ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure
|
|
2020-10-26
|
Genexis Platinum-4410 - 'SSID' Persistent XSS
|
|
2020-10-26
|
PDW File Browser 1.3 - 'new_filename' Cross-Site Scripting (XSS)
|
|
2020-10-26
|
InoERP 0.7.2 - Remote Code Execution (Unauthenticated)
|
|
2020-10-26
|
Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored)
|
|
2020-10-26
|
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
|
|
2020-10-26
|
TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated)
|
|
2020-10-23
|
Bludit 3.9.2 - Auth Bruteforce Bypass
|
|
2020-10-23
|
Gym Management System 1.0 - Stored Cross Site Scripting
|
|
2020-10-23
|
Gym Management System 1.0 - Authentication Bypass
|
|
2020-10-23
|
School Faculty Scheduling System 1.0 - 'username' SQL Injection
|
|
2020-10-23
|
School Faculty Scheduling System 1.0 - 'id' SQL Injection
|
|
2020-10-23
|
Point of Sales 1.0 - 'username' SQL Injection
|
|
2020-10-23
|
Gym Management System 1.0 - 'id' SQL Injection
|
|
2020-10-23
|
Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored)
|
|
2020-10-23
|
Lot Reservation Management System 1.0 - Authentication Bypass
|
|
2020-10-23
|
Point of Sales 1.0 - 'id' SQL Injection
|
|
2020-10-23
|
User Registration & Login and User Management System 2.1 - SQL Injection
|
|
2020-10-23
|
Car Rental Management System 1.0 - Arbitrary File Upload
|
|
2020-10-23
|
Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection
|
|
2020-10-23
|
Ajenti 2.1.36 - Remote Code Execution (Authenticated)
|
|
2020-10-23
|
Online Library Management System 1.0 - Arbitrary File Upload
|
|
2020-10-23
|
Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
|
|
2020-10-21
|
Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
|
|
2020-10-21
|
Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scripting
|
|
2020-10-21
|
Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scripting
|
|
2020-10-21
|
GOautodial 4.0 - Authenticated Shell Upload
|
|
2020-10-21
|
School Faculty Scheduling System 1.0 - Authentication Bypass POC
|
|
2020-10-21
|
School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
|
|
2020-10-21
|
Hrsale 2.0.0 - Local File Inclusion
|
|
2020-10-21
|
WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting (Authenticated)
|
|
2020-10-20
|
WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection
|
|
2020-10-20
|
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
|
|
2020-10-20
|
Mobile Shop System v1.0 - SQL Injection Authentication Bypass
|
|
2020-10-20
|
RiteCMS 2.2.1 - Remote Code Execution (Authenticated)
|
|
2020-10-20
|
User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS
|
|
2020-10-20
|
WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload
|
|
2020-10-20
|
Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated)
|
|
2020-10-20
|
Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
|
|
2020-10-20
|
Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Courses Content Disclosure
|
|
2020-10-20
|
Loan Management System 1.0 - Multiple Cross Site Scripting (Stored)
|
|
2020-10-20
|
Comtrend AR-5387un router - Persistent XSS (Authenticated)
|
|
2020-10-20
|
Textpattern CMS 4.6.2 - Cross-site Request Forgery
|
|
2020-10-19
|
Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
|
|
2020-10-19
|
Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
|
|
2020-10-19
|
Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
|
|
2020-10-19
|
HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
|
|
2020-10-19
|
HiSilicon Video Encoders - Full admin access via backdoor password
|
|
2020-10-19
|
HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware
|
|
2020-10-19
|
HiSilicon Video Encoders - RCE via unauthenticated command injection
|
|
2020-10-19
|