Blog RSSExploits RSSFacebook

WEB

Date D   Description Plat. Author
2016-05-04   NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities 2 WEB Bhadresh Patel
2016-05-04   WordPress Plugin Acunetix WP Security Plugin 3.0.3 - Cross-Site Scripting 2 WEB Johto Robbie
2016-05-04   CMS Made Simple < 1.12.1 / < 2.1.3 - Web Server Cache Poisoning 2 WEB Mickaël Walter
2016-05-04   Alibaba Clone B2B Script - Admin Authentication Bypass 2 WEB Meisam Monsef
2016-05-02   WordPress Plugin Ghost 0.5.5 - Unrestricted Export Download 2 WEB Josh Brody
2016-04-29   GLPi 0.90.2 - SQL Injection 2 WEB High-Tech Bridge SA
2016-04-29   Merit Lilin IP Cameras - Multiple Vulnerabilities 2 WEB Orwelllabs
2016-04-29   Observium 0.16.7533 - (Authenticated) Arbitrary Command Execution 2 WEB Dolev Farhi
2016-04-29   Observium 0.16.7533 - Cross-Site Request Forgery 2 WEB Dolev Farhi
2016-04-27   RomPager 4.34 (Multiple Router Vendors) - 'Misfortune Cookie' Authentication Bypass 1 WEB Milad Doorbash
2016-04-27   EMC ViPR SRM - Cross-Site Request Forgery 2 WEB Han Sahin
2016-04-26   ImpressCMS 1.3.9 - SQL Injection 2 WEB Manuel García Cárdenas
2016-04-25   NationBuilder - Multiple Persistent Cross-Site Scripting Vulnerabilities 2 WEB LiquidWorm
2016-04-25   Gemtek CPE7000 - WLTCS-106 'sysconf.cgi' Remote Command Execution (Metasploit) 2 WEB Federico Scalco
2016-04-25   Gemtek CPE7000 - WLTCS-106 Administrator SID Retriever (Metasploit) 2 WEB Federico Scalco
2016-04-25   C/C++ Offline Compiler and C For OS - Persistent Cross-Site Scripting 2 WEB Vulnerability-Lab
2016-04-25   Totemomail 4.x/5.x - Persistent Cross-Site Scripting 1 WEB Vulnerability-Lab
2016-04-21   Gemtek CPE7000 / WLTCS-106 - Multiple Vulnerabilities 2 WEB Federico Ramondino
2016-04-21   Symantec Brightmail 10.6.0-7 - LDAP Credentials Disclosure (Metasploit) 1 WEB Fakhir Karim Reda
2016-04-21   phpLiteAdmin 1.9.6 - Multiple Vulnerabilities 0 WEB Ozer Goker
2016-04-20   PHPBack 1.3.0 - SQL Injection 0 WEB hyp3rlinx
2016-04-19   modified eCommerce Shopsoftware 2.0.0.0 rev 9678 - Blind SQL Injection 0 WEB Felix Maduakor
2016-04-18   pfSense Community Edition 2.2.6 - Multiple Vulnerabilities 0 WEB Security-Assessment.com
2016-04-18   Webutler CMS 3.2 - Cross-Site Request Forgery 1 WEB Keerati T.
2016-04-18   WordPress Plugin Kento Post View Counter 2.8 - Cross-Site Request Forgery / Cross-Site Scripting 1 WEB cor3sm4sh3r
2016-04-18   WordPress Plugin leenk.me 2.5.0 - Cross-Site Request Forgery / Cross-Site Scripting 1 WEB cor3sm4sh3r
2016-04-15   AirOS 6.x - Arbitrary File Upload 1 WEB 93c08539
2016-04-14   PHPmongoDB 1.0.0 - Multiple Vulnerabilities 2 WEB Ozer Goker
2016-04-14   Brickcom Corporation Network Cameras - Multiple Vulnerabilities 2 WEB Orwelllabs
2016-04-14   pfSense Firewall 2.2.6 - Services Cross-Site Request Forgery 2 WEB Aatif Shahdad
2016-04-13   Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload 1 WEB Zhou Yu
2016-04-12   Ovidentia troubleticketsModule 7.6 - Remote File Inclusion 2 WEB bd0rk
2016-04-11   Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities 2 WEB Pedro Ribeiro
2016-04-11   Axis Network Cameras - Multiple Vulnerabilities 1 WEB Orwelllabs
2016-04-11   RockMongo PHP MongoDB Administrator 1.1.8 - Multiple Vulnerabilities 1 WEB Ozer Goker
2016-04-11   OpenCart 2.1.0.2 < 2.2.0.0 - json_decode Function Remote Code Execution 2 WEB Naser Farhadi
2016-04-11   WPN-XM Serverstack 0.8.6 - Cross-Site Request Forgery 2 WEB hyp3rlinx
2016-04-11   Hikvision Digital Video Recorder - Cross-Site Request Forgery 2 WEB LiquidWorm
2016-04-08   op5 7.1.9 - Remote Command Execution 1 WEB hyp3rlinx
2016-04-07   PLANET Technology IP Surveillance Cameras - Multiple Vulnerabilities 1 WEB Orwelllabs
2016-04-06   SocialEngine 4.8.9 - SQL Injection 2 WEB High-Tech Bridge SA
2016-04-06   Asbru Web Content Management System 9.2.7 - Multiple Vulnerabilities 2 WEB LiquidWorm
2016-04-05   ManageEngine Password Manager Pro 8102 to 8302 - Multiple Vulnerabilities 3 WEB S3ba
2016-04-04   PQI Air Pen Express 6W51-0000R2/6W51-0000R2XXX - Multiple Vulnerabilities 1 WEB Orwelllabs
2016-04-01   WordPress Plugin Advanced Video 1.0 - Local File Inclusion 2 WEB evait security GmbH
2016-03-31   Apache OpenMeetings 1.9.x < 3.1.0 - '.ZIP' File Directory Traversal 1 WEB Andreas Lindh
2016-03-31   MOBOTIX Video Security Cameras - Cross-Site Request Forgery (Add Admin) 1 WEB LiquidWorm
2016-03-30   CubeCart 6.0.10 - Multiple Vulnerabilities 1 WEB High-Tech Bridge SA
2016-03-28   Liferay Portal 5.1.2 - Persistent Cross-Site Scripting 2 WEB Sarim Kiani
2016-03-27   WordPress Plugin Photocart Link 1.6 - Local File Inclusion 2 WEB CrashBandicot
2016-03-27   Trend Micro Deep Discovery Inspector 3.8/3.7 - Cross-Site Request Forgery 1 WEB hyp3rlinx
2016-03-27   WordPress Plugin IMDb Profile Widget 1.0.8 - Local File Inclusion 2 WEB CrashBandicot
2016-03-23   MiCollab 7.0 - SQL Injection 2 WEB Goran Tuzovic
2016-03-22   WordPress Plugin Memphis Document Library 3.1.5 - Arbitrary File Download 1 WEB Felipe Molina
2016-03-22   WordPress Plugin Dharma Booking 2.38.3 - Remote File Inclusion 2 WEB AMAR^SHG
2016-03-22   WordPress Plugin Brandfolder 3.0 - Local/Remote File Inclusion 1 WEB AMAR^SHG
2016-03-22   Joomla! Component Easy Youtube Gallery 1.0.2 - SQL Injection 2 WEB Persian Hack Team
2016-03-22   WordPress Plugin HB Audio Gallery Lite 1.0.0 - Arbitrary File Download 2 WEB CrashBandicot
2016-03-21   ProjectSend r582 - Multiple Cross-Site Scripting Vulnerabilities 2 WEB Michael Helwig
2016-03-21   iTop 2.2.1 - Cross-Site Request Forgery 2 WEB High-Tech Bridge SA
2016-03-21   Dating Pro Genie 2015.7 - Cross-Site Request Forgery 3 WEB High-Tech Bridge SA
2016-03-21   WordPress Plugin Image Export 1.1.0 - Arbitrary File Disclosure 2 WEB AMAR^SHG
2016-03-21   XOOPS 2.5.7.2 - Directory Traversal Bypass 1 WEB hyp3rlinx
2016-03-21   Xoops 2.5.7.2 - Cross-Site Request Forgery (Arbitrary User Deletions) 2 WEB hyp3rlinx
2016-03-21   D-Link DWR-932 Firmware 4.00 - Authentication Bypass 2 WEB Saeed reza Zamanian
2016-03-21   Disc ORGanizer (DORG) - Multiple Vulnerabilities 2 WEB SECUPENT
2016-03-21   WordPress Plugin Abtest - Local File Inclusion 2 WEB CrashBandicot
2016-03-21   WordPress Plugin Import CSV 1.0 - Directory Traversal 1 WEB Wadeek
2016-03-21   WordPress Plugin eBook Download 1.1 - Directory Traversal 2 WEB Wadeek
2016-03-20   Wildfly - 'WEB-INF' / 'META-INF' Information Disclosure via Filter Restriction Bypass 2 WEB Tal Solomon of Palantir Security
2016-03-17   PivotX 2.3.11 - Directory Traversal 2 WEB Curesec Research Team
2016-03-17   ZenPhoto 1.4.11 - Remote File Inclusion 2 WEB Curesec Research Team
2016-03-16   Monstra CMS 3.0.3 - Multiple Vulnerabilities 2 WEB Sarim Kiani
2016-03-16   AKIPS Network Monitor 15.37 through 16.5 - OS Command Injection 2 WEB BrianWGray
2016-03-15   Kaltura Community Edition < 11.1.0-2 - Multiple Vulnerabilities 2 WEB Security-Assessment.com
2016-03-14   TeamPass 2.1.24 - Multiple Vulnerabilities 2 WEB Vincent Malguy
2016-03-14   WordPress Plugin Site Import 1.0.1 - Local/Remote File Inclusion 1 WEB Wadeek
2016-03-11   WordPress Plugin DZS Videogallery < 8.60 - Multiple Vulnerabilities 2 WEB Colette Chamberland
2016-03-11   WordPress Theme Beauty & Clean 1.0.8 - Arbitrary File Upload 2 WEB Colette Chamberland
2016-03-10   WordPress Plugin WP Advanced Comment 0.10 - Persistent Cross-Site Scripting 1 WEB Mohammad Khaleghi
2016-03-10   WordPress Plugin Best Web Soft Captcha 4.1.5 - Multiple Vulnerabilities 2 WEB Colette Chamberland
2016-03-09   WordPress Theme SiteMile Project 2.0.9.5 - Multiple Vulnerabilities 1 WEB LSE Leading Security Experts GmbH
2016-03-09   Bluethrust Clan Scripts v4 R17 - Multiple Vulnerabilities 1 WEB Brandon Murphy
2016-03-07   Cerberus Helpdesk (Cerb5) 5 < 6.7 - Password Hash Disclosure 1 WEB asdizzle_
2016-03-07   ATutor LMS - '/install_modules.php' Cross-Site Request Forgery / Remote Code Execution 2 WEB mr_me
2016-03-03   WordPress Plugin Bulk Delete 5.5.3 - Privilege Escalation 2 WEB Panagiotis Vagenas
2016-03-01   WordPress Plugin CP Polls 1.0.8 - Multiple Vulnerabilities 2 WEB i0akiN SEC-LABORATORY
2016-02-29   WordPress Plugin More Fields 2.1 - Cross-Site Request Forgery 1 WEB Aatif Shahdad
2016-02-26   Joomla! Component com_poweradmin 2.3.0 - Multiple Vulnerabilities 2 WEB RatioSec Research
2016-02-26   Centreon 2.5.3 - Remote Command Execution 2 WEB Sysdream
2016-02-26   Zimbra 8.0.9 GA - Cross-Site Request Forgery 2 WEB Sysdream
2016-02-26   WordPress Plugin Ocim MP3 - SQL Injection 2 WEB xevil & Blankon33
2016-02-26   Infor CRM 8.2.0.1136 - Multiple HTML Script Injection Vulnerabilities 2 WEB LiquidWorm
2016-02-25   IBM Lotus Domino R8 - Password Hash Extraction 1 WEB Jonathan Broche
2016-02-24   WordPress Plugin Extra User Details 0.4.2 - Privilege Escalation 1 WEB Panagiotis Vagenas
2016-02-23   Ubiquiti Networks UniFi 3.2.10 - Cross-Site Request Forgery 1 WEB Julien Ahrens
2016-02-23   Dell OpenManage Server Administrator 8.2 - (Authenticated) Directory Traversal 1 WEB hantwister
2016-02-22   Thru Managed File Transfer Portal 9.0.2 - SQL Injection 1 WEB SySS GmbH
2016-02-22   BlackBerry Enterprise Service < 12.4 (BES12) Self-Service - Multiple Vulnerabilities 1 WEB Security-Assessment.com
2016-02-22   InstantCoder 1.0 iOS - Multiple Vulnerabilities 1 WEB Vulnerability-Lab
2016-02-20   SOLIDserver < 5.0.4 - Local File Inclusion 2 WEB Saeed reza Zamanian
2016-02-19   ManageEngine Firewall Analyzer 8.5 - Multiple Vulnerabilities 2 WEB Sachin Wagh
2016-02-19   Chamilo LMS - Persistent Cross-Site Scripting 1 WEB Vulnerability-Lab
2016-02-19   Chamilo LMS IDOR - 'messageId' Delete POST Injection 1 WEB Vulnerability-Lab
2016-02-18   DirectAdmin 1.491 - Cross-Site Request Forgery 1 WEB Necmettin COSKUN
2016-02-18   Vesta Control Panel 0.9.8-15 - Persistent Cross-Site Scripting 0 WEB Necmettin COSKUN
2016-02-17   Redaxo 5.0.0 - Multiple Vulnerabilities 2 WEB LSE Leading Security Experts GmbH
2016-02-17   OCS Inventory NG 2.2 - SQL Injection 1 WEB Ephreet
2016-02-17   JMX2 Email Tester - 'save_email.php' Arbitrary File Upload 0 WEB HaHwul
2016-02-16   phpMyBackupPro 2.5 - Remote Command Execution / Cross-Site Request Forgery 1 WEB hyp3rlinx
2016-02-16   WordPress Plugin ALO EasyMail NewsLetter 2.6.01 - Cross-Site Request Forgery 2 WEB Mohsen Lotfi
2016-02-16   ManageEngine Network Configuration Management Build 11000 - Privilege Escalation 2 WEB Kaustubh G. Padwad
2016-02-16   ManageEngine OPutils 8.0 - Multiple Vulnerabilities 2 WEB Kaustubh G. Padwad
2016-02-15   Tiny Tiny RSS - Blind SQL Injection 1 WEB Kacper Szurek
2015-08-27   Oracle GlassFish Server 4.1 - Directory Traversal 1 WEB Trustwave's SpiderLabs
2016-02-10   Yeager CMS 1.2.1 - Multiple Vulnerabilities 2 WEB SEC Consult
2016-02-10   Apache Sling Framework (Adobe AEM) 2.3.6 - Information Disclosure 1 WEB Vulnerability-Lab
2010-03-10   Employee TimeClock Software 0.99 - SQL Injection 2 WEB Secunia Research
2016-02-08   WordPress Plugin Booking Calendar Contact Form 1.0.23 - Multiple Vulnerabilities 2 WEB i0akiN SEC-LABORATORY
2016-02-08   WordPress Plugin WP User Frontend < 2.3.11 - Unrestricted Arbitrary File Upload 1 WEB Panagiotis Vagenas
2016-02-08   WordPress Plugin WooCommerce Store Toolkit 1.5.5 - Privilege Escalation 1 WEB Panagiotis Vagenas
2016-02-08   WordPress Plugin User Meta Manager 3.4.6 - Information Disclosure 1 WEB Panagiotis Vagenas
2016-02-08   dotDefender Firewall 5.00.12865/5.13-13282 - Cross-Site Request Forgery 1 WEB hyp3rlinx
2016-02-08   Solr 3.5.0 - Arbitrary Data Deletion 0 WEB N37
2016-02-04   Symphony CMS 2.6.3 - Multiple SQL Injections 0 WEB Sachin Wagh