2024-03-10
|
|
Numbas < v7.3 - Remote Code Execution
|
6 |
WEB
|
Matheus Alexandre
|
2024-03-10
|
|
TP-Link TL-WR740N - Buffer Overflow 'DOS'
|
6 |
WEB
|
Anish Feroz
|
2024-03-06
|
|
GLiNet - Router Authentication Bypass
|
5 |
WEB
|
Daniele Linguaglossa
|
2024-03-06
|
|
elFinder Web file manager Version - 2.1.53 Remote Command Execution
|
5 |
WEB
|
tmrswrr
|
2024-03-06
|
|
CSZ CMS Version 1.3.0 - Authenticated Remote Command Execution
|
4 |
WEB
|
tmrswrr
|
2024-03-06
|
|
CVE-2023-50071 - Multiple SQL Injection
|
4 |
WEB
|
Geraldo Alcantara
|
2024-03-06
|
|
Lot Reservation Management System - Unauthenticated File Disclosure
|
6 |
WEB
|
Elijah Mandila Syoyi
|
2024-03-06
|
|
Lot Reservation Management System - Unauthenticated File Upload and Remote Code Execution
|
3 |
WEB
|
Elijah Mandila Syoyi
|
2024-03-05
|
|
kk Star Ratings < 5.4.6 - Rating Tampering via Race Condition
|
5 |
WEB
|
Mohammad Reza Omrani
|
2024-03-05
|
|
Neontext Wordpress Plugin - Stored XSS
|
3 |
WEB
|
Eren Car
|
2024-03-05
|
|
Solar-Log 200 PM+ 3.6.0 Build 99 - 15.10.2019 - Stored XSS
|
3 |
WEB
|
Vincent McRae_ Mesut Cetin
|
2024-03-03
|
|
Easywall 0.3.1 - Authenticated Remote Command Execution
|
5 |
WEB
|
Melvin Mejia
|
2024-03-03
|
|
Boss Mini 1.4.0 - local file inclusion
|
6 |
WEB
|
nltt0
|
2024-03-03
|
|
Magento ver. 2.4.6 - XSLT Server Side Injection
|
6 |
WEB
|
tmrswrr
|
2024-02-28
|
|
WP Fastest Cache 1.2.2 - Unauthenticated SQL Injection
|
6 |
WEB
|
Meryem Taşkın
|
2024-02-28
|
|
Blood Bank v1.0 - Multiple SQL Injection
|
5 |
WEB
|
Ersin Erenler
|
2024-02-28
|
|
WordPress Plugin Admin Bar & Dashboard Access Control Version: 1.2.8 - _Dashboard Redirect_ field St
|
7 |
WEB
|
Rachit Arora
|
2024-02-28
|
|
WP Rocket < 2.10.3 - Local File Inclusion (LFI)
|
6 |
WEB
|
E1 Coders
|
2024-02-27
|
|
Atlassian Confluence Data Center and Server - Authentication Bypass (Metasploit)
|
7 |
WEB
|
Emir Polat
|
2024-02-27
|
|
Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)
|
6 |
WEB
|
Leopoldo Angulo (leoanggal1)
|
2024-02-27
|
|
Automatic-Systems SOC FL9600 FastLine - The device contains hardcoded login and password for super a
|
5 |
WEB
|
Marcin Kozlowski
|
2024-02-27
|
|
Automatic-Systems SOC FL9600 FastLine - Directory Transversal
|
4 |
WEB
|
Marcin Kozlowski
|
2024-02-27
|
|
SuperStoreFinder - Multiple Vulnerabilities
|
5 |
WEB
|
bRpsd
|
2024-02-27
|
|
Moodle 4.3 - Insecure Direct Object Reference
|
4 |
WEB
|
tmrswrr
|
2024-02-27
|
|
Zoo Management System 1.0 - Unauthenticated RCE
|
5 |
WEB
|
Çağatay Ceyhan
|
2024-02-27
|
|
dawa-pharma 1.0-2022 - Multiple-SQLi
|
6 |
WEB
|
nu11secur1ty
|
2024-02-26
|
|
Online Shopping System Advanced - Sql Injection
|
6 |
WEB
|
Furkan Gedik
|
2024-02-26
|
|
taskhub 2.8.7 - SQL Injection
|
6 |
WEB
|
CraCkEr
|
2024-02-26
|
|
comments-like-dislike < 1.2.0 - Authenticated (Subscriber+) Plugin Setting Reset
|
5 |
WEB
|
Diaa Hanna
|
2024-02-21
|
|
WEBIGniter v28.7.23 - Stored Cross Site Scripting (XSS)
|
6 |
WEB
|
Sagar Banwa
|
2024-02-19
|
|
JFrog Artifactory < 7.25.4 - Blind SQL Injection
|
5 |
WEB
|
ardr
|
2024-02-19
|
|
Wondercms 4.3.2 - XSS to RCE
|
5 |
WEB
|
Anas Zakir
|
2024-02-19
|
|
SureMDM On-premise < 6.31 - CAPTCHA Bypass User Enumeration
|
6 |
WEB
|
Jonas Benjamin Friedli
|
2024-02-19
|
|
Employee Management System v1 - 'email' SQL Injection
|
6 |
WEB
|
SoSPiro
|
2024-02-19
|
|
phpFox < 4.8.13 - (redirect) PHP Object Injection Exploit
|
20 |
WEB
|
Egidio Romano
|
2024-02-15
|
|
Metabase 0.46.6 - Pre-Auth Remote Code Execution
|
9 |
WEB
|
Musyoka Ian
|
2024-02-15
|
|
SISQUALWFM 7.1.319.103 - Host Header Injection
|
6 |
WEB
|
Omer Shaik
|
2024-02-13
|
|
Lost and Found Information System v1.0 - ( IDOR ) leads to Account Take over
|
6 |
WEB
|
Or4nG.M4N
|
2024-02-13
|
|
ManageEngine ADManager Plus Build < 7183 - Recovery Password Disclosure
|
15 |
WEB
|
Metin Yunus Kandemir
|
2024-02-13
|
|
Splunk 9.0.4 - Information Disclosure
|
20 |
WEB
|
Parsa Rezaie Khiabanloo
|
2024-02-09
|
|
Online Nurse Hiring System 1.0 - Time-Based SQL Injection
|
7 |
WEB
|
yozgatalperen1
|
2024-02-09
|
|
Rail Pass Management System 1.0 - Time-Based SQL Injection
|
9 |
WEB
|
yozgatalperen1
|
2024-02-09
|
|
Wordpress Seotheme - Remote Code Execution Unauthenticated
|
8 |
WEB
|
Milad karimi
|
2024-02-09
|
|
Wordpress Augmented-Reality - Remote Code Execution Unauthenticated
|
19 |
WEB
|
Milad karimi
|
2024-02-09
|
|
Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)
|
4 |
WEB
|
Furkan ÖZER
|
2024-02-05
|
|
WhatsUp Gold 2022 (22.1.0 Build 39) - XSS
|
6 |
WEB
|
Andreas Finstad
|
2024-02-05
|
|
MISP 2.4.171 - Stored XSS
|
6 |
WEB
|
Mücahit Çeri
|
2024-02-05
|
|
Clinic's Patient Management System 1.0 - Unauthenticated RCE
|
6 |
WEB
|
Oğulcan Hami Gül
|
2024-02-05
|
|
Curfew e-Pass Management System 1.0 - FromDate SQL Injection
|
4 |
WEB
|
Puja Dey
|
2024-02-05
|
|
GYM MS - GYM Management System - Cross Site Scripting (Stored)
|
7 |
WEB
|
yozgatalperen1
|
2024-02-02
|
|
Juniper-SRX-Firewalls&EX-switches - (PreAuth-RCE) (PoC)
|
4 |
WEB
|
whiteOwl
|
2024-02-02
|
|
Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution
|
13 |
WEB
|
LiquidWorm
|
2024-02-02
|
|
Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal
|
15 |
WEB
|
LiquidWorm
|
2024-02-02
|
|
Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass
|
7 |
WEB
|
LiquidWorm
|
2024-02-02
|
|
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
|
7 |
WEB
|
LiquidWorm
|
2024-02-02
|
|
Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure
|
7 |
WEB
|
LiquidWorm
|
2024-02-02
|
|
TP-LINK TL-WR740N - Multiple HTML Injection
|
6 |
WEB
|
Shujaat Amin (ZEROXINN)
|
2024-02-02
|
|
TP-Link TL-WR740N - UnAuthenticated Directory Transversal
|
7 |
WEB
|
Syed Affan Ahmed (ZEROXINN)
|
2024-01-31
|
|
GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities
|
7 |
WEB
|
Syed Affan Ahmed (ZEROXINN)
|
2024-01-31
|
|
Grocy <=4.0.2 - CSRF
|
5 |
WEB
|
Chance Proctor
|
2024-01-31
|
|
101 News 1.0 - Multiple-SQLi
|
7 |
WEB
|
nu11secur1ty
|
2024-01-31
|
|
Academy LMS 6.2 - SQL Injection
|
5 |
WEB
|
CraCkEr
|
2024-01-29
|
|
PHP Shopping Cart 4.2 - Multiple-SQLi
|
6 |
WEB
|
nu11secur1ty
|
2024-01-29
|
|
Fundraising Script 1.0 - SQLi
|
7 |
WEB
|
nu11secur1ty
|
2024-01-29
|
|
Bank Locker Management System - SQL Injection
|
6 |
WEB
|
SoSPiro
|
2023-10-09
|
|
Splunk 9.0.5 - admin account take over
|
22 |
WEB
|
Redway Security
|
2023-10-09
|
|
Shuttle-Booking-Software v1.0 - Multiple-SQLi
|
18 |
WEB
|
nu11secur1ty
|
2023-10-09
|
|
Limo Booking Software v1.0 - CORS
|
4 |
WEB
|
nu11secur1ty
|
2023-10-09
|
|
Webedition CMS v2.9.8.8 - Blind SSRF
|
4 |
WEB
|
Mirabbas Ağalarov
|
2023-10-09
|
|
BoidCMS v2.0.0 - authenticated file upload vulnerability
|
4 |
WEB
|
1337kid
|
2023-10-09
|
|
Cacti 1.2.24 - Authenticated command injection when using SNMP options
|
5 |
WEB
|
Antonio Francesco Sardella
|
2023-10-09
|
|
Wordpress Sonaar Music Plugin 4.7 - Stored XSS
|
4 |
WEB
|
Furkan Karaarslan
|
2023-10-09
|
|
Coppermine Gallery 1.6.25 - RCE
|
4 |
WEB
|
Mirabbas Ağalarov
|
2023-10-09
|
|
Media Library Assistant Wordpress Plugin - RCE and LFI
|
3 |
WEB
|
Florent MONTEL
|
2023-10-09
|
|
WEBIGniter v28.7.23 File Upload - Remote Code Execution
|
5 |
WEB
|
nu11secur1ty
|
2023-10-09
|
|
Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
|
4 |
WEB
|
Revan Arifio
|
2023-10-09
|
|
Minio 2022-07-29T19-40-48Z - Path traversal
|
6 |
WEB
|
Jenson Zhao
|
2023-10-09
|
|
Clcknshop 1.0.0 - SQL Injection
|
18 |
WEB
|
CraCkEr
|
2023-10-09
|
|
Online ID Generator 1.0 - Remote Code Execution (RCE)
|
9 |
WEB
|
nu11secur1ty
|
2023-10-09
|
|
GLPI GZIP(Py3) 9.4.5 - RCE
|
14 |
WEB
|
Brian Peters
|
2023-09-08
|
|
Drupal 10.1.2 - web-cache-poisoning-External-service-interaction
|
8 |
WEB
|
nu11secur1ty
|
2023-09-08
|
|
Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS
|
14 |
WEB
|
AmirZargham
|
2023-09-08
|
|
soosyze 2.0.0 - File Upload
|
4 |
WEB
|
nu11secur1ty
|
2023-09-08
|
|
Wp2Fac - OS Command Injection
|
5 |
WEB
|
Ahmet Ümit BAYRAM
|
2023-09-08
|
|
Wordpress Plugin Elementor 3.5.5 - Iframe Injection
|
4 |
WEB
|
Miguel Santareno
|
2023-09-08
|
|
Jorani v1.0.3-(c)2014-2023 - XSS Reflected & Information Disclosure
|
5 |
WEB
|
nu11secur1ty
|
2023-09-08
|
|
SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
|
4 |
WEB
|
CraCkEr
|
2023-09-04
|
|
SPA-Cart eCommerce CMS 1.9.0.3 - Reflected XSS
|
4 |
WEB
|
CraCkEr
|
2023-09-04
|
|
Bus Reservation System 1.1 - Multiple-SQLi
|
5 |
WEB
|
nu11secur1ty
|
2023-09-04
|
|
WP Statistics Plugin 13.1.5 current_page_id - Time based SQL injection (Unauthenticated)
|
5 |
WEB
|
psychoSherlock
|
2023-09-04
|
|
Member Login Script 3.3 - Client-side desync
|
4 |
WEB
|
nu11secur1ty
|
2023-09-04
|
|
DLINK DPH-400SE - Exposure of Sensitive Information
|
5 |
WEB
|
tahaafarooq
|
2023-09-04
|
|
FileMage Gateway 1.10.9 - Local File Inclusion
|
6 |
WEB
|
Bryce Raindayzz Harty
|
2023-09-04
|
|
AdminLTE PiHole 5.18 - Broken Access Control
|
5 |
WEB
|
kv1to
|
2023-09-04
|
|
CSZ CMS 1.3.0 - Stored Cross-Site Scripting (Plugin 'Gallery')
|
5 |
WEB
|
Daniel González
|
2023-09-04
|
|
CSZ CMS 1.3.0 - Stored Cross-Site Scripting ('Photo URL' and 'YouTube URL' )
|
5 |
WEB
|
Daniel González
|
2023-09-04
|
|
Academy LMS 6.1 - Arbitrary File Upload
|
4 |
WEB
|
CraCkEr
|
2023-09-04
|
|
Credit Lite 1.5.4 - SQL Injection
|
5 |
WEB
|
CraCkEr
|
2023-09-04
|
|
Hyip Rio 2.1 - Arbitrary File Upload
|
5 |
WEB
|
CraCkEr
|
2023-09-04
|
|
Blood Donor Management System v1.0 - Stored XSS
|
7 |
WEB
|
Ehlullah Albayrak
|
2023-08-24
|
|
Uvdesk 1.1.4 - Stored XSS (Authenticated)
|
7 |
WEB
|
Hubert Wojciechowski
|
2023-08-24
|
|
User Registration & Login and User Management System v3.0 - SQL Injection (Unauthenticated)
|
7 |
WEB
|
Ashutosh Singh Umath
|
2023-08-24
|
|
User Registration & Login and User Management System v3.0 - Stored Cross-Site Scripting (XSS)
|
13 |
WEB
|
Ashutosh Singh Umath
|
2023-08-21
|
|
Taskhub CRM Tool 2.8.6 - SQL Injection
|
15 |
WEB
|
Ahmet Ümit BAYRAM
|
2023-08-21
|
|
OVOO Movie Portal CMS v3.3.3 - SQL Injection
|
8 |
WEB
|
Ahmet Ümit BAYRAM
|
2023-08-21
|
|
Global - Multi School Management System Express v1.0- SQL Injection
|
7 |
WEB
|
Ahmet Ümit BAYRAM
|
2023-08-21
|
|
Color Prediction Game v1.0 - SQL Injection
|
7 |
WEB
|
Ahmet Ümit BAYRAM
|
2023-08-21
|
|
Crypto Currency Tracker (CCT) 9.5 - Admin Account Creation (Unauthenticated)
|
5 |
WEB
|
0xBr
|
2023-08-21
|
|
PHPJabbers Business Directory Script v3.2 - Multiple Vulnerabilities
|
6 |
WEB
|
Kerimcan Ozturk
|
2023-08-21
|
|
Dolibarr Version 17.0.1 - Stored XSS
|
5 |
WEB
|
Furkan Karaarslan
|
2023-08-08
|
|
Emagic Data Center Management Suite v6.0 - OS Command Injection
|
5 |
WEB
|
thewhiteh4t
|
2023-08-08
|
|
PHPJabbers Vacation Rental Script 4.0 - CSRF
|
3 |
WEB
|
Hasan Ali YILDIR
|
2023-08-08
|
|
Social-Commerce 3.1.6 - Reflected XSS
|
3 |
WEB
|
CraCkEr
|
2023-08-08
|
|
mooSocial 3.1.8 - Reflected XSS
|
3 |
WEB
|
CraCkEr
|
2023-08-08
|
|
Pyro CMS 3.9 - Server-Side Template Injection (SSTI) (Authenticated)
|
5 |
WEB
|
Daniel Barros
|
2023-08-08
|
|
Lucee 5.4.2.17 - Authenticated Reflected XSS
|
5 |
WEB
|
Yehia Elghaly
|
2023-08-08
|
|
Adlisting Classified Ads 2.14.0 - WebPage Content Information Disclosure
|
7 |
WEB
|
CraCkEr
|
2023-08-04
|
|
WordPress Plugin Forminator 1.24.6 - Unauthenticated Remote Command Execution
|
5 |
WEB
|
Mehmet Kelepçe
|
2023-08-04
|
|
WordPress adivaha Travel Plugin 2.3 - Reflected XSS
|
5 |
WEB
|
CraCkEr
|
2023-08-04
|
|
Webedition CMS v2.9.8.8 - Stored XSS
|
5 |
WEB
|
Mirabbas Ağalarov
|
2023-08-04
|
|
Webedition CMS v2.9.8.8 - Remote Code Execution (RCE)
|
4 |
WEB
|
Mirabbas Ağalarov
|
2023-08-04
|
|
Webutler v3.2 - Remote Code Execution (RCE)
|
5 |
WEB
|
Mirabbas Ağalarov
|
2023-08-04
|
|
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
|
5 |
WEB
|
Miguel Santareno
|
2023-08-04
|
|
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
|
5 |
WEB
|
Miguel Santareno
|
2023-08-04
|
|
Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
|
4 |
WEB
|
Rajdip Dey Sarkar
|