Exploits (Total: 96983)

    
    
    
openMAINT 1.1-2.4.2 - Arbitrary File Upload
2020-10-09
DynPG 4.9.1 - Persistent Cross-Site Scripting (Authenticated)
2020-10-09
Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
2020-10-09
D-Link DSR-250N 3.12 - Denial of Service (PoC)
2020-10-08
SEO Panel 4.6.0 - Remote Code Execution
2020-10-08
Textpattern CMS 4.6.2 - 'body' Persistent Cross-Site Scripting
2020-10-07
BACnet Test Server 1.01 - Remote Denial of Service (PoC)
2020-10-07
EasyPMS 1.0.0 - Authentication Bypass
2020-10-06
Karel IP Phone IP1211 Web Management Panel - Directory Traversal
2020-10-06
Qmail SMTP 1.03 - Bash Environment Variable Injection
2020-10-06
SpamTitan 7.07 - Unauthenticated Remote Code Execution
2020-10-05
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
2020-10-05
Photo Share Website 1.0 - Persistent Cross-Site Scripting
2020-10-02
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated)
2020-10-02
Exhibitor Web UI 1.7.1 - Remote Code Execution
2020-10-01
Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting
2020-10-01
CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)
2020-10-01
GetSimple CMS 3.3.16 - Persistent Cross-Site Scripting (Authenticated)
2020-10-01
WebsiteBaker 2.12.2 - 'display_name' SQL Injection (authenticated)
2020-10-01
MonoCMS Blog 1.0 - Arbitrary File Deletion (Authenticated)
2020-10-01
SpinetiX Fusion Digital Signage 3.4.8 - Username Enumeration
2020-10-01
SpinetiX Fusion Digital Signage 3.4.8 - Cross-Site Request Forgery (Add Admin)
2020-10-01
SpinetiX Fusion Digital Signage 3.4.8 - Database Backup Disclosure
2020-10-01
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - File Delete Path Traversal
2020-10-01
BrightSign Digital Signage Diagnostic Web Server 8.2.26 - Server-Side Request Forgery (Unauthenticated)
2020-10-01
Sony IPELA Network Camera 1.82.01 - 'ftpclient.cgi' Remote Stack Buffer Overflow
2020-10-01
CloudMe 1.11.2 - Buffer Overflow ROP (DEP,ASLR)
2020-09-29
BearShare Lite 5.2.5 - 'Advanced Search'Buffer Overflow in (PoC)
2020-09-29
WebsiteBaker 2.12.2 - Remote Code Execution
2020-09-29
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
2020-09-29
MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
2020-09-29
Mida eFramework 2.8.9 - Remote Code Execution
2020-09-29
B-swiss 3 Digital Signage System 3.6.5 - Database Disclosure
2020-09-25
B-swiss 3 Digital Signage System 3.6.5 - Cross-Site Request Forgery (Add Maintenance Admin)
2020-09-25
Anchor CMS 0.12.7 - Persistent Cross-Site Scripting (Authenticated)
2020-09-25
BigTree CMS 4.4.10 - Remote Code Execution
2020-09-25
Visitor Management System in PHP 1.0 - Persistent Cross-Site Scripting
2020-09-24
Simple Online Food Ordering System 1.0 - 'id' SQL Injection (Unauthenticated)
2020-09-24
Online Food Ordering System 1.0 - Remote Code Execution
2020-09-23
Flatpress Add Blog 1.0.3 - Persistent Cross-Site Scripting
2020-09-22
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
2020-09-22
B-swiss 3 Digital Signage System 3.6.5 - Remote Code Execution
2020-09-21
Mida eFramework 2.9.0 - Back Door Access
2020-09-21
Seat Reservation System 1.0 - 'id' SQL Injection
2020-09-21
ForensiTAppxService 2.2.0.4 - 'ForensiTAppxService.exe' Unquoted Service Path
2020-09-21
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
2020-09-21
Online Shop Project 1.0 - 'p' SQL Injection
2020-09-21
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
2020-09-18
SpamTitan 7.07 - Remote Code Execution (Authenticated)
2020-09-18
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
2020-09-17
Windows TCPIP Finger Command - C2 Channel and Bypassing Security Software
2020-09-16
Piwigo 2.10.1 - Cross Site Scripting
2020-09-16
Tailor MS 1.0 - Reflected Cross-Site Scripting
2020-09-16
ThinkAdmin 6 - Arbitrarily File Read
2020-09-16
Joomla! paGO Commerce 2.5.9.0 - SQL Injection (Authenticated)
2020-09-16
Pearson Vue VTS 2.3.1911 Installer - 'VUEApplicationWrapper' Unquoted Service Path
2020-09-16
RAD SecFlow-1v SF_0290_2.3.01.26 - Cross-Site Request Forgery (Reboot)
2020-09-16
Rapid7 Nexpose Installer 6.6.39 - 'nexposeengine' Unquoted Service Path
2020-09-16
RAD SecFlow-1v SF_0290_2.3.01.26 - Persistent Cross-Site Scripting
2020-09-16
Internet Explorer 11 - Use-After-Free
2020-09-16
Tea LaTex 1.0 - Remote Code Execution (Unauthenticated)
2020-09-16
VTENEXT 19 CE - Remote Code Execution
2020-09-16
Gnome Fonts Viewer 3.34.0 - Heap Corruption
2020-09-16
ZTE Router F602W - Captcha Bypass
2020-09-16
CuteNews 2.1.2 - Remote Code Execution
2020-09-16
Tiandy IPC and NVR 9.12.7 - Credential Disclosure
2020-09-16
Scopia XT Desktop 8.3.915.4 - Cross-Site Request Forgery (change admin password)
2020-09-16
Tailor Management System - 'id' SQL Injection
2020-09-16
Audio Playback Recorder 3.2.2 - Local Buffer Overflow (SEH)
2020-09-16
Input Director 1.4.3 - 'Input Director' Unquoted Service Path
2020-09-16
ShareMouse 5.0.43 - 'ShareMouse Service' Unquoted Service Path
2020-09-08
ManageEngine Applications Manager 14700 - Remote Code Execution (Authenticated)
2020-09-07
grocy 2.7.1 - Persistent Cross-Site Scripting
2020-09-07
Cabot 0.11.12 - Persistent Cross-Site Scripting
2020-09-07
Nord VPN-6.31.13.0 - 'nordvpn-service' Unquoted Service Path
2020-09-04
BarracudaDrive v6.5 - Insecure Folder Permissions
2020-09-03
SiteMagic CMS 4.4.2 - Arbitrary File Upload (Authenticated)
2020-09-03
Daily Tracker System 1.0 - Authentication Bypass
2020-09-03
BloodX CMS 1.0 - Authentication Bypass
2020-09-03
Savsoft Quiz Enterprise Version 5.5 - Persistent Cross-Site Scripting
2020-09-03
Stock Management System 1.0 - Cross-Site Request Forgery (Change Username)
2020-09-02
moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)
2020-09-01
Mara CMS 7.5 - Remote Code Execution (Authenticated)
2020-09-01
CMS Made Simple 2.2.14 - Arbitrary File Upload (Authenticated)
2020-08-31
Fuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated)
2020-08-31
Mara CMS 7.5 - Reflective Cross-Site Scripting
2020-08-31
BlazeDVD 7.0 Professional - '.plf' Local Buffer Overflow (SEH,ASLR,DEP)
2020-08-31
Online Book Store 1.0 - 'id' SQL Injection
2020-08-31
Eibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation
2020-08-28
SymphonyCMS 3.0.0 - Persistent Cross-Site Scripting
2020-08-28
Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting
2020-08-28
Online Shopping Alphaware 1.0 - 'id' SQL Injection
2020-08-28
Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
2020-08-27
ASX to MP3 converter 3.1.3.7.2010.11.05 - '.wax' Local Buffer Overflow (DEP,ASLR Bypass) (PoC)
2020-08-27
Mida eFramework 2.9.0 - Remote Code Execution
2020-08-27
Eibiz i-Media Server Digital Signage 3.8.0 - Directory Traversal
2020-08-26
Ericom Access Server x64 9.2.0 - Server-Side Request Forgery
2020-08-26
Eibiz i-Media Server Digital Signage 3.8.0 - Configuration Disclosure
2020-08-24
Eibiz i-Media Server Digital Signage 3.8.0 - Authentication Bypass
2020-08-24
LimeSurvey 4.3.10 - 'Survey Menu' Persistent Cross-Site Scripting
2020-08-24
Exploits/page:


Page:
1-4-2 (www01)