2016-05-04
|
|
NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities
|
2 |
WEB
|
Bhadresh Patel
|
2016-05-04
|
|
WordPress Plugin Acunetix WP Security Plugin 3.0.3 - Cross-Site Scripting
|
2 |
WEB
|
Johto Robbie
|
2016-05-04
|
|
CMS Made Simple < 1.12.1 / < 2.1.3 - Web Server Cache Poisoning
|
2 |
WEB
|
Mickaël Walter
|
2016-05-04
|
|
Alibaba Clone B2B Script - Admin Authentication Bypass
|
2 |
WEB
|
Meisam Monsef
|
2016-05-02
|
|
WordPress Plugin Ghost 0.5.5 - Unrestricted Export Download
|
2 |
WEB
|
Josh Brody
|
2016-04-29
|
|
GLPi 0.90.2 - SQL Injection
|
2 |
WEB
|
High-Tech Bridge SA
|
2016-04-29
|
|
Merit Lilin IP Cameras - Multiple Vulnerabilities
|
2 |
WEB
|
Orwelllabs
|
2016-04-29
|
|
Observium 0.16.7533 - (Authenticated) Arbitrary Command Execution
|
2 |
WEB
|
Dolev Farhi
|
2016-04-29
|
|
Observium 0.16.7533 - Cross-Site Request Forgery
|
2 |
WEB
|
Dolev Farhi
|
2016-04-27
|
|
RomPager 4.34 (Multiple Router Vendors) - 'Misfortune Cookie' Authentication Bypass
|
1 |
WEB
|
Milad Doorbash
|
2016-04-27
|
|
EMC ViPR SRM - Cross-Site Request Forgery
|
2 |
WEB
|
Han Sahin
|
2016-04-26
|
|
ImpressCMS 1.3.9 - SQL Injection
|
2 |
WEB
|
Manuel García Cárdenas
|
2016-04-25
|
|
NationBuilder - Multiple Persistent Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
LiquidWorm
|
2016-04-25
|
|
Gemtek CPE7000 - WLTCS-106 'sysconf.cgi' Remote Command Execution (Metasploit)
|
2 |
WEB
|
Federico Scalco
|
2016-04-25
|
|
Gemtek CPE7000 - WLTCS-106 Administrator SID Retriever (Metasploit)
|
2 |
WEB
|
Federico Scalco
|
2016-04-25
|
|
C/C++ Offline Compiler and C For OS - Persistent Cross-Site Scripting
|
2 |
WEB
|
Vulnerability-Lab
|
2016-04-25
|
|
Totemomail 4.x/5.x - Persistent Cross-Site Scripting
|
1 |
WEB
|
Vulnerability-Lab
|
2016-04-21
|
|
Gemtek CPE7000 / WLTCS-106 - Multiple Vulnerabilities
|
2 |
WEB
|
Federico Ramondino
|
2016-04-21
|
|
Symantec Brightmail 10.6.0-7 - LDAP Credentials Disclosure (Metasploit)
|
1 |
WEB
|
Fakhir Karim Reda
|
2016-04-21
|
|
phpLiteAdmin 1.9.6 - Multiple Vulnerabilities
|
0 |
WEB
|
Ozer Goker
|
2016-04-20
|
|
PHPBack 1.3.0 - SQL Injection
|
0 |
WEB
|
hyp3rlinx
|
2016-04-19
|
|
modified eCommerce Shopsoftware 2.0.0.0 rev 9678 - Blind SQL Injection
|
0 |
WEB
|
Felix Maduakor
|
2016-04-18
|
|
pfSense Community Edition 2.2.6 - Multiple Vulnerabilities
|
0 |
WEB
|
Security-Assessment.com
|
2016-04-18
|
|
Webutler CMS 3.2 - Cross-Site Request Forgery
|
1 |
WEB
|
Keerati T.
|
2016-04-18
|
|
WordPress Plugin Kento Post View Counter 2.8 - Cross-Site Request Forgery / Cross-Site Scripting
|
1 |
WEB
|
cor3sm4sh3r
|
2016-04-18
|
|
WordPress Plugin leenk.me 2.5.0 - Cross-Site Request Forgery / Cross-Site Scripting
|
1 |
WEB
|
cor3sm4sh3r
|
2016-04-15
|
|
AirOS 6.x - Arbitrary File Upload
|
1 |
WEB
|
93c08539
|
2016-04-14
|
|
PHPmongoDB 1.0.0 - Multiple Vulnerabilities
|
2 |
WEB
|
Ozer Goker
|
2016-04-14
|
|
Brickcom Corporation Network Cameras - Multiple Vulnerabilities
|
2 |
WEB
|
Orwelllabs
|
2016-04-14
|
|
pfSense Firewall 2.2.6 - Services Cross-Site Request Forgery
|
2 |
WEB
|
Aatif Shahdad
|
2016-04-13
|
|
Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload
|
1 |
WEB
|
Zhou Yu
|
2016-04-12
|
|
Ovidentia troubleticketsModule 7.6 - Remote File Inclusion
|
2 |
WEB
|
bd0rk
|
2016-04-11
|
|
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
|
2 |
WEB
|
Pedro Ribeiro
|
2016-04-11
|
|
Axis Network Cameras - Multiple Vulnerabilities
|
1 |
WEB
|
Orwelllabs
|
2016-04-11
|
|
RockMongo PHP MongoDB Administrator 1.1.8 - Multiple Vulnerabilities
|
1 |
WEB
|
Ozer Goker
|
2016-04-11
|
|
OpenCart 2.1.0.2 < 2.2.0.0 - json_decode Function Remote Code Execution
|
2 |
WEB
|
Naser Farhadi
|
2016-04-11
|
|
WPN-XM Serverstack 0.8.6 - Cross-Site Request Forgery
|
2 |
WEB
|
hyp3rlinx
|
2016-04-11
|
|
Hikvision Digital Video Recorder - Cross-Site Request Forgery
|
2 |
WEB
|
LiquidWorm
|
2016-04-08
|
|
op5 7.1.9 - Remote Command Execution
|
1 |
WEB
|
hyp3rlinx
|
2016-04-07
|
|
PLANET Technology IP Surveillance Cameras - Multiple Vulnerabilities
|
1 |
WEB
|
Orwelllabs
|
2016-04-06
|
|
SocialEngine 4.8.9 - SQL Injection
|
2 |
WEB
|
High-Tech Bridge SA
|
2016-04-06
|
|
Asbru Web Content Management System 9.2.7 - Multiple Vulnerabilities
|
2 |
WEB
|
LiquidWorm
|
2016-04-05
|
|
ManageEngine Password Manager Pro 8102 to 8302 - Multiple Vulnerabilities
|
3 |
WEB
|
S3ba
|
2016-04-04
|
|
PQI Air Pen Express 6W51-0000R2/6W51-0000R2XXX - Multiple Vulnerabilities
|
1 |
WEB
|
Orwelllabs
|
2016-04-01
|
|
WordPress Plugin Advanced Video 1.0 - Local File Inclusion
|
2 |
WEB
|
evait security GmbH
|
2016-03-31
|
|
Apache OpenMeetings 1.9.x < 3.1.0 - '.ZIP' File Directory Traversal
|
1 |
WEB
|
Andreas Lindh
|
2016-03-31
|
|
MOBOTIX Video Security Cameras - Cross-Site Request Forgery (Add Admin)
|
1 |
WEB
|
LiquidWorm
|
2016-03-30
|
|
CubeCart 6.0.10 - Multiple Vulnerabilities
|
1 |
WEB
|
High-Tech Bridge SA
|
2016-03-28
|
|
Liferay Portal 5.1.2 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Sarim Kiani
|
2016-03-27
|
|
WordPress Plugin Photocart Link 1.6 - Local File Inclusion
|
2 |
WEB
|
CrashBandicot
|
2016-03-27
|
|
Trend Micro Deep Discovery Inspector 3.8/3.7 - Cross-Site Request Forgery
|
1 |
WEB
|
hyp3rlinx
|
2016-03-27
|
|
WordPress Plugin IMDb Profile Widget 1.0.8 - Local File Inclusion
|
2 |
WEB
|
CrashBandicot
|
2016-03-23
|
|
MiCollab 7.0 - SQL Injection
|
2 |
WEB
|
Goran Tuzovic
|
2016-03-22
|
|
WordPress Plugin Memphis Document Library 3.1.5 - Arbitrary File Download
|
1 |
WEB
|
Felipe Molina
|
2016-03-22
|
|
WordPress Plugin Dharma Booking 2.38.3 - Remote File Inclusion
|
2 |
WEB
|
AMAR^SHG
|
2016-03-22
|
|
WordPress Plugin Brandfolder 3.0 - Local/Remote File Inclusion
|
1 |
WEB
|
AMAR^SHG
|
2016-03-22
|
|
Joomla! Component Easy Youtube Gallery 1.0.2 - SQL Injection
|
2 |
WEB
|
Persian Hack Team
|
2016-03-22
|
|
WordPress Plugin HB Audio Gallery Lite 1.0.0 - Arbitrary File Download
|
2 |
WEB
|
CrashBandicot
|
2016-03-21
|
|
ProjectSend r582 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Michael Helwig
|
2016-03-21
|
|
iTop 2.2.1 - Cross-Site Request Forgery
|
2 |
WEB
|
High-Tech Bridge SA
|
2016-03-21
|
|
Dating Pro Genie 2015.7 - Cross-Site Request Forgery
|
3 |
WEB
|
High-Tech Bridge SA
|
2016-03-21
|
|
WordPress Plugin Image Export 1.1.0 - Arbitrary File Disclosure
|
2 |
WEB
|
AMAR^SHG
|
2016-03-21
|
|
XOOPS 2.5.7.2 - Directory Traversal Bypass
|
1 |
WEB
|
hyp3rlinx
|
2016-03-21
|
|
Xoops 2.5.7.2 - Cross-Site Request Forgery (Arbitrary User Deletions)
|
2 |
WEB
|
hyp3rlinx
|
2016-03-21
|
|
D-Link DWR-932 Firmware 4.00 - Authentication Bypass
|
2 |
WEB
|
Saeed reza Zamanian
|
2016-03-21
|
|
Disc ORGanizer (DORG) - Multiple Vulnerabilities
|
2 |
WEB
|
SECUPENT
|
2016-03-21
|
|
WordPress Plugin Abtest - Local File Inclusion
|
2 |
WEB
|
CrashBandicot
|
2016-03-21
|
|
WordPress Plugin Import CSV 1.0 - Directory Traversal
|
1 |
WEB
|
Wadeek
|
2016-03-21
|
|
WordPress Plugin eBook Download 1.1 - Directory Traversal
|
2 |
WEB
|
Wadeek
|
2016-03-20
|
|
Wildfly - 'WEB-INF' / 'META-INF' Information Disclosure via Filter Restriction Bypass
|
2 |
WEB
|
Tal Solomon of Palantir Security
|
2016-03-17
|
|
PivotX 2.3.11 - Directory Traversal
|
2 |
WEB
|
Curesec Research Team
|
2016-03-17
|
|
ZenPhoto 1.4.11 - Remote File Inclusion
|
2 |
WEB
|
Curesec Research Team
|
2016-03-16
|
|
Monstra CMS 3.0.3 - Multiple Vulnerabilities
|
2 |
WEB
|
Sarim Kiani
|
2016-03-16
|
|
AKIPS Network Monitor 15.37 through 16.5 - OS Command Injection
|
2 |
WEB
|
BrianWGray
|
2016-03-15
|
|
Kaltura Community Edition < 11.1.0-2 - Multiple Vulnerabilities
|
2 |
WEB
|
Security-Assessment.com
|
2016-03-14
|
|
TeamPass 2.1.24 - Multiple Vulnerabilities
|
2 |
WEB
|
Vincent Malguy
|
2016-03-14
|
|
WordPress Plugin Site Import 1.0.1 - Local/Remote File Inclusion
|
1 |
WEB
|
Wadeek
|
2016-03-11
|
|
WordPress Plugin DZS Videogallery < 8.60 - Multiple Vulnerabilities
|
2 |
WEB
|
Colette Chamberland
|
2016-03-11
|
|
WordPress Theme Beauty & Clean 1.0.8 - Arbitrary File Upload
|
2 |
WEB
|
Colette Chamberland
|
2016-03-10
|
|
WordPress Plugin WP Advanced Comment 0.10 - Persistent Cross-Site Scripting
|
1 |
WEB
|
Mohammad Khaleghi
|
2016-03-10
|
|
WordPress Plugin Best Web Soft Captcha 4.1.5 - Multiple Vulnerabilities
|
2 |
WEB
|
Colette Chamberland
|
2016-03-09
|
|
WordPress Theme SiteMile Project 2.0.9.5 - Multiple Vulnerabilities
|
1 |
WEB
|
LSE Leading Security Experts GmbH
|
2016-03-09
|
|
Bluethrust Clan Scripts v4 R17 - Multiple Vulnerabilities
|
1 |
WEB
|
Brandon Murphy
|
2016-03-07
|
|
Cerberus Helpdesk (Cerb5) 5 < 6.7 - Password Hash Disclosure
|
1 |
WEB
|
asdizzle_
|
2016-03-07
|
|
ATutor LMS - '/install_modules.php' Cross-Site Request Forgery / Remote Code Execution
|
2 |
WEB
|
mr_me
|
2016-03-03
|
|
WordPress Plugin Bulk Delete 5.5.3 - Privilege Escalation
|
2 |
WEB
|
Panagiotis Vagenas
|
2016-03-01
|
|
WordPress Plugin CP Polls 1.0.8 - Multiple Vulnerabilities
|
2 |
WEB
|
i0akiN SEC-LABORATORY
|
2016-02-29
|
|
WordPress Plugin More Fields 2.1 - Cross-Site Request Forgery
|
1 |
WEB
|
Aatif Shahdad
|
2016-02-26
|
|
Joomla! Component com_poweradmin 2.3.0 - Multiple Vulnerabilities
|
2 |
WEB
|
RatioSec Research
|
2016-02-26
|
|
Centreon 2.5.3 - Remote Command Execution
|
2 |
WEB
|
Sysdream
|
2016-02-26
|
|
Zimbra 8.0.9 GA - Cross-Site Request Forgery
|
2 |
WEB
|
Sysdream
|
2016-02-26
|
|
WordPress Plugin Ocim MP3 - SQL Injection
|
2 |
WEB
|
xevil & Blankon33
|
2016-02-26
|
|
Infor CRM 8.2.0.1136 - Multiple HTML Script Injection Vulnerabilities
|
2 |
WEB
|
LiquidWorm
|
2016-02-25
|
|
IBM Lotus Domino R8 - Password Hash Extraction
|
1 |
WEB
|
Jonathan Broche
|
2016-02-24
|
|
WordPress Plugin Extra User Details 0.4.2 - Privilege Escalation
|
1 |
WEB
|
Panagiotis Vagenas
|
2016-02-23
|
|
Ubiquiti Networks UniFi 3.2.10 - Cross-Site Request Forgery
|
1 |
WEB
|
Julien Ahrens
|
2016-02-23
|
|
Dell OpenManage Server Administrator 8.2 - (Authenticated) Directory Traversal
|
1 |
WEB
|
hantwister
|
2016-02-22
|
|
Thru Managed File Transfer Portal 9.0.2 - SQL Injection
|
1 |
WEB
|
SySS GmbH
|
2016-02-22
|
|
BlackBerry Enterprise Service < 12.4 (BES12) Self-Service - Multiple Vulnerabilities
|
1 |
WEB
|
Security-Assessment.com
|
2016-02-22
|
|
InstantCoder 1.0 iOS - Multiple Vulnerabilities
|
1 |
WEB
|
Vulnerability-Lab
|
2016-02-20
|
|
SOLIDserver < 5.0.4 - Local File Inclusion
|
2 |
WEB
|
Saeed reza Zamanian
|
2016-02-19
|
|
ManageEngine Firewall Analyzer 8.5 - Multiple Vulnerabilities
|
2 |
WEB
|
Sachin Wagh
|
2016-02-19
|
|
Chamilo LMS - Persistent Cross-Site Scripting
|
1 |
WEB
|
Vulnerability-Lab
|
2016-02-19
|
|
Chamilo LMS IDOR - 'messageId' Delete POST Injection
|
1 |
WEB
|
Vulnerability-Lab
|
2016-02-18
|
|
DirectAdmin 1.491 - Cross-Site Request Forgery
|
1 |
WEB
|
Necmettin COSKUN
|
2016-02-18
|
|
Vesta Control Panel 0.9.8-15 - Persistent Cross-Site Scripting
|
0 |
WEB
|
Necmettin COSKUN
|
2016-02-17
|
|
Redaxo 5.0.0 - Multiple Vulnerabilities
|
2 |
WEB
|
LSE Leading Security Experts GmbH
|
2016-02-17
|
|
OCS Inventory NG 2.2 - SQL Injection
|
1 |
WEB
|
Ephreet
|
2016-02-17
|
|
JMX2 Email Tester - 'save_email.php' Arbitrary File Upload
|
0 |
WEB
|
HaHwul
|
2016-02-16
|
|
phpMyBackupPro 2.5 - Remote Command Execution / Cross-Site Request Forgery
|
1 |
WEB
|
hyp3rlinx
|
2016-02-16
|
|
WordPress Plugin ALO EasyMail NewsLetter 2.6.01 - Cross-Site Request Forgery
|
2 |
WEB
|
Mohsen Lotfi
|
2016-02-16
|
|
ManageEngine Network Configuration Management Build 11000 - Privilege Escalation
|
2 |
WEB
|
Kaustubh G. Padwad
|
2016-02-16
|
|
ManageEngine OPutils 8.0 - Multiple Vulnerabilities
|
2 |
WEB
|
Kaustubh G. Padwad
|
2016-02-15
|
|
Tiny Tiny RSS - Blind SQL Injection
|
1 |
WEB
|
Kacper Szurek
|
2015-08-27
|
|
Oracle GlassFish Server 4.1 - Directory Traversal
|
1 |
WEB
|
Trustwave's SpiderLabs
|
2016-02-10
|
|
Yeager CMS 1.2.1 - Multiple Vulnerabilities
|
2 |
WEB
|
SEC Consult
|
2016-02-10
|
|
Apache Sling Framework (Adobe AEM) 2.3.6 - Information Disclosure
|
1 |
WEB
|
Vulnerability-Lab
|
2010-03-10
|
|
Employee TimeClock Software 0.99 - SQL Injection
|
2 |
WEB
|
Secunia Research
|
2016-02-08
|
|
WordPress Plugin Booking Calendar Contact Form 1.0.23 - Multiple Vulnerabilities
|
2 |
WEB
|
i0akiN SEC-LABORATORY
|
2016-02-08
|
|
WordPress Plugin WP User Frontend < 2.3.11 - Unrestricted Arbitrary File Upload
|
1 |
WEB
|
Panagiotis Vagenas
|
2016-02-08
|
|
WordPress Plugin WooCommerce Store Toolkit 1.5.5 - Privilege Escalation
|
1 |
WEB
|
Panagiotis Vagenas
|
2016-02-08
|
|
WordPress Plugin User Meta Manager 3.4.6 - Information Disclosure
|
1 |
WEB
|
Panagiotis Vagenas
|
2016-02-08
|
|
dotDefender Firewall 5.00.12865/5.13-13282 - Cross-Site Request Forgery
|
1 |
WEB
|
hyp3rlinx
|
2016-02-08
|
|
Solr 3.5.0 - Arbitrary Data Deletion
|
0 |
WEB
|
N37
|
2016-02-04
|
|
Symphony CMS 2.6.3 - Multiple SQL Injections
|
0 |
WEB
|
Sachin Wagh
|