ForensiTAppxService 2.2.0.4 - 'ForensiTAppxService.exe' Unquoted Service Path
|
|
2020-09-21
|
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
|
|
2020-09-21
|
Online Shop Project 1.0 - 'p' SQL Injection
|
|
2020-09-21
|
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
|
|
2020-09-18
|
SpamTitan 7.07 - Remote Code Execution (Authenticated)
|
|
2020-09-18
|
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
|
|
2020-09-17
|
Windows TCPIP Finger Command - C2 Channel and Bypassing Security Software
|
|
2020-09-16
|
Piwigo 2.10.1 - Cross Site Scripting
|
|
2020-09-16
|
Tailor MS 1.0 - Reflected Cross-Site Scripting
|
|
2020-09-16
|
ThinkAdmin 6 - Arbitrarily File Read
|
|
2020-09-16
|
Joomla! paGO Commerce 2.5.9.0 - SQL Injection (Authenticated)
|
|
2020-09-16
|
Pearson Vue VTS 2.3.1911 Installer - 'VUEApplicationWrapper' Unquoted Service Path
|
|
2020-09-16
|
RAD SecFlow-1v SF_0290_2.3.01.26 - Cross-Site Request Forgery (Reboot)
|
|
2020-09-16
|
Rapid7 Nexpose Installer 6.6.39 - 'nexposeengine' Unquoted Service Path
|
|
2020-09-16
|
RAD SecFlow-1v SF_0290_2.3.01.26 - Persistent Cross-Site Scripting
|
|
2020-09-16
|
Internet Explorer 11 - Use-After-Free
|
|
2020-09-16
|
Tea LaTex 1.0 - Remote Code Execution (Unauthenticated)
|
|
2020-09-16
|
VTENEXT 19 CE - Remote Code Execution
|
|
2020-09-16
|
Gnome Fonts Viewer 3.34.0 - Heap Corruption
|
|
2020-09-16
|
ZTE Router F602W - Captcha Bypass
|
|
2020-09-16
|
CuteNews 2.1.2 - Remote Code Execution
|
|
2020-09-16
|
Tiandy IPC and NVR 9.12.7 - Credential Disclosure
|
|
2020-09-16
|
Scopia XT Desktop 8.3.915.4 - Cross-Site Request Forgery (change admin password)
|
|
2020-09-16
|
Tailor Management System - 'id' SQL Injection
|
|
2020-09-16
|
Audio Playback Recorder 3.2.2 - Local Buffer Overflow (SEH)
|
|
2020-09-16
|
Input Director 1.4.3 - 'Input Director' Unquoted Service Path
|
|
2020-09-16
|
ShareMouse 5.0.43 - 'ShareMouse Service' Unquoted Service Path
|
|
2020-09-08
|
ManageEngine Applications Manager 14700 - Remote Code Execution (Authenticated)
|
|
2020-09-07
|
grocy 2.7.1 - Persistent Cross-Site Scripting
|
|
2020-09-07
|
Cabot 0.11.12 - Persistent Cross-Site Scripting
|
|
2020-09-07
|
Nord VPN-6.31.13.0 - 'nordvpn-service' Unquoted Service Path
|
|
2020-09-04
|
BarracudaDrive v6.5 - Insecure Folder Permissions
|
|
2020-09-03
|
SiteMagic CMS 4.4.2 - Arbitrary File Upload (Authenticated)
|
|
2020-09-03
|
Daily Tracker System 1.0 - Authentication Bypass
|
|
2020-09-03
|
BloodX CMS 1.0 - Authentication Bypass
|
|
2020-09-03
|
Savsoft Quiz Enterprise Version 5.5 - Persistent Cross-Site Scripting
|
|
2020-09-03
|
Stock Management System 1.0 - Cross-Site Request Forgery (Change Username)
|
|
2020-09-02
|
moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)
|
|
2020-09-01
|
Mara CMS 7.5 - Remote Code Execution (Authenticated)
|
|
2020-09-01
|
CMS Made Simple 2.2.14 - Arbitrary File Upload (Authenticated)
|
|
2020-08-31
|
Fuel CMS 1.4.8 - 'fuel_replace_id' SQL Injection (Authenticated)
|
|
2020-08-31
|
Mara CMS 7.5 - Reflective Cross-Site Scripting
|
|
2020-08-31
|
BlazeDVD 7.0 Professional - '.plf' Local Buffer Overflow (SEH,ASLR,DEP)
|
|
2020-08-31
|
Online Book Store 1.0 - 'id' SQL Injection
|
|
2020-08-31
|
Eibiz i-Media Server Digital Signage 3.8.0 - Privilege Escalation
|
|
2020-08-28
|
SymphonyCMS 3.0.0 - Persistent Cross-Site Scripting
|
|
2020-08-28
|
Nagios Log Server 2.1.6 - Persistent Cross-Site Scripting
|
|
2020-08-28
|
Online Shopping Alphaware 1.0 - 'id' SQL Injection
|
|
2020-08-28
|
Wordpress Plugin Autoptimize 2.7.6 - Arbitrary File Upload (Authenticated)
|
|
2020-08-27
|
ASX to MP3 converter 3.1.3.7.2010.11.05 - '.wax' Local Buffer Overflow (DEP,ASLR Bypass) (PoC)
|
|
2020-08-27
|