2016-09-09
|
|
Vodafone Mobile Wifi - Reset Admin Password
|
1 |
WEB
|
Daniele Linguaglossa
|
2016-09-08
|
|
Zabbix 2.0 < 3.0.3 - SQL Injection
|
2 |
WEB
|
Zzzians
|
2016-09-08
|
|
Jobberbase 2.0 - Multiple Vulnerabilities
|
2 |
WEB
|
Ross Marks
|
2016-09-07
|
|
Adobe ColdFusion < 11 Update 10 - XML External Entity Injection
|
1 |
WEB
|
Dawid Golunski
|
2016-09-07
|
|
FreePBX 13.0.x < 13.0.154 - Remote Command Execution
|
1 |
WEB
|
i-Hmx
|
2016-09-07
|
|
CumulusClips 2.4.1 - Multiple Vulnerabilities
|
2 |
WEB
|
kor3k
|
2016-09-06
|
|
PHPIPAM 1.2.1 - Multiple Vulnerabilities
|
1 |
WEB
|
Saeed reza Zamanian
|
2016-09-05
|
|
WordPress Plugin RB Agency 2.4.7 - Local File Disclosure
|
2 |
WEB
|
Persian Hack Team
|
2016-09-04
|
|
Belkin F9K1122v1 1.00.30 - Buffer Overflow (via Cross-Site Request Forgery)
|
3 |
WEB
|
b1ack0wl
|
2016-08-31
|
|
ZKTeco ZKAccess Security System 5.3.1 - Persistent Cross-Site Scripting
|
1 |
WEB
|
LiquidWorm
|
2016-08-31
|
|
ZKTeco ZKBioSecurity 3.0 - 'visLogin.jsp' Local Authentication Bypass
|
2 |
WEB
|
LiquidWorm
|
2016-08-31
|
|
ZKTeco ZKBioSecurity 3.0 - Directory Traversal
|
2 |
WEB
|
LiquidWorm
|
2016-08-31
|
|
ZKTeco ZKBioSecurity 3.0 - Cross-Site Request Forgery (Add Superadmin)
|
2 |
WEB
|
LiquidWorm
|
2016-08-31
|
|
ZKTeco ZKBioSecurity 3.0 - Hard-Coded Credentials SYSTEM Remote Code Execution
|
2 |
WEB
|
LiquidWorm
|
2016-08-29
|
|
FreePBX 13.0.35 - SQL Injection
|
1 |
WEB
|
i-Hmx
|
2016-08-29
|
|
PLC Wireless Router GPN2.4P21-C-CN - Arbitrary File Disclosure
|
1 |
WEB
|
Rahul Raz
|
2016-08-29
|
|
Intellinet IP Camera INT-L100M20N - Unauthorized Admin Credential Change
|
1 |
WEB
|
Todor Donev
|
2016-08-29
|
|
HelpDeskZ 1.0.2 - Arbitrary File Upload
|
2 |
WEB
|
Lars Morgenroth
|
2016-08-29
|
|
FreePBX 13.0.35 - Remote Command Execution
|
1 |
WEB
|
0x4148
|
2016-08-24
|
|
WordPress Plugin CYSTEME Finder 1.3 - Arbitrary File Disclosure/Arbitrary File Upload
|
1 |
WEB
|
T0w3ntum
|
2016-08-23
|
|
chatNow - Multiple Vulnerabilities
|
1 |
WEB
|
HaHwul
|
2016-08-23
|
|
SimplePHPQuiz - Blind SQL Injection
|
1 |
WEB
|
HaHwul
|
2016-08-23
|
|
WordPress Plugin Mail Masta 1.0 - Local File Inclusion
|
2 |
WEB
|
Guillermo Garcia Marcos
|
2016-08-22
|
|
WordPress Core 4.5.3 - Directory Traversal / Denial of Service
|
2 |
WEB
|
Yorick Koster
|
2016-08-22
|
|
Sakai 10.7 - Multiple Vulnerabilities
|
2 |
WEB
|
LiquidWorm
|
2016-08-22
|
|
Ocomon 2.0 - SQL Injection
|
2 |
WEB
|
Jonatas Fil
|
2016-08-22
|
|
VideoIQ Camera - Local File Disclosure
|
3 |
WEB
|
Yakir Wizman
|
2016-08-22
|
|
Honeywell IP-Camera HICC-1100PT - Local File Disclosure
|
2 |
WEB
|
Yakir Wizman
|
2016-08-22
|
|
JVC IP-Camera VN-T216VPRU - Local File Disclosure
|
1 |
WEB
|
Yakir Wizman
|
2016-08-22
|
|
Vanderbilt IP-Camera CCPW3025-IR / CVMW3025-IR - Local File Disclosure
|
1 |
WEB
|
Yakir Wizman
|
2016-08-19
|
|
tcPbX - 'tcpbx_lang' Local File Inclusion
|
1 |
WEB
|
0x4148
|
2016-08-19
|
|
MESSOA IP Cameras (Multiple Models) - Password Change
|
1 |
WEB
|
Todor Donev
|
2016-08-19
|
|
Fortigate Firewalls - 'EGREGIOUSBLUNDER' Remote Code Execution
|
1 |
WEB
|
Shadow Brokers
|
2016-08-19
|
|
TOPSEC Firewalls - 'ELIGIBLEBOMBSHELL' Remote Code Execution
|
1 |
WEB
|
Shadow Brokers
|
2016-08-19
|
|
TOPSEC Firewalls - 'ELIGIBLECANDIDATE' Remote Code Execution
|
1 |
WEB
|
Shadow Brokers
|
2016-08-19
|
|
TOPSEC Firewalls - 'ELIGIBLECONTESTANT' Remote Code Execution
|
2 |
WEB
|
Shadow Brokers
|
2016-08-19
|
|
ZYCOO IP Phone System - Remote Command Execution
|
2 |
WEB
|
0x4148
|
2016-08-19
|
|
MESSOA IP-Camera NIC990 - Authentication Bypass / Configuration Download
|
2 |
WEB
|
Todor Donev
|
2016-08-19
|
|
TOSHIBA IP-Camera IK-WP41A - Authentication Bypass / Configuration Download
|
1 |
WEB
|
Todor Donev
|
2016-08-19
|
|
C2S DVR Management IRDOME-II-C2S / IRBOX-II-C2S / DVR - Credentials Disclosure / Authentication Bypa
|
2 |
WEB
|
Yakir Wizman
|
2016-08-19
|
|
JVC IP-Camera VN-T216VPRU - Credentials Disclosure
|
2 |
WEB
|
Yakir Wizman
|
2016-08-19
|
|
Vanderbilt IP-Camera CCPW3025-IR / CVMW3025-IR - Credentials Disclosure
|
2 |
WEB
|
Yakir Wizman
|
2016-08-19
|
|
SIEMENS IP Cameras (Multiple Models) - Credential Disclosure / Configuration Download
|
2 |
WEB
|
Todor Donev
|
2016-08-18
|
|
Honeywell IP-Camera HICC-1100PT - Credentials Disclosure
|
2 |
WEB
|
Yakir Wizman
|
2016-08-18
|
|
SIEMENS IP Camera CCMW1025 x.2.2.1798 - Remote Admin Credentials Change
|
2 |
WEB
|
Todor Donev
|
2016-08-17
|
|
SIEMENS IP-Camera CVMS2025-IR / CCMS2025 - Credentials Disclosure
|
2 |
WEB
|
Yakir Wizman
|
2016-08-16
|
|
Nagios Incident Manager 2.0.0 - Multiple Vulnerabilities
|
2 |
WEB
|
Security-Assessment.com
|
2016-08-16
|
|
Nagios Network Analyzer 2.2.0 - Multiple Vulnerabilities
|
3 |
WEB
|
Security-Assessment.com
|
2016-08-16
|
|
Nagios Log Server 1.4.1 - Multiple Vulnerabilities
|
2 |
WEB
|
Security-Assessment.com
|
2016-08-16
|
|
Pi-Hole Web Interface 2.8.1 - Persistent Cross-Site Scripting in Whitelist/Blacklist
|
2 |
WEB
|
loneferret
|
2016-08-16
|
|
Lepton CMS 2.2.0/2.2.1 - PHP Code Injection
|
1 |
WEB
|
hyp3rlinx
|
2016-08-16
|
|
Lepton CMS 2.2.0/2.2.1 - Directory Traversal
|
2 |
WEB
|
hyp3rlinx
|
2016-08-16
|
|
WSO2 Carbon 4.4.5 - Denial of Service / Cross-Site Request Forgery
|
2 |
WEB
|
hyp3rlinx
|
2016-08-16
|
|
WSO2 Carbon 4.4.5 - Persistent Cross-Site Scripting
|
2 |
WEB
|
hyp3rlinx
|
2016-08-16
|
|
WSO2 Carbon 4.4.5 - Local File Inclusion
|
2 |
WEB
|
hyp3rlinx
|
2016-08-16
|
|
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
|
1 |
WEB
|
hyp3rlinx
|
2016-08-15
|
|
Zabbix 2.2.x/3.0.x - SQL Injection
|
2 |
WEB
|
1n3
|
2016-08-15
|
|
GitLab - 'impersonate' Feature Privilege Escalation
|
1 |
WEB
|
Kaimi
|
2016-08-11
|
|
ColoradoFTP 1.3 Prime Edition (Build 8) - Directory Traversal
|
2 |
WEB
|
Rv3Laboratory
|
2016-08-10
|
|
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
|
2 |
WEB
|
Pedro Ribeiro
|
2016-08-10
|
|
EyeLock nano NXT 3.5 - Remote Code Execution
|
2 |
WEB
|
LiquidWorm
|
2016-08-10
|
|
EyeLock nano NXT 3.5 - Local File Disclosure
|
2 |
WEB
|
LiquidWorm
|
2016-08-10
|
|
vBulletin 5.2.2 - Server-Side Request Forgery
|
2 |
WEB
|
Dawid Golunski
|
2016-08-10
|
|
Nagios Network Analyzer 2.2.1 - Multiple Cross-Site Request Forgery Vulnerabilities
|
2 |
WEB
|
hyp3rlinx
|
2016-08-08
|
|
WordPress Plugin Add From Server < 3.3.2 - Cross-Site Request Forgery (Arbitrary File Upload)
|
2 |
WEB
|
Edwin Molenaar
|
2016-08-08
|
|
PHPCollab CMS 2.5 - 'emailusers.php' SQL Injection
|
3 |
WEB
|
Vulnerability-Lab
|
2016-08-08
|
|
Navis Webaccess - SQL Injection
|
1 |
WEB
|
bRpsd
|
2016-08-06
|
|
NUUO NVRmini 2 3.0.8 - 'strong_user.php' Backdoor Remote Shell Access
|
2 |
WEB
|
LiquidWorm
|
2016-08-06
|
|
NUUO NVRmini 2 3.0.8 - Arbitrary File Deletion
|
2 |
WEB
|
LiquidWorm
|
2016-08-06
|
|
NUUO NVRmini 2 3.0.8 - Remote Command Injection (Shellshock)
|
1 |
WEB
|
LiquidWorm
|
2016-08-06
|
|
NUUO NVRmini 2 3.0.8 - Multiple OS Command Injections
|
2 |
WEB
|
LiquidWorm
|
2016-08-06
|
|
NUUO NVRmini 2 3.0.8 - Local File Disclosure
|
2 |
WEB
|
LiquidWorm
|
2016-08-06
|
|
NUUO NVRmini 2 3.0.8 - Cross-Site Request Forgery (Add Admin)
|
2 |
WEB
|
LiquidWorm
|
2016-08-06
|
|
NUUO NVRmini 2 3.0.8 - Remote Code Execution
|
2 |
WEB
|
LiquidWorm
|
2016-08-05
|
|
NASdeluxe NDL-2400r 2.01.09 - OS Command Injection
|
2 |
WEB
|
SySS GmbH
|
2016-08-05
|
|
WordPress Plugin Count Per Day 3.5.4 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Julien Rentrop
|
2016-08-05
|
|
Davolink DV-2051 - Multiple Vulnerabilities
|
2 |
WEB
|
Eric Flokstra
|
2016-08-05
|
|
PHP Power Browse 1.2 - Directory Traversal
|
3 |
WEB
|
Manuel Mancera
|
2016-08-05
|
|
Subrion CMS 4.0.5 - SQL Injection
|
2 |
WEB
|
Vulnerability-Lab
|
2016-08-02
|
|
Open Upload 0.4.2 - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
Vinesh Redkar
|
2016-08-01
|
|
WordPress Plugin ALO EasyMail NewsLetter 2.9.2 - Cross-Site Request Forgery (Add/Import Arbitrary Su
|
1 |
WEB
|
Yorick Koster
|
2016-08-01
|
|
WordPress Plugin WP Live Chat Support 6.2.03 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Dennis Kerdijk & Erwin Kievith
|
2016-08-01
|
|
WordPress Plugin Booking Calendar 6.2 - SQL Injection
|
1 |
WEB
|
Edwin Molenaar
|
2016-07-29
|
|
phpMyAdmin 4.6.2 - (Authenticated) Remote Code Execution
|
2 |
WEB
|
@iamsecurity
|
2016-07-29
|
|
Trend Micro Deep Discovery 3.7/3.8 SP1 (3.81)/3.8 SP2 (3.82) - 'hotfix_upload.cgi' Filename Remote C
|
2 |
WEB
|
korpritzombie
|
2016-07-29
|
|
WordPress Plugin Ultimate Product Catalog 3.9.8 - do_shortcode via ajax Blind SQL Injection
|
2 |
WEB
|
i0akiN SEC-LABORATORY
|
2016-07-29
|
|
AXIS (Multiple Products) - 'devtools ' (Authenticated) Remote Command Execution
|
2 |
WEB
|
Orwelllabs
|
2016-07-26
|
|
Iris ID IrisAccess ICU 7000-2 - Remote Command Execution
|
2 |
WEB
|
LiquidWorm
|
2016-07-26
|
|
Iris ID IrisAccess ICU 7000-2 - Multiple Vulnerabilities
|
3 |
WEB
|
LiquidWorm
|
2016-07-26
|
|
PHP File Vault 0.9 - Directory Traversal
|
2 |
WEB
|
N_A
|
2016-07-25
|
|
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
|
2 |
WEB
|
SEC Consult
|
2016-07-25
|
|
Bellini/Supercook Wi-Fi Yumi SC200 - Multiple Vulnerabilities
|
2 |
WEB
|
James McLean
|
2016-07-25
|
|
Compal CH7465LG-LC Modem/Router CH7465LG-NCIP-4.50.18.13-NOSH - Multiple Vulnerabilities
|
2 |
WEB
|
Gergely Eberhardt
|
2016-07-25
|
|
Hitron CGNV4 Modem/Router 4.3.9.9-SIP-UPC - Multiple Vulnerabilities
|
3 |
WEB
|
Gergely Eberhardt
|
2016-07-25
|
|
Technicolor TC7200 Modem/Router STD6.02.11 - Multiple Vulnerabilities
|
2 |
WEB
|
Gergely Eberhardt
|
2016-07-25
|
|
Ubee EVW3226 Modem/Router 1.0.20 - Multiple Vulnerabilities
|
1 |
WEB
|
Gergely Eberhardt
|
2016-07-25
|
|
PHP gettext 1.0.12 - 'gettext.php' Code Execution
|
2 |
WEB
|
kmkz
|
2016-07-25
|
|
GRR Système de Gestion et de Réservations de Ressources 3.0.0-RC1 - Arbitrary File Upload
|
2 |
WEB
|
kmkz
|
2016-07-25
|
|
CodoForum 3.2.1 - SQL Injection
|
2 |
WEB
|
Yakir Wizman
|
2016-07-25
|
|
Drupal Module CODER 2.5 - Remote Command Execution (Metasploit)
|
0 |
WEB
|
Mehmet Ince
|
2016-07-21
|
|
TeamPass Passwords Management System 2.1.26 - Arbitrary File Download
|
2 |
WEB
|
Hasan Emre Ozer
|
2016-07-20
|
|
WordPress Plugin Video Player 1.5.16 - SQL Injection
|
2 |
WEB
|
David Vaartjes
|
2016-07-20
|
|
Wowza Streaming Engine 4.5.0 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
LiquidWorm
|
2016-07-20
|
|
Wowza Streaming Engine 4.5.0 - Cross-Site Request Forgery (Add Advanced Admin)
|
2 |
WEB
|
LiquidWorm
|
2016-07-20
|
|
Wowza Streaming Engine 4.5.0 - Remote Privilege Escalation
|
1 |
WEB
|
LiquidWorm
|
2016-07-20
|
|
Django CMS 3.3.0 - Editor Snippet Persistent Cross-Site Scripting
|
2 |
WEB
|
Vulnerability-Lab
|
2016-07-19
|
|
newsp.eu PHP Calendar Script 1.0 - User Credentials Disclosure
|
2 |
WEB
|
Meisam Monsef
|
2016-07-19
|
|
NewsP Free News Script 1.4.7 - User Credentials Disclosure
|
2 |
WEB
|
Meisam Monsef
|
2014-10-12
|
|
vBulletin 4.x - breadcrumbs via xmlrpc API (Authenticated) SQL Injection
|
2 |
WEB
|
tintinweb
|
2014-10-12
|
|
vBulletin 4.x/5.x - AdminCP/ApiLog via xmlrpc API (Authenticated) Persistent Cross-Site Scripting
|
1 |
WEB
|
tintinweb
|
2016-07-15
|
|
Clear Voyager Hotspot IMW-C910W - Arbitrary File Disclosure
|
1 |
WEB
|
Damaster
|
2016-07-14
|
|
Joomla! Component Guru Pro - 'Itemid' SQL Injection
|
2 |
WEB
|
s0nk3y
|
2016-07-13
|
|
Apache Archiva 1.3.9 - Multiple Cross-Site Request Forgery Vulnerabilities
|
2 |
WEB
|
Julien Ahrens
|
2016-07-13
|
|
GSX Analyzer 10.12/11 - 'main.swf' Hard-Coded Superadmin Credentials
|
2 |
WEB
|
ndevnull
|
2016-07-11
|
|
Clinic Management System - Blind SQL Injection
|
2 |
WEB
|
Yakir Wizman
|
2016-07-11
|
|
Beauty Parlour & SPA Saloon Management System - Blind SQL Injection
|
2 |
WEB
|
Yakir Wizman
|
2016-07-11
|
|
Tiki Wiki 15.1 - File Upload (Metasploit)
|
2 |
WEB
|
Mehmet Ince
|
2016-07-11
|
|
IPS Community Suite 4.1.12.3 - PHP Code Injection
|
1 |
WEB
|
Egidio Romano
|
2016-07-11
|
|
WordPress Plugin Activity Log 2.3.1 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Han Sahin
|
2016-07-11
|
|
WordPress Plugin All in One SEO Pack 2.3.6.1 - Persistent Cross-Site Scripting
|
1 |
WEB
|
David Vaartjes
|
2016-07-11
|
|
Belkin AC1200 Router Firmware 1.00.27 - Authentication Bypass
|
1 |
WEB
|
Gregory Smiley
|
2016-07-11
|
|
Tiki Wiki CMS 15.0 - Arbitrary File Download
|
2 |
WEB
|
Kacper Szurek
|
2016-07-08
|
|
Streamo Online Radio And TV Streaming CMS - SQL Injection
|
2 |
WEB
|
N4TuraL
|
2016-07-08
|
|
CyberPower Systems PowerPanel 3.1.2 - XML External Entity Out-Of-Band Data Retrieval
|
3 |
WEB
|
LiquidWorm
|
2016-07-08
|
|
PHP Real Estate Script 3 - Arbitrary File Disclosure
|
2 |
WEB
|
Meisam Monsef
|