Exploits (Total: 96850)

    
    
    
Online Shopping Alphaware 1.0 - Authentication Bypass
2020-07-30
Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting
2020-07-29
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
2020-07-29
Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
2020-07-29
eGroupWare 1.14 - 'spellchecker.php' Remote Command Execution
2020-07-29
docPrint Pro 8.0 - 'Add URL' Buffer Overflow (SEH Egghunter)
2020-07-29
Windows/x86 - Download using mshta.exe Shellcode (100 bytes)
2020-07-29
Rails 5.0.1 - Remote Code Execution
2020-07-29
Virtual Airlines Manager 2.6.2 - Persistent Cross-Site Scripting
2020-07-29
pfSense 2.4.4-p3 - Cross-Site Request Forgery
2020-07-29
Socket.io-file 2.0.31 - Arbitrary File Upload
2020-07-29
Sickbeard 0.1 - Cross-Site Request Forgery (Disable Authentication)
2020-07-29
F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
2020-07-29
Webtareas 2.1p - Arbitrary File Upload (Authenticated)
2020-07-29
Bio Star 2.8.2 - Local File Inclusion
2020-07-29
PandoraFMS 7.0 NG 746 - Persistent Cross-Site Scripting
2020-07-29
Koken CMS 0.22.24 - Arbitrary File Upload (Authenticated)
2020-07-29
elaniin CMS - Authentication Bypass
2020-07-29
Online Course Registration 1.0 - Unauthenticated Remote Code Execution
2020-07-29
Linux/x86 - Egghunter(0x50905090) + sigaction + execve(/bin/sh) Shellcode (35 bytes)
2020-07-29
LibreHealth 2.0.0 - Authenticated Remote Code Execution
2020-07-29
Bludit 3.9.2 - Directory Traversal
2020-07-29
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injection (Unauthenticated)
2020-07-29
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File Download
2020-07-29
Calavera UpLoader 3.5 - 'FTP Logi' Denial of Service (PoC + SEH Overwrite)
2020-07-29
Free MP3 CD Ripper 2.8 - Stack Buffer Overflow (SEH + Egghunter)
2020-07-29
Port Forwarding Wizard 4.8.0 - Buffer Overflow (SEH)
2020-07-29
UBICOD Medivision Digital Signage 1.5.1 - Cross-Site Request Forgery (Add Admin)
2020-07-29
INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
2020-07-29
ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
2020-07-29
Socusoft Photo to Video Converter Professional 8.07 - 'Output Folder' Buffer Overflow (SEH Egghunter)
2020-07-29
GOautodial 4.0 - Persistent Cross-Site Scripting (Authenticated)
2020-07-29
DiskBoss 7.7.14 - 'Reports and Data Directory' Buffer Overflow (SEH Egghunter)
2020-07-29
Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)
2020-07-29
Nidesoft DVD Ripper 5.2.18 - Local Buffer Overflow (SEH)
2020-07-29
Snes9K 0.09z - 'Port Number' Buffer Overflow (SEH)
2020-07-29
FTPDummy 4.80 - Local Buffer Overflow (SEH)
2020-07-29
UBICOD Medivision Digital Signage 1.5.1 - Authorization Bypass
2020-07-29
Sophos VPN Web Panel 2020 - Denial of Service (Poc)
2020-07-29
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
2020-07-29
Docsify.js 4.11.4 - Reflective Cross-Site Scripting
2020-07-29
NetPCLinker 1.0.0.0 - Buffer Overflow (SEH Egghunter)
2020-07-29
CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
2020-07-29
Simple Startup Manager 1.17 - 'File' Local Buffer Overflow (PoC)
2020-07-29
Sonar Qube 8.3.1 - 'SonarQube Service' Unquoted Service Path
2020-07-29
Wing FTP Server 6.3.8 - Remote Code Execution (Authenticated)
2020-07-29
Infor Storefront B2B 1.0 - 'usr_name' SQL Injection
2020-07-29
Online Farm Management System 0.1.0 - Persistent Cross-Site Scripting
2020-07-29
Web Based Online Hotel Booking System 0.1.0 - Authentication Bypass
2020-07-29
Online Polling System 1.0 - Authentication Bypass
2020-07-29
Zyxel Armor X1 WAP6806 - Directory Traversal
2020-07-29
SuperMicro IPMI WebInterface 03.40 - Cross-Site Request Forgery (Add Admin)
2020-07-29
Linux/x86 - ASLR deactivation polymorphic Shellcode (124 bytes)
2020-07-29
TeamCity Agent XML-RPC 10.0 - Remote Code Execution
2020-07-29
Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 - Remote Code Execution (Metasploit)
2020-07-14
BSA Radar 1.6.7234.24750 - Local File Inclusion
2020-07-14
Park Ticketing Management System 1.0 - Authentication Bypass
2020-07-13
Park Ticketing Management System 1.0 - 'viewid' SQL Injection
2020-07-13
Aruba ClearPass Policy Manager 6.7.0 - Unauthenticated Remote Command Execution
2020-07-10
Barangay Management System 1.0 - Authentication Bypass
2020-07-10
HelloWeb 2.0 - Arbitrary File Download
2020-07-10
Savsoft Quiz 5 - Persistent Cross-Site Scripting
2020-07-09
FrootVPN 4.8 - 'frootvpn' Unquoted Service Path
2020-07-09
Wordpress Plugin Powie's WHOIS Domain Check 0.9.31 - Persistent Cross-Site Scripting
2020-07-09
PHP 7.4 FFI - 'disable_functions' Bypass
2020-07-09
BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
2020-07-08
SuperMicro IPMI 03.40 - Cross-Site Request Forgery (Add Admin)
2020-07-08
Microsoft Windows mshta.exe 2019 - XML External Entity Injection
2020-07-07
BSA Radar 1.6.7234.24750 - Authenticated Privilege Escalation
2020-07-07
Joomla! J2 JOBS 1.3.0 - 'sortby' Authenticated SQL Injection
2020-07-07
Online Shopping Portal 3.1 - 'email' SQL Injection
2020-07-07
Sickbeard 0.1 - Remote Command Injection
2020-07-07
Sony Playstation 2 (PS2): FreeDVDBoot - Hacking the PlayStation 2 through its DVD player
2020-07-07
Sony Playstation 4 (PS4) < 7.02 / FreeBSD 9 / FreeBSD 12 - 'ip6_setpktopt' Kernel Local Privilege Escalation (PoC)
2020-07-07
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI' Remote Code Execution (PoC)
2020-07-07
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI' Remote Code Execution
2020-07-07
Nagios XI 5.6.12 - 'export-rrd.php' Remote Code Execution
2020-07-06
RSA IG&L Aveksa 7.1.1 - Remote Code Execution
2020-07-06
Grafana 7.0.1 - Denial of Service (PoC)
2020-07-06
Fire Web Server 0.1 - Remote Denial of Service (PoC)
2020-07-06
RiteCMS 2.2.1 - Authenticated Remote Code Execution
2020-07-06
File Management System 1.1 - Persistent Cross-Site Scripting
2020-07-06
OCS Inventory NG 2.7 - Remote Code Execution
2020-07-02
ZenTao Pro 8.8.2 - Command Injection
2020-07-02
Online Shopping Portal 3.1 - Authentication Bypass
2020-07-01
PHP-Fusion 9.03.60 - PHP Object Injection
2020-07-01
e-learning Php Script 0.1.0 - 'search' SQL Injection
2020-07-01
RM Downloader 2.50.60 2006.06.23 - 'Load' Local Buffer Overflow (EggHunter) (SEH) (PoC)
2020-07-01
Reside Property Management 3.0 - 'profile' SQL Injection
2020-06-30
Victor CMS 1.0 - 'user_firstname' Persistent Cross-Site Scripting
2020-06-30
KiteService 1.2020.618.0 - Unquoted Service Path
2020-06-28
Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
2020-06-28
OpenEMR 5.0.1 - 'controller' Remote Code Execution
2020-06-28
FHEM 6.0 - Local File Inclusion
2020-06-28
mySCADA myPRO 7 - Hardcoded Credentials
2020-06-28
BSA Radar 1.6.7234.24750 - Persistent Cross-Site Scripting
2020-06-28
Lansweeper 7.2 - Incorrect Access Control
2020-06-28
Code Blocks 20.03 - Denial Of Service (PoC)
2020-06-28
Online Student Enrollment System 1.0 - Cross-Site Request Forgery (Add Student)
2020-06-28
Responsive Online Blog 1.0 - 'id' SQL Injection
2020-06-28
Frigate 2.02 - Denial Of Service (PoC)
2020-06-28
WebPort 1.19.1 - 'setup' Reflected Cross-Site Scripting
2020-06-28
WebPort 1.19.1 - Reflected Cross-Site Scripting
2020-06-28
Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload
2020-06-28
Odoo 12.0 - Local File Inclusion
2020-06-28
Student Enrollment 1.0 - Unauthenticated Remote Code Execution
2020-06-28
FileRun 2019.05.21 - Reflected Cross-Site Scripting
2020-06-28
Beauty Parlour Management System 1.0 - Authentication Bypass
2020-06-28
OpenCTI 3.3.1 - Directory Traversal
2020-06-28
Code Blocks 17.12 - 'File Name' Local Buffer Overflow (Unicode) (SEH) (PoC)
2020-06-28
College-Management-System-Php 1.0 - Authentication Bypass
2020-06-28
Bandwidth Monitor 3.9 - 'Svc10StrikeBandMontitor' Unquoted Service Path
2020-06-28
Gila CMS 1.11.8 - 'query' SQL Injection
2020-06-28
Netgear R7000 Router - Remote Code Execution
2020-06-28
SOS JobScheduler 1.13.3 - Stored Password Decryption
2020-06-28
Linux/ARM - Bind (0.0.0.0:1337/TCP) Shell (/bin/sh) + Null-Free Shellcode (100 bytes)
2020-06-28
Linux/ARM - execve /bin/dash Shellcode (32 bytes)
2020-06-28
Sysax MultiServer 6.90 - Reflected Cross Site Scripting
2020-06-28
Avaya IP Office 11 - Password Disclosure
2020-06-28
SmarterMail 16 - Arbitrary File Upload
2020-06-28
Frigate Professional 3.36.0.9 - 'Find Computer' Local Buffer Overflow (SEH) (PoC)
2020-06-28
Virtual Airlines Manager 2.6.2 - 'id' SQL Injection
2020-06-28
WinGate 9.4.1.5998 - Insecure Folder Permissions
2020-06-28
Joomla! J2 Store 3.3.11 - 'filter_order_Dir' Authenticated SQL Injection
2020-06-28
Sistem Informasi Pengumuman Kelulusan Online 1.0 - Cross-Site Request Forgery (Add Admin)
2020-06-28
10-Strike Bandwidth Monitor 3.9 - Buffer Overflow (SEH,DEP,ASLR)
2020-06-28
HFS Http File Server 2.3m Build 300 - Buffer Overflow (PoC)
2020-06-28
Library CMS Powerful Book Management System 2.2.0 - Session Fixation
2020-06-28
WordPress Plugin Simple File List 5.4 - Remote Code Execution
2020-06-28
Prestashop 1.7.6.4 - Cross-Site Request Forgery
2020-06-28
WordPress Plugin Helpful 2.4.11 - SQL Injection
2020-06-28
PHP-Fusion 9.03.50 - 'panels.php' Remote Code Execution
2020-06-28
Wordpress Plugin PicUploader 1.0 - Remote File Upload
2020-06-28
Joomla! Component ACYMAILING 3.9.0 - Unauthenticated Arbitrary File Upload
2020-06-28
UADMIN Botnet 1.0 - 'link' SQL Injection
2020-06-28
WordPress Plugin Custom Searchable Data System - Unauthenticated Data M]odification
2020-06-28
Wing FTP Server - Authenticated CSRF (Delete Admin)
2020-06-28
PlaySMS 1.4.3 - Template Injection / Remote Code Execution
2020-06-28
Joomla! 3.9.0 < 3.9.7 - CSV Injection
2020-06-28
CTROMS Terminal OS Port Portal - 'Password Reset' Authentication Bypass (Metasploit)
2020-06-28
CoreFTP 2.0 Build 674 MDTM - Directory Traversal (Metasploit)
2020-06-28
CoreFTP 2.0 Build 674 SIZE - Directory Traversal (Metasploit)
2020-06-28
WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting
2020-06-28
WordPress Plugin WOOF Products Filter for WooCommerce 1.2.3 - Persistent Cross-Site Scripting
2020-06-28
WordPress Plugin ultimate-member 2.1.3 - Local File Inclusion
2020-06-28
WordPress Plugin contact-form-7 5.1.6 - Remote File Upload
2020-06-28
WordPress Plugin Wordfence.7.4.5 - Local File Disclosure
2020-06-28
WordPress Plugin tutor.1.5.3 - Persistent Cross-Site Scripting
2020-06-28
WordPress Plugin Tutor.1.5.3 - Local File Inclusion
2020-06-28
Microsoft Windows Media Center WMV / WMA 6.3.9600.16384 - Code Execution
2020-06-28
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
2020-06-28
SpotDialup 1.6.7 - 'Key' Denial of Service (PoC)
2020-06-28
SpotFTP FTP Password Recovery 3.0.0.0 - 'Key' Denial of Service (PoC)
2020-06-28
XnConvert 1.82 - Denial of Service (PoC)
2020-06-28
SurfOffline Professional 2.2.0.103 - 'Project Name' Denial of Service (SEH)
2020-06-28
DeviceViewer 3.12.0.1 - Arbitrary Password Change
2020-06-28
DotNetNuke 9.3.2 - Cross-Site Scripting
2020-06-28
WordPress Plugin ARforms 3.7.1 - Arbitrary File Deletion
2020-06-28
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
2020-06-28
InputMapper 1.6.10 - Denial of Service
2020-06-28
SpotIE Internet Explorer Password Recovery 2.9.5 - 'Key' Denial of Service
2020-06-28
Notepad++ < 7.7 (x64) - Denial of Service
2020-06-28
NetGain EM Plus 10.1.68 - Remote Command Execution
2020-06-28
Publisure Hybrid - Multiple Vulnerabilities
2020-06-28
Wolters Kluwer TeamMate 3.1 - Cross-Site Request Forgery
2020-06-28
Webmin < 1.920 - 'rpc.cgi' Remote Code Execution (Metasploit)
2020-06-28
Nagios XI 5.6.5 - Remote Code Execution / Root Privilege Escalation
2020-06-28
MyBB < 1.8.21 - Remote Code Execution
2020-06-28
Android 7 < 9 - Remote Code Execution
2020-06-28
Siemens TIA Portal - Remote Command Execution
2020-06-28
FreeBSD 12.0 - 'fd' Local Privilege Escalation
2020-06-28
Bludit 3.9.12 - Directory Traversal
2020-06-09
Virtual Airlines Manager 2.6.2 - 'airport' SQL Injection
2020-06-09
Quick Player 1.3 - '.m3l' Buffer Overflow (Unicode & SEH)
2020-06-08
Frigate 3.36.0.9 - 'Command Line' Local Buffer Overflow (SEH) (PoC)
2020-06-08
Virtual Airlines Manager 2.6.2 - 'notam' SQL Injection
2020-06-08
Kyocera Printer d-COPIA253MF - Directory Traversal (PoC)
2020-06-08
Online-Exam-System 2015 - 'feedback' SQL Injection
2020-06-05
Online Course Registration 1.0 - Authentication Bypass
2020-06-05
Cayin Digital Signage System xPost 2.5 - Remote Command Injection
2020-06-04
Cayin Signage Media Player 3.0 - Remote Command Injection (root)
2020-06-04
Secure Computing SnapGear Management Console SG560 3.1.5 - Arbitrary File Read
2020-06-04
SnapGear Management Console SG560 3.1.5 - Cross-Site Request Forgery (Add Super User)
2020-06-04
Cayin Content Management Server 11.0 - Remote Command Injection (root)
2020-06-04
Online Marriage Registration System 1.0 - Remote Code Execution
2020-06-04
D-Link DIR-615 T1 20.10 - CAPTCHA Bypass
2020-06-04
Navigate CMS 2.8.7 - Authenticated Directory Traversal
2020-06-04
VMWAre vCloud Director 9.7.0.15498291 - Remote Code Execution
2020-06-04
Navigate CMS 2.8.7 - Cross-Site Request Forgery (Add Admin)
2020-06-04
Clinic Management System 1.0 - Authenticated Arbitrary File Upload
2020-06-04
Oriol Espinal CMS 1.0 - 'id' SQL Injection
2020-06-04
Navigate CMS 2.8.7 - ''sidx' SQL Injection (Authenticated)
2020-06-04
Clinic Management System 1.0 - Unauthenticated Remote Code Execution
2020-06-04
IObit Uninstaller 9.5.0.15 - 'IObit Uninstaller Service' Unquoted Service Path
2020-06-04
Hostel Management System 2.0 - 'id' SQL Injection (Unauthenticated)
2020-06-04
AirControl 1.4.2 - PreAuth Remote Code Execution
2020-06-04
vCloud Director 9.7.0.15498291 - Remote Code Execution
2020-06-03
OpenCart 3.0.3.2 - Stored Cross Site Scripting (Authenticated)
2020-06-02
Clinic Management System 1.0 - Authentication Bypass
2020-06-02
Microsoft Windows - 'SMBGhost' Remote Code Execution
2020-06-02
QuickBox Pro 2.1.8 - Authenticated Remote Code Execution
2020-06-01
VMware vCenter Server 6.7 - Authentication Bypass
2020-06-01
Wordpress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
2020-06-01
Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass
2020-05-29
WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete User)
2020-05-29
QNAP QTS and Photo Station 6.0.3 - Remote Command Execution
2020-05-28
EyouCMS 1.4.6 - Persistent Cross-Site Scripting
2020-05-28
Online-Exam-System 2015 - 'fid' SQL Injection
2020-05-28
NOKIA VitalSuite SPM 2020 - 'UserName' SQL Injection
2020-05-28
OXID eShop 6.3.4 - 'sorting' SQL Injection
2020-05-27
Kuicms PHP EE 2.0 - Persistent Cross-Site Scripting
2020-05-27
osTicket 1.14.1 - 'Saved Search' Persistent Cross-Site Scripting
2020-05-27
osTicket 1.14.1 - 'Ticket Queue' Persistent Cross-Site Scripting
2020-05-27
LimeSurvey 4.1.11 - 'Permission Roles' Persistent Cross-Site Scripting
2020-05-27
Online Marriage Registration System 1.0 - Persistent Cross-Site Scripting
2020-05-27
BIND - 'TSIG' Denial of Service
2020-05-27
WordPress Plugin Drag and Drop File Upload Contact Form 1.3.3.2 - Remote Code Execution
2020-05-26
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
2020-05-26
Joomla! Plugin XCloner Backup 3.5.3 - Local File Inclusion (Authenticated)
2020-05-26
StreamRipper32 2.6 - Buffer Overflow (PoC)
2020-05-26
Open-AudIT 3.3.0 - Reflective Cross-Site Scripting (Authenticated)
2020-05-26
OpenEMR 5.0.1 - Remote Code Execution
2020-05-26
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
2020-05-25
Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
2020-05-25
Online Discussion Forum Site 1.0 - Remote Code Execution
2020-05-25
Victor CMS 1.0 - 'add_user' Persistent Cross-Site Scripting
2020-05-25
GoldWave - Buffer Overflow (SEH Unicode)
2020-05-25
Wordpress Plugin Form Maker 5.4.1 - 's' SQL Injection (Authenticated)
2020-05-25
WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
2020-05-23
VUPlayer 2.49 .m3u - Local Buffer Overflow (DEP,ASLR)
2020-05-23
Gym Management System 1.0 - Unauthenticated Remote Code Execution
2020-05-23
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation
2020-05-23
Dolibarr 11.0.3 - Persistent Cross-Site Scripting
2020-05-23
Filetto 1.0 - 'FEAT' Denial of Service (PoC)
2020-05-23
Konica Minolta FTP Utility 1.0 - 'NLST' Denial of Service (PoC)
2020-05-23
Konica Minolta FTP Utility 1.0 - 'LIST' Denial of Service (PoC)
2020-05-23
OpenEDX platform Ironwood 2.5 - Remote Code Execution
2020-05-23
CloudMe 1.11.2 - Buffer Overflow (SEH,DEP,ASLR)
2020-05-23
PHPFusion 9.03.50 - Persistent Cross-Site Scripting
2020-05-23
Composr CMS 10.0.30 - Persistent Cross-Site Scripting
2020-05-23
forma.lms 5.6.40 - Cross-Site Request Forgery (Change Admin Email)
2020-05-23
AbsoluteTelnet 11.21 - 'Username' Denial of Service (PoC)
2020-05-23
CraftCMS 3 vCard Plugin 1.0.0 - Remote Code Execution
2020-05-23
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
2020-05-23
Victor CMS 1.0 - Authenticated Arbitrary File Upload
2020-05-23
NukeViet VMS 4.4.00 - Cross-Site Request Forgery (Change Admin Password)
2020-05-23
Submitty 20.04.01 - Persistent Cross-Site Scripting
2020-05-23
php-fusion 9.03.50 - 'ctype' SQL Injection
2020-05-23
qdPM 9.1 - 'cfg[app_app_name]' Persistent Cross-Site Scripting
2020-05-23
Victor CMS 1.0 - 'cat_id' SQL Injection
2020-05-23
Victor CMS 1.0 - 'comment_author' Persistent Cross-Site Scripting
2020-05-23
HP LinuxKI 6.01 - Remote Command Injection
2020-05-23
Online Healthcare management system 1.0 - Authentication Bypass
2020-05-23
Online Healthcare Patient Record Management System 1.0 - Authentication Bypass
2020-05-23
online Chatting System 1.0 - 'id' SQL Injection
2020-05-23
Monstra CMS 3.0.4 - Authenticated Arbitrary File Upload
2020-05-23
forma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site Scripting
2020-05-23
Oracle Hospitality RES 3700 5.7 - Remote Code Execution
2020-05-23
Online Examination System 1.0 - 'eid' SQL Injection
2020-05-23
Wordpress Plugin Ajax Load More 5.3.1 - '#1' Authenticated SQL Injection
2020-05-23
Mikrotik Router Monitoring System 1.2.3 - 'community' SQL Injection
2020-05-23
ManageEngine Service Desk 10.0 - Cross-Site Scripting
2020-05-23
vBulletin 5.6.1 - 'nodeId' SQL Injection
2020-05-23
E-Commerce System 1.0 - Unauthenticated Remote Code Execution
2020-05-23
Netlink XPON 1GE WiFi V2801RGW - Remote Command Execution
2020-05-23
Dameware Remote Support 12.1.1.273 - Buffer Overflow (SEH)
2020-05-23
Complaint Management System 1.0 - 'username' SQL Injection
2020-05-23
Sellacious eCommerce 4.6 - Persistent Cross-Site Scripting
2020-05-13
Tryton 5.4 - Persistent Cross-Site Scripting
2020-05-13
Remote Desktop Audit 2.3.0.157 - Buffer Overflow (SEH)
2020-05-13
MacOS 320.whatis Script - Privilege Escalation
2020-05-12
TylerTech Eagle 2018.3.11 - Remote Code Execution
2020-05-12
LanSend 3.2 - Buffer Overflow (SEH)
2020-05-12
qdPM 9.1 - Arbitrary File Upload
2020-05-12
Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site Scripting
2020-05-12
CuteNews 2.1.2 - Authenticated Arbitrary File Upload
2020-05-12
ChopSlider3 Wordpress Plugin3.4 - 'id' SQL Injection
2020-05-12
Orchard Core RC1 - Persistent Cross-Site Scripting
2020-05-12
Phase Botnet - Blind SQL Injection
2020-05-12
LibreNMS 1.46 - 'search' SQL Injection
2020-05-11
Complaint Management System 1.0 - Authentication Bypass
2020-05-11
Victor CMS 1.0 - 'post' SQL Injection
2020-05-11
OpenZ ERP 3.6.60 - Persistent Cross-Site Scripting
2020-05-11
SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
2020-05-11
CuteNews 2.1.2 - Arbitrary File Deletion
2020-05-11
Sentrifugo CMS 3.2 - Persistent Cross-Site Scripting
2020-05-11
Kartris 1.6 - Arbitrary File Upload
2020-05-11
Online AgroCulture Farm Management System 1.0 - 'uname' SQL Injection
2020-05-11
Pi-hole < 4.4 - Remote Code Execution / Privileges Escalation
2020-05-11
Pi-hole < 4.4 - Remote Code Execution
2020-05-11
Extreme Networks Aerohive HiveOS 11.0 - Remote Denial of Service (PoC)
2020-05-08
Online AgroCulture Farm Management System 1.0 - 'pid' SQL Injection
2020-05-07
Pisay Online E-Learning System 1.0 - Remote Code Execution
2020-05-07
Online Clothing Store 1.0 - Arbitrary File Upload
2020-05-07
School File Management System 1.0 - 'username' SQL Injection
2020-05-07
Draytek VigorAP 1000C - Persistent Cross-Site Scripting
2020-05-07
Car Park Management System 1.0 - Authentication Bypass
2020-05-07
FlashGet 1.9.6 - Denial of Service (PoC)
2020-05-07
MPC Sharj 3.11.1 - Arbitrary File Download
2020-05-06
YesWiki cercopitheque 2020.04.18.1 - 'id' SQL Injection
2020-05-06
GitLab 12.9.0 - Arbitrary File Read
2020-05-06
webTareas 2.0.p8 - Arbitrary File Deletion
2020-05-06
Online Clothing Store 1.0 - 'username' SQL Injection
2020-05-06
Booked Scheduler 2.7.7 - Authenticated Directory Traversal
2020-05-06
i-doit Open Source CMDB 1.14.1 - Arbitrary File Deletion
2020-05-06
Online Clothing Store 1.0 - Persistent Cross-Site Scripting
2020-05-06
NEC Electra Elite IPK II WebPro 01.03.01 - Session Enumeration
2020-05-05
SimplePHPGal 0.7 - Remote File Inclusion
2020-05-05
PhreeBooks ERP 5.2.5 - Remote Command Execution
2020-05-05
BlogEngine 3.3 - 'syndication.axd' XML External Entity Injection
2020-05-05
Saltstack 3000.2 - Remote Code Execution
2020-05-05
webERP 4.15.1 - Unauthenticated Backup File Access
2020-05-05
Online Scheduling System 1.0 - 'username' SQL Injection
2020-05-05
Oracle Database 11g Release 2 - 'OracleDBConsoleorcl' Unquoted Service Path
2020-05-05
Fishing Reservation System 7.5 - 'uid' SQL Injection
2020-05-05
addressbook 9.0.0.1 - 'id' SQL Injection
2020-05-04
Frigate 3.36 - Buffer Overflow (SEH)
2020-05-04
Outline Service 1.3.3 - 'Outline Service ' Unquoted Service Path
2020-05-04
osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting
2020-05-04
BoltWire 6.03 - Local File Inclusion
2020-05-04
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
2020-05-01
Online Scheduling System 1.0 - Authentication Bypass
2020-05-01
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
2020-05-01
HardDrive 2.1 for iOS - Arbitrary File Upload
2020-05-01
Super Backup 2.0.5 for iOS - Directory Traversal
2020-05-01
php-fusion 9.03.50 - Persistent Cross-Site Scripting
2020-05-01
Online Scheduling System 1.0 - Persistent Cross-Site Scripting
2020-05-01
VirtualTablet Server 3.0.2 - Denial of Service (PoC)
2020-05-01
ChemInv 1.0 - Authenticated Persistent Cross-Site Scripting
2020-05-01
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
2020-04-29
hits script 1.0 - 'item_name' SQL Injection
2020-04-29
EmEditor 19.8 - Insecure File Permissions
2020-04-29
Internet Download Manager 6.37.11.1 - Stack Buffer Overflow (PoC)
2020-04-29
Andrea ST Filters Service 1.0.64.7 - 'Andrea ST Filters Service ' Unquoted Service Path
2020-04-29
Easy Transfer 1.7 for iOS - Directory Traversal
2020-04-29
School ERP Pro 1.0 - Arbitrary File Read
2020-04-29
Open-AudIT Professional 3.3.1 - Remote Code Execution
2020-04-29
School ERP Pro 1.0 - Remote Code Execution
2020-04-29
NVIDIA Update Service Daemon 1.0.21 - 'nvUpdatusService' Unquoted Service Path
2020-04-29
School ERP Pro 1.0 - 'es_messagesid' SQL Injection
2020-04-29
CloudMe 1.11.2 - Buffer Overflow (PoC)
2020-04-29
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
2020-04-29
Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
2020-04-29
Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
2020-04-29
Online Course Registration 2.0 - Authentication Bypass
2020-04-29
Netis E1+ V1.2.32533 - Unauthenticated WiFi Password Leak
2020-04-29
Online shopping system advanced 1.0 - 'p' SQL Injection
2020-04-29
Netis E1+ 1.2.32533 - Backdoor Account (root)
2020-04-29
PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
2020-04-29
Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
2020-04-29
Linux/x64 - Password Protected Bindshell + Null-free Shellcode (272 Bytes)
2020-04-29
Popcorn Time 6.2 - 'Update service' Unquoted Service Path
2020-04-29
Edimax EW-7438RPn 1.13 - Remote Code Execution
2020-04-29
EspoCRM 5.8.5 - Privilege Escalation
2020-04-29
Sky File 2.1.0 iOS - Directory Traversal
2020-04-29
Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)
2020-04-23
Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
2020-04-23
Complaint Management System 4.2 - Authentication Bypass
2020-04-23
Complaint Management System 4.2 - Persistent Cross-Site Scripting
2020-04-23
User Management System 2.0 - Authentication Bypass
2020-04-23
User Management System 2.0 - Persistent Cross-Site Scripting
2020-04-23
Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
2020-04-22
Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)
2020-04-22
Edimax EW-7438RPn - Information Disclosure (WiFi Password)
2020-04-22
RM Downloader 3.1.3.2.2010.06.13 - 'Load' Buffer Overflow (SEH)
2020-04-22
Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
2020-04-21
P5 FNIP-8x16A FNIP-4xSH 1.0.20 - Cross-Site Request Forgery (Add Admin)
2020-04-21
jizhi CMS 1.6.7 - Arbitrary File Download
2020-04-21
NSClient++ 0.5.2.35 - Authenticated Remote Code Execution
2020-04-21
Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
2020-04-21
IQrouter 3.3.1 Firmware - Remote Code Execution
2020-04-21
CSZ CMS 1.2.7 - 'title' HTML Injection
2020-04-21
PMB 5.6 - 'logid' SQL Injection
2020-04-21
Windows/x86 - MSVCRT System + Dynamic Null-free + Add RDP Admin + Disable Firewall + Enable RDP Shellcode (644 Bytes)
2020-04-21
CSZ CMS 1.2.7 - Persistent Cross-Site Scripting
2020-04-21
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
2020-04-20
Atomic Alarm Clock x86 6.3 - 'AtomicAlarmClock' Unquoted Service Path
2020-04-20
Rubo DICOM Viewer 2.0 - Buffer Overflow (SEH)
2020-04-20
Nsauditor 3.2.1.0 - Buffer Overflow (SEH+ASLR bypass (3 bytes overwrite))
2020-04-20
Fork CMS 5.8.0 - Persistent Cross-Site Scripting
2020-04-20
Atomic Alarm Clock 6.3 - Stack Overflow (Unicode+SEH)
2020-04-20
Centreon 19.10.5 - 'id' SQL Injection
2020-04-20
Code Blocks 16.01 - Buffer Overflow (SEH) UNICODE
2020-04-18
Nexus Repository Manager - Java EL Injection RCE (Metasploit)
2020-04-18
Cisco IP Phone 11.7 - Denial of service (PoC)
2020-04-18
TAO Open Source Assessment Platform 3.3.0 RC02 - HTML Injection
2020-04-18
Playable 9.18 iOS - Persistent Cross-Site Scripting
2020-04-18
Easy MPEG to DVD Burner 1.7.11 - Buffer Overflow (SEH + DEP)
2020-04-18
Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
2020-04-18
VMware Fusion - USB Arbitrator Setuid Privilege Escalation (Metasploit)
2020-04-18
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
2020-04-18
PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metasploit)
2020-04-18
Pandora FMS - Ping Authenticated Remote Code Execution (Metasploit)
2020-04-18
ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
2020-04-18
Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
2020-04-18
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
2020-04-18
BlazeDVD 7.0.2 - Buffer Overflow (SEH)
2020-04-15
Xeroneit Library Management System 3.0 - 'category' SQL Injection
2020-04-15
File Transfer iFamily 2.1 - Directory Traversal
2020-04-15
DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting
2020-04-15
Macs Framework 1.14f CMS - Persistent Cross-Site Scripting
2020-04-15
SeedDMS 5.1.18 - Persistent Cross-Site Scripting
2020-04-15
Pinger 1.0 - Remote Code Execution
2020-04-15
SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting
2020-04-15
AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting
2020-04-15
Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
2020-04-14
WSO2 3.1.0 - Persistent Cross-Site Scripting
2020-04-14
Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
2020-04-14
B64dec 1.1.2 - Buffer Overflow (SEH Overflow + Egg Hunter)
2020-04-14
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
2020-04-13
Wordpress Plugin Media Library Assistant 2.81 - Local File Inclusion
2020-04-13
Free Desktop Clock x86 Venetian Blinds Zipper 3.0 - Unicode Stack Overflow (SEH)
2020-04-13
WSO2 3.1.0 - Arbitrary File Delete
2020-04-13
Webtateas 2.0 - Arbitrary File Read
2020-04-13
TVT NVMS 1000 - Directory Traversal
2020-04-13
Huawei HG630 2 Router - Authentication Bypass
2020-04-13
Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal
2020-04-10
Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
2020-04-10
AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)
2020-04-10
Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)
2020-04-08
Django 3.0 - Cross-Site Request Forgery Token Bypass
2020-04-08
dnsmasq-utils 2.79-1 - 'dhcp_release' Denial of Service (PoC)
2020-04-07
ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)
2020-04-07
pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
2020-04-06
Microsoft NET USE win10 - Insufficient Authentication Logic
2020-04-06
LimeSurvey 4.1.11 - 'File Manager' Path Traversal
2020-04-06
Bolt CMS 3.7.0 - Authenticated Remote Code Execution
2020-04-06
WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
2020-04-06
Vesta Control Panel 0.9.8-26 - Authenticated Remote Code Execution (Metasploit)
2020-04-06
Triologic Media Player 8 - '.m3l' Buffer Overflow (Unicode) (SEH)
2020-04-06
ZOC Terminal v7.25.5 - 'Private key file' Denial of Service (PoC)
2020-04-06
UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service (PoC)
2020-04-06
UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service (PoC)
2020-04-06
LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
2020-04-06
UltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service (PoC)
2020-04-06
Frigate 3.36 - Denial of Service (PoC)
2020-04-06
Nsauditor 3.2.0.0 - 'Name' Denial of Service (PoC)
2020-04-06
SpotAuditor 5.3.4 - 'Name' Denial of Service (PoC)
2020-04-06
Product Key Explorer 4.2.2.0 - 'Key' Denial of Service (PoC)
2020-04-06
Memu Play 7.1.3 - Insecure Folder Permissions
2020-04-06
AIDA64 Engineer 6.20.5300 - 'Report File' filename Buffer Overflow (SEH)
2020-04-03
Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution
2020-04-03
DiskBoss 7.7.14 - 'Input Directory' Local Buffer Overflow (PoC)
2020-04-02
10Strike LANState 9.32 - 'Force Check' Buffer Overflow (SEH)
2020-04-01
DiskBoss 7.7.14 - Denial of Service (PoC)
2020-04-01
SharePoint Workflows - XOML Injection (Metasploit)
2020-03-31
DLINK DWL-2600 - Authenticated Remote Command Injection (Metasploit)
2020-03-31
IBM TM1 / Planning Analytics - Unauthenticated Remote Code Execution (Metasploit)
2020-03-31
Redis - Replication Code Execution (Metasploit)
2020-03-31
Grandstream UCM6200 Series WebSocket 1.0.20.20 - 'user_password' SQL Injection
2020-03-31
Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection
2020-03-31
FlashFXP 4.2.0 Build 1730 - Denial of Service (PoC)
2020-03-31
Multiple DrayTek Products - Pre-authentication Remote Root Code Execution
2020-03-30
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation
2020-03-30
Zen Load Balancer 3.10.1 - Remote Code Execution
2020-03-30
10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow (SEH)(ROP)
2020-03-30
Joomla! com_fabrik 3.9.11 - Directory Traversal
2020-03-30
Odin Secure FTP Expert 7.6.3 - 'Site Info' Denial of Service (PoC)
2020-03-30
rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
2020-03-27
Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal
2020-03-27
Everest 5.50.2100 - 'Open File' Denial of Service (PoC)
2020-03-27
ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
2020-03-27
Easy RM to MP3 Converter 2.7.3.700 - 'Input' Local Buffer Overflow (SEH)
2020-03-27
Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
2020-03-26
TP-Link Archer C50 3 - Denial of Service (PoC)
2020-03-26
10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)
2020-03-25
Windows/x64 - WinExec Add-Admin Dynamic Null-Free Shellcode (210 Bytes)
2020-03-25
10-Strike Network Inventory Explorer - 'srvInventoryWebServer' Unquoted Service Path
2020-03-25
LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
2020-03-25
AVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service Path
2020-03-25
Joomla! Component GMapFP 3.30 - Arbitrary File Upload
2020-03-25
UCM6202 1.0.18.13 - Remote Command Injection
2020-03-24
Veyon 4.3.4 - 'VeyonService' Unquoted Service Path
2020-03-24
Wordpress Plugin WPForms 1.5.9 - Persistent Cross-Site Scripting
2020-03-24
UliCMS 2020.1 - Persistent Cross-Site Scripting
2020-03-24
Linux\x86 - 'reboot' polymorphic Shellcode (26 bytes)
2020-03-23
Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
2020-03-23
rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
2020-03-23
FIBARO System Home Center 5.021 - Remote File Include
2020-03-23
CyberArk PSMP 10.9.1 - Policy Restriction Bypass
2020-03-23
Google Chrome 80.0.3987.87 - Heap-Corruption Remote Denial of Service (PoC)
2020-03-23
ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service (PoC)
2020-03-23
VMware Fusion 11.5.2 - Privilege Escalation
2020-03-20
Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
2020-03-20
Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
2020-03-19
VMWare Fusion - Local Privilege Escalation
2020-03-18
Microsoft VSCode Python Extension - Code Execution
2020-03-18
Windows\x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
2020-03-18
Microtik SSH Daemon 6.44.3 - Denial of Service (PoC)
2020-03-18
NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path
2020-03-18
Netlink GPON Router 1.0.11 - Remote Code Execution
2020-03-18
ManageEngine Desktop Central - Java Deserialization (Metasploit)
2020-03-17
Rconfig 3.x - Chained Remote Code Execution (Metasploit)
2020-03-17
PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution
2020-03-16
PHPKB Multi-Language 9 - Authenticated Directory Traversal
2020-03-16
PHPKB Multi-Language 9 - Authenticated Remote Code Execution
2020-03-16
MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
2020-03-16
Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin)
2020-03-16
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)
2020-03-14
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
2020-03-14
Drobo 5N2 4.1.1 - Remote Command Injection
2020-03-13
Centos WebPanel 7 - 'term' SQL Injection
2020-03-13
AnyBurn 4.8 - Buffer Overflow (SEH)
2020-03-13
Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
2020-03-12
Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
2020-03-12
rConfig 3.9 - 'searchColumn' SQL Injection
2020-03-12
rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
2020-03-12
ASUS AAHM 1.00.22 - 'asHmComSvc' Unquoted Service Path
2020-03-12
HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
2020-03-12
Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
2020-03-12
WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
2020-03-12
Joomla! Component com_newsfeeds 1.0 - 'feedid' SQL Injection
2020-03-12
Wordpress Plugin Search Meter 2.13.2 - CSV injection
2020-03-11
ASUS AXSP 1.02.00 - 'asComSvc' Unquoted Service Path
2020-03-11
PHPStudy - Backdoor Remote Code execution (Metasploit)
2020-03-11
Nagios XI - Authenticated Remote Command Execution (Metasploit)
2020-03-11
Persian VIP Download Script 1.0 - 'active' SQL Injection
2020-03-11
YzmCMS 5.5 - 'url' Persistent Cross-Site Scripting
2020-03-11
Sysaid 20.1.11 b26 - Remote Command Execution
2020-03-11
Counter Strike: GO - '.bsp' Memory Control (PoC)
2020-03-11
Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)
2020-03-11
OpenSMTPD - OOB Read Local Privilege Escalation (Metasploit)
2020-03-11
Google Chrome 67, 68 and 69 - Object.create Type Confusion (Metasploit)
2020-03-11
Google Chrome 72 and 73 - Array.map Out-of-Bounds Write (Metasploit)
2020-03-11
PHP-FPM - Underflow Remote Code Execution (Metasploit)
2020-03-11
Apache ActiveMQ 5.x-5.11.1 - Directory Traversal Shell Upload (Metasploit)
2020-03-11
Microsoft Windows - 'WizardOpium' Local Privilege Escalation
2020-03-11
Sentrifugo HRMS 3.2 - 'id' SQL Injection
2020-03-11
60CycleCMS - 'news.php' SQL Injection
2020-03-11
ManageEngine Desktop Central - 'FileStorage getChartImage' Deserialization / Unauthenticated Remote Code Execution
2020-03-11
Deep Instinct Windows Agent 1.2.29.0 - 'DeepMgmtService' Unquoted Service Path
2020-03-11
ASUS GiftBox Desktop 1.1.1.127 - 'ASUSGiftBoxDesktop' Unquoted Service Path
2020-03-11
SpyHunter 4 - 'SpyHunter 4 Service' Unquoted Service Path
2020-03-11
Iskysoft Application Framework Service 2.4.3.241 - 'IsAppService' Unquoted Service Path
2020-03-11
netkit-telnet-0.17 telnetd (Fedora 31) - 'BraveStarr' Remote Code Execution
2020-03-11
EyesOfNetwork - AutoDiscovery Target Command Execution (Metasploit)
2020-03-11
Exchange Control Panel - Viewstate Deserialization (Metasploit)
2020-03-11
UniSharp Laravel File Manager 2.0.0 - Arbitrary File Read
2020-03-11
RICOH Aficio SP 5210SF Printer - 'entryNameIn' HTML Injection
2020-03-04
GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
2020-03-04
Alfresco 5.2.4 - Persistent Cross-Site Scripting
2020-03-04
RICOH Aficio SP 5200S Printer - 'entryNameIn' HTML Injection
2020-03-04
Wing FTP Server 6.2.3 - Privilege Escalation
2020-03-02
Cacti v1.2.8 - Unauthenticated Remote Code Execution (Metasploit)
2020-03-02
Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
2020-03-02
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
2020-03-02
TP LINK TL-WR849N - Remote Code Execution
2020-03-02
Wing FTP Server 6.2.5 - Privilege Escalation
2020-03-02
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
2020-03-02
TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
2020-03-02
Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
2020-03-02
Netis WF2419 2.2.36123 - Remote Code Execution
2020-03-02
Cyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH)
2020-03-02
Joplin Desktop 1.0.184 - Cross-Site Scripting
2020-03-02
qdPM < 9.1 - Remote Code Execution
2020-02-28
Cacti 1.2.8 - Unauthenticated Remote Code Execution
2020-02-27
Cacti 1.2.8 - Authenticated Remote Code Execution
2020-02-27
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
2020-02-27
Comtrend VR-3033 - Command Injection
2020-02-27
Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin)
2020-02-27
OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
2020-02-26
OpenSMTPD 6.6.3 - Arbitrary File Read
2020-02-26
PhpIX 2012 Professional - 'id' SQL Injection
2020-02-26
Core FTP LE 2.2 - Denial of Service (PoC)
2020-02-26
GUnet OpenEclass E-learning platform 1.7.3 - 'uname' SQL Injection
2020-02-26
Odin Secure FTP Expert 7.6.3 - Denial of Service (PoC)
2020-02-25
Magento WooCommerce CardGate Payment Gateway 2.0.30 - Payment Process Bypass
2020-02-25
WordPress Plugin WooCommerce CardGate Payment Gateway 3.1.15 - Payment Process Bypass
2020-02-25
aSc TimeTables 2020.11.4 - Denial of Service (PoC)
2020-02-25
SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
2020-02-25
Diamorphine Rootkit - Signal Privilege Escalation (Metasploit)
2020-02-24
Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Metasploit)
2020-02-24
Android Binder - Use-After-Free (Metasploit)
2020-02-24
Cacti 1.2.8 - Remote Code Execution
2020-02-24
Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure
2020-02-24
DotNetNuke 9.5 - File Upload Restrictions Bypass
2020-02-24
DotNetNuke 9.5 - Persistent Cross-Site Scripting
2020-02-24
eLection 2.0 - 'id' SQL Injection
2020-02-24
Go SSH servers 0.0.2 - Denial of Service (PoC)
2020-02-24
ManageEngine EventLog Analyzer 10.0 - Information Disclosure
2020-02-24
I6032B-P POE 2.0MP Outdoor Camera - Remote Configuration Disclosure
2020-02-24
ATutor 2.2.4 - 'id' SQL Injection
2020-02-24
Windows\x86 - Null-Free WinExec Calc.exe Shellcode (195 bytes)
2020-02-24
SecuSTATION SC-831 HD Camera - Remote Configuration Disclosure
2020-02-24
AMSS++ 4.7 - Backdoor Admin Account
2020-02-24
CandidATS 2.1.0 - Cross-Site Request Forgery (Add Admin)
2020-02-24
Quick N Easy Web Server 3.3.8 - Denial of Service (PoC)
2020-02-24
SecuSTATION IPCAM-130 HD Camera - Remote Configuration Disclosure
2020-02-24
AMSS++ v 4.31 - 'id' SQL Injection
2020-02-24
ESCAM QD-900 WIFI HD Camera - Remote Configuration Disclosure
2020-02-24
Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
2020-02-24
Core FTP Lite 1.3 - Denial of Service (PoC)
2020-02-20
Easy2Pilot 7 - Cross-Site Request Forgery (Add User)
2020-02-20
Nanometrics Centaur 4.3.23 - Unauthenticated Remote Memory Leak
2020-02-20
DBPower C300 HD Camera - Remote Configuration Disclosure
2020-02-20
Virtual Freer 1.58 - Remote Command Execution
2020-02-20
Anviz CrossChex - Buffer Overflow (Metasploit)
2020-02-20
LabVantage 8.3 - Information Disclosure
2020-02-20
SOPlanning 1.45 - 'users' SQL Injection
2020-02-20
Cuckoo Clock v5.0 - Buffer Overflow
2020-02-20
SOPlanning 1.45 - Cross-Site Request Forgery (Add User)
2020-02-20
TFTP Turbo 4.6.1273 - 'TFTP Turbo 4' Unquoted Service Path
2020-02-20
WordPress Theme Fruitful 3.8 - Persistent Cross-Site Scripting
2020-02-20
Ice HRM 26.2.0 - Cross-Site Request Forgery (Add User)
2020-02-20
DHCP Turbo 4.61298 - 'DHCP Turbo 4' Unquoted Service Path
2020-02-20
MSI Packages Symbolic Links Processing - Windows 10 Privilege Escalation
2020-02-20
BOOTP Turbo 2.0.1214 - 'BOOTP Turbo' Unquoted Service Path
2020-02-20
Avaya Aura Communication Manager 5.2 - Remote Code Execution
2020-02-20
Wordpress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scripting
2020-02-20
HP System Event 1.2.9.0 - 'HPWMISVC' Unquoted Service Path
2020-02-20
SOPlanning 1.45 - 'by' SQL Injection
2020-02-20
Hypervisor Necromancy; Reanimating Kernel Protectors
2020-02-20
PHP 7.0 < 7.4 (Unix) - 'debug_backtrace' disable_functions Bypass
2020-02-20
Windows Kernel - Information Disclosure
2020-02-20
SprintWork 2.3.1 - Local Privilege Escalation
2020-02-20
EPSON EasyMP Network Projection 2.81 - 'EMP_NSWLSV' Unquoted Service Path
2020-02-20
HomeGuard Pro 9.3.1 - Insecure Folder Permissions
2020-02-20
phpMyChat Plus 1.98 - 'pmc_username' SQL Injection
2020-02-20
PANDORAFMS 7.0 - Authenticated Remote Code Execution
2020-02-20
OpenTFTP 1.66 - Local Privilege Escalation
2020-02-20
HP System Event Utility - Local Privilege Escalation
2020-02-12
MyVideoConverter Pro 3.14 - 'TVSeries' Buffer Overflow
2020-02-12
MyVideoConverter Pro 3.14 - 'Output Folder' Buffer Overflow
2020-02-12
MyVideoConverter Pro 3.14 - 'Movie' Buffer Overflow
2020-02-12
Microsoft SharePoint - Deserialization Remote Code Execution
2020-02-11
Sudo 1.8.25p - 'pwfeedback' Buffer Overflow
2020-02-11
OpenSMTPD 6.6.1 - Local Privilege Escalation
2020-02-11
Wedding Slideshow Studio 1.36 - 'Name' Buffer Overflow
2020-02-11
Disk Savvy Enterprise 12.3.18 - Unquoted Service Path
2020-02-11
Disk Sorter Enterprise 12.4.16 - 'Disk Sorter Enterprise' Unquoted Service Path
2020-02-11
WordPress InfiniteWP - Client Authentication Bypass (Metasploit)
2020-02-11
DVD Photo Slideshow Professional 8.07 - 'Name' Buffer Overflow
2020-02-11
Sync Breeze Enterprise 12.4.18 - 'Sync Breeze Enterprise' Unquoted Service Path
2020-02-11
FreeSSHd 1.3.1 - 'FreeSSHDService' Unquoted Service Path
2020-02-11
freeFTPd v1.0.13 - 'freeFTPdService' Unquoted Service Path
2020-02-11
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
2020-02-11
DVD Photo Slideshow Professional 8.07 - 'Key' Buffer Overflow
2020-02-11
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
2020-02-11
Torrent iPod Video Converter 1.51 - Stack Overflow
2020-02-11
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
2020-02-10
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
2020-02-10
Ricoh Driver - Privilege Escalation (Metasploit)
2020-02-10
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
2020-02-10
usersctp - Out-of-Bounds Reads in sctp_load_addresses_from_init
2020-02-10
Linux/x86 - Bind Shell Generator Shellcode (114 bytes)
2020-02-10
Dota 2 7.23f - Denial of Service (PoC)
2020-02-10
LearnDash WordPress LMS Plugin 3.1.2 - Reflective Cross-Site Scripting
2020-02-10
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
2020-02-10
Wedding Slideshow Studio 1.36 - 'Key' Buffer Overflow
2020-02-10
Google Invisible RECAPTCHA 3 - Spoof Bypass
2020-02-07
ExpertGPS 6.38 - XML External Entity Injection
2020-02-07
EyesOfNetwork 5.3 - Remote Code Execution
2020-02-07
PackWeb Formap E-learning 1.0 - 'NumCours' SQL Injection
2020-02-07
VehicleWorkshop 1.0 - 'bookingid' SQL Injection
2020-02-07
QuickDate 1.3.2 - SQL Injection
2020-02-07
Windscribe - WindscribeService Named Pipe Privilege Escalation (Metasploit)
2020-02-07
Cisco Data Center Network Manager 11.2.1 - 'LanFabricImpl' Command Injection
2020-02-06
Cisco Data Center Network Manager 11.2.1 - 'getVmHostData' SQL Injection
2020-02-06
Cisco Data Center Network Manager 11.2 - Remote Code Execution
2020-02-06
Ecommerce Systempay 1.0 - Production KEY Brute Force
2020-02-06
Online Job Portal 1.0 - Cross Site Request Forgery (Add User)
2020-02-06
RarmaRadio 2.72.4 - 'server' Denial of Service (PoC)
2020-02-06
RarmaRadio 2.72.4 - 'username' Denial of Service (PoC)
2020-02-06
TapinRadio 2.12.3 - 'username' Denial of Service (PoC)
2020-02-06
Online Job Portal 1.0 - Remote Code Execution
2020-02-06
TapinRadio 2.12.3 - 'address' Denial of Service (PoC)
2020-02-06
AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service (PoC)
2020-02-06
ELAN Smart-Pad 11.10.15.1 - 'ETDService' Unquoted Service Path
2020-02-06
VIM 8.2 - Denial of Service (PoC)
2020-02-06
Online Job Portal 1.0 - 'user_email' SQL Injection
2020-02-06
AbsoluteTelnet 11.12 - 'license name' Denial of Service (PoC)
2020-02-06
AbsoluteTelnet 11.12 - "license name" Denial of Service (PoC)
2020-02-06
HiSilicon DVR/NVR hi3520d firmware - Remote Backdoor Account
2020-02-05
AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
2020-02-05
Verodin Director Web Console 3.5.4.0 - Remote Authenticated Password Disclosure (PoC)
2020-02-05
Kronos WebTA 4.0 - Authenticated Remote Privilege Escalation
2020-02-05
xglance-bin 11.00 - Privilege Escalation
2020-02-05
Socat 1.7.3.4 - Heap-Based Overflow (PoC)
2020-02-05
Wago PFC200 - Authenticated Remote Code Execution (Metasploit)
2020-02-05
AVideo Platform 8.1 - Information Disclosure (User Enumeration)
2020-02-05
F-Secure Internet Gatekeeper 5.40 - Heap Overflow (PoC)
2020-02-04
Sudo 1.8.25p - Buffer Overflow
2020-02-04
Centreon 19.10.5 - 'Pollers' Remote Command Execution (Metasploit)
2020-02-04
P2PWIFICAM2 for iOS 10.4.1 - 'Camera ID' Denial of Service (PoC)
2020-02-03
School ERP System 1.0 - Cross Site Request Forgery (Add Admin)
2020-02-03
Schneider Electric U.Motion Builder 1.3.4 - Authenticated Command Injection
2020-02-03
ira 8.3.4 - Information Disclosure (Username Enumeration)
2020-02-03
phpList 3.5.0 - Authentication Bypass
2020-02-03
IceWarp WebMail 11.4.4.1 - Reflective Cross-Site Scripting
2020-02-03
BearFTP 0.1.0 - 'PASV' Denial of Service
2020-02-03
FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)
2020-01-31
Lotus Core CMS 1.0.1 - Local File Inclusion
2020-01-31
OpenSMTPD 6.6.2 - Remote Code Execution
2020-01-30
rConfig 3.9.3 - Authenticated Remote Code Execution
2020-01-30
Windows/x86 - Dynamic Bind Shell + Null-Free Shellcode (571 Bytes)
2020-01-30
Fifthplay S.A.M.I 2019.2_HP - Persistent Cross-Site Scripting
2020-01-29
Centreon 19.10.5 - 'centreontrapd' Remote Command Execution
2020-01-29
Centreon 19.10.5 - 'Pollers' Remote Command Execution
2020-01-29
Satellian 1.12 - Remote Code Execution
2020-01-29
Microsoft Windows 10 - Theme API 'ThemePack' File Parsing
2020-01-29
XMLBlueprint 16.191112 - XML External Entity Injection
2020-01-29
Cups Easy 1.0 - Cross Site Request Forgery (Password Reset)
2020-01-29
Liferay CE Portal 6.0.2 - Remote Command Execution
2020-01-29
Kibana 6.6.1 - CSV Injection
2020-01-29
macOS/iOS ImageIO - Heap Corruption when Processing Malformed TIFF Image
2020-01-28
Centreon 19.10.5 - Remote Command Execution
2020-01-28
Centreon 19.10.5 - Database Credentials Disclosure
2020-01-28
Octeth Oempro 4.8 - 'CampaignID' SQL Injection
2020-01-28
Adive Framework 2.0.8 - Cross-Site Request Forgery (Change Admin Password)
2020-01-28
Torrent 3GP Converter 1.51 - Stack Overflow (SEH)
2020-01-27
Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)
2020-01-24
Ricoh Printer Drivers - Local Privilege Escalation
2020-01-24
Genexis Platinum-4410 2.1 - Authentication Bypass
2020-01-24
OLK Web Store 2020 - Cross-Site Request Forgery
2020-01-24
Webtareas 2.0 - 'id' SQL Injection
2020-01-24
TP-Link TP-SG105E 1.0.0 - Unauthenticated Remote Reboot
2020-01-24
Reliable Datagram Sockets (RDS) - rds_atomic_free_op NULL pointer dereference Privilege Escalation (Metasploit)
2020-01-23
Pachev FTP Server 1.0 - Path Traversal
2020-01-23
BOOTP Turbo 2.0 - Denial of Service (SEH)(PoC)
2020-01-23
qdPM 9.1 - Remote Code Execution
2020-01-23
Windows/7 - Screen Lock Shellcode (9 bytes)
2020-01-22
KeePass 2.44 - Denial of Service (PoC)
2020-01-22
Citrix XenMobile Server 10.8 - XML External Entity Injection
2020-01-22
NEOWISE CARBONFTP 1.4 - Weak Password Encryption
2020-01-21
ManageEngine Network Configuration Manager 12.2 - 'apiKey' SQL Injection
2020-01-21
Centreon 19.04 - Authenticated Remote Code Execution (Metasploit)
2020-01-20
Sysax Multi Server 5.50 - Denial of Service (PoC)
2020-01-20
Adive Framework 2.0.8 - Persistent Cross-Site Scripting
2020-01-20
Easy XML Editor 1.7.8 - XML External Entity Injection
2020-01-20
Plantronics Hub 3.13.2 - SpokesUpdateService Privilege Escalation (Metasploit)
2020-01-17
Trend Micro Maximum Security 2019 - Privilege Escalation
2020-01-17
GTalk Password Finder 2.2.1 - 'Key' Denial of Service (PoC)
2020-01-17
Wordpress Time Capsule Plugin 1.21.16 - Authentication Bypass
2020-01-17
Trend Micro Maximum Security 2019 - Arbitrary Code Execution
2020-01-17
Wordpress Plugin InfiniteWP Client 1.9.4.5 - Authentication Bypass
2020-01-17
Torrent FLV Converter 1.51 Build 117 - Stack Oveflow (SEH partial overwrite)
2020-01-17
APKF Product Key Finder 2.5.8.0 - 'Name' Denial of Service (PoC)
2020-01-17
Sagemcom [email protected] 3890 (50_10_19-T1) Cable Modem - 'Cable Haunt' Remote Code Execution
2020-01-16
Microsoft Windows 10 (19H1 1901 x64) - 'ws2ifsl.sys' Use After Free Local Privilege Escalation (kASLR kCFG SMEP)
2020-01-16
Rukovoditel Project Management CRM 2.5.2 - 'filters' SQL Injection
2020-01-16
Microsoft Windows - CryptoAPI (Crypt32.dll) Elliptic Curve Cryptography (ECC) Spoof Code-Signing Certificate
2020-01-16
SunOS 5.10 Generic_147148-26 - Local Privilege Escalation
2020-01-16
Rukovoditel Project Management CRM 2.5.2 - 'entities_id' SQL Injection
2020-01-16
Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal
2020-01-16
Tautulli 2.1.9 - Denial of Service ( Metasploit )
2020-01-16
Online Book Store 1.0 - Arbitrary File Upload
2020-01-16
Jenkins Gitlab Hook Plugin 1.4.2 - Reflected Cross-Site Scripting
2020-01-16
Rukovoditel Project Management CRM 2.5.2 - 'reports_id' SQL Injection
2020-01-16
WordPress Plugin Postie 1.9.40 - Persistent Cross-Site Scripting
2020-01-16
Barco WePresent - file_transfer.cgi Command Injection (Metasploit)
2020-01-15
Huawei HG255 - Directory Traversal ( Metasploit )
2020-01-15
Online Book Store 1.0 - 'bookisbn' SQL Injection
2020-01-15
Android - ashmem Readonly Bypasses via remap_file_pages() and ASHMEM_UNPIN
2020-01-14
WeChat - Memory Corruption in CAudioJBM::InputAudioFrameToJBM
2020-01-14
Redir 3.3 - Denial of Service (PoC)
2020-01-14
IBM RICOH 6400 Printer - HTML Injection
2020-01-14
IBM RICOH InfoPrint 6500 Printer - HTML Injection
2020-01-14
VPN unlimited 6.1 - Unquoted Service Path
2020-01-14
Microsoft Windows 10 build 1809 - Local Privilege Escalation (UAC Bypass)
2020-01-13
Digi AnywhereUSB 14 - Reflective Cross-Site Scripting
2020-01-13
Citrix Application Delivery Controller and Gateway 10.5 - Remote Code Execution (Metasploit)
2020-01-13
Top Password Firefox Password Recovery 2.8 - Denial of Service (PoC)
2020-01-13
TaskCanvas 1.4.0 - 'Registration' Denial Of Service
2020-01-13
Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 - Stack Overflow (SEH)
2020-01-13
Backup Key Recovery 2.2.5 - 'Name' Denial of Service (PoC)
2020-01-13
Allok Video Converter 4.6.1217 - Stack Overflow (SEH)
2020-01-13
Top Password Software Dialup Password Recovery 1.30 - Denial of Service (PoC)
2020-01-13
SpotOutlook 1.2.6 - 'Name' Denial of Service (PoC)
2020-01-13
Advanced System Repair Pro 1.9.1.7 - Insecure File Permissions
2020-01-13
SpotDialup 1.6.7 - 'Name' Denial of Service (PoC)
2020-01-13
Chevereto 3.13.4 Core - Remote Code Execution
2020-01-13
Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution
2020-01-11
Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution (PoC)
2020-01-11
ASTPP 4.0.1 VoIP Billing - Database Backup Download
2020-01-10
PixelStor 5000 K:4.0.1580-20150629 - Remote Code Execution
2020-01-10
Pandora 7.0NG - Remote Code Execution
2020-01-10
TotalAV 2020 4.14.31 - Privilege Escalation
2020-01-10
MSN Password Recovery 1.30 - XML External Entity Injection
2020-01-09
Oracle Weblogic 10.3.6.0.0 - Remote Command Execution
2020-01-09
ZIP Password Recovery 2.30 - 'ZIP File' Denial of Service (PoC)
2020-01-09
Sony Playstation 4 (PS4) < 6.72 - WebKit Code Execution (PoC)
2020-01-08
Tomcat proprietaryEvaluate 9.0.0.M1 - Sandbox Escape
2020-01-08
JetBrains TeamCity 2018.2.4 - Remote Code Execution
2020-01-08
Linux/x86 - Random Bytes Encoder + XOR/SUB/NOT/ROR execve(/bin/sh) Shellcode (114 bytes)
2020-01-08
ASTPP VoIP 4.0.1 - Remote Code Execution
2020-01-08
EBBISLAND EBBSHAVE 6100-09-04-1441 - Remote Buffer Overflow
2020-01-08
Online Book Store 1.0 - Unauthenticated Remote Code Execution
2020-01-08
Codoforum 4.8.3 - 'input_txt' Persistent Cross-Site Scripting
2020-01-08
Cisco DCNM JBoss 10.4 - Credential Leakage
2020-01-08
Complaint Management System 4.0 - Remote Code Execution
2020-01-07
AnyDesk 5.4.0 - Unquoted Service Path
2020-01-07
piSignage 2.6.4 - Directory Traversal
2020-01-07
Job Portal 1.0 - Remote Code Execution
2020-01-07
Windows - Shell COM Server Registrar Local Privilege Escalation
2020-01-06
Django < 3.0 < 2.2 < 1.11 - Account Hijack
2020-01-06
Microsoft Outlook VCF cards - Denial of Service (PoC)
2020-01-06
Linux/x86 - Execve() Alphanumeric Shellcode (66 bytes)
2020-01-06
Codoforum 4.8.3 - Persistent Cross-Site Scripting
2020-01-06
Voyager 1.3.0 - Directory Traversal
2020-01-06
Small CRM 2.0 - Authentication Bypass
2020-01-06
Duplicate Cleaner Pro 4 - Denial of Service (PoC)
2020-01-06
FTPGetter Professional 5.97.0.223 - Denial of Service (PoC)
2020-01-06
SpotIM 2.2 - 'Name' Denial Of Service
2020-01-06
SpotMSN 2.4.6 - 'Name' Denial of Service (PoC)
2020-01-06
SpotFTP FTP Password Recovery 3.0.0.0 - 'Name' Denial of Service (PoC)
2020-01-06
Office Product Key Finder 1.5.4 - Denial of Service (PoC)
2020-01-06
NBMonitor 1.6.6.0 - 'Key' Denial of Service (PoC)
2020-01-06
RemShutdown 2.9.0.0 - 'Name' Denial of Service (PoC)
2020-01-06
Backup Key Recovery Recover Keys Crashed Hard Disk Drive 2.2.5 - 'Key' Denial of Service (PoC)
2020-01-06
RemShutdown 2.9.0.0 - 'Key' Denial of Service (PoC)
2020-01-06
TextCrawler Pro3.1.1 - Denial of Service (PoC)
2020-01-06
Dnss Domain Name Search Software - 'Name' Denial of Service (PoC)
2020-01-06
NetShareWatcher 1.5.8.0 - 'Key' Denial of Service (PoC)
2020-01-06
ShareAlarmPro Advanced Network Access Control - 'Key' Denial of Service (PoC)
2020-01-06
elaniin CMS 1.0 - Authentication Bypass
2020-01-06
BlueAuditor 1.7.2.0 - 'Name' Denial of Service (PoC)
2020-01-06
Dnss Domain Name Search Software - 'Key' Denial of Service (PoC)
2020-01-06
SpotIE 2.9.5 - 'Key' Denial of Service (PoC)
2020-01-06
Hostel Management System 2.0 - 'id' SQL Injection
2020-01-06
NetworkSleuth 3.0.0.0 - 'Key' Denial of Service (PoC)
2020-01-06
Adaware Web Companion 4.9.2159 - 'WCAssistantService' Unquoted Service Path
2020-01-06
Subrion CMS 4.0.5 - Cross-Site Request Forgery (Add Admin)
2020-01-06
IBM RICOH Infoprint 1532 Printer - Persistent Cross-Site Scripting
2020-01-06
NetShareWatcher 1.5.8.0 - 'Name' Denial Of Service
2020-01-06
Complaint Management System 4.0 - 'cid' SQL injection
2020-01-06
Dairy Farm Shop Management System 1.0 - 'username' SQL Injection
2020-01-06
Plantronics Hub 3.13.2 - Local Privilege Escalation
2020-01-03
Karakuzu ERP Management Web 5.7.0 - 'k_adi_duz' SQL Injection
2020-01-03
Online Course Registration 2.0 - Remote Code Execution
2020-01-03
BloodX 1.0 - Authentication Bypass
2020-01-02
Hospital Management System 4.0 - Persistent Cross-Site Scripting
2020-01-02
Hospital Management System 4.0 - 'searchdata' SQL Injection
2020-01-02
MSN Password Recovery 1.30 - Denial of Service (PoC)
2020-01-02
Microsoft Windows .Group File - Code Execution
2020-01-01
nostromo 1.9.6 - Remote Code Execution
2020-01-01
Hospital Management System 4.0 - Authentication Bypass
2020-01-01
IBM InfoPrint 4247-Z03 Impact Matrix Printer - Directory Traversal
2020-01-01
Shopping Portal ProVersion 3.0 - Authentication Bypass
2020-01-01
Wordpress Ultimate Addons for Beaver Builder 1.2.4.1 - Authentication Bypass
2019-12-31
NextVPN v4.10 - Insecure File Permissions
2019-12-31
FreeBSD-SA-19:15.mqueuefs - Privilege Escalation
2019-12-30
FreeBSD-SA-19:02.fd - Privilege Escalation
2019-12-30
Heatmiser Netmonitor 3.03 - HTML Injection
2019-12-30
RICOH Web Image Monitor 1.09 - HTML Injection
2019-12-30
RICOH SP 4510SF Printer - HTML Injection
2019-12-30
Domain Quester Pro 6.02 - Stack Overflow (SEH)
2019-12-30
MyDomoAtHome REST API Domoticz ISS Gateway 0.2.40 - Information Disclosure
2019-12-30
Heatmiser Netmonitor 3.03 - Hardcoded Credentials
2019-12-30
AVE DOMINAplus 1.10.x - Authentication Bypass
2019-12-30
AVE DOMINAplus 1.10.x - Cross-Site Request Forgery (enable/disable alarm)
2019-12-30
AVE DOMINAplus 1.10.x - Unauthenticated Remote Reboot
2019-12-30
AVE DOMINAplus 1.10.x - Credential Disclosure
2019-12-30
Wing FTP Server 6.0.7 - Unquoted Service Path
2019-12-30
WEMS BEMS 21.3.1 - Undocumented Backdoor Account
2019-12-30
XEROX WorkCentre 7830 Printer - Cross-Site Request Forgery (Add Admin)
2019-12-30
XEROX WorkCentre 7855 Printer - Cross-Site Request Forgery (Add Admin)
2019-12-30
Thrive Smart Home 1.1 - Authentication Bypass
2019-12-30
XEROX WorkCentre 6655 Printer - Cross-Site Request Forgery (Add Admin)
2019-12-30
FTP Navigator 8.03 - Stack Overflow (SEH)
2019-12-30
elearning-script 1.0 - Authentication Bypass
2019-12-30
AVS Audio Converter 9.1.2.600 - Stack Overflow (PoC)
2019-12-30
HomeAutomation 3.3.2 - Remote Code Execution
2019-12-30
HomeAutomation 3.3.2 - Cross-Site Request Forgery (Add Admin)
2019-12-30
HomeAutomation 3.3.2 - Authentication Bypass
2019-12-30
HomeAutomation 3.3.2 - Persistent Cross-Site Scripting
2019-12-30
Microsoft UPnP - Local Privilege Elevation (Metasploit)
2019-12-30
Reptile Rootkit - reptile_cmd Privilege Escalation (Metasploit)
2019-12-30
OpenBSD - Dynamic Loader chpass Privilege Escalation (Metasploit)
2019-12-30
Prime95 Version 29.8 build 6 - Buffer Overflow (SEH)
2019-12-24
WordPress Core < 5.3.x - 'xmlrpc.php' Denial of Service
2019-12-21
FreeSWITCH 1.10.1 - Command Execution
2019-12-21
phpMyChat-Plus 1.98 - 'pmc_username' Reflected Cross-Site Scripting
2019-12-21
Microsoft Windows 10 BasicRender.sys - Denial of Service (PoC)
2019-12-21
Deutsche Bahn Ticket Vending Machine Local Kiosk - Privilege Escalation
2019-12-19
FTP Navigator 8.03 - 'Custom Command' Denial of Service (SEH)
2019-12-19
Telerik UI - Remote Code Execution via Insecure Deserialization
2019-12-18
OpenMRS - Java Deserialization RCE (Metasploit)
2019-12-18
macOS 10.14.6 (18G87) - Kernel Use-After-Free due to Race Condition in wait_for_namespace_event()
2019-12-18
Rumpus FTP Web File Manager 8.2.9.1 - Reflected Cross-Site Scripting
2019-12-18
AVS Audio Converter 9.1 - 'Exit folder' Buffer Overflow
2019-12-18
Xerox AltaLink C8035 Printer - Cross-Site Request Forgery (Add Admin)
2019-12-18
XnView 2.49.1 - 'Research' Denial of Service (PoC)
2019-12-18
Tautulli 2.1.9 - Cross-Site Request Forgery (ShutDown)
2019-12-18
Linux/x64 - Reverse TCP Stager Shellcode (188 bytes)
2019-12-17
NopCommerce 4.2.0 - Privilege Escalation
2019-12-17
Netgear R6400 - Remote Code Execution
2019-12-17
Zendesk App SweetHawk Survey 1.6 - Persistent Cross-Site Scripting
2019-12-17
Roxy Fileman 1.4.5 - Directory Traversal
2019-12-17
D-Link DIR-615 Wireless Router  -  Persistent Cross-Site Scripting
2019-12-17
OpenBSD 6.x - Dynamic Loader Privilege Escalation
2019-12-16
Linux 5.3 - Privilege Escalation via io_uring Offload of sendmsg() onto Kernel Thread with Kernel Creds
2019-12-16
D-Link DIR-615 - Privilege Escalation
2019-12-16
FTP Commander Pro 8.03 - Local Stack Overflow
2019-12-13
NVMS 1000 - Directory Traversal
2019-12-13
Bullwark Momentum Series JAWS 1.0 - Directory Traversal
2019-12-12
OpenNetAdmin 18.1.1 - Command Injection Exploit (Metasploit)
2019-12-12
Lenovo Power Management Driver 1.67.17.48 - 'pmdrvs.sys' Denial of Service (PoC)
2019-12-12
Apache Olingo OData 4.0 - XML External Entity Injection
2019-12-11
Adobe Acrobat Reader DC - Heap-Based Memory Corruption due to Malformed TTF Font
2019-12-11
AppXSvc 17763 - Arbitrary File Overwrite (DoS)
2019-12-11
Product Key Explorer 4.2.0.0 - 'Key' Denial of Service (PoC)
2019-12-11
Product Key Explorer 4.2.0.0 - 'Name' Denial of Service (POC)
2019-12-11
Inim Electronics Smartliving SmartLAN 6.x - Remote Command Execution
2019-12-10
Inim Electronics Smartliving SmartLAN 6.x - Unauthenticated Server-Side Request Forgery
2019-12-10
Inim Electronics Smartliving SmartLAN 6.x - Hard-coded Credentials
2019-12-10
Oracle Siebel Sales 8.1 - Persistent Cross-Site Scripting
2019-12-09
Alcatel-Lucent Omnivista 8770 - Remote Code Execution
2019-12-09
Yachtcontrol Webapplication 1.0 - Unauthenticated Remote Code Execution
2019-12-09
SpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH)
2019-12-09
PRO-7070 Hazır Profesyonel Web Sitesi 1.0 - Authentication Bypass
2019-12-09
Omron PLC 1.0.0 - Denial of Service (PoC)
2019-12-09
Snipe-IT Open Source Asset Management 4.7.5 - Persistent Cross-Site Scripting
2019-12-09
Microsoft Windows 10 - 'WSReset' UAC Protection Bypass (propsys.dll)
2019-12-09
Microsoft Windows - 'WSReset' UAC Protection Bypass (Registry)
2019-12-09
Microsoft Windows - Multiple UAC Protection Bypasses
2019-12-09
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
2019-12-09
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
2019-12-06
Integard Pro NoJs 2.2.0.9026 - Remote Buffer Overflow
2019-12-06
Verot 2.0.3 - Remote Code Execution
2019-12-06
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
2019-12-05
Amiti Antivirus 25.0.640 - Unquoted Service Path
2019-12-05
NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Path
2019-12-05
OwnCloud 8.1.8 - Username Disclosure
2019-12-04
Cisco WLC 2504 8.9 - Denial of Service (PoC)
2019-12-04
Microsoft Visual Basic 2010 Express - XML External Entity Injection
2019-12-04
SSDWLAB 6.1 - Authentication Bypass
2019-12-04
Online Clinic Management System 2.2 - HTML Injection
2019-12-04
Microsoft Windows Media Center 2002 - XML External Entity MotW Bypass
2019-12-03
Revive Adserver 4.2 - Remote Code Execution
2019-12-03
Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery
2019-12-03
Online Invoicing System 2.6 - 'description' Persistent Cross-Site Scripting
2019-12-03
Xinet Elegant 6 Asset Library Web Interface 6.1.655 - 'username' SQL Injection
2019-12-02
Microsoft Excel 2016 1901 - XML External Entity Injection