2017-10-30
|
|
Mailing List Manager Pro 3.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
MyBuilder Clone 1.0 - 'subcategory' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
PG All Share Video 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
PHP CityPortal 2.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Same Sex Dating Software Pro 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
SoftDatepro Dating Social Network 1.3 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Sokial Social Network Script 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
tPanel 2009 - Authentication Bypass
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Vastal I-Tech Dating Zone 0.9.9 - 'product_id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
ZeeBuddy 2x - 'groupid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Protected Links - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
AROX School ERP PHP Script - 'id' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Shareet - 'photo' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
US Zip Codes Database - 'state' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Newspaper 1.0 - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
News 1.0 - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
MyMagazine 1.0 - 'id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
CmsLite 1.4 - 'S' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Basic B2B Script - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
CPA Lead Reward Script - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Fake Magazine Cover Script - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Nice PHP FAQ Script - 'nice_theme' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Online Exam Test Application - 'sort' SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Php Inventory - Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Vastal I-Tech Agent Zone - 'searchCommercial.php' / 'searchResidential.php' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Website Broker Script - 'status_id' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
Zomato Clone Script - 'resid' SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-10-30
|
|
WordPress Plugin Ultimate Product Catalog 4.2.24 - PHP Object Injection
|
2 |
WEB
|
tomplixsee
|
2017-10-27
|
|
phpMyFAQ 2.9.8 - Cross-Site Request Forgery
|
2 |
WEB
|
Nikhil Mittal
|
2017-10-28
|
|
PHPMyFAQ 2.9.8 - Cross-Site Scripting (3)
|
2 |
WEB
|
Nikhil Mittal
|
2017-10-28
|
|
PHP Melody 2.6.1 - SQL Injection
|
2 |
WEB
|
Venkat Rajgor
|
2017-10-25
|
|
PHPMailer < 5.2.21 - Local File Disclosure
|
2 |
WEB
|
Maciek Krupa
|
2017-10-25
|
|
KeystoneJS 4.0.0-beta.5 - Cross-Site Scripting
|
3 |
WEB
|
Ishaq Mohammed
|
2017-10-25
|
|
KeystoneJS 4.0.0-beta.5 - CSV Excel Macro Injection
|
3 |
WEB
|
Ishaq Mohammed
|
2017-10-24
|
|
FS Realtor Clone - 'id' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-24
|
|
FS Crowdfunding Script - 'id' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-24
|
|
FS Care Clone - 'sitterService' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-24
|
|
FS Monster Clone - 'id' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-24
|
|
FS Trademe Clone - 'id' SQL Injection
|
4 |
WEB
|
8bitsec
|
2017-10-24
|
|
FS Thumbtack Clone - 'ser' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-24
|
|
FS Shutter Stock Clone - 'keywords' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-24
|
|
Mura CMS < 6.2 - Server-Side Request Forgery / XML External Entity Injection
|
3 |
WEB
|
Anthony Cole
|
2017-10-23
|
|
FS OLX Clone - 'catg_id' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-23
|
|
FS Lynda Clone - 'category' SQL Injection
|
2 |
WEB
|
8bitsec
|
2017-10-23
|
|
FS Indiamart Clone - 'keywords' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-23
|
|
FS Groupon Clone - 'category' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-23
|
|
FS Freelancer Clone - 'sk' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-23
|
|
FS Expedia Clone - 'hid' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-23
|
|
FS Food Delivery Script - 'keywords' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-23
|
|
FS Ebay Clone - 'pd_maincat_id' SQL Injection
|
2 |
WEB
|
8bitsec
|
2017-10-23
|
|
FS Book Store Script - 'category' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-23
|
|
FS Amazon Clone - 'category_id' SQL Injection
|
2 |
WEB
|
8bitsec
|
2017-10-23
|
|
FS Car Rental Script - 'pickup_location' SQL Injection
|
2 |
WEB
|
8bitsec
|
2017-10-23
|
|
Kaltura < 13.2.0 - Remote Code Execution
|
3 |
WEB
|
Robin Verton
|
2017-10-22
|
|
CometChat < 6.2.0 BETA 1 - Local File Inclusion
|
2 |
WEB
|
Paradoxis
|
2017-10-14
|
|
Logitech Media Server - Cross-Site Scripting
|
2 |
WEB
|
Thiago Sena
|
2017-10-12
|
|
TP-Link TL-MR3220 - Cross-Site Scripting
|
2 |
WEB
|
Thiago Sena
|
2017-10-17
|
|
TP-Link WR940N - (Authenticated) Remote Code
|
3 |
WEB
|
Fidus InfoSecurity
|
2017-10-18
|
|
Check_MK 1.2.8p25 - Information Disclosure
|
3 |
WEB
|
Julien Ahrens
|
2017-08-18
|
|
ZKTime Web Software 2.0 - Improper Access Restrictions
|
2 |
WEB
|
Arvind V
|
2017-08-18
|
|
ZKTime Web Software 2.0 - Cross-Site Request Forgery
|
3 |
WEB
|
Arvind V
|
2017-10-18
|
|
Afian AB FileRun 2017.03.18 - Multiple Vulnerabilities
|
3 |
WEB
|
SEC Consult
|
2017-10-18
|
|
Linksys E Series - Multiple Vulnerabilities
|
3 |
WEB
|
SEC Consult
|
2017-10-17
|
|
WordPress Plugin Car Park Booking - SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-17
|
|
Career Portal 1.0 - SQL Injection
|
2 |
WEB
|
8bitsec
|
2017-10-17
|
|
Apache Solr 7.0.1 - XML External Entity Expansion / Remote Code Execution
|
1 |
WEB
|
Michael Stepankin & Olga Barinova
|
2017-10-17
|
|
OpenText Documentum Content Server - Arbitrary File Download
|
3 |
WEB
|
Andrey B. Panfilov
|
2017-10-17
|
|
OpenText Documentum Content Server - 'dmr_content' Privilege Escalation
|
2 |
WEB
|
Andrey B. Panfilov
|
2017-10-17
|
|
OpenText Documentum Content Server - Arbitrary File Download Privilege Escalation
|
3 |
WEB
|
Andrey B. Panfilov
|
2017-10-17
|
|
OpenText Documentum Content Server - Privilege Escalation
|
3 |
WEB
|
Andrey B. Panfilov
|
2017-10-17
|
|
Squid Analysis Report Generator 2.3.10 - Remote Code Execution
|
2 |
WEB
|
Pavel Suprunyuk
|
2017-10-16
|
|
3CX Phone System 15.5.3554.1 - Directory Traversal
|
3 |
WEB
|
Jens Regel
|
2017-10-15
|
|
Webmin 1.850 - Multiple Vulnerabilities
|
2 |
WEB
|
hyp3rlinx
|
2017-10-13
|
|
AlienVault Unified Security Management (USM) 5.4.2 - Cross-Site Request Forgery
|
2 |
WEB
|
Julien Ahrens
|
2017-10-13
|
|
phpMyFAQ 2.9.8 - Cross-Site Scripting (2)
|
3 |
WEB
|
Ishaq Mohammed
|
2017-10-12
|
|
Dreambox Plugin BouquetEditor - Cross-Site Scripting
|
3 |
WEB
|
Thiago Sena
|
2017-10-13
|
|
TYPO3 Extension Restler 1.7.0 - Local File Disclosure
|
3 |
WEB
|
CrashBandicot
|
2017-10-12
|
|
E-Sic Software livre CMS - Cross Site Scripting
|
2 |
WEB
|
Elber Tavares
|
2017-10-12
|
|
E-Sic Software livre CMS - 'f' SQL Injection
|
2 |
WEB
|
Elber Tavares
|
2017-10-12
|
|
E-Sic Software livre CMS - 'cpfcnpj' SQL Injection
|
3 |
WEB
|
Elber Tavares
|
2017-10-12
|
|
E-Sic Software livre CMS - Autentication Bypass
|
3 |
WEB
|
Elber Tavares
|
2017-10-12
|
|
E-Sic Software livre CMS - 'q' SQL Injection
|
3 |
WEB
|
Guilherme Assmann
|
2017-10-12
|
|
OctoberCMS 1.0.425 (Build 425) - Cross-Site Scripting
|
4 |
WEB
|
Ishaq Mohammed
|
2017-10-11
|
|
Trend Micro Data Loss Prevention Virtual Appliance 5.2 - Path Traversal
|
4 |
WEB
|
Leonardo Duarte
|
2017-10-11
|
|
Trend Micro InterScan Messaging Security (Virtual Appliance) - 'Proxy.php' Remote Code Execution (Me
|
3 |
WEB
|
Mehmet Ince
|
2017-10-11
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - Remote Code Execution (Metasploit)
|
3 |
WEB
|
Mehmet Ince
|
2017-10-10
|
|
Complain Management System - Hard-Coded Credentials / Blind SQL injection
|
3 |
WEB
|
havysec
|
2017-10-09
|
|
ClipShare 7.0 - SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-10-09
|
|
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execu
|
3 |
WEB
|
intx0x80
|
2017-08-30
|
|
Metasploit Web UI < 4.14.1-20170828 - Cross-Site Request Forgery
|
2 |
WEB
|
Dhiraj Mishra
|
2017-08-08
|
|
Unitrends UEB 9.1 - Privilege Escalation
|
3 |
WEB
|
Jared Arave
|
2017-09-27
|
|
Netgear ReadyNAS Surveillance 1.4.3-16 - Remote Command Execution
|
3 |
WEB
|
Kacper Szurek
|
2017-10-04
|
|
ClipBucket 2.8.3 - Remote Code Execution
|
4 |
WEB
|
Meisam Monsef
|
2017-09-20
|
|
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execu
|
3 |
WEB
|
xxlegend
|
2017-10-03
|
|
EPESI 1.8.2 rev20170830 - Cross-Site Scripting
|
2 |
WEB
|
Zeeshan Shaikh
|
2017-10-03
|
|
Fiberhome AN5506-04-F - Command Injection
|
3 |
WEB
|
Tauco
|
2017-10-02
|
|
OpenText Document Sciences xPression 4.5SP1 Patch 13 - 'documentId' SQL Injection
|
2 |
WEB
|
Marcin Woloszyn
|
2017-10-02
|
|
OpenText Document Sciences xPression 4.5SP1 Patch 13 - 'jobRunId' SQL Injection
|
2 |
WEB
|
Marcin Woloszyn
|
2017-10-02
|
|
phpCollab 2.5.1 - SQL Injection
|
3 |
WEB
|
Sysdream
|
2017-10-02
|
|
phpCollab 2.5.1 - Arbitrary File Upload
|
2 |
WEB
|
Sysdream
|
2017-10-02
|
|
NPM-V (Network Power Manager) 2.4.1 - Password Reset
|
2 |
WEB
|
Saeed reza Zamanian
|
2017-09-24
|
|
HBGK DVR 3.0.0 build20161206 - Authentication Bypass
|
2 |
WEB
|
RAT - ThiefKing
|
2017-09-29
|
|
ConverTo Video Downloader & Converter 1.4.1 - Arbitrary File Download
|
1 |
WEB
|
Ihsan Sencan
|
2017-09-28
|
|
Real Estate MLM plan script 1.0 - 'srch' SQL Injection
|
2 |
WEB
|
8bitsec
|
2017-09-28
|
|
PHP Multi Vendor Script 1.02 - 'sid' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-09-29
|
|
WordPress Plugin WPHRM - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-27
|
|
SmarterStats 11.3.6347 - Cross-Site Scripting
|
3 |
WEB
|
sqlhacker
|
2017-09-29
|
|
FileRun < 2017.09.18 - SQL Injection
|
3 |
WEB
|
SPARC
|
2017-09-28
|
|
Easy Blog PHP Script 1.3a - 'id' SQL Injection
|
3 |
WEB
|
8bitsec
|
2017-09-28
|
|
Roteador Wireless Intelbras WRN150 - Autentication Bypass
|
3 |
WEB
|
Elber Tavares
|
2017-09-28
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - 'Host' Header Injection
|
3 |
WEB
|
hyp3rlinx
|
2017-09-28
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - Server Side Request Forgery
|
2 |
WEB
|
hyp3rlinx
|
2017-09-28
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - Information Disclosure
|
3 |
WEB
|
hyp3rlinx
|
2017-09-28
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - Code Execution / Memory Corruption
|
3 |
WEB
|
hyp3rlinx
|
2017-09-28
|
|
Trend Micro OfficeScan 11.0/XG (12.0) - Private Key Disclosure
|
3 |
WEB
|
hyp3rlinx
|
2017-02-22
|
|
Fibaro Home Center 2 - Remote Command Execution / Privilege Escalation
|
2 |
WEB
|
forsec
|
2017-09-26
|
|
WordPress Plugin WPAMS - SQL Injection
|
3 |
WEB
|
Ihsan Sencan
|
2017-09-26
|
|
WordPress Plugin School Management System - SQL Injection
|
1 |
WEB
|
Ihsan Sencan
|
2017-09-26
|
|
WordPress Plugin Hospital Management System - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-26
|
|
WordPress Plugin WPGYM - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-26
|
|
WordPress Plugin WPCHURCH - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-26
|
|
AMC Master - Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-26
|
|
SMSmaster - SQL Injection
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-26
|
|
Photo Fusion - Arbitrary File Upload
|
2 |
WEB
|
Ihsan Sencan
|
2017-09-26
|
|
TicketPlus - Arbitrary File Upload
|
3 |
WEB
|
Ihsan Sencan
|