AnyDesk 5.5.2 - Remote Code Execution
|
|
2021-03-03
|
SMBGhost (SMBv3 Vulnerability) - Paper
|
|
2021-03-03
|
Chrome Browser FileReader (UAF) - Paper
|
|
2021-03-03
|
Local Services Search Engine Management System (LSSMES) 1.0 - Blind & Error based SQL injection (Authenticated)
|
|
2021-03-03
|
Local Services Search Engine Management System (LSSMES) 1.0 - 'name' Persistent Cross-Site Scripting (XSS)
|
|
2021-03-03
|
Zen Cart 1.5.7b - Remote Code Execution (Authenticated)
|
|
2021-03-02
|
Web Based Quiz System 1.0 - 'name' Persistent/Stored Cross-Site Scripting
|
|
2021-03-02
|
Tiny Tiny RSS - Remote Code Execution
|
|
2021-03-02
|
Web Based Quiz System 1.0 - 'MCQ options' Persistent/Stored Cross-Site Scripting
|
|
2021-03-02
|
Covid-19 Contact Tracing System 1.0 - Remote Code Execution (Unauthenticated)
|
|
2021-03-01
|
Online Catering Reservation System 1.0 - Remote Code Execution (Unauthenticated)
|
|
2021-03-01
|
VMware vCenter Server 7.0 - Unauthenticated File Upload
|
|
2021-03-01
|
WiFi Mouse 1.7.8.5 - Remote Code Execution
|
|
2021-03-01
|
FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit)
|
|
2021-03-01
|
Remote Desktop Web Access - Authentication Timing Attack (Metasploit Module)
|
|
2021-02-26
|
LightCMS 1.3.4 - 'exclusive' Stored XSS
|
|
2021-02-26
|
Triconsole 3.75 - Reflected XSS
|
|
2021-02-26
|
Simple Employee Records System 1.0 - File Upload RCE (Unauthenticated)
|
|
2021-02-26
|
Vehicle Parking Management System 1.0 - 'catename' Persistent Cross-Site Scripting (XSS)
|
|
2021-02-25
|
ASUS Remote Link 1.1.2.13 - Remote Code Execution
|
|
2021-02-25
|
LayerBB 1.1.4 - 'search_query' SQL Injection
|
|
2021-02-24
|
Windows/x86 - Add User Alfred to Administrators/Remote Desktop Users Group Shellcode (240 bytes)
|
|
2021-02-24
|
Product Key Explorer 4.2.7 - 'multiple' Denial of Service (PoC)
|
|
2021-02-24
|
SpotAuditor 5.3.5 - 'multiple' Denial Of Service (PoC)
|
|
2021-02-24
|
Softros LAN Messenger 9.6.4 - 'SoftrosSpellChecker' Unquoted Service Path
|
|
2021-02-24
|
Unified Remote 3.9.0.2463 - Remote Code Execution
|
|
2021-02-24
|
LogonExpert 8.1 - 'LogonExpertSvc' Unquoted Service Path
|
|
2021-02-24
|
python jsonpickle 2.0.0 - Remote Code Execution
|
|
2021-02-24
|
HFS (HTTP File Server) 2.3.x - Remote Command Execution (3)
|
|
2021-02-23
|
Batflat CMS 1.3.6 - 'multiple' Stored XSS
|
|
2021-02-23
|
Monica 2.19.1 - 'last_name' Stored XSS
|
|
2021-02-23
|
Beauty Parlour Management System 1.0 - 'sername' SQL Injection
|
|
2021-02-19
|
OpenText Content Server 20.3 - 'multiple' Stored Cross-Site Scripting
|
|
2021-02-19
|
dataSIMS Avionics ARINC 664-1 - Local Buffer Overflow (PoC)
|
|
2021-02-19
|
Online Exam System With Timer 1.0 - 'email' SQL injection Auth Bypass
|
|
2021-02-19
|
Comment System 1.0 - 'multiple' Stored Cross-Site Scripting
|
|
2021-02-19
|
PEEL Shopping 9.3.0 - 'Comments/Special Instructions' Stored Cross-Site Scripting
|
|
2021-02-19
|
Microsoft GamingServices 2.47.10001.0 - 'GamingServices' Unquoted Service Path
|
|
2021-02-18
|
Rukovoditel 2.7.1 - Remote Code Execution (2) (Authenticated)
|
|
2021-02-18
|
BacklinkSpeed 2.4 - Buffer Overflow PoC (SEH)
|
|
2021-02-18
|
Batflat CMS 1.3.6 - Remote Code Execution (Authenticated)
|
|
2021-02-18
|
Apport 2.20 - Local Privilege Escalation
|
|
2021-02-18
|
Gitea 1.12.5 - Remote Code Execution (Authenticated)
|
|
2021-02-18
|
Billing Management System 2.0 - 'email' SQL injection Auth Bypass
|
|
2021-02-17
|
Faulty Evaluation System 1.0 - 'multiple' Stored Cross-Site Scripting
|
|
2021-02-17
|
Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS
|
|
2021-02-17
|
Nsauditor 3.2.2.0 - 'Event Description' Denial of Service (PoC)
|
|
2021-02-16
|
AgataSoft PingMaster Pro 2.1 - Denial of Service (PoC)
|
|
2021-02-16
|
Managed Switch Port Mapping Tool 2.85.2 - Denial of Service (PoC)
|
|
2021-02-16
|
BlackCat CMS 1.3.6 - 'Display name' Cross Site Scripting (XSS)
|
|
2021-02-16
|