HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal
|
|
2020-10-19
|
Online Job Portal 1.0 - Cross Site Scripting (Stored)
|
|
2020-10-19
|
Online Discussion Forum Site 1.0 - XSS in Messaging System
|
|
2020-10-19
|
Online Student's Management System 1.0 - Remote Code Execution (Authenticated)
|
|
2020-10-19
|
Nagios XI 5.7.3 - 'SNMP Trap Interface' Authenticated SQL Injection
|
|
2020-10-19
|
Nagios XI 5.7.3 - 'Manage Users' Authenticated SQL Injection
|
|
2020-10-19
|
Nagios XI 5.7.3 - 'Contact Templates' Persistent Cross-Site Scripting
|
|
2020-10-19
|
Tourism Management System 1.0 - Arbitrary File Upload
|
|
2020-10-19
|
CS-Cart 1.3.3 - authenticated RCE
|
|
2020-10-19
|
CS-Cart 1.3.3 - 'classes_dir' LFI
|
|
2020-10-19
|
Seat Reservation System 1.0 - Unauthenticated SQL Injection
|
|
2020-10-19
|
Hotel Management System 1.0 - Remote Code Execution (Authenticated)
|
|
2020-10-19
|
Seat Reservation System 1.0 - Remote Code Execution (Unauthenticated)
|
|
2020-10-19
|
aaPanel 6.6.6 - Privilege Escalation & Remote Code Execution (Authenticated)
|
|
2020-10-19
|
Restaurant Reservation System 1.0 - 'date' SQL Injection (Authenticated)
|
|
2020-10-19
|
Company Visitor Management System (CVMS) 1.0 - Authentication Bypass
|
|
2020-10-19
|
Alumni Management System 1.0 - Authentication Bypass
|
|
2020-10-19
|
Employee Management System 1.0 - Authentication Bypass
|
|
2020-10-19
|
Employee Management System 1.0 - Cross Site Scripting (Stored)
|
|
2020-10-19
|
Zoo Management System 1.0 - Authentication Bypass
|
|
2020-10-19
|
Simple Grocery Store Sales And Inventory System 1.0 - Authentication Bypass
|
|
2020-10-19
|
rConfig 3.9.5 - Remote Code Execution (Unauthenticated)
|
|
2020-10-19
|
Vehicle Parking Management System 1.0 - Authentication Bypass
|
|
2020-10-19
|
Guild Wars 2 - Insecure Folder Permissions
|
|
2020-10-19
|
NodeBB Forum 1.12.2-1.14.2 - Account Takeover
|
|
2020-10-19
|
TimeClock Software 1.01 0 - (Authenticated) Time-Based SQL Injection
|
|
2020-10-19
|
Battle.Net 1.27.1.12428 - Insecure File Permissions
|
|
2020-10-19
|
berliCRM 1.0.24 - 'src_record' SQL Injection
|
|
2020-10-19
|
Cisco ASA and FTD 9.6.4.42 - Path Traversal
|
|
2020-10-19
|
Online Students Management System 1.0 - 'username' SQL Injections
|
|
2020-10-19
|
Liman 0.7 - Cross-Site Request Forgery (Change Password)
|
|
2020-10-19
|
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Unauthenticated)
|
|
2020-10-19
|
Small CRM 2.0 - 'email' SQL Injection
|
|
2020-10-19
|
openMAINT 1.1-2.4.2 - Arbitrary File Upload
|
|
2020-10-09
|
DynPG 4.9.1 - Persistent Cross-Site Scripting (Authenticated)
|
|
2020-10-09
|
Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
|
|
2020-10-09
|
D-Link DSR-250N 3.12 - Denial of Service (PoC)
|
|
2020-10-08
|
SEO Panel 4.6.0 - Remote Code Execution
|
|
2020-10-08
|
Textpattern CMS 4.6.2 - 'body' Persistent Cross-Site Scripting
|
|
2020-10-07
|
BACnet Test Server 1.01 - Remote Denial of Service (PoC)
|
|
2020-10-07
|
EasyPMS 1.0.0 - Authentication Bypass
|
|
2020-10-06
|
Karel IP Phone IP1211 Web Management Panel - Directory Traversal
|
|
2020-10-06
|
Qmail SMTP 1.03 - Bash Environment Variable Injection
|
|
2020-10-06
|
SpamTitan 7.07 - Unauthenticated Remote Code Execution
|
|
2020-10-05
|
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
|
|
2020-10-05
|
Photo Share Website 1.0 - Persistent Cross-Site Scripting
|
|
2020-10-02
|
MedDream PACS Server 6.8.3.751 - Remote Code Execution (Authenticated)
|
|
2020-10-02
|
Exhibitor Web UI 1.7.1 - Remote Code Execution
|
|
2020-10-01
|
Typesetter CMS 5.1 - 'Site Title' Persistent Cross-Site Scripting
|
|
2020-10-01
|
CMS Made Simple 2.2.14 - Persistent Cross-Site Scripting (Authenticated)
|
|
2020-10-01
|