2016-06-06
|
|
WordPress Theme Newspaper 6.7.1 - Privilege Escalation
|
3 |
WEB
|
wp0Day.com
|
2016-06-06
|
|
WordPress Plugin WP PRO Advertising System 4.6.18 - SQL Injection
|
2 |
WEB
|
wp0Day.com
|
2016-06-06
|
|
WordPress Theme Creative Multi-Purpose 9.1.3 - Persistent Cross-Site Scripting
|
2 |
WEB
|
wp0Day.com
|
2016-06-06
|
|
WordPress Plugin WP Mobile Detector 3.5 - Arbitrary File Upload
|
1 |
WEB
|
Aaditya Purani
|
2016-06-06
|
|
Electroweb Online Examination System 1.0 - SQL Injection
|
2 |
WEB
|
Ali Ghanbari
|
2016-06-06
|
|
ArticleSetup 1.00 - Cross-Site Request Forgery (Change Admin Password)
|
1 |
WEB
|
Ali Ghanbari
|
2016-06-06
|
|
Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock)
|
2 |
WEB
|
lastc0de
|
2016-06-06
|
|
Apache Continuum 1.4.2 - Multiple Vulnerabilities
|
2 |
WEB
|
David Shanahan
|
2016-06-06
|
|
Dream Gallery 1.0 - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
Ali Ghanbari
|
2016-06-06
|
|
WordPress Plugin Simple Backup 2.7.11 - Multiple Vulnerabilities
|
3 |
WEB
|
PizzaHatHacker
|
2016-06-02
|
|
Relay Ajax Directory Manager relayb01-071706/1.5.1/1.5.3 - Arbitrary File Upload
|
3 |
WEB
|
RedTeam Pentesting GmbH
|
2016-06-02
|
|
Liferay CE < 6.2 CE GA6 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Fernando Câmara
|
2016-06-02
|
|
Joomla! Component SecurityCheck 2.8.9 - Multiple Vulnerabilities
|
3 |
WEB
|
ADEO Security
|
2016-06-01
|
|
AjaxExplorer 1.10.3.2 - Multiple Vulnerabilities
|
3 |
WEB
|
hyp3rlinx
|
2016-05-31
|
|
ProcessMaker 3.0.1.7 - Multiple Vulnerabilities
|
3 |
WEB
|
Mickael Dorigny
|
2016-05-31
|
|
AirOS NanoStation M2 5.6-beta - Multiple Vulnerabilities
|
3 |
WEB
|
Pablo Rebolini
|
2016-05-31
|
|
Flatpress 1.0.3 - Cross-Site Request Forgery / Arbitrary File Upload
|
3 |
WEB
|
LiquidWorm
|
2016-05-30
|
|
Open Source Real Estate Script 3.6.0 - SQL Injection
|
3 |
WEB
|
Meisam Monsef
|
2016-05-27
|
|
PHP Realestate Script Script 4.9.0 - SQL Injection
|
3 |
WEB
|
Meisam Monsef
|
2016-05-26
|
|
EduSec 4.2.5 - SQL Injection
|
3 |
WEB
|
Bikramaditya Guha
|
2016-05-26
|
|
Real Estate Portal 4.1 - Multiple Vulnerabilities
|
3 |
WEB
|
Bikramaditya Guha
|
2016-05-24
|
|
AfterLogic WebMail Pro ASP.NET 6.2.6 - Administrator Account Disclosure via XML External Entity Inje
|
3 |
WEB
|
Mehmet Ince
|
2016-05-23
|
|
XenAPI 1.4.1 for XenForo - Multiple SQL Injections
|
3 |
WEB
|
Julien Ahrens
|
2016-05-23
|
|
WordPress Plugin Job Script by Scubez - Remote Code Execution
|
3 |
WEB
|
Bikramaditya Guha
|
2016-05-19
|
|
SAP NetWeaver AS JAVA 7.1 < 7.5 - Information Disclosure
|
2 |
WEB
|
ERPScan
|
2016-05-19
|
|
SAP NetWeaver AS JAVA 7.1 < 7.5 - SQL Injection
|
3 |
WEB
|
ERPScan
|
2016-05-18
|
|
Magento < 2.0.6 - Arbitrary Unserialize / Arbitrary Write File
|
3 |
WEB
|
agix
|
2016-05-17
|
|
SAP xMII 15.0 - Directory Traversal
|
3 |
WEB
|
ERPScan
|
2016-05-17
|
|
Meteocontrol WEB’log - Admin Password Disclosure (Metasploit)
|
3 |
WEB
|
Karn Ganeshen
|
2016-05-16
|
|
Web2py 2.14.5 - Multiple Vulnerabilities
|
2 |
WEB
|
Narendra Bhati
|
2016-05-16
|
|
Web Interface for DNSmasq / Mikrotik - SQL Injection
|
4 |
WEB
|
hyp3rlinx
|
2016-05-16
|
|
eXtplorer 2.1.9 - '.ZIP' Directory Traversal
|
4 |
WEB
|
hyp3rlinx
|
2016-05-16
|
|
CakePHP Framework 3.2.4 - IP Spoofing
|
3 |
WEB
|
Dawid Golunski
|
2016-05-12
|
|
Trend Micro - 'CoreServiceShell.exe' Multiple HTTP s
|
4 |
WEB
|
Google Security Research
|
2016-05-12
|
|
WordPress Plugin Huge-IT Image Gallery 1.8.9 - Multiple Vulnerabilities
|
4 |
WEB
|
Gwendal Le Coguic
|
2016-05-12
|
|
WordPress Plugin Q and A (Focus Plus) FAQ 1.3.9.7 - Multiple Vulnerabilities
|
3 |
WEB
|
Gwendal Le Coguic
|
2016-05-10
|
|
JVC HDRs / Net (Multiple Cameras) - Multiple Vulnerabilities
|
3 |
WEB
|
Orwelllabs
|
2016-05-09
|
|
ZeewaysCMS - Multiple Vulnerabilities
|
4 |
WEB
|
Bikramaditya Guha
|
2016-05-09
|
|
Ajaxel CMS 8.0 - Multiple Vulnerabilities
|
3 |
WEB
|
DizzyDuck
|
2016-05-06
|
|
ManageEngine Applications Manager Build 12700 - Multiple Vulnerabilities
|
3 |
WEB
|
Saif El-Sherei
|
2016-05-06
|
|
DotNetNuke 07.04.00 - Administration Authentication Bypass
|
3 |
WEB
|
Marios Nicolaides
|
2016-05-04
|
|
Imagick 3.3.0 (PHP 5.4) - disable_functions Bypass
|
2 |
WEB
|
RicterZ
|
2016-05-04
|
|
IPFire < 2.19 Core Update 101 - Remote Command Execution
|
2 |
WEB
|
Yann CAM
|
2016-05-04
|
|
NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities
|
4 |
WEB
|
Bhadresh Patel
|
2016-05-04
|
|
WordPress Plugin Acunetix WP Security Plugin 3.0.3 - Cross-Site Scripting
|
4 |
WEB
|
Johto Robbie
|
2016-05-04
|
|
CMS Made Simple < 1.12.1 / < 2.1.3 - Web Server Cache Poisoning
|
4 |
WEB
|
Mickaël Walter
|
2016-05-04
|
|
Alibaba Clone B2B Script - Admin Authentication Bypass
|
3 |
WEB
|
Meisam Monsef
|
2016-05-02
|
|
WordPress Plugin Ghost 0.5.5 - Unrestricted Export Download
|
3 |
WEB
|
Josh Brody
|
2016-04-29
|
|
GLPi 0.90.2 - SQL Injection
|
3 |
WEB
|
High-Tech Bridge SA
|
2016-04-29
|
|
Merit Lilin IP Cameras - Multiple Vulnerabilities
|
3 |
WEB
|
Orwelllabs
|
2016-04-29
|
|
Observium 0.16.7533 - (Authenticated) Arbitrary Command Execution
|
3 |
WEB
|
Dolev Farhi
|
2016-04-29
|
|
Observium 0.16.7533 - Cross-Site Request Forgery
|
4 |
WEB
|
Dolev Farhi
|
2016-04-27
|
|
RomPager 4.34 (Multiple Router Vendors) - 'Misfortune Cookie' Authentication Bypass
|
2 |
WEB
|
Milad Doorbash
|
2016-04-27
|
|
EMC ViPR SRM - Cross-Site Request Forgery
|
3 |
WEB
|
Han Sahin
|
2016-04-26
|
|
ImpressCMS 1.3.9 - SQL Injection
|
3 |
WEB
|
Manuel García Cárdenas
|
2016-04-25
|
|
NationBuilder - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
LiquidWorm
|
2016-04-25
|
|
Gemtek CPE7000 - WLTCS-106 'sysconf.cgi' Remote Command Execution (Metasploit)
|
3 |
WEB
|
Federico Scalco
|
2016-04-25
|
|
Gemtek CPE7000 - WLTCS-106 Administrator SID Retriever (Metasploit)
|
3 |
WEB
|
Federico Scalco
|
2016-04-25
|
|
C/C++ Offline Compiler and C For OS - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2016-04-25
|
|
Totemomail 4.x/5.x - Persistent Cross-Site Scripting
|
3 |
WEB
|
Vulnerability-Lab
|
2016-04-21
|
|
Gemtek CPE7000 / WLTCS-106 - Multiple Vulnerabilities
|
2 |
WEB
|
Federico Ramondino
|
2016-04-21
|
|
Symantec Brightmail 10.6.0-7 - LDAP Credentials Disclosure (Metasploit)
|
2 |
WEB
|
Fakhir Karim Reda
|
2016-04-21
|
|
phpLiteAdmin 1.9.6 - Multiple Vulnerabilities
|
3 |
WEB
|
Ozer Goker
|
2016-04-20
|
|
PHPBack 1.3.0 - SQL Injection
|
2 |
WEB
|
hyp3rlinx
|
2016-04-19
|
|
modified eCommerce Shopsoftware 2.0.0.0 rev 9678 - Blind SQL Injection
|
2 |
WEB
|
Felix Maduakor
|
2016-04-18
|
|
pfSense Community Edition 2.2.6 - Multiple Vulnerabilities
|
4 |
WEB
|
Security-Assessment.com
|
2016-04-18
|
|
Webutler CMS 3.2 - Cross-Site Request Forgery
|
4 |
WEB
|
Keerati T.
|
2016-04-18
|
|
WordPress Plugin Kento Post View Counter 2.8 - Cross-Site Request Forgery / Cross-Site Scripting
|
3 |
WEB
|
cor3sm4sh3r
|
2016-04-18
|
|
WordPress Plugin leenk.me 2.5.0 - Cross-Site Request Forgery / Cross-Site Scripting
|
3 |
WEB
|
cor3sm4sh3r
|
2016-04-15
|
|
AirOS 6.x - Arbitrary File Upload
|
3 |
WEB
|
93c08539
|
2016-04-14
|
|
PHPmongoDB 1.0.0 - Multiple Vulnerabilities
|
4 |
WEB
|
Ozer Goker
|
2016-04-14
|
|
Brickcom Corporation Network Cameras - Multiple Vulnerabilities
|
3 |
WEB
|
Orwelllabs
|
2016-04-14
|
|
pfSense Firewall 2.2.6 - Services Cross-Site Request Forgery
|
3 |
WEB
|
Aatif Shahdad
|
2016-04-13
|
|
Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload
|
2 |
WEB
|
Zhou Yu
|
2016-04-12
|
|
Ovidentia troubleticketsModule 7.6 - Remote File Inclusion
|
3 |
WEB
|
bd0rk
|
2016-04-11
|
|
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
|
3 |
WEB
|
Pedro Ribeiro
|
2016-04-11
|
|
Axis Network Cameras - Multiple Vulnerabilities
|
4 |
WEB
|
Orwelllabs
|
2016-04-11
|
|
RockMongo PHP MongoDB Administrator 1.1.8 - Multiple Vulnerabilities
|
2 |
WEB
|
Ozer Goker
|
2016-04-11
|
|
OpenCart 2.1.0.2 < 2.2.0.0 - json_decode Function Remote Code Execution
|
3 |
WEB
|
Naser Farhadi
|
2016-04-11
|
|
WPN-XM Serverstack 0.8.6 - Cross-Site Request Forgery
|
3 |
WEB
|
hyp3rlinx
|
2016-04-11
|
|
Hikvision Digital Video Recorder - Cross-Site Request Forgery
|
3 |
WEB
|
LiquidWorm
|
2016-04-08
|
|
op5 7.1.9 - Remote Command Execution
|
2 |
WEB
|
hyp3rlinx
|
2016-04-07
|
|
PLANET Technology IP Surveillance Cameras - Multiple Vulnerabilities
|
2 |
WEB
|
Orwelllabs
|
2016-04-06
|
|
SocialEngine 4.8.9 - SQL Injection
|
3 |
WEB
|
High-Tech Bridge SA
|
2016-04-06
|
|
Asbru Web Content Management System 9.2.7 - Multiple Vulnerabilities
|
3 |
WEB
|
LiquidWorm
|
2016-04-05
|
|
ManageEngine Password Manager Pro 8102 to 8302 - Multiple Vulnerabilities
|
4 |
WEB
|
S3ba
|
2016-04-04
|
|
PQI Air Pen Express 6W51-0000R2/6W51-0000R2XXX - Multiple Vulnerabilities
|
3 |
WEB
|
Orwelllabs
|
2016-04-01
|
|
WordPress Plugin Advanced Video 1.0 - Local File Inclusion
|
4 |
WEB
|
evait security GmbH
|
2016-03-31
|
|
Apache OpenMeetings 1.9.x < 3.1.0 - '.ZIP' File Directory Traversal
|
3 |
WEB
|
Andreas Lindh
|
2016-03-31
|
|
MOBOTIX Video Security Cameras - Cross-Site Request Forgery (Add Admin)
|
4 |
WEB
|
LiquidWorm
|
2016-03-30
|
|
CubeCart 6.0.10 - Multiple Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge SA
|
2016-03-28
|
|
Liferay Portal 5.1.2 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Sarim Kiani
|
2016-03-27
|
|
WordPress Plugin Photocart Link 1.6 - Local File Inclusion
|
3 |
WEB
|
CrashBandicot
|
2016-03-27
|
|
Trend Micro Deep Discovery Inspector 3.8/3.7 - Cross-Site Request Forgery
|
3 |
WEB
|
hyp3rlinx
|
2016-03-27
|
|
WordPress Plugin IMDb Profile Widget 1.0.8 - Local File Inclusion
|
3 |
WEB
|
CrashBandicot
|
2016-03-23
|
|
MiCollab 7.0 - SQL Injection
|
5 |
WEB
|
Goran Tuzovic
|
2016-03-22
|
|
WordPress Plugin Memphis Document Library 3.1.5 - Arbitrary File Download
|
2 |
WEB
|
Felipe Molina
|
2016-03-22
|
|
WordPress Plugin Dharma Booking 2.38.3 - Remote File Inclusion
|
3 |
WEB
|
AMAR^SHG
|
2016-03-22
|
|
WordPress Plugin Brandfolder 3.0 - Local/Remote File Inclusion
|
2 |
WEB
|
AMAR^SHG
|
2016-03-22
|
|
Joomla! Component Easy Youtube Gallery 1.0.2 - SQL Injection
|
3 |
WEB
|
Persian Hack Team
|
2016-03-22
|
|
WordPress Plugin HB Audio Gallery Lite 1.0.0 - Arbitrary File Download
|
3 |
WEB
|
CrashBandicot
|
2016-03-21
|
|
ProjectSend r582 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Michael Helwig
|
2016-03-21
|
|
iTop 2.2.1 - Cross-Site Request Forgery
|
3 |
WEB
|
High-Tech Bridge SA
|
2016-03-21
|
|
Dating Pro Genie 2015.7 - Cross-Site Request Forgery
|
3 |
WEB
|
High-Tech Bridge SA
|
2016-03-21
|
|
WordPress Plugin Image Export 1.1.0 - Arbitrary File Disclosure
|
4 |
WEB
|
AMAR^SHG
|
2016-03-21
|
|
XOOPS 2.5.7.2 - Directory Traversal Bypass
|
3 |
WEB
|
hyp3rlinx
|
2016-03-21
|
|
Xoops 2.5.7.2 - Cross-Site Request Forgery (Arbitrary User Deletions)
|
3 |
WEB
|
hyp3rlinx
|
2016-03-21
|
|
D-Link DWR-932 Firmware 4.00 - Authentication Bypass
|
3 |
WEB
|
Saeed reza Zamanian
|
2016-03-21
|
|
Disc ORGanizer (DORG) - Multiple Vulnerabilities
|
3 |
WEB
|
SECUPENT
|
2016-03-21
|
|
WordPress Plugin Abtest - Local File Inclusion
|
3 |
WEB
|
CrashBandicot
|
2016-03-21
|
|
WordPress Plugin Import CSV 1.0 - Directory Traversal
|
3 |
WEB
|
Wadeek
|
2016-03-21
|
|
WordPress Plugin eBook Download 1.1 - Directory Traversal
|
4 |
WEB
|
Wadeek
|
2016-03-20
|
|
Wildfly - 'WEB-INF' / 'META-INF' Information Disclosure via Filter Restriction Bypass
|
3 |
WEB
|
Tal Solomon of Palantir Security
|
2016-03-17
|
|
PivotX 2.3.11 - Directory Traversal
|
3 |
WEB
|
Curesec Research Team
|
2016-03-17
|
|
ZenPhoto 1.4.11 - Remote File Inclusion
|
3 |
WEB
|
Curesec Research Team
|
2016-03-16
|
|
Monstra CMS 3.0.3 - Multiple Vulnerabilities
|
4 |
WEB
|
Sarim Kiani
|
2016-03-16
|
|
AKIPS Network Monitor 15.37 through 16.5 - OS Command Injection
|
3 |
WEB
|
BrianWGray
|
2016-03-15
|
|
Kaltura Community Edition < 11.1.0-2 - Multiple Vulnerabilities
|
3 |
WEB
|
Security-Assessment.com
|
2016-03-14
|
|
TeamPass 2.1.24 - Multiple Vulnerabilities
|
3 |
WEB
|
Vincent Malguy
|
2016-03-14
|
|
WordPress Plugin Site Import 1.0.1 - Local/Remote File Inclusion
|
2 |
WEB
|
Wadeek
|
2016-03-11
|
|
WordPress Plugin DZS Videogallery < 8.60 - Multiple Vulnerabilities
|
5 |
WEB
|
Colette Chamberland
|
2016-03-11
|
|
WordPress Theme Beauty & Clean 1.0.8 - Arbitrary File Upload
|
4 |
WEB
|
Colette Chamberland
|
2016-03-10
|
|
WordPress Plugin WP Advanced Comment 0.10 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Mohammad Khaleghi
|
2016-03-10
|
|
WordPress Plugin Best Web Soft Captcha 4.1.5 - Multiple Vulnerabilities
|
2 |
WEB
|
Colette Chamberland
|
2016-03-09
|
|
WordPress Theme SiteMile Project 2.0.9.5 - Multiple Vulnerabilities
|
1 |
WEB
|
LSE Leading Security Experts GmbH
|