2015-08-12
|
|
Geoserver < 2.7.1.1 / < 2.6.4 / < 2.5.5.1 - XML External Entity
|
3 |
WEB
|
David Bloom
|
2015-08-10
|
|
WordPress Plugin Candidate Application Form 1.0 - Arbitrary File Download
|
3 |
WEB
|
Larry W. Cashdollar
|
2015-08-10
|
|
WordPress Plugin Simple Image Manipulator 1.0 - Arbitrary File Download
|
3 |
WEB
|
Larry W. Cashdollar
|
2015-08-10
|
|
WordPress Plugin Recent Backups 0.7 - Arbitrary File Download
|
3 |
WEB
|
Larry W. Cashdollar
|
2015-08-10
|
|
WordPress Plugin WPTF Image Gallery 1.03 - Arbitrary File Download
|
3 |
WEB
|
Larry W. Cashdollar
|
2015-08-10
|
|
WDS CMS - SQL Injection
|
3 |
WEB
|
Ismail Marzouk
|
2015-08-09
|
|
WordPress Plugin Video Gallery 2.7 - SQL Injection
|
4 |
WEB
|
Kacper Szurek
|
2015-08-07
|
|
WordPress Plugin Job Manager 0.7.22 - Persistent Cross-Site Scripting
|
2 |
WEB
|
Owais Mehtab
|
2015-08-07
|
|
Microweber 1.0.3 - Arbitrary File Upload / Filter Bypass / PHP Remote Code Execution
|
2 |
WEB
|
LiquidWorm
|
2015-08-07
|
|
Microweber 1.0.3 - Persistent Cross-Site Scripting / Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
LiquidWorm
|
2015-08-07
|
|
PHP News Script 4.0.0 - SQL Injection
|
3 |
WEB
|
Meisam Monsef
|
2015-08-07
|
|
Froxlor Server Management Panel 0.9.33.1 - MySQL Login Information Disclosure
|
2 |
WEB
|
Dustin Dörr
|
2015-07-31
|
|
Netgear ReadyNAS LAN /dbbroker 6.2.4 - Credential Disclosure
|
1 |
WEB
|
St0rn
|
2015-07-29
|
|
Tendoo CMS 1.3 - Cross-Site Scripting
|
1 |
WEB
|
Arash Khazaei
|
2015-07-29
|
|
JoomShopping - Blind SQL Injection
|
2 |
WEB
|
Mormoroth
|
2015-07-29
|
|
2Moons - Multiple Vulnerabilities
|
2 |
WEB
|
bRpsd
|
2015-07-29
|
|
phpFileManager 0.9.8 - Cross-Site Request Forgery
|
2 |
WEB
|
hyp3rlinx
|
2015-07-28
|
|
phpFileManager 0.9.8 - Remote Command Execution
|
0 |
WEB
|
hyp3rlinx
|
2015-07-27
|
|
Xceedium Xsuite - Multiple Vulnerabilities
|
2 |
WEB
|
modzero
|
2015-07-27
|
|
WordPress Plugin Count Per Day 3.4 - SQL Injection
|
2 |
WEB
|
High-Tech Bridge SA
|
2015-07-27
|
|
WordPress Plugin Unite Gallery Lite 1.4.6 - Multiple Vulnerabilities
|
4 |
WEB
|
Nitin Venkatesh
|
2015-07-27
|
|
Hawkeye-G 3.0.1.4912 - Persistent Cross-Site Scripting / Information Leakage
|
1 |
WEB
|
hyp3rlinx
|
2012-09-05
|
|
Kayako Fusion - 'download.php' Cross-Site Scripting
|
2 |
WEB
|
High-Tech Bridge
|
2012-09-04
|
|
PHPFox 3.0.1 - 'ajax.php' Multiple Cross-Site Scripting Vulnerabilities
|
0 |
WEB
|
Crim3R
|
2012-09-05
|
|
Cm3 CMS - 'search.asp' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Crim3R
|
2012-09-04
|
|
Sciretech (Multiple Products) - Multiple SQL Injections
|
2 |
WEB
|
AkaStep
|
2012-08-04
|
|
Wiki Web Help - 'configpath' Remote File Inclusion
|
3 |
WEB
|
L0n3ly-H34rT
|
2012-09-03
|
|
Sitemax Maestro - SQL Injection / Local File Inclusion
|
2 |
WEB
|
AkaStep
|
2012-08-31
|
|
SugarCRM Community Edition - Multiple Information Disclosure Vulnerabilities
|
2 |
WEB
|
Brendan Coles
|
2012-08-30
|
|
Crowbar - 'file' Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
Matthias Weckbecker
|
2012-08-30
|
|
XM Forum - 'search.asp' SQL Injection
|
3 |
WEB
|
Crim3R
|
2012-08-30
|
|
TomatoCart - 'example_form.ajax.php' Cross-Site Scripting
|
3 |
WEB
|
HauntIT
|
2015-07-24
|
|
Hawkeye-G 3.0.1.4912 - Cross-Site Request Forgery
|
2 |
WEB
|
hyp3rlinx
|
2012-08-29
|
|
PrestaShop 1.4.7 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge
|
2012-08-29
|
|
Phorum 5.2.18 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
High-Tech Bridge
|
2012-08-28
|
|
WordPress Plugin Simple:Press Forum - Arbitrary File Upload
|
3 |
WEB
|
Iranian Dark Coders
|
2012-08-28
|
|
WordPress Plugin Cloudsafe365 - 'file' Remote File Disclosure
|
3 |
WEB
|
Jan Van Niekerk
|
2012-08-25
|
|
Mihalism Multi Host - 'users.php' Cross-Site Scripting
|
3 |
WEB
|
Explo!ter
|
2012-08-25
|
|
LibGuides - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Crim3R
|
2012-08-25
|
|
Web Wiz Forums - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Crim3R
|
2012-08-25
|
|
WordPress Plugin Finder - 'order' Cross-Site Scripting
|
3 |
WEB
|
Crim3R
|
2012-08-25
|
|
Power-eCommerce - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Crim3R
|
2012-08-27
|
|
Joomla! Component Komento - 'cid' SQL Injection
|
3 |
WEB
|
Crim3R
|
2012-08-24
|
|
PHP Web Scripts Text Exchange Pro - 'page' Local File Inclusion
|
2 |
WEB
|
Yakir Wizman
|
2012-08-29
|
|
JW Player - 'logo.link' Cross-Site Scripting
|
4 |
WEB
|
MustLive
|
2015-07-21
|
|
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
|
4 |
WEB
|
Simon Rawet
|
2015-07-20
|
|
AirDroid iOS / Android / Win 3.1.3 - Persistent
|
3 |
WEB
|
Vulnerability-Lab
|
2015-07-20
|
|
phpVibe < 4.20 - Persistent Cross-Site Scripting
|
3 |
WEB
|
Filippos Mastrogiannis
|
2012-08-23
|
|
PHP Web Scripts Ad Manager Pro - 'page' Local File Inclusion
|
3 |
WEB
|
Corrado Liotta
|
2012-08-22
|
|
WordPress Plugin Monsters Editor for WP Super Edit - Arbitrary File Upload
|
2 |
WEB
|
Crim3R
|
2012-08-22
|
|
WordPress Plugin Rich Widget - Arbitrary File Upload
|
3 |
WEB
|
Crim3R
|
2012-08-23
|
|
KindEditor - 'name' Cross-Site Scripting
|
2 |
WEB
|
LiquidWorm
|
2012-08-23
|
|
Monstra CMS 1.2.1 - Multiple HTML Injection Vulnerabilities
|
2 |
WEB
|
LiquidWorm
|
2012-08-22
|
|
1024 CMS 2.1.1 - 'p' SQL Injection
|
2 |
WEB
|
kallimero
|
2012-08-23
|
|
SiNG cms - 'Password.php' Cross-Site Scripting
|
2 |
WEB
|
LiquidWorm
|
2012-08-22
|
|
Joomla! Component CiviCRM - Multiple Arbitrary File Upload Vulnerabilities
|
2 |
WEB
|
Crim3R
|
2012-08-22
|
|
Banana Dance - Cross-Site Scripting / SQL Injection
|
3 |
WEB
|
Canberk BOLAT
|
2012-08-22
|
|
OrderSys 1.6.4 - Multiple SQL Injections / Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Canberk BOLAT
|
2012-08-22
|
|
Jara 1.6 - Multiple SQL Injections / Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Canberk BOLAT
|
2012-08-27
|
|
IBM Rational ClearQuest 8.0 - Multiple Vulnerabilities
|
2 |
WEB
|
anonymous
|
2012-08-18
|
|
SaltOS - 'download.php' Cross-Site Scripting
|
2 |
WEB
|
Stefan Schurtz
|
2012-08-21
|
|
JPM Article Blog Script 6 - 'tid' Cross-Site Scripting
|
2 |
WEB
|
Mr.0c3aN
|
2012-08-17
|
|
LISTSERV 16 - 'SHOWTPL' Cross-Site Scripting
|
2 |
WEB
|
Jose Carlos de Arriba
|
2012-08-17
|
|
Elastix 2.2.0 - 'graph.php' Local File Inclusion
|
2 |
WEB
|
cheki
|
2012-08-02
|
|
WordPress Theme ShopperPress - SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
Benjamin Kunz Mejri
|
2012-08-10
|
|
GalaxyScripts Mini File Host and DaddyScripts Daddy's File Host - Local File Inclusion
|
2 |
WEB
|
L0n3ly-H34rT
|
2012-08-11
|
|
MindTouch DekiWiki - Multiple Local/Remote File Inclusions
|
2 |
WEB
|
L0n3ly-H34rT
|
2012-08-10
|
|
mIRC - 'projects.php' Cross-Site Scripting
|
3 |
WEB
|
TayfunBasoglu
|
2012-08-13
|
|
Total Shop UK eCommerce CodeIgniter - Multiple Cross-Site Scripting Vulnerabilities
|
1 |
WEB
|
Chris Cooper
|
2012-08-09
|
|
Hotel Booking Portal 0.1 - Multiple SQL Injections / Cross-Site Scripting
|
1 |
WEB
|
Yakir Wizman
|
2015-07-17
|
|
WordPress Plugin BuddyPress Activity Plus 1.5 - Cross-Site Request Forgery
|
3 |
WEB
|
Tom Adams
|
2015-07-16
|
|
8 TOTOLINK Router Models - Backdoor Access / Remote Code Execution
|
2 |
WEB
|
Pierre Kim
|
2015-07-16
|
|
4 TOTOLINK Router Models - Backdoor Credentials
|
2 |
WEB
|
Pierre Kim
|
2015-07-16
|
|
4 TOTOLINK Router Models - Cross-Site Request Forgery / Cross-Site Scripting
|
2 |
WEB
|
Pierre Kim
|
2015-07-16
|
|
15 TOTOLINK Router Models - Multiple Remote Code Execution Vulnerabilities
|
2 |
WEB
|
Pierre Kim
|
2015-07-16
|
|
WordPress Plugin Download Manager Free 2.7.94 & Pro 4 - (Authenticated) Persistent Cross-Site Script
|
2 |
WEB
|
Filippos Mastrogiannis
|
2015-07-15
|
|
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (1)
|
2 |
WEB
|
Pedro Ribeiro
|
2015-07-15
|
|
Joomla! Component com_docman - Multiple Vulnerabilities
|
2 |
WEB
|
Hugo Santiago
|
2012-08-08
|
|
dirLIST 0.3.0 - Local File Inclusion
|
2 |
WEB
|
L0n3ly-H34rT
|
2012-08-08
|
|
PBBoard - 'admin.php?xml_name' Arbitrary PHP Code Execution
|
2 |
WEB
|
High-Tech Bridge
|
2012-08-08
|
|
PBBoard - 'member_id' Validation Password Manipulation
|
2 |
WEB
|
High-Tech Bridge
|
2012-08-08
|
|
PBBoard - 'index.php' Multiple SQL Injections
|
2 |
WEB
|
High-Tech Bridge
|
2012-08-08
|
|
phpList 2.10.18 - 'index.php' SQL Injection
|
2 |
WEB
|
High-Tech Bridge SA
|
2015-07-14
|
|
sysPass 1.0.9 - SQL Injection
|
1 |
WEB
|
SySS GmbH
|
2015-07-14
|
|
Pimcore CMS Build 3450 - Directory Traversal
|
2 |
WEB
|
Portcullis
|
2015-07-13
|
|
SO Planning 1.32 - Multiple Vulnerabilities
|
2 |
WEB
|
Huy-Ngoc DAU
|
2015-07-13
|
|
WordPress Plugin CP Contact Form with Paypal 1.1.5 - Multiple Vulnerabilities
|
2 |
WEB
|
Nitin Venkatesh
|
2015-07-13
|
|
ZenPhoto 1.4.8 - Multiple Vulnerabilities
|
2 |
WEB
|
Tim Coen
|
2015-07-13
|
|
WordPress Plugin Swim Team 1.44.10777 - Arbitrary File Download
|
2 |
WEB
|
Larry W. Cashdollar
|
2015-07-13
|
|
ArticleFR 3.0.6 - Multiple Vulnerabilities
|
2 |
WEB
|
LiquidWorm
|
2015-07-13
|
|
phpVibe - Arbitrary File Disclosure
|
2 |
WEB
|
ali ahmady
|
2015-07-13
|
|
Arab Portal 3 - SQL Injection
|
2 |
WEB
|
ali ahmady
|
2015-07-13
|
|
FreiChat 9.6 - SQL Injection
|
2 |
WEB
|
Kacper Szurek
|
2012-08-08
|
|
AraDown - 'id' SQL Injection
|
1 |
WEB
|
G-B
|
2012-08-08
|
|
phpList 2.10.18 - 'unconfirmed' Cross-Site Scripting
|
2 |
WEB
|
High-Tech Bridge SA
|
2012-08-08
|
|
ConcourseSuite - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
|
3 |
WEB
|
Matthew Joyce
|
2015-07-13
|
|
phpSQLiteCMS - Multiple Vulnerabilities
|
3 |
WEB
|
hyp3rlinx
|
2012-08-07
|
|
Getsimple CMS 3.1.2 - 'path' Local File Inclusion
|
2 |
WEB
|
PuN!Sh3r
|
2012-08-07
|
|
PBBoard - Authentication Bypass
|
2 |
WEB
|
i-Hmx
|
2012-08-07
|
|
TCExam 11.2.x - '/admin/code/tce_edit_question.php?subject_module_id' SQL Injection
|
2 |
WEB
|
Chris Cooper
|
2012-08-07
|
|
TCExam 11.2.x - '/admin/code/tce_edit_answer.php' Multiple SQL Injections
|
2 |
WEB
|
Chris Cooper
|
2012-08-06
|
|
YT-Videos Script - 'id' SQL Injection
|
2 |
WEB
|
3spi0n
|
2012-08-05
|
|
Mibew Messenger 1.6.4 - 'threadid' SQL Injection
|
2 |
WEB
|
Ucha Gobejishvili
|
2012-08-07
|
|
Dir2web - '/system/src/dispatcher.php?oid' SQL Injection
|
2 |
WEB
|
Daniel Correa
|
2012-08-04
|
|
Open Constructor - 'confirm.php?q' Cross-Site Scripting
|
1 |
WEB
|
Lorenzo Cantoni
|
2012-08-04
|
|
Open Constructor - '/data/file/edit.php?result' Cross-Site Scripting
|
2 |
WEB
|
Lorenzo Cantoni
|
2012-08-04
|
|
Open Constructor - '/users/users.php?keyword' Cross-Site Scripting
|
2 |
WEB
|
Lorenzo Cantoni
|
2012-08-05
|
|
PolarisCMS - 'WebForm_OnSubmit()' Cross-Site Scripting
|
2 |
WEB
|
Gjoko Krstic
|
2012-08-06
|
|
Joomla! Component com_photo - Multiple SQL Injections
|
3 |
WEB
|
Chokri Ben Achor
|
2012-08-06
|
|
Worksforweb iAuto - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
|
2 |
WEB
|
Benjamin Kunz Mejri
|
2012-08-03
|
|
Elefant CMS - 'id' Cross-Site Scripting
|
2 |
WEB
|
PuN!Sh3r
|
2012-07-30
|
|
Zenoss 3.2.1 - Multiple Vulnerabilities
|
2 |
WEB
|
Brendan Coles
|
2012-07-30
|
|
Zenoss 3.2.1 - (Authenticated) Remote Command Execution
|
2 |
WEB
|
Brendan Coles
|
2012-08-03
|
|
ntop - 'arbfile' Cross-Site Scripting
|
2 |
WEB
|
Marcos Garcia
|
2012-08-01
|
|
tekno.Portal 0.1b - 'link.php' SQL Injection
|
2 |
WEB
|
Socket_0x03
|
2012-08-02
|
|
Mahara 1.4.1 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
|
2 |
WEB
|
anonymous
|
2012-08-01
|
|
WordPress Plugin G-Lock Double Opt-in Manager - SQL Injection
|
2 |
WEB
|
BEASTIAN
|
2015-07-10
|
|
WordPress Plugin CP Multi View Event Calendar 1.1.7 - SQL Injection
|
2 |
WEB
|
i0akiN SEC-LABORATORY
|
2015-07-10
|
|
WordPress Plugin CP Image Store with Slideshow 1.0.5 - Arbitrary File Download
|
2 |
WEB
|
i0akiN SEC-LABORATORY
|
2012-08-01
|
|
ManageEngine Applications Manager - Multiple Cross-Site Scripting / SQL Injections
|
2 |
WEB
|
Ibrahim El-Sayed
|
2012-08-01
|
|
Distimo Monitor - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Benjamin Kunz Mejri
|
2012-08-01
|
|
ManageEngine Applications Manager - Multiple SQL Injections
|
2 |
WEB
|
Ibrahim El-Sayed
|
2012-07-31
|
|
Limny - 'index.php' Multiple SQL Injections
|
2 |
WEB
|
L0n3ly-H34rT
|
2012-07-29
|
|
eNdonesia - 'cid' SQL Injection
|
2 |
WEB
|
Crim3R
|
2012-07-29
|
|
JW Player - 'playerready' Cross-Site Scripting
|
2 |
WEB
|
MustLive
|