2017-06-16
|
|
iBall Baton iB-WRA150N - DNS Change
|
2 |
WEB
|
Todor Donev
|
2017-06-16
|
|
IBM Informix Dynamic Server - Code Injection / Remote Code Execution
|
2 |
WEB
|
IMgod
|
2017-06-15
|
|
Joomla! Component JoomRecipe 1.0.3 - SQL Injection
|
1 |
WEB
|
EziBilisim
|
2017-06-14
|
|
KBVault MySQL 0.16a - Arbitrary File Upload
|
2 |
WEB
|
Fatih Emiral
|
2017-05-22
|
|
Aerohive HiveOS 5.1r5 < 6.1r5 - Remote Code Execution
|
1 |
WEB
|
Ike-Clinton
|
2017-06-04
|
|
WordPress Plugin Event List < 0.7.8 - SQL Injection
|
2 |
WEB
|
Dimitrios Tsagkarakis
|
2017-06-11
|
|
WordPress Plugin WP Jobs < 1.5 - SQL Injection
|
1 |
WEB
|
Dimitrios Tsagkarakis
|
2017-06-12
|
|
Real Estate Classifieds Script - SQL Injection
|
1 |
WEB
|
EziBilisim
|
2017-06-03
|
|
WordPress Plugin WP-Testimonials < 3.4.1 - SQL Injection
|
2 |
WEB
|
Dimitrios Tsagkarakis
|
2017-06-09
|
|
Nuevomailer < 6.0 - SQL Injection
|
1 |
WEB
|
Oleg Boytsev
|
2017-06-10
|
|
PaulShop - SQL Injection
|
2 |
WEB
|
Se0pHpHack3r
|
2017-06-09
|
|
EFS Easy Chat Server 3.1 - Password Reset
|
2 |
WEB
|
Aitezaz Mohsin
|
2017-06-09
|
|
EFS Easy Chat Server 3.1 - Password Disclosure
|
2 |
WEB
|
Aitezaz Mohsin
|
2017-06-10
|
|
eCom Cart 1.3 - SQL Injection
|
2 |
WEB
|
Alperen Eymen Ozcan
|
2017-06-09
|
|
Uniview NVR - Password Disclosure
|
2 |
WEB
|
B1t
|
2017-06-09
|
|
IPFire 2.19 - Remote Code Execution
|
2 |
WEB
|
0x09AL
|
2017-06-08
|
|
Craft CMS 2.6 - Cross-Site Scripting
|
2 |
WEB
|
Ahsan Tahir
|
2017-06-07
|
|
Robert 0.5 - Multiple Vulnerabilities
|
2 |
WEB
|
Cyril Vallicari
|
2017-06-07
|
|
Xavier 2.4 - SQL Injection
|
2 |
WEB
|
Vulnerability-Lab
|
2017-06-07
|
|
Grav CMS 1.4.2 Admin Plugin - Cross-Site Scripting
|
2 |
WEB
|
Ahsan Tahir
|
2017-06-06
|
|
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclos
|
1 |
WEB
|
X41 D-Sec GmbH
|
2017-06-06
|
|
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclos
|
1 |
WEB
|
X41 D-Sec GmbH
|
2017-06-06
|
|
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclos
|
2 |
WEB
|
X41 D-Sec GmbH
|
2017-06-06
|
|
WordPress Plugin Tribulant Newsletters 4.6.4.2 - File Disclosure / Cross-Site Scripting
|
2 |
WEB
|
defensecode
|
2017-06-05
|
|
Kronos Telestaff < 2.92EU29 - SQL Injection
|
2 |
WEB
|
Goran Tuzovic
|
2017-06-05
|
|
Subsonic 6.1.1 - Cross-Site Request Forgery / Cross-Site Scripting
|
1 |
WEB
|
hyp3rlinx
|
2017-06-05
|
|
Subsonic 6.1.1 - Server-Side Request Forgery
|
2 |
WEB
|
hyp3rlinx
|
2017-06-05
|
|
Subsonic 6.1.1 - Cross-Site Request Forgery
|
1 |
WEB
|
hyp3rlinx
|
2017-06-04
|
|
EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 - Remote Code Execution
|
1 |
WEB
|
LiquidWorm
|
2017-06-03
|
|
Joomla! Component Payage 2.05 - 'aid' SQL Injection
|
2 |
WEB
|
Persian Hack Team
|
2017-06-02
|
|
Sungard eTRAKiT3 <= 3.2.1.17 - SQL Injection
|
1 |
WEB
|
Goran Tuzovic
|
2017-06-01
|
|
WebKit - 'Document::prepareForDestruction' / 'CachedFrame' Universal Cross-Site Scripting
|
0 |
WEB
|
Google Security Research
|
2017-06-01
|
|
WebKit - 'CachedFrameBase::restore' Universal Cross-Site Scripting
|
1 |
WEB
|
Google Security Research
|
2017-06-01
|
|
WebKit - CachedFrame does not Detach Openers Universal Cross-Site Scripting
|
1 |
WEB
|
Google Security Research
|
2017-06-01
|
|
Riverbed SteelHead VCX 9.6.0a - Arbitrary File Read
|
1 |
WEB
|
Gregory Draperi
|
2017-05-31
|
|
Piwigo Plugin Facetag 0.0.3 - Cross-Site Scripting
|
1 |
WEB
|
Touhid M.Shaikh
|
2017-05-31
|
|
OV3 Online Administration 3.0 - SQL Injection
|
1 |
WEB
|
LiquidWorm
|
2017-05-31
|
|
OV3 Online Administration 3.0 - Remote Code Execution
|
1 |
WEB
|
LiquidWorm
|
2017-05-31
|
|
OV3 Online Administration 3.0 - Directory Traversal
|
1 |
WEB
|
LiquidWorm
|
2017-05-30
|
|
Piwigo Plugin Facetag 0.0.3 - SQL Injection
|
1 |
WEB
|
Touhid M.Shaikh
|
2017-05-30
|
|
TerraMaster F2-420 NAS TOS 3.0.30 - Root Remote Code Execution
|
1 |
WEB
|
Simone Margaritelli
|
2017-05-30
|
|
IBM Informix Dynamic Server / Informix Open Admin Tool - DLL Injection / Remote Code Execution / Hea
|
1 |
WEB
|
SecuriTeam
|
2017-05-30
|
|
KEMP LoadMaster 7.135.0.13245 - Persistent Cross-Site Scripting / Remote Code Execution
|
2 |
WEB
|
SecuriTeam
|
2017-05-30
|
|
Trend Micro Deep Security 6.5 - XML External Entity Injection / Local Privilege Escalation / Remote
|
2 |
WEB
|
SecuriTeam
|
2017-05-30
|
|
uc-http Daemon - Local File Inclusion / Directory Traversal
|
2 |
WEB
|
Project Insecurity
|
2017-05-29
|
|
WordPress Plugin Huge-IT Video Gallery 2.0.4 - SQL Injection
|
1 |
WEB
|
defensecode
|
2017-05-26
|
|
QWR-1104 Wireless-N Router - Cross-Site Scripting
|
1 |
WEB
|
Touhid M.Shaikh
|
2017-02-22
|
|
D-Link DCS Series Cameras - Insecure Crossdomain
|
2 |
WEB
|
SlidingWindow
|
2017-05-25
|
|
Apple Safari 10.0.3(12602.4.8) / WebKit - 'HTMLObjectElement::updateWidget' Universal Cross-Site Scr
|
3 |
WEB
|
Google Security Research
|
2017-05-25
|
|
WebKit - 'FrameLoader::clear' Stealing Variables via Page Navigation
|
1 |
WEB
|
Google Security Research
|
2017-05-25
|
|
WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting
|
1 |
WEB
|
Google Security Research
|
2017-05-25
|
|
WebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site Scripting
|
3 |
WEB
|
Google Security Research
|
2017-05-25
|
|
WebKit - 'ContainerNode::parserRemoveChild' Universal Cross-Site Scripting
|
1 |
WEB
|
Google Security Research
|
2017-05-25
|
|
Apple WebKit / Safari 10.0.3(12602.4.8) - 'Editor::Command::execute' Universal Cross-Site Scripting
|
2 |
WEB
|
Google Security Research
|
2017-05-25
|
|
Sophos Cyberoam - Cross-site scripting
|
1 |
WEB
|
Bhadresh Patel
|
2017-05-24
|
|
NetGain EM 7.2.647 build 941 - Authentication Bypass / Local File Inclusion
|
2 |
WEB
|
f3ci
|
2017-05-24
|
|
NetGain EM 7.2.647 build 941 - Authentication Bypass / Local File Inclusion
|
2 |
WEB
|
f3ci
|
2017-05-21
|
|
PlaySMS 1.4 - 'import.php' Remote Code Execution
|
2 |
WEB
|
Touhid M.Shaikh
|
2017-05-20
|
|
Mantis Bug Tracker 1.3.10/2.3.0 - Cross-Site Request Forgery
|
2 |
WEB
|
hyp3rlinx
|
2017-05-20
|
|
KMCIS CaseAware - Cross-Site Scripting
|
2 |
WEB
|
justpentest
|
2017-05-19
|
|
D-Link DIR-600M Wireless N 150 - Authentication Bypass
|
1 |
WEB
|
Touhid M.Shaikh
|
2017-05-19
|
|
PlaySMS 1.4 - Remote Code Execution
|
1 |
WEB
|
Touhid M.Shaikh
|
2017-05-19
|
|
ManageEngine ServiceDesk Plus 9.0 - Authentication Bypass
|
1 |
WEB
|
ByteM3
|
2017-05-19
|
|
SAP Business One for Android 1.2.3 - XML External Entity Injection
|
1 |
WEB
|
Ravindra Singh Rathore
|
2017-05-19
|
|
Belden Garrettcom 6K/10K Switches - Authentication Bypass / Memory Corruption
|
1 |
WEB
|
David Tomaschik
|
2017-05-19
|
|
Oracle PeopleSoft - Server-Side Request Forgery
|
1 |
WEB
|
ERPScan
|
2017-05-19
|
|
Joomla! 3.7.0 - 'com_fields' SQL Injection
|
1 |
WEB
|
Mateus Lino
|
2017-05-17
|
|
INFOR EAM 11.0 Build 201410 - Persistent Cross-Site Scripting via Comment Fields
|
1 |
WEB
|
Yoroi
|
2017-05-17
|
|
INFOR EAM 11.0 Build 201410 - 'filtervalue' SQL Injection
|
1 |
WEB
|
Yoroi
|
2017-01-12
|
|
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
|
1 |
WEB
|
SlidingWindow
|
2017-02-28
|
|
Sophos Web Appliance 4.3.1.1 - Session Fixation
|
1 |
WEB
|
SlidingWindow
|
2017-04-28
|
|
Admidio 3.2.8 - Cross-Site Request Forgery
|
1 |
WEB
|
Faiz Ahmed Zaidi
|
2017-05-15
|
|
Mailcow 0.14 - Cross-Site Request Forgery
|
1 |
WEB
|
hyp3rlinx
|
2017-05-14
|
|
PlaySMS 1.4 - '/sendfromfile.php' Remote Code Execution / Unrestricted File Upload
|
1 |
WEB
|
Touhid M.Shaikh
|
2017-05-02
|
|
Zyxel P-660HW-61 Firmware < 3.40(PE.11)C0 Router - Local File Inclusion
|
2 |
WEB
|
ReverseBrain
|
2017-05-10
|
|
CMS Made Simple 2.1.6 - Multiple Vulnerabilities
|
1 |
WEB
|
Osanda Malith Jayathissa
|
2017-05-10
|
|
Gongwalker API Manager 1.1 - Cross-Site Request Forgery
|
1 |
WEB
|
HaHwul
|
2017-05-10
|
|
BanManager WebUI 1.5.8 - PHP Code Injection
|
0 |
WEB
|
HaHwul
|
2017-05-10
|
|
QNAP PhotoStation 5.2.4 / MusicStation 4.8.4 - Authentication Bypass
|
0 |
WEB
|
Kacper Szurek
|
2017-05-09
|
|
Personify360 7.5.2/7.6.1 - Improper Database Schema Access Restrictions
|
1 |
WEB
|
Pesach Zirkind
|
2017-05-09
|
|
Personify360 7.5.2/7.6.1 - Improper Access Restrictions
|
1 |
WEB
|
Pesach Zirkind
|
2017-05-09
|
|
I_ Librarian 4.6/4.7 - Command Injection / Server Side Request Forgery / Directory Enumeration / Cro
|
1 |
WEB
|
SEC Consult
|
2017-05-09
|
|
I_ Librarian 4.6/4.7 - Command Injection / Server Side Request Forgery / Directory Enumeration / Cro
|
1 |
WEB
|
SEC Consult
|
2017-04-24
|
|
LogRhythm Network Monitor - Authentication Bypass / Command Injection
|
1 |
WEB
|
Francesco Oddo
|
2017-05-05
|
|
ViMbAdmin 3.0.15 - Multiple Cross-Site Request Forgery Vulnerabilities
|
1 |
WEB
|
Sysdream
|
2017-05-05
|
|
WordPress Plugin WebDorado Gallery 1.3.29 - SQL Injection
|
1 |
WEB
|
defensecode
|
2017-05-03
|
|
WordPress Core < 4.7.4 - Unauthorized Password Reset
|
1 |
WEB
|
Dawid Golunski
|
2017-05-03
|
|
WordPress Core 4.6 - Remote Code Execution
|
1 |
WEB
|
Dawid Golunski
|
2017-05-03
|
|
Serviio PRO 1.8 DLNA Media Streaming Server - REST API Arbitrary Code Execution
|
2 |
WEB
|
LiquidWorm
|
2017-05-03
|
|
Serviio PRO 1.8 DLNA Media Streaming Server - REST API Arbitrary Password Change
|
2 |
WEB
|
LiquidWorm
|
2017-05-03
|
|
Serviio PRO 1.8 DLNA Media Streaming Server - REST API Information Disclosure
|
2 |
WEB
|
LiquidWorm
|
2017-05-01
|
|
Tuleap Project Wiki 8.3 < 9.6.99.86 - Command Injection
|
1 |
WEB
|
Ben Nott
|
2017-05-01
|
|
Alerton Webtalk 2.5/3.3 - Multiple Vulnerabilities
|
1 |
WEB
|
David Tomaschik
|
2017-04-30
|
|
Emby MediaServer 3.2.5 - Directory Traversal
|
2 |
WEB
|
LiquidWorm
|
2017-04-30
|
|
Emby MediaServer 3.2.5 - Password Reset
|
2 |
WEB
|
LiquidWorm
|
2017-04-30
|
|
Emby MediaServer 3.2.5 - SQL Injection
|
2 |
WEB
|
LiquidWorm
|
2017-04-27
|
|
Easy File Uploader - Arbitrary File Upload
|
2 |
WEB
|
Daniel Godoy
|
2017-04-27
|
|
Simple File Uploader - Arbitrary File Download
|
2 |
WEB
|
Daniel Godoy
|
2017-04-27
|
|
TYPO3 Extension News - SQL Injection
|
2 |
WEB
|
Charles Fol
|
2017-04-26
|
|
Revive Ad Server 4.0.1 - Cross-Site Scripting / Cross-Site Request Forgery
|
1 |
WEB
|
Cyril Vallicari
|
2017-04-25
|
|
October CMS 1.0.412 - Multiple Vulnerabilities
|
3 |
WEB
|
Anti Räis
|
2017-04-24
|
|
Joomla! Component Myportfolio 3.0.2 - 'pid' SQL Injection
|
2 |
WEB
|
Persian Hack Team
|
2017-04-25
|
|
OpenText Documentum Content Server - dm_bp_transition.ebs docbase Method Arbitrary Code Execution
|
1 |
WEB
|
Andrey B. Panfilov
|
2017-04-25
|
|
HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion
|
1 |
WEB
|
Paolo Stagno
|
2017-04-25
|
|
HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion
|
2 |
WEB
|
Paolo Stagno
|
2017-04-25
|
|
Oracle E-Business Suite 12.2.3 - 'IESFOOTPRINT' SQL Injection
|
1 |
WEB
|
ERPScan
|
2017-04-25
|
|
Oracle PeopleSoft - 'PeopleSoftServiceListeningConnector' XML External Entity via DOCTYPE
|
1 |
WEB
|
ERPScan
|
2017-04-25
|
|
WordPress Plugin Wow Forms 2.1 - SQL Injection
|
2 |
WEB
|
TAD GROUP
|
2017-04-25
|
|
WordPress Plugin Wow Viral Signups 2.1 - SQL Injection
|
1 |
WEB
|
TAD GROUP
|
2017-04-25
|
|
WordPress Plugin Car Rental System 2.5 - SQL Injection
|
2 |
WEB
|
TAD GROUP
|
2017-04-25
|
|
WordPress Plugin KittyCatfish 2.2 - SQL Injection
|
1 |
WEB
|
TAD GROUP
|
2017-04-25
|
|
FlySpray 1.0-rc4 - Cross-Site Scripting / Cross-Site Request Forgery
|
0 |
WEB
|
Cyril Vallicari
|
2017-04-20
|
|
Apple WebKit / Safari 10.0.2(12602.3.12.0.1) - 'operationSpreadGeneric' Universal Cross-Site Scripti
|
1 |
WEB
|
Google Security Research
|
2017-04-20
|
|
Apple WebKit / Safari 10.0.2(12602.3.12.0.1) - 'PrototypeMap::createEmptyStructure' Universal Cross-
|
2 |
WEB
|
Google Security Research
|
2017-04-16
|
|
Mantis Bug Tracker 1.3.0/2.3.0 - Password Reset
|
2 |
WEB
|
hyp3rlinx
|
2017-04-14
|
|
Concrete5 CMS 8.1.0 - 'Host' Header Injection
|
2 |
WEB
|
hyp3rlinx
|
2017-04-13
|
|
Alienvault OSSIM/USM 5.3.4/5.3.5 - Remote Command Execution (Metasploit)
|
2 |
WEB
|
Peter Lapp
|
2017-04-13
|
|
agorum core Pro 7.8.1.4-251 - Persistent Cross-Site Scripting
|
2 |
WEB
|
SySS GmbH
|
2017-04-13
|
|
agorum core Pro 7.8.1.4-251 - Cross-Site Request Forgery
|
1 |
WEB
|
SySS GmbH
|
2016-01-11
|
|
SedSystems D3 Decimator - Multiple Vulnerabilities
|
2 |
WEB
|
prdelka
|
2017-02-15
|
|
Coppermine Gallery < 1.5.44 - Directory Traversal
|
2 |
WEB
|
Hacker Fantastic
|
2017-04-11
|
|
Apple WebKit / Safari 10.0.3 (12602.4.8) - Universal Cross-Site Scripting via a Focus Event and a Li
|
2 |
WEB
|
Google Security Research
|
2017-04-11
|
|
Apple WebKit / Safari 10.0.3 (12602.4.8) - Synchronous Page Load Universal Cross-Site Scripting
|
2 |
WEB
|
Google Security Research
|
2017-04-11
|
|
Horde Groupware Webmail 3/4/5 - Multiple Remote Code Executions
|
2 |
WEB
|
SecuriTeam
|
2017-04-11
|
|
Brother MFC-J6520DW - Authentication Bypass / Password Change
|
2 |
WEB
|
Patryk Bogdan
|