09
|
|
Bacula-Web < 8.0.0-rc2 - SQL Injection
|
2 |
WEB
|
Gustavo Sorondo
|
2018-03-07
|
|
antMan 0.9.0c - Authentication Bypass
|
1 |
WEB
|
Joshua Bowser
|
2018-03-07
|
|
Redaxo CMS Addon MyEvents 2.2.1 - SQL Injection
|
1 |
WEB
|
h0n1gsp3cht
|
2018-03-06
|
|
Bravo Tejari Web Portal - Cross-Site Request Forgery
|
1 |
WEB
|
Arvind V
|
2017-07-01
|
|
Joomla! Component Joomanager 2.0.0 - 'com_Joomanager' Arbitrary File Download
|
1 |
WEB
|
Luth1er
|
2018-03-05
|
|
ClipBucket < 4.0.0 - Release 4902 - Command Injection / File Upload / SQL Injection
|
2 |
WEB
|
SEC Consult
|
2018-03-05
|
|
ClipBucket < 4.0.0 - Release 4902 - Command Injection / File Upload / SQL Injection
|
3 |
WEB
|
SEC Consult
|
2018-02-22
|
|
Parallels Remote Application Server 15.5 - Path Traversal
|
2 |
WEB
|
Nicolas Markitanis
|
2018-03-02
|
|
uWSGI < 2.0.17 - Directory Traversal
|
1 |
WEB
|
Marios Nicolaides
|
2018-03-02
|
|
antMan < 0.9.1a - Authentication Bypass
|
2 |
WEB
|
Joshua Bowser
|
2018-03-02
|
|
D-Link DIR-600M Wireless - Cross-Site Scripting
|
1 |
WEB
|
Prasenjit Kanti Paul
|
2018-02-28
|
|
Routers2 2.24 - Cross-Site Scripting
|
1 |
WEB
|
Lorenzo Di Fuccia
|
2018-02-27
|
|
Concrete5 CMS < 8.3.0 - Username / Comments Enumeration
|
0 |
WEB
|
Chapman Schleiss
|
2018-02-27
|
|
CMS Made Simple 2.1.6 - Remote Code Execution
|
3 |
WEB
|
Keerati T.
|
2018-02-27
|
|
School Management Script 3.0.4 - Authentication Bypass
|
2 |
WEB
|
Samiran Santra
|
2018-02-27
|
|
MyBB My Arcade Plugin 1.3 - Cross-Site Scripting
|
2 |
WEB
|
0xB9
|
2018-02-22
|
|
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
|
1 |
WEB
|
Core Security
|
2018-02-22
|
|
Joomla! Component OS Property Real Estate 3.12.7 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-22
|
|
Joomla! Component Proclaim 9.1.1 - Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-22
|
|
Joomla! Component CheckList 1.1.1 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-22
|
|
Joomla! Component Alexandria Book Library 3.1.2 - 'letter' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-22
|
|
Joomla! Component Ek Rishta 2.9 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-22
|
|
Joomla! Component PrayerCenter 3.0.2 - 'sessionid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-22
|
|
Joomla! Component Proclaim 9.1.1 - Backup File Download
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-22
|
|
Joomla! Component CW Tags 2.0.6 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-19
|
|
October CMS < 1.0.431 - Cross-Site Scripting
|
2 |
WEB
|
Samrat Das
|
2018-02-16
|
|
Oracle Primavera P6 Enterprise Project Portfolio Management - HTTP Response Splitting
|
2 |
WEB
|
Marios Nicolaides
|
2018-02-16
|
|
PSNews Website 1.0.0 - 'Keywords' SQL Injection
|
2 |
WEB
|
L0RD
|
2018-02-16
|
|
PHIMS - Hospital Management Information System - 'Password' SQL Injection
|
1 |
WEB
|
L0RD
|
2018-02-16
|
|
Front Accounting ERP 2.4.3 - Cross-Site Request Forgery
|
2 |
WEB
|
Samrat Das
|
2018-02-16
|
|
Joomla! Component Saxum Picker 3.2.10 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component SquadManagement 1.0.3 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Saxum Numerology 3.0.4 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Saxum Astro 4.0.14 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component ccNewsletter 2.x.x 'id' - SQL Injection
|
0 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Pinterest Clone Social Pinboard 2.0 - SQL Injection
|
0 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Timetable Responsive Schedule For Joomla! 1.5 - 'alias' SQL Injection
|
0 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Staff Master 1.0 RC 1 - SQL Injection
|
0 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Solidres 2.5.1 - SQL Injection
|
0 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Smart Shoutbox 3.0.0 - SQL Injection
|
0 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component SimpleCalendar 3.1.9 - SQL Injection
|
0 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Realpin 1.5.04 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Project Log 1.5.3 - 'search' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component NeoRecruit 4.1 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component MediaLibrary Free 4.0.12 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component JTicketing 2.0.16 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component JS Jobs 1.1.9 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component JS Autoz 1.0.9 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component JquickContact 1.3.2.2.1 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component JomEstate PRO 3.7 - 'id' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component jGive 2.0.9 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component JB Bus 2.3 - 'order_number' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component InviteX 3.0.5 - 'invite_type' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Google Map Landkarten 4.2.3 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Gallery WD 1.3.6 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Form Maker 3.6.12 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component File Download Tracker 3.0 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Fastball 2.5 - 'season' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component DT Register 3.2.7 - 'id' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component AllVideos Reloaded 1.2.x - 'divid' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Aist 2.0 - 'id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Advertisement Board 3.1.0 - 'catname' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-16
|
|
Joomla! Component Kubik-Rubik Simple Image Gallery Extended (SIGE) 3.2.3 - Cross-Site Scripting
|
2 |
WEB
|
Alwin Peppels
|
2018-02-16
|
|
Twig < 2.4.4 - Server Side Template Injection
|
2 |
WEB
|
JameelNabbo
|
2018-02-16
|
|
UserSpice 4.3 - Blind SQL Injection
|
2 |
WEB
|
Dolev Farhi
|
2018-02-16
|
|
TV - Video Subscription - Authentication Bypass SQL Injection
|
2 |
WEB
|
L0RD
|
2018-02-16
|
|
EPIC MyChart - X-Path Injection
|
2 |
WEB
|
Shayan S
|
2017-12-06
|
|
Dasan Networks GPON ONT WiFi Router H640X 12.02-01121 / 2.77p1-1124 / 3.03p2-1146 - Remote Code Exec
|
1 |
WEB
|
SecuriTeam
|
2017-07-16
|
|
Geneko Routers - Path Traversal
|
2 |
WEB
|
SecuriTeam
|
2017-06-08
|
|
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities
|
2 |
WEB
|
SecuriTeam
|
2017-05-10
|
|
Cisco DPC3928 Router - Arbitrary File Disclosure
|
2 |
WEB
|
SecuriTeam
|
2017-06-19
|
|
Sophos XG Firewall 16.05.4 MR-4 - Path Traversal
|
2 |
WEB
|
SecuriTeam
|
2017-09-07
|
|
McAfee LiveSafe 16.0.3 - Man In The Middle Registry Modification Leading to Remote Command Execution
|
2 |
WEB
|
SecuriTeam
|
2017-09-11
|
|
Hanbanggaoke IP Camera - Arbitrary Password Change
|
2 |
WEB
|
SecuriTeam
|
2017-10-09
|
|
QNAP HelpDesk < 1.1.12 - SQL Injection
|
1 |
WEB
|
SecuriTeam
|
2017-08-03
|
|
Horde Groupware 5.2.21 - Unauthorized File Download
|
2 |
WEB
|
SecuriTeam
|
2017-08-03
|
|
Tiandy IP Cameras 5.56.17.120 - Sensitive Information Disclosure
|
2 |
WEB
|
SecuriTeam
|
2017-10-09
|
|
PHP Melody 2.7.3 - Multiple Vulnerabilities
|
2 |
WEB
|
SecuriTeam
|
2017-10-13
|
|
FiberHome - Directory Traversal
|
2 |
WEB
|
SecuriTeam
|
2017-11-21
|
|
DblTek - Multiple Vulnerabilities
|
2 |
WEB
|
SecuriTeam
|
2017-11-07
|
|
Ametys CMS 4.0.2 - Password Reset
|
1 |
WEB
|
SecuriTeam
|
2018-01-15
|
|
GitStack - Remote Code Execution
|
2 |
WEB
|
SecuriTeam
|
2018-01-29
|
|
iBall WRA150N - Multiple Vulnerabilities
|
1 |
WEB
|
SecuriTeam
|
2017-03-17
|
|
Oracle Knowledge Management 12.1.1 < 12.2.5 - XML External Entity Leading To Remote Code Execution
|
1 |
WEB
|
SecuriTeam
|
2018-02-14
|
|
Dell EMC Isilon OneFS - Multiple Vulnerabilities
|
1 |
WEB
|
Core Security
|
2018-02-14
|
|
userSpice 4.3 - Cross-Site Scripting
|
1 |
WEB
|
Dolev Farhi
|
2018-02-14
|
|
SOA School Management - 'access_login' SQL Injection
|
1 |
WEB
|
L0RD
|
2018-02-14
|
|
Social Oauth Login PHP - Authentication Bypass
|
1 |
WEB
|
L0RD
|
2018-02-14
|
|
NAT32 2.2 Build 22284 - Cross-Site Request Forgery
|
0 |
WEB
|
hyp3rlinx
|
2018-02-14
|
|
NAT32 2.2 Build 22284 - Remote Command Execution
|
1 |
WEB
|
hyp3rlinx
|
2018-02-13
|
|
News Website Script 2.0.4 - 'search' SQL Injection
|
2 |
WEB
|
Varun Bagaria
|
2018-02-13
|
|
TypeSetter CMS 5.1 - Cross-Site Request Forgery
|
1 |
WEB
|
Navina Asrani
|
2018-02-13
|
|
TypeSetter CMS 5.1 - 'Host' Header Injection
|
2 |
WEB
|
Navina Asrani
|
2018-02-12
|
|
LogicalDOC Enterprise 7.7.4 - Root Remote Code Execution
|
2 |
WEB
|
LiquidWorm
|
2018-02-12
|
|
LogicalDOC Enterprise 7.7.4 - User Enumeration
|
1 |
WEB
|
LiquidWorm
|
2018-02-12
|
|
LogicalDOC Enterprise 7.7.4 - Directory Traversal
|
3 |
WEB
|
LiquidWorm
|
2018-02-11
|
|
Readymade Video Sharing Script 3.2 - 'search' SQL Injection
|
2 |
WEB
|
Varun Bagaria
|
2018-02-11
|
|
Paypal Clone Script 1.0.9 - 'id' / 'acctype' SQL Injection
|
2 |
WEB
|
L0RD
|
2018-02-10
|
|
Multi Language Olx Clone Script - Cross-Site Scripting
|
1 |
WEB
|
Varun Bagaria
|
2018-02-10
|
|
Naukri Clone Script 3.0.3 - 'indus' SQL Injection
|
2 |
WEB
|
L0RD
|
2018-02-07
|
|
Entrepreneur Dating Script 2.0.2 - Authentication Bypass
|
2 |
WEB
|
L0RD
|
2018-02-07
|
|
Online Test Script 2.0.7 - 'cid' SQL Injection
|
2 |
WEB
|
L0RD
|
2018-02-05
|
|
Netis WF2419 Router - Cross-Site Scripting
|
2 |
WEB
|
Sajibe Kanti
|
2018-02-05
|
|
Student Profile Management System Script 2.0.6 - Authentication Bypass
|
1 |
WEB
|
L0RD
|
2018-02-05
|
|
Joomla! Component JSP Tickets 1.1 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-05
|
|
Joomla! Component jLike 1.0 - Information Leak
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-05
|
|
Joomla! Component Zh GoogleMap 8.4.0.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-05
|
|
Joomla! Component Zh YandexMap 6.2.1.0 - 'id' SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2018-02-05
|
|
Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-05
|
|
Online Voting System - Authentication Bypass
|
2 |
WEB
|
Giulio Comi
|
2018-02-05
|
|
NixCMS 1.0 - 'category_id' SQL Injection
|
2 |
WEB
|
Bora Bozdogan
|
2018-02-05
|
|
Matrimonial Website Script 2.1.6 - 'uid' SQL Injection
|
2 |
WEB
|
L0RD
|
2018-02-05
|
|
Wonder CMS 2.3.1 - 'Host' Header Injection
|
2 |
WEB
|
Samrat Das
|
2018-02-05
|
|
Wonder CMS 2.3.1 - Unrestricted File Upload
|
2 |
WEB
|
Samrat Das
|
2018-02-02
|
|
FiberHome AN5506 - Remote DNS Change
|
3 |
WEB
|
r0ots3c
|