2012-06-11
|
|
BMC Identity Management - Cross-Site Request Forgery
|
3 |
WEB
|
Travis Lee
|
2012-06-03
|
|
WordPress Plugin Picturesurf Gallery - 'upload.php' Arbitrary File Upload
|
3 |
WEB
|
Sammy FORGIT
|
2012-06-07
|
|
WordPress Plugin FCChat Widget 2.2.x - 'upload.php' Arbitrary File Upload
|
3 |
WEB
|
Sammy FORGIT
|
2015-06-24
|
|
Vesta Control Panel 0.9.8 - OS Command Injection
|
3 |
WEB
|
High-Tech Bridge SA
|
2015-06-24
|
|
Joomla! Component com_simpleimageupload - Arbitrary File Upload
|
3 |
WEB
|
CrashBandicot
|
2015-06-24
|
|
GeniXCMS 0.0.3 - 'register.php' SQL Injection
|
3 |
WEB
|
cfreer
|
2015-06-24
|
|
WordPress Plugin Huge-IT Slider 2.7.5 - Multiple Vulnerabilities
|
2 |
WEB
|
i0akiN SEC-LABORATORY
|
2015-06-24
|
|
GeniXCMS 0.0.3 - Cross-Site Scripting
|
3 |
WEB
|
hyp3rlinx
|
2012-06-07
|
|
WordPress Plugin VideoWhisper Video Presentation 3.17 - 'vw_upload.php' Arbitrary File Upload
|
3 |
WEB
|
Sammy FORGIT
|
2012-06-07
|
|
WordPress Plugin Email NewsLetter 8.0 - 'option' Information Disclosure
|
3 |
WEB
|
Sammy FORGIT
|
2012-06-06
|
|
MyBB 1.6.8 - 'member.php' SQL Injection
|
2 |
WEB
|
MR.XpR
|
2012-06-05
|
|
Bigware Shop 2.1x - 'main_bigware_54.php' SQL Injection
|
3 |
WEB
|
rwenzel
|
2015-06-05
|
|
WordPress Plugin Nmedia WordPress Member Conversation 1.35.0 - 'doupload.php' Arbitrary File Upload
|
3 |
WEB
|
Sammy FORGIT
|
2012-06-03
|
|
Ignite Solutions CMS - 'car-details.php' SQL Injection
|
3 |
WEB
|
Am!r
|
2012-06-03
|
|
AdaptCMS 2.0.2 TinyURL Plugin - 'admin.php' Multiple SQL Injections
|
3 |
WEB
|
KedAns-Dz
|
2012-06-03
|
|
AdaptCMS 2.0.2 TinyURL Plugin - 'index.php?id' SQL Injection
|
3 |
WEB
|
KedAns-Dz
|
2012-06-03
|
|
TinyCMS 1.3 - '/admin/admin.php?do' Traversal Local File Inclusion
|
2 |
WEB
|
KedAns-Dz
|
2012-06-03
|
|
TinyCMS 1.3 - 'index.php?page' Traversal Local File Inclusion
|
2 |
WEB
|
KedAns-Dz
|
2012-06-03
|
|
TinyCMS 1.3 - Arbitrary File Upload / Cross-Site Request Forgery
|
2 |
WEB
|
KedAns-Dz
|
2012-06-01
|
|
VoipNow Professional 2.5.3 - 'nsextt' Cross-Site Scripting
|
2 |
WEB
|
Aboud-el
|
2012-05-31
|
|
WHMCompleteSolution (WHMCS) 5.0 - 'KnowledgeBase.php?search' Cross-Site Scripting
|
2 |
WEB
|
Shadman Tanjim
|
2012-05-31
|
|
WHMCompleteSolution (WHMCS) 5.0 - Cross-Site Request Forgery (Multiple Application Function)
|
2 |
WEB
|
Shadman Tanjim
|
2012-05-29
|
|
WHMCompleteSolution (WHMCS) - 'boleto_bb.php' SQL Injection
|
2 |
WEB
|
dex
|
2012-05-28
|
|
Yamamah Photo Gallery 1.1 - Database Information Disclosure
|
2 |
WEB
|
L3b-r1'z
|
2012-05-27
|
|
Nilehoster Topics Viewer 2.3 - Multiple SQL Injections / Local File Inclusion
|
2 |
WEB
|
n4ss1m
|
2012-05-26
|
|
Small-Cms - 'hostname' Remote PHP Code Injection
|
2 |
WEB
|
L3b-r1'z
|
2015-06-19
|
|
Lively Cart - SQL Injection
|
2 |
WEB
|
Manish Tanwar
|
2015-06-19
|
|
ZTE ZXV10 W300 v3.1.0c_DR0 - UI Session Delete
|
2 |
WEB
|
Vulnerability-Lab
|
2015-06-19
|
|
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
|
2 |
WEB
|
Vulnerability-Lab
|
2012-05-25
|
|
DynPage 1.0 - 'ckfinder' Multiple Arbitrary File Upload Vulnerabilities
|
3 |
WEB
|
KedAns-Dz
|
2015-06-19
|
|
Tango FTP 1.0 (Build 136) - Activex HeapSpray
|
4 |
WEB
|
metacom
|
2015-06-19
|
|
Tango DropBox 3.1.5 + PRO - Activex HeapSpray
|
4 |
WEB
|
metacom
|
2012-05-26
|
|
phpList 2.10.9 - 'Sajax.php' PHP Code Injection
|
3 |
WEB
|
L3b-r1'z
|
2012-05-27
|
|
AzDGDatingMedium 1.9.3 - Multiple Remote Vulnerabilities
|
3 |
WEB
|
AkaStep
|
2012-05-24
|
|
phpCollab 2.5 - Direct Request Multiple Protected Page Access
|
3 |
WEB
|
team ' & 1=1--
|
2012-05-24
|
|
PHPCollab 2.5 - 'uploadfile.php' Crafted Request Arbitrary Non-PHP File Upload
|
3 |
WEB
|
team ' & 1=1--
|
2012-05-23
|
|
Yellow Duck Framework 2.0 Beta1 - Local File Disclosure
|
3 |
WEB
|
L3b-r1'z
|
2012-05-23
|
|
pragmaMx 1.12.1 - '/includes/wysiwyg/spaw/editor/plugins/imgpopup/img_popup.php?img_url' Cross-Site
|
3 |
WEB
|
High-Tech Bridge SA
|
2012-05-23
|
|
pragmaMx 1.12.1 - 'modules.php' URI Cross-Site Scripting
|
3 |
WEB
|
High-Tech Bridge SA
|
2012-05-23
|
|
Pligg CMS 1.x - 'module.php' Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2012-05-23
|
|
Ajaxmint Gallery 1.0 - Local File Inclusion
|
3 |
WEB
|
AkaStep
|
2012-05-23
|
|
phpCollab 2.5 - Database Backup Information Disclosure
|
3 |
WEB
|
team ' & 1=1--
|
2012-05-23
|
|
Ruubikcms 1.1.x - Cross-Site Scripting / Information Disclosure / Directory Traversal
|
3 |
WEB
|
AkaStep
|
2012-05-21
|
|
PHPhq.Net phAlbum 1.5.1 - 'index.php' Cross-Site Scripting
|
3 |
WEB
|
Eyup CELIK
|
2012-05-22
|
|
Plogger Photo Gallery - SQL Injection
|
3 |
WEB
|
Eyup CELIK
|
2015-06-17
|
|
BlackCat CMS 1.1.1 - Arbitrary File Download
|
3 |
WEB
|
d4rkr0id
|
2015-06-16
|
|
E-Detective Lawful Interception System - Multiple Vulnerabilities
|
3 |
WEB
|
Mustafa Al-Bassam
|
2015-06-16
|
|
TYPO3 Extension Akronymmanager 0.5.0 - SQL Injection
|
3 |
WEB
|
RedTeam Pentesting
|
2015-06-16
|
|
Apexis IP CAM - Information Disclosure
|
3 |
WEB
|
Sunplace Solutions
|
2015-06-16
|
|
Ektron CMS 9.10 SP1 (Build 9.1.0.184.1.114) - Cross-Site Request Forgery
|
3 |
WEB
|
Jerold Hoong
|
2015-06-15
|
|
Milw0rm Clone Script 1.0 - '/admin/login.php' Authentication Bypass
|
4 |
WEB
|
walid naceri
|
2012-05-20
|
|
AZ Photo Album - Cross-Site Scripting / Arbitrary File Upload
|
3 |
WEB
|
Eyup CELIK
|
2015-06-12
|
|
WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Upload
|
4 |
WEB
|
Larry W. Cashdollar
|
2015-06-12
|
|
WordPress Plugin SE HTML5 Album Audio Player 1.1.0 - Directory Traversal
|
3 |
WEB
|
Larry W. Cashdollar
|
2015-06-12
|
|
ZCMS 1.1 - Multiple Vulnerabilities
|
2 |
WEB
|
hyp3rlinx
|
2015-06-12
|
|
Opsview 4.6.2 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Dolev Farhi
|
2015-06-12
|
|
Nakid CMS - Multiple Vulnerabilities
|
3 |
WEB
|
hyp3rlinx
|
2015-06-12
|
|
ClickHeat 1.14 - Cross-Site Request Forgery (Change Admin Password)
|
3 |
WEB
|
David Shanahan
|
2015-06-10
|
|
WordPress Plugin Encrypted Contact Form 1.0.4 - Cross-Site Request Forgery
|
3 |
WEB
|
Nitin Venkatesh
|
2015-06-10
|
|
AnimaGallery 2.6 - Local File Inclusion
|
3 |
WEB
|
d4rkr0id
|
2015-06-10
|
|
Alcatel-Lucent OmniSwitch - Cross-Site Request Forgery
|
4 |
WEB
|
RedTeam Pentesting
|
2015-06-10
|
|
Bonita BPM 6.5.1 - Multiple Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2015-06-10
|
|
ISPConfig 3.0.5.4p6 - Multiple Vulnerabilities
|
3 |
WEB
|
High-Tech Bridge SA
|
2015-06-10
|
|
GeoVision (GeoHttpServer) Webcams - Remote File Disclosure
|
3 |
WEB
|
Viktor Minin
|
2015-06-10
|
|
FiverrScript - Cross-Site Request Forgery (Add Admin)
|
3 |
WEB
|
Mahmoud Gamal
|
2015-06-10
|
|
Pandora FMS 5.0/5.1 - Authentication Bypass
|
2 |
WEB
|
Manuel Mancera
|
2015-06-10
|
|
WordPress Plugin History Collection 1.1.1 - Arbitrary File Download
|
3 |
WEB
|
Kuroi'SH
|
2015-06-10
|
|
WordPress Plugin Paypal Currency Converter Basic For WooCommerce - File Read
|
3 |
WEB
|
Kuroi'SH
|
2015-06-10
|
|
WordPress Plugin RobotCPA V5 - Local File Inclusion
|
3 |
WEB
|
T3N38R15
|
2015-06-10
|
|
HP WebInspect 10.4 - XML External Entity Injection
|
3 |
WEB
|
Jakub Palaczynski
|
2015-06-09
|
|
Milw0rm Clone Script 1.0 - 'related.php?program' Blind SQL Injection
|
3 |
WEB
|
Pancaker
|
2015-06-08
|
|
Pasworld - 'detail.php' Blind SQL Injection
|
2 |
WEB
|
Sebastian khan
|
2015-06-08
|
|
WordPress Plugin WP Mobile Edition - Local File Inclusion
|
2 |
WEB
|
Ali Khalil
|
2015-06-08
|
|
WordPress Plugin Wp-ImageZoom 1.1.0 - Multiple Vulnerabilities
|
2 |
WEB
|
T3N38R15
|
2015-06-08
|
|
D-Link DSL-526B ADSL2+ AU_2.01 - Remote DNS Change
|
3 |
WEB
|
Todor Donev
|
2015-06-08
|
|
D-Link DSL-2730B AU_2.01 - Authentication Bypass DNS Change
|
2 |
WEB
|
Todor Donev
|
2015-06-08
|
|
TP-Link TD-W8950ND ADSL2+ - Remote DNS Change
|
2 |
WEB
|
Todor Donev
|
2015-06-08
|
|
D-Link DSL-2780B DLink_1.01.14 - Remote DNS Change
|
2 |
WEB
|
Todor Donev
|
2012-05-20
|
|
Concrete5 CMS FlashUploader - Arbitrary '.SWF' File Upload
|
2 |
WEB
|
AkaStep
|
2012-05-20
|
|
Concrete CMS < 5.5.21 - Multiple Vulnerabilities
|
2 |
WEB
|
AkaStep
|
2012-05-21
|
|
Yandex.Server 2010 9.0 - 'text' Cross-Site Scripting
|
2 |
WEB
|
MustLive
|
2012-05-21
|
|
Acuity CMS 2.6.2 - '/admin/file_manager/browse.asp?path' Traversal Arbitrary File Access
|
2 |
WEB
|
Aung Khant
|
2012-05-21
|
|
Acuity CMS 2.6.2 - '/admin/file_manager/file_upload_submit.asp' Multiple Arbitrary File Upload / Cod
|
2 |
WEB
|
Aung Khant
|
2012-05-17
|
|
Atlassian JIRA FishEye 2.5.7 / Crucible 2.5.7 Plugins - XML Parsing Security
|
2 |
WEB
|
anonymous
|
2012-05-03
|
|
OpenKM 5.1.7 - Cross-Site Request Forgery
|
2 |
WEB
|
Cyrill Brunschwiler
|
2012-05-17
|
|
PHP Address Book 7.0 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Stefan Schurtz
|
2012-05-17
|
|
ArtiPHP 5.5.0 Neo - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Gjoko Krstic
|
2012-05-16
|
|
Unijimpe Captcha - 'captchademo.php' Cross-Site Scripting
|
2 |
WEB
|
Daniel Godoy
|
2015-06-06
|
|
Broadlight Residential Gateway DI3124 - Remote DNS Change
|
2 |
WEB
|
Todor Donev
|
2015-06-06
|
|
WiFi HD 8.1 - Directory Traversal / Denial of Service
|
1 |
WEB
|
Wh1t3Rh1n0 (Michael Allen)
|
2015-06-05
|
|
WordPress Plugin Really Simple Guest Post 1.0.6 - Local File Inclusion
|
2 |
WEB
|
Kuroi'SH
|
2012-05-16
|
|
backupDB() 1.2.7a - 'onlyDB' Cross-Site Scripting
|
2 |
WEB
|
LiquidWorm
|
2012-05-16
|
|
SiliSoftware PHPThumb() 1.7.11-201108081537 - '/demo/PHPThumb.demo.random.php?dir' Cross-Site Script
|
2 |
WEB
|
Gjoko Krstic
|
2012-05-16
|
|
SiliSoftware PHPThumb() 1.7.11-201108081537 - '/demo/PHPThumb.demo.showpic.php?title' Cross-Site Scr
|
2 |
WEB
|
Gjoko Krstic
|
2012-05-16
|
|
LongTail JW Player - 'debug' Cross-Site Scripting
|
2 |
WEB
|
gainover
|
2012-05-15
|
|
WordPress Plugin Track That Stat 1.0.8 - Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin Soundcloud Is Gold 2.1 - 'width' Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin Share and Follow 1.80.3 - 'admin.php' Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin Sharebar 1.2.1 - SQL Injection / Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2015-06-04
|
|
WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion
|
2 |
WEB
|
Panagiotis Vagenas
|
2012-05-15
|
|
WordPress Plugin Pretty Link Lite 1.5.2 - SQL Injection / Cross-Site Scripting
|
1 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin WP Forum Server 1.7.3 - '/fs-admin/fs-admin.php' Multiple Cross-Site Scripting Vuln
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin Mingle Forum 1.0.33 - 'admin.php' Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin GD Star Rating 1.9.16 - 'tpl_section' Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin Leaflet Maps Marker 0.0.1 - 'leaflet_marker.php?id' Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin Leaflet Maps Marker 0.0.1 - 'leaflet_layer.php?id' Cross-Site Scripting
|
3 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin LeagueManager 3.7 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin Media Library Categories - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Heine Pedersen
|
2015-06-03
|
|
VFront 0.99.2 - Cross-Site Request Forgery / Persistent Cross-Site Scripting
|
2 |
WEB
|
hyp3rlinx
|
2015-06-03
|
|
Seagate Central 2014.0410.0026-F - Remote Facebook Access Token
|
2 |
WEB
|
Jeremy Brown
|
2015-06-02
|
|
WordPress Plugin LeagueManager 3.9.11 - SQL Injection
|
3 |
WEB
|
javabudd
|
2012-05-15
|
|
WordPress Plugin NewsLetter Manager 1.0 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin iFrame Admin Pages 0.1 - 'main_page.php' Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin 2 Click Social Media Buttons 0.32.2 - Multiple Cross-Site Scripting Vulnerabilities
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin CataBlog 1.6 - 'admin.php' Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin PDF & Print Button Joliprint 1.3.0 - Multiple Cross-Site Scripting Vulnerabilities
|
3 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin Network Publisher 5.0.1 - 'networkpub_key' Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2015-06-01
|
|
Aruba ClearPass Policy Manager - Persistent Cross-Site Scripting
|
2 |
WEB
|
Cristiano Maruti
|
2015-06-01
|
|
WordPress Plugin dzs-zoomsounds 2.0 - Arbitrary File Upload
|
2 |
WEB
|
nabil chris
|
2012-05-15
|
|
WordPress Plugin Dynamic Widgets 1.5.1 - 'themes.php' Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2012-05-15
|
|
WordPress Plugin GRAND Flash Album Gallery 1.71 - 'admin.php' Cross-Site Scripting
|
2 |
WEB
|
Heine Pedersen
|
2012-05-13
|
|
WordPress Plugin WP-FaceThumb 0.1 - 'pagination_wp_facethum' Cross-Site Scripting
|
2 |
WEB
|
d3v1l
|
2015-05-29
|
|
ESC 8832 Data Controller - Multiple Vulnerabilities
|
2 |
WEB
|
Balazs Makany
|
2015-05-29
|
|
JSPMyAdmin 1.1 - Multiple Vulnerabilities
|
2 |
WEB
|
hyp3rlinx
|
2015-05-29
|
|
TCPDF Library 5.9 - Arbitrary File Deletion
|
0 |
WEB
|
Filippo Roncari
|