2018-02-02
|
|
Oracle Hospitality Simphony (MICROS) 2.7 < 2.9 - Directory Traversal
|
2 |
WEB
|
Dmitry Chastuhin
|
2018-02-02
|
|
Joomla! Component JMS Music 1.1.1 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-02
|
|
Joomla! Component Jimtawl 2.1.6 - Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-02
|
|
Joomla! Component JEXTN Classified 1.0.0 - 'sid' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-02-02
|
|
Joomla! Component JEXTN Reverse Auction 3.1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-02
|
|
Event Manager 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-02
|
|
Joomla! Component JE PayperVideo 3.0.0 - 'usr_plan' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-02-02
|
|
IPSwitch MOVEit 8.1 < 9.4 - Cross-Site Scripting
|
2 |
WEB
|
1n3
|
2018-02-02
|
|
Advance Loan Management System - 'id' SQL Injection
|
2 |
WEB
|
8bitsec
|
2018-02-02
|
|
Real Estate Custom Script - 'route' SQL Injection
|
2 |
WEB
|
8bitsec
|
2018-02-02
|
|
Fancy Clone Script - 'search_browse_product' SQL Injection
|
2 |
WEB
|
8bitsec
|
2018-02-02
|
|
Joomla! Component JEXTN Membership 3.1.0 - 'usr_plan' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-30
|
|
BMC BladeLogic RSCD Agent 8.3.00.64 - Windows Users Disclosure
|
1 |
WEB
|
Paul Taylor
|
2018-01-30
|
|
Joomla! Component Visual Calendar 3.1.3 - 'id' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-01-30
|
|
Joomla! Component CP Event Calendar 3.0.1 - 'id' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-01-30
|
|
Joomla! Component Picture Calendar for Joomla! 3.1.4 - Directory Traversal
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-30
|
|
Advantech WebAccess < 8.3 - SQL Injection
|
2 |
WEB
|
Chris Lyne
|
2018-01-28
|
|
KeystoneJS < 4.0.0-beta.7 - Cross-Site Request Forgery
|
2 |
WEB
|
Saurabh Banawar
|
2018-01-28
|
|
Netis WF2419 Router - Cross-Site Request Forgery
|
2 |
WEB
|
Sajibe Kanti
|
2018-01-28
|
|
Buddy Zone 2.9.9 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-28
|
|
Multilanguage Real Estate MLM Script 3.0 - 'srch' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-28
|
|
Hot Scripts Clone - 'subctid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-28
|
|
TSiteBuilder 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-28
|
|
Task Rabbit Clone 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-28
|
|
Joomla! Component Jtag Members Directory 5.3.7 - Arbitrary File Download
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-28
|
|
Joomla! Component JS Support Ticket 1.1.0 - Cross-Site Request Forgery
|
3 |
WEB
|
Ihsan Sencan
|
2018-01-28
|
|
Nexpose < 6.4.66 - Cross-Site Request Forgery
|
2 |
WEB
|
Shwetabh Vishnoi
|
2018-01-28
|
|
Gnew 2018.1 - Cross-Site Request Forgery
|
2 |
WEB
|
Cyril Vallicari
|
2018-01-28
|
|
PACSOne Server 6.6.2 DICOM Web Viewer - SQL Injection
|
2 |
WEB
|
Carlos Avila
|
2018-01-28
|
|
PACSOne Server 6.6.2 DICOM Web Viewer - Directory Trasversal
|
2 |
WEB
|
Carlos Avila
|
2018-01-26
|
|
WordPress Plugin Learning Management System - 'course_id' SQL Injection
|
2 |
WEB
|
Esecurity.ir
|
2018-01-25
|
|
ASUS DSL-N14U B1 Router 1.1.2.3_345 - Change Administrator Password
|
2 |
WEB
|
Víctor Calvo
|
2018-01-26
|
|
Dodocool DC38 N300 - Cross-site Request Forgery
|
2 |
WEB
|
Raffaele Sabato
|
2014-11-09
|
|
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
|
2 |
WEB
|
Pedro Ribeiro
|
2014-12-03
|
|
ManageEngine Netflow Analyzer / IT360 - Arbitrary File Download
|
2 |
WEB
|
Pedro Ribeiro
|
2015-02-09
|
|
ManageEngine OpManager / Applications Manager / IT360 - 'FailOverServlet' Multiple Vulnerabilities
|
2 |
WEB
|
Pedro Ribeiro
|
2014-11-05
|
|
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (2)
|
2 |
WEB
|
Pedro Ribeiro
|
2015-01-15
|
|
ManageEngine Desktop Central - Create Administrator
|
2 |
WEB
|
Pedro Ribeiro
|
2014-10-12
|
|
CMS Made Simple 1.11.9 - Multiple Vulnerabilities
|
1 |
WEB
|
Pedro Ribeiro
|
2014-10-12
|
|
GetSimple CMS 3.3.1 - Cross-Site Scripting
|
2 |
WEB
|
Pedro Ribeiro
|
2014-10-12
|
|
Pimcore CMS 1.4.9 <2.1.0 - Multiple Vulnerabilities
|
2 |
WEB
|
Pedro Ribeiro
|
2015-06-10
|
|
SysAid Help Desk 14.4 - Multiple Vulnerabilities
|
2 |
WEB
|
Pedro Ribeiro
|
2017-01-31
|
|
Billion / TrueOnline / ZyXEL Routers - Multiple Vulnerabilities
|
0 |
WEB
|
Pedro Ribeiro
|
2015-09-28
|
|
BMC Track-It! 11.4 - Multiple Vulnerabilities
|
2 |
WEB
|
Pedro Ribeiro
|
2015-09-28
|
|
Kaseya Virtual System Administrator (VSA) 7.0 < 9.1 - (Authenticated) Arbitrary File Upload
|
1 |
WEB
|
Pedro Ribeiro
|
2018-01-24
|
|
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Arbitrary File Upload
|
1 |
WEB
|
Paul Taylor
|
2018-01-24
|
|
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Encryption Keys Disclosure
|
2 |
WEB
|
Paul Taylor
|
2018-01-24
|
|
WordPress Plugin Email Subscribers & Newsletters 3.4.7 - Information Disclosure
|
1 |
WEB
|
ThreatPress Security
|
2018-01-24
|
|
Professional Local Directory Script 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
Flexible Poll 1.2 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
Quickad 4.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
Photography CMS 1.0 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
Tumder 2.1 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
Zechat 1.5 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
Wchat 1.5 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
Easy Car Script 2014 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
RSVP Invitation Online 1.0 - Cross-Site Request Forgery (Update Admin)
|
1 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
Affiligator 2.1.0 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
LiveCRM SaaS Cloud 1.0 - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2018-01-23
|
|
NEC Univerge SV9100/SV8100 WebPro 10.0 - Configuration Download
|
1 |
WEB
|
LiquidWorm
|
2018-01-23
|
|
CentOS Web Panel 0.9.8.12 - 'row_id' / 'domain' SQL Injection
|
2 |
WEB
|
Vulnerability-Lab
|
2018-01-21
|
|
OTRS 5.0.x/6.0.x - Remote Command Execution (1)
|
2 |
WEB
|
Bæln0rn
|
2018-01-21
|
|
CentOS Web Panel 0.9.8.12 - Multiple Vulnerabilities
|
1 |
WEB
|
Vulnerability-Lab
|
2018-01-21
|
|
Shopware 5.2.5/5.3 - Cross-Site Scripting
|
1 |
WEB
|
Vulnerability-Lab
|
2018-01-21
|
|
Oracle JDeveloper 11.1.x/12.x - Directory Traversal
|
1 |
WEB
|
hyp3rlinx
|
2018-01-15
|
|
DarkComet (C2 Server) - File Upload
|
1 |
WEB
|
Pseudo Laboratories
|
2018-01-15
|
|
D-Link DNS-325 ShareCenter < 1.05B03 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2018-01-15
|
|
D-Link DNS-343 ShareCenter < 1.05 - Command Injection
|
2 |
WEB
|
GulfTech Security
|
2018-01-08
|
|
Synology Photostation < 6.7.2-3429 - Multiple Vulnerabilities
|
0 |
WEB
|
GulfTech Security
|
2016-10-04
|
|
Mambo < 4.5.4 - SQL Injection
|
1 |
WEB
|
GulfTech Security
|
2016-08-18
|
|
X-Cart < 4.1.3 - Arbitrary Variable Overwrite
|
0 |
WEB
|
GulfTech Security
|
2016-08-14
|
|
Claroline < 1.7.7 - Arbitrary File Inclusion
|
0 |
WEB
|
GulfTech Security
|
2016-08-28
|
|
CubeCart < 3.0.12 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2016-08-11
|
|
SquirrelMail < 1.4.7 - Arbitrary Variable Overwrite
|
0 |
WEB
|
GulfTech Security
|
2016-03-05
|
|
PHPLib < 7.4 - SQL Injection
|
1 |
WEB
|
GulfTech Security
|
2016-03-02
|
|
Gallery 2 < 2.0.2 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2016-02-26
|
|
phpRPC < 0.7 - Remote Code Execution
|
1 |
WEB
|
GulfTech Security
|
2016-02-24
|
|
Mambo < 4.5.3h - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2016-02-21
|
|
PEAR LiveUser < 0.16.8 - Arbitrary File Access
|
1 |
WEB
|
GulfTech Security
|
2016-02-19
|
|
Geeklog < 1.4.0 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2016-02-18
|
|
ADOdb < 4.71 - Cross Site Scripting
|
1 |
WEB
|
GulfTech Security
|
2015-07-21
|
|
XPCOM - Race Condition
|
1 |
WEB
|
GulfTech Security
|
2015-07-14
|
|
SquirrelMail < 1.4.5-RC1 - Arbitrary Variable Overwrite
|
1 |
WEB
|
GulfTech Security
|
2015-07-02
|
|
PHPXMLRPC < 1.1 - Remote Code Execution
|
1 |
WEB
|
GulfTech Security
|
2015-07-01
|
|
PEAR XML_RPC < 1.3.0 - Remote Code Execution
|
1 |
WEB
|
GulfTech Security
|
2015-06-29
|
|
XOOPS < 2.0.11 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2015-05-16
|
|
Burning Board < 2.3.1 - SQL Injection
|
1 |
WEB
|
GulfTech Security
|
2015-05-05
|
|
Invision Power Board (IP.Board) < 2.0.3 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2015-04-19
|
|
AZBB < 1.0.07d - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2015-01-03
|
|
PhotoPost < 4.85 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2015-01-02
|
|
ReviewPost < 2.84 - Multiple Vulnerabilities
|
2 |
WEB
|
GulfTech Security
|
2015-01-01
|
|
PhotoPost Classifieds < 2.01 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2014-12-29
|
|
PHP-Calendar < 0.10.1 - Arbitrary File Inclusion
|
0 |
WEB
|
GulfTech Security
|
2014-12-27
|
|
WHM.AutoPilot < 2.4.6.5 - Multiple Vulnerabilities
|
0 |
WEB
|
GulfTech Security
|
2014-08-23
|
|
LiveWorld Multiple Products - Cross Site Scripting
|
1 |
WEB
|
GulfTech Security
|
2004-05-17
|
|
HelpCenter Live! < 1.2.7 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2004-05-04
|
|
Invision Power Board (IP.Board) < 1.3.1 - Design Error
|
2 |
WEB
|
GulfTech Security
|
2004-05-04
|
|
PHPX < 3.26 - Multiple Vulnerabilities
|
2 |
WEB
|
GulfTech Security
|
2004-04-24
|
|
OpenBB < 1.0.6 - Multiple Vulnerabilities
|
2 |
WEB
|
GulfTech Security
|
2004-04-14
|
|
phpBugTracker < 0.9.1 - Multiple Vulnerabilities
|
2 |
WEB
|
GulfTech Security
|
2004-04-11
|
|
TikiWiki < 1.8.1 - Multiple Vulnerabilities
|
0 |
WEB
|
GulfTech Security
|
2004-03-28
|
|
PhotoPost < 4.6 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2004-03-21
|
|
Invision Gallery < 1.0.1 - SQL Injection
|
0 |
WEB
|
GulfTech Security
|
2004-03-21
|
|
Invision Power Top Site List < 1.1 RC 2 - SQL Injection
|
1 |
WEB
|
GulfTech Security
|
2004-03-20
|
|
phpBB < 2.0.7a - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2004-03-15
|
|
Mambo < 4.5 - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2004-03-15
|
|
vBulletin < 3.0.0 RC4 - Cross Site Scripting
|
1 |
WEB
|
GulfTech Security
|
2004-03-15
|
|
Phorum < 5.0.3 Beta - Cross Site Scripting
|
1 |
WEB
|
GulfTech Security
|
2004-03-12
|
|
phpBB < 2.0.6d - Cross Site Scripting
|
2 |
WEB
|
GulfTech Security
|
2004-03-02
|
|
Invision Power Board (IP.Board) < 1.3 - SQL Injection
|
1 |
WEB
|
GulfTech Security
|
2004-01-13
|
|
phpShop < 0.6.1-b - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2004-01-13
|
|
phpGedView < 2.65 beta 5 - Multiple Vulnerabilities
|
2 |
WEB
|
GulfTech Security
|
2004-01-12
|
|
MetaDot < 5.6.5.4b5 - Multiple Vulnerabilities
|
2 |
WEB
|
GulfTech Security
|
2004-01-03
|
|
PostNuke < 0.726 Phoenix - Multiple Vulnerabilities
|
1 |
WEB
|
GulfTech Security
|
2003-12-22
|
|
osCommerce < 2.2-MS2 - Multiple Vulnerabilities
|
2 |
WEB
|
GulfTech Security
|
2003-12-18
|
|
ASPapp Multiple Products - Multiple Vulnerabilities
|
2 |
WEB
|
GulfTech Security
|
2003-12-18
|
|
AutoRank PHP < 2.0.4 - SQL Injection (PoC)
|
2 |
WEB
|
GulfTech Security
|
2003-12-16
|
|
Aardvark Topsites < 4.1.0 - Multiple Vulnerabilities
|
3 |
WEB
|
GulfTech Security
|
2003-12-16
|
|
Invision Power Board (IP.Board) < 2.0 Alpha 3 - SQL Injection (PoC)
|
1 |
WEB
|
GulfTech Security
|
2003-12-15
|
|
Invision Power Top Site List < 2.0 Alpha 3 - SQL Injection (PoC)
|
2 |
WEB
|
GulfTech Security
|
2003-12-15
|
|
DUWare Multiple Products - Multiple Vulnerabilities
|
2 |
WEB
|
GulfTech Security
|
2018-01-18
|
|
GitStack 2.3.10 - Remote Code Execution
|
2 |
WEB
|
Kacper Szurek
|
2018-01-18
|
|
Primefaces 5.x - Remote Code Execution (Metasploit)
|
2 |
WEB
|
Bjoern Schuette
|
2018-01-17
|
|
SugarCRM 3.5.1 - Cross-Site Scripting
|
2 |
WEB
|
Guilherme Assmann
|
2018-01-17
|
|
Belkin N600DB Wireless Router - Multiple Vulnerabilities
|
1 |
WEB
|
Wadeek
|