Exploits (Total: 97216)

    
    
    
BlogEngine 3.3.8 - 'Content' Stored XSS
2020-11-06
Sentrifugo Version 3.2 - 'announcements' Remote Code Execution (Authenticated)
2020-11-06
Sentrifugo 3.2 - 'assets' Remote Code Execution (Authenticated)
2020-11-06
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
2020-11-06
SmartBlog 2.0.1 - 'id_post' Blind SQL injection
2020-11-06
TP-Link WDR4300 - Remote Code Execution (Authenticated)
2020-11-05
Amarok 2.8.0 - Denial-of-Service
2020-11-05
iDS6 DSSPro Digital Signage System 6.2 - Improper Access Control Privilege Escalation
2020-11-05
iDS6 DSSPro Digital Signage System 6.2 - CAPTCHA Security Bypass
2020-11-05
iDS6 DSSPro Digital Signage System 6.2 - Cross-Site Request Forgery (CSRF)
2020-11-05
Student Attendance Management System 1.0 - 'username' SQL Injection / Remote Code Execution
2020-11-04
School Log Management System 1.0 - 'username' SQL Injection / Remote Code Execution
2020-11-04
PDW File Browser < v1.3 - Remote Code Execution
2020-11-04
Processwire CMS 2.4.0 - 'download' Local File Inclusion
2020-11-04
Exploit Title: Complaints Report Management System 1.0 - 'username' SQL Injection / Remote Code Execution
2020-11-03
Multi Restaurant Table Reservation System 1.0 - 'table_id' Unauthenticated SQL Injection
2020-11-03
Quick N Easy FTP Service 3.2 - Unquoted Service Path
2020-11-02
Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
2020-11-02
Monitorr 1.7.6m - Authorization Bypass
2020-11-02
Monitorr 1.7.6m - Remote Code Execution (Unauthenticated)
2020-11-02
WordPress Plugin Simple File List 5.4 - Arbitrary File Upload
2020-11-02
Apache Flink 1.9.x - File Upload RCE (Unauthenticated)
2020-11-02
Simple College Website 1.0 - 'username' SQL Injection / Remote Code Execution
2020-10-30
Online Job Portal 1.0 - 'userid' SQL Injection
2020-10-30
Citadel WebCit < 926 - Session Hijacking Exploit
2020-10-30
DedeCMS v.5.8 - "keyword" Cross-Site Scripting
2020-10-30
CSE Bookstore 1.0 - 'quantity' Persistent Cross-site Scripting
2020-10-30
Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot
2020-10-29
WebLogic Server 10.3.6.0.0 / 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 - Unauthenticated RCE via GET request
2020-10-29
Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS)
2020-10-29
Online Examination System 1.0 - 'name' Stored Cross Site Scripting
2020-10-29
IP Watcher v3.0.0.30 - 'PACService.exe' Unquoted Service Path
2020-10-28
Prey 1.9.6 - "CronService" Unquoted Service Path
2020-10-28
Program Access Controller v1.2.0.0 - 'PACService.exe' Unquoted Service Path
2020-10-28
Exploit - EPSON 1.124 - 'seksmdb.exe' Unquoted Service Path
2020-10-28
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
2020-10-28
Blueman < 2.1.4 - Local Privilege Escalation
2020-10-28
aptdaemon < 1.1.1 - File Existence Disclosure
2020-10-28
PackageKit < 1.1.13 - File Existence Disclosure
2020-10-28
CSE Bookstore 1.0 - Authentication Bypass
2020-10-28
Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
2020-10-28
GoAhead Web Server 5.1.1 - Digest Authentication Capture Replay Nonce Reuse
2020-10-27
Sphider Search Engine 1.3.6 - 'word_upper_bound' RCE (Authenticated)
2020-10-27
Client Management System 1.0 - 'searchdata' SQL injection
2020-10-27
Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
2020-10-27
Adtec Digital Multiple Products - Default Hardcoded Credentials Remote Root
2020-10-27
TDM Digital Signage PC Player 4.1 - Insecure File Permissions
2020-10-27
ReQuest Serious Play F3 Media Server 7.0.3 - Remote Code Execution (Unauthenticated)
2020-10-26
ReQuest Serious Play F3 Media Server 7.0.3 - Remote Denial of Service
2020-10-26
ReQuest Serious Play F3 Media Server 7.0.3 - Debug Log Disclosure
2020-10-26
ReQuest Serious Play Media Player 3.0 - Directory Traversal File Disclosure
2020-10-26
Genexis Platinum-4410 - 'SSID' Persistent XSS
2020-10-26
PDW File Browser 1.3 - 'new_filename' Cross-Site Scripting (XSS)
2020-10-26
InoERP 0.7.2 - Remote Code Execution (Unauthenticated)
2020-10-26
Online Health Care System 1.0 - Multiple Cross Site Scripting (Stored)
2020-10-26
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
2020-10-26
TextPattern CMS 4.8.3 - Remote Code Execution (Authenticated)
2020-10-23
Bludit 3.9.2 - Auth Bruteforce Bypass
2020-10-23
Gym Management System 1.0 - Stored Cross Site Scripting
2020-10-23
Gym Management System 1.0 - Authentication Bypass
2020-10-23
School Faculty Scheduling System 1.0 - 'username' SQL Injection
2020-10-23
School Faculty Scheduling System 1.0 - 'id' SQL Injection
2020-10-23
Point of Sales 1.0 - 'username' SQL Injection
2020-10-23
Gym Management System 1.0 - 'id' SQL Injection
2020-10-23
Lot Reservation Management System 1.0 - Cross-Site Scripting (Stored)
2020-10-23
Lot Reservation Management System 1.0 - Authentication Bypass
2020-10-23
Point of Sales 1.0 - 'id' SQL Injection
2020-10-23
User Registration & Login and User Management System 2.1 - SQL Injection
2020-10-23
Car Rental Management System 1.0 - Arbitrary File Upload
2020-10-23
Stock Management System 1.0 - 'brandId and categoriesId' SQL Injection
2020-10-23
Ajenti 2.1.36 - Remote Code Execution (Authenticated)
2020-10-23
Online Library Management System 1.0 - Arbitrary File Upload
2020-10-23
Tiki Wiki CMS Groupware 21.1 - Authentication Bypass
2020-10-21
Stock Management System 1.0 - 'Brand Name' Persistent Cross-Site Scripting
2020-10-21
Stock Management System 1.0 - 'Categories Name' Persistent Cross-Site Scripting
2020-10-21
Stock Management System 1.0 - 'Product Name' Persistent Cross-Site Scripting
2020-10-21
GOautodial 4.0 - Authenticated Shell Upload
2020-10-21
School Faculty Scheduling System 1.0 - Authentication Bypass POC
2020-10-21
School Faculty Scheduling System 1.0 - Stored Cross Site Scripting POC
2020-10-21
Hrsale 2.0.0 - Local File Inclusion
2020-10-21
WordPress Plugin Colorbox Lightbox v1.1.1 - Persistent Cross-Site Scripting (Authenticated)
2020-10-20
WordPress Plugin Rest Google Maps < 7.11.18 - SQL Injection
2020-10-20
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
2020-10-20
Mobile Shop System v1.0 - SQL Injection Authentication Bypass
2020-10-20
RiteCMS 2.2.1 - Remote Code Execution (Authenticated)
2020-10-20
User Registration & Login and User Management System With admin panel 2.1 - Persistent XSS
2020-10-20
WordPress Plugin HS Brand Logo Slider 2.1 - 'logoupload' File Upload
2020-10-20
Ultimate Project Manager CRM PRO Version 2.0.5 - SQLi (Authenticated)
2020-10-20
Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
2020-10-20
Wordpress Plugin WP Courses < 2.0.29 - Broken Access Controls leading to Courses Content Disclosure
2020-10-20
Loan Management System 1.0 - Multiple Cross Site Scripting (Stored)
2020-10-20
Comtrend AR-5387un router - Persistent XSS (Authenticated)
2020-10-20
Textpattern CMS 4.6.2 - Cross-site Request Forgery
2020-10-19
Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
2020-10-19
Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
2020-10-19
Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
2020-10-19
HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
2020-10-19
HiSilicon Video Encoders - Full admin access via backdoor password
2020-10-19
HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware
2020-10-19
HiSilicon Video Encoders - RCE via unauthenticated command injection
2020-10-19
Exploits/page:


Page:
1-4-2 (www01)