2016-11-06
|
|
SweetRice 1.5.1 - Backup Disclosure
|
2 |
WEB
|
Ashiyane Digital Security Team
|
2016-11-06
|
|
SweetRice 1.5.1 - Arbitrary File Upload
|
1 |
WEB
|
Ashiyane Digital Security Team
|
2016-11-03
|
|
Redaxo 5.2.0 - Cross-Site Request Forgery
|
2 |
WEB
|
Amir.ght
|
2016-11-03
|
|
nodCMS - Cross-Site Request Forgery
|
2 |
WEB
|
Amir.ght
|
2016-11-03
|
|
sNews 1.7.1 - Arbitrary File Upload
|
2 |
WEB
|
Amir.ght
|
2016-11-03
|
|
sNews 1.7.1 - Cross-Site Request Forgery
|
1 |
WEB
|
Amir.ght
|
2016-11-03
|
|
ETchat 3.7 - Cross-Site Request Forgery
|
1 |
WEB
|
Hesam Bazvand
|
2016-11-03
|
|
SweetRice 1.5.1 - Cross-Site Request Forgery / PHP Code Execution
|
1 |
WEB
|
Ashiyane Digital Security Team
|
2016-11-03
|
|
SweetRice 1.5.1 - Arbitrary File Download
|
2 |
WEB
|
Ashiyane Digital Security Team
|
2016-11-02
|
|
SweetRice 1.5.1 - Cross-Site Request Forgery
|
1 |
WEB
|
Ashiyane Digital Security Team
|
2016-11-02
|
|
LifeSize Room 5.0.9 - Multiple Vulnerabilities
|
2 |
WEB
|
Xiphos Research Ltd
|
2016-11-02
|
|
Alienvault OSSIM/USM 5.3.1 - SQL Injection
|
2 |
WEB
|
Peter Lapp
|
2016-11-02
|
|
Alienvault OSSIM/USM 5.3.1 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Peter Lapp
|
2016-11-02
|
|
Alienvault OSSIM/USM 5.3.1 - PHP Object Injection
|
0 |
WEB
|
Peter Lapp
|
2016-11-01
|
|
My Little Forum 2.3.7 - Multiple Vulnerabilities
|
2 |
WEB
|
Ashiyane Digital Security Team
|
2016-11-01
|
|
School Registration and Fee System - Authentication Bypass
|
1 |
WEB
|
opt1lc
|
2016-10-31
|
|
S9Y Serendipity 2.0.4 - Cross-Site Scripting
|
1 |
WEB
|
Besim
|
2016-10-28
|
|
InfraPower PPS-02-S Q213V1 - Cross-Site Request Forgery
|
1 |
WEB
|
LiquidWorm
|
2016-10-28
|
|
InfraPower PPS-02-S Q213V1 - Authentication Bypass
|
1 |
WEB
|
LiquidWorm
|
2016-10-28
|
|
InfraPower PPS-02-S Q213V1 - Insecure Direct Object Reference
|
1 |
WEB
|
LiquidWorm
|
2016-10-28
|
|
InfraPower PPS-02-S Q213V1 - Local File Disclosure
|
1 |
WEB
|
LiquidWorm
|
2016-10-28
|
|
InfraPower PPS-02-S Q213V1 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
LiquidWorm
|
2016-10-28
|
|
InfraPower PPS-02-S Q213V1 - Remote Command Execution
|
2 |
WEB
|
LiquidWorm
|
2016-10-27
|
|
Joomla! 3.4.4 < 3.6.4 - Account Creation / Privilege Escalation
|
2 |
WEB
|
Xiphos Research Ltd
|
2016-10-26
|
|
Boonex Dolphin 7.3.2 - Authentication Bypass
|
3 |
WEB
|
Saadi Siddiqui
|
2016-10-24
|
|
Industrial Secure Routers EDR-810 / EDR-G902 / EDR-G903 - Insecure Configuration Management
|
2 |
WEB
|
Sniper Pex
|
2016-10-24
|
|
EC-CUBE 2.12.6 - Server-Side Request Forgery
|
3 |
WEB
|
Wadeek
|
2016-10-24
|
|
Orange Inventel LiveBox 5.08.3-sp - Cross-Site Request Forgery
|
2 |
WEB
|
BlackMamba
|
2016-10-23
|
|
Zenbership 107 - Multiple Vulnerabilities
|
1 |
WEB
|
Besim
|
2016-10-21
|
|
FreePBX 13 - Remote Command Execution / Privilege Escalation
|
2 |
WEB
|
Christopher Davis
|
2016-10-21
|
|
Just Dial Clone Script - 'srch' SQL Injection
|
2 |
WEB
|
Arbin Godar
|
2016-10-20
|
|
SPIP 3.1.2 - Cross-Site Request Forgery
|
1 |
WEB
|
Sysdream
|
2016-10-20
|
|
SPIP 3.1.1/3.1.2 - File Enumeration / Path Traversal
|
1 |
WEB
|
Sysdream
|
2016-10-20
|
|
SPIP 3.1.2 Template Compiler/Composer - PHP Code Execution
|
1 |
WEB
|
Sysdream
|
2016-10-20
|
|
Event Calendar PHP 1.5 - SQL Injection
|
1 |
WEB
|
Ehsan Hosseini
|
2016-10-20
|
|
Classifieds Rental Script - SQL Injection
|
2 |
WEB
|
Arbin Godar
|
2016-10-20
|
|
Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection
|
2 |
WEB
|
Jakub Palaczynski
|
2016-10-19
|
|
Intel(R) PROSet/Wireless WiFi Software 15.01.1000.0927 - Unquoted Service Path Privilege Escalation
|
1 |
WEB
|
Joey Lane
|
2016-10-19
|
|
XhP CMS 0.5.1 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
|
2 |
WEB
|
Ahsan Tahir
|
2016-10-19
|
|
CNDSOFT 2.3 - Cross-Site Request Forgery / Arbitrary File Upload
|
1 |
WEB
|
Besim
|
2016-10-18
|
|
Cgiemail 1.6 - Source Code Disclosure
|
1 |
WEB
|
Finbar Crago
|
2016-10-18
|
|
ManageEngine ServiceDesk Plus 9.2 Build 9207 - Unauthorized Information Disclosure
|
2 |
WEB
|
p0z
|
2016-10-18
|
|
Pluck CMS 4.7.3 - Cross-Site Request Forgery (Add Page)
|
2 |
WEB
|
Ahsan Tahir
|
2016-10-17
|
|
PHP Business Directory - Multiple Vulnerabilities
|
2 |
WEB
|
larrycompress
|
2016-10-14
|
|
School Full CBT 0.1 - SQL Injection
|
2 |
WEB
|
lahilote
|
2016-10-16
|
|
PHP NEWS 1.3.0 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
Meryem AKDOĞAN
|
2016-10-14
|
|
Simple Shopping Cart Application 0.1 - SQL Injection
|
2 |
WEB
|
lahilote
|
2016-10-16
|
|
PHP Image Database - Multiple Vulnerabilities
|
2 |
WEB
|
larrycompress
|
2016-10-17
|
|
Subrion CMS 4.0.5 - Cross-Site Request Forgery Bypass / Persistent Cross-Site Scripting
|
1 |
WEB
|
Ahsan Tahir
|
2016-10-16
|
|
PHP Telephone Directory - Multiple Vulnerabilities
|
2 |
WEB
|
larrycompress
|
2016-10-14
|
|
Health Record System 0.1 - Authentication Bypass
|
2 |
WEB
|
lahilote
|
2016-10-14
|
|
Fashion Shopping Cart 0.1 - SQL Injection
|
2 |
WEB
|
lahilote
|
2016-10-14
|
|
Learning Management System 0.1 - Authentication Bypass
|
2 |
WEB
|
lahilote
|
2016-10-14
|
|
Simple Dynamic Web 0.1 - SQL Injection
|
1 |
WEB
|
lahilote
|
2016-10-14
|
|
Web Based Alumni Tracking System 0.1 - SQL Injection
|
2 |
WEB
|
lahilote
|
2016-10-14
|
|
Student Information System (SIS) 0.1 - Authentication Bypass
|
3 |
WEB
|
lahilote
|
2016-10-14
|
|
YouTube Automated CMS 1.0.7 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
|
1 |
WEB
|
Arbin Godar
|
2016-10-14
|
|
Simple Forum PHP 2.4 - Cross-Site Request Forgery (Edit Options)
|
2 |
WEB
|
Ehsan Hosseini
|
2016-10-14
|
|
Simple Forum PHP 2.4 - SQL Injection
|
1 |
WEB
|
Ehsan Hosseini
|
2016-10-13
|
|
JonhCMS 4.5.1 - SQL Injection
|
2 |
WEB
|
Besim
|
2016-10-13
|
|
RSS News AutoPilot Script 1.0.1/3.1.0 - Admin Panel Authentication Bypass
|
2 |
WEB
|
Arbin Godar
|
2016-10-13
|
|
Colorful Blog - Cross-Site Request Forgery (Change Admin Password)
|
2 |
WEB
|
Besim
|
2016-10-13
|
|
Colorful Blog - Persistent Cross-Site Scripting
|
2 |
WEB
|
Besim
|
2016-10-13
|
|
Thatware 0.4.6 - SQL Injection
|
2 |
WEB
|
Besim
|
2016-10-13
|
|
Simple Blog PHP 2.0 - SQL Injection
|
2 |
WEB
|
Ehsan Hosseini
|
2016-10-13
|
|
Simple Blog PHP 2.0 - Multiple Vulnerabilities
|
1 |
WEB
|
Ehsan Hosseini
|
2016-10-12
|
|
ApPHP MicroCMS 3.9.5 - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
Besim
|
2016-10-12
|
|
ApPHP MicroCMS 3.9.5 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Besim
|
2016-10-12
|
|
OpenCimetiere 3.0.0-a5 - Blind SQL Injection
|
1 |
WEB
|
Wadeek
|
2016-10-12
|
|
NetBilletterie 2.8 - Multiple Vulnerabilities
|
1 |
WEB
|
Wadeek
|
2016-10-12
|
|
Categorizator 0.3.1 - SQL Injection
|
1 |
WEB
|
Wadeek
|
2016-10-11
|
|
ApPHP MicroBlog 1.0.2 - Cross-Site Request Forgery (Add New Author)
|
2 |
WEB
|
Besim
|
2016-10-11
|
|
ApPHP MicroBlog 1.0.2 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Besim
|
2016-10-11
|
|
RSA Enterprise Compromise Assessment Tool 4.1.0.1 - XML External Entity Injection
|
2 |
WEB
|
SEC Consult
|
2016-10-11
|
|
AVTECH IP Camera / NVR / DVR Devices - Multiple Vulnerabilities
|
2 |
WEB
|
Gergely Eberhardt
|
2016-10-11
|
|
phpEnter 4.2.7 - Cross-Site Request Forgery (Add New Post)
|
2 |
WEB
|
Besim
|
2016-10-11
|
|
BirdBlog 1.4.0 - Cross-Site Request Forgery (Add New Post)
|
2 |
WEB
|
Besim
|
2016-10-10
|
|
Spacemarc News - Cross-Site Request Forgery (Add New Post)
|
2 |
WEB
|
Besim
|
2016-10-10
|
|
Maian Weblog 4.0 - Cross-Site Request Forgery (Add New Post)
|
2 |
WEB
|
Besim
|
2016-10-09
|
|
PHP Press Release - Persistent Cross-Site Scripting
|
2 |
WEB
|
Besim
|
2016-10-09
|
|
PHP Press Release - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
Besim
|
2016-09-19
|
|
ShoreTel Connect ONSITE - Blind SQL Injection
|
2 |
WEB
|
Iraklis Mathiopoulos
|
2016-10-09
|
|
miniblog 1.0.1 - Cross-Site Request Forgery (Add New Post)
|
2 |
WEB
|
Besim
|
2016-10-07
|
|
Entrepreneur Job Portal Script 2.06 - SQL Injection
|
2 |
WEB
|
OoN_Boy
|
2016-10-07
|
|
Simple PHP Blog 0.8.4 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
Besim
|
2016-10-06
|
|
Just Dial Clone Script - 'fid' SQL Injection
|
1 |
WEB
|
OoN_Boy
|
2016-10-06
|
|
MLM Unilevel Plan Script 1.0.2 - SQL Injection
|
1 |
WEB
|
N4TuraL
|
2016-10-06
|
|
B2B Portal Script - Blind SQL Injection
|
1 |
WEB
|
OoN_Boy
|
2016-10-06
|
|
PHP Classifieds Rental Script - Blind SQL Injection
|
1 |
WEB
|
OoN_Boy
|
2016-10-06
|
|
Advance MLM Script - SQL Injection
|
1 |
WEB
|
OoN_Boy
|
2016-10-05
|
|
Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion
|
1 |
WEB
|
KoreLogic
|
2016-10-05
|
|
Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution
|
1 |
WEB
|
KoreLogic
|
2016-10-05
|
|
Witbe - Remote Code Execution
|
1 |
WEB
|
BeLmar
|
2016-10-05
|
|
Picosafe Web GUI - Multiple Vulnerabilities
|
2 |
WEB
|
Shahab Shamsi
|
2016-09-28
|
|
Symantec Messaging Gateway 10.6.1 - Directory Traversal
|
1 |
WEB
|
R-73eN
|
2016-09-27
|
|
TP-Link Archer CR-700 - Cross-Site Scripting
|
2 |
WEB
|
Ayushman Dutta
|
2016-09-26
|
|
Joomla! Component Event Booking 2.10.1 - SQL Injection
|
2 |
WEB
|
Persian Hack Team
|
2016-09-22
|
|
Matrimonial Website Script 1.0.2 - SQL Injection
|
1 |
WEB
|
N4TuraL
|
2016-09-22
|
|
Kerio Control Unified Threat Management 9.1.0 build 1087/9.1.1 build 1324 - Multiple Vulnerabilities
|
2 |
WEB
|
SEC Consult
|
2016-09-22
|
|
Joomla! Component com_videogallerylite 1.0.9 - SQL Injection
|
0 |
WEB
|
Larry W. Cashdollar
|
2016-09-22
|
|
Exponent CMS 2.3.9 - Blind SQL Injection
|
1 |
WEB
|
Manuel García Cárdenas
|
2016-09-22
|
|
Microix Timesheet Module - SQL Injection
|
2 |
WEB
|
Anthony Cole
|
2016-09-20
|
|
Dolphin 7.3.0 - Error-Based SQL Injection
|
2 |
WEB
|
Kacper Szurek
|
2016-09-20
|
|
VegaDNS 0.13.2 - Remote Command Injection
|
1 |
WEB
|
Wireghoul
|
2016-09-19
|
|
ZineBasic 1.1 - Arbitrary File Disclosure
|
2 |
WEB
|
bd0rk
|
2016-09-19
|
|
MuM MapEdit 3.2.6.0 - Multiple Vulnerabilities
|
1 |
WEB
|
Paul Baade & Sven Krewitt
|
2016-09-19
|
|
MyBB 1.8.6 - SQL Injection
|
1 |
WEB
|
Curesec Research Team
|
2016-09-19
|
|
Kajona 4.7 - Cross-Site Scripting / Directory Traversal
|
2 |
WEB
|
Curesec Research Team
|
2016-09-19
|
|
WordPress Plugin Order Export Import for WooCommerce - Order Information Disclosure
|
2 |
WEB
|
david-peltier
|
2016-09-19
|
|
BuilderEngine 3.5.0 - Arbitrary File Upload
|
2 |
WEB
|
metanubix
|
2016-09-16
|
|
AnoBBS 1.0.1 - Remote File Inclusion
|
2 |
WEB
|
bd0rk
|
2016-09-15
|
|
Cisco EPC 3925 - Multiple Vulnerabilities
|
2 |
WEB
|
Patryk Bogdan
|
2016-09-13
|
|
Open-Xchange App Suite 7.8.2 - Cross-Site Scripting
|
2 |
WEB
|
Jakub A>>oczek
|
2016-09-13
|
|
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Benjamin Daniel Mussler
|
2016-09-13
|
|
ASUS DSL-X11 ADSL Router - DNS Change
|
3 |
WEB
|
Todor Donev
|
2016-09-13
|
|
COMTREND ADSL Router CT-5367 C01_R12 / CT-5624 C01_R03 - DNS Change
|
1 |
WEB
|
Todor Donev
|
2016-09-13
|
|
Tenda ADSL2/2+ Modem 963281TAN - DNS Change
|
1 |
WEB
|
Todor Donev
|
2016-09-13
|
|
PLANET VDR-300NU ADSL Router - DNS Change
|
1 |
WEB
|
Todor Donev
|
2016-09-13
|
|
PIKATEL 96338WS_ 96338L-2M-8M - DNS Change
|
1 |
WEB
|
Todor Donev
|
2016-09-13
|
|
Inteno EG101R1 VoIP Router - DNS Change
|
1 |
WEB
|
Todor Donev
|
2016-09-13
|
|
Exper EWM-01 ADSL/MODEM - DNS Change
|
2 |
WEB
|
Todor Donev
|
2016-09-13
|
|
Contrexx CMS egov Module 1.0.0 - SQL Injection
|
2 |
WEB
|
hamidreza borghei
|
2016-09-13
|
|
wdCalendar 2 - SQL Injection
|
2 |
WEB
|
Alfonso Castillo Angel
|
2016-09-13
|
|
Cherry Music 0.35.1 - Arbitrary File Disclosure
|
2 |
WEB
|
feedersec
|
2016-09-09
|
|
Airmail 3.0.2 - Cross-Site Scripting
|
2 |
WEB
|
redrain
|