Responsive FileManager 9.13.4 - 'path' Path Traversal
|
|
2021-01-05
|
Baby Care System 1.0 - 'Post title' Stored XSS
|
|
2021-01-05
|
Responsive ELearning System 1.0 - 'id' Sql Injection
|
|
2021-01-05
|
Online Movie Streaming 1.0 - Authentication Bypass
|
|
2021-01-05
|
WordPress Plugin WP-Paginate 2.1.3 - 'preset' Stored XSS
|
|
2021-01-05
|
WordPress Plugin Stripe Payments 2.0.39 - 'AcceptStripePayments-settings[currency_code]' Stored XSS
|
|
2021-01-05
|
Resumes Management and Job Application Website 1.0 - Authentication Bypass (Sql Injection)
|
|
2021-01-05
|
House Rental and Property Listing 1.0 - Multiple Stored XSS
|
|
2021-01-05
|
IncomCMS 2.0 - Insecure File Upload
|
|
2021-01-05
|
Intel(R) Matrix Storage Event Monitor x86 8.0.0.1039 - 'IAANTMON' Unquoted Service Path
|
|
2021-01-05
|
Parallels Remote Application Server (RAS) 18 IP Disclosure - Paper
|
|
2021-01-04
|
Arteco Web Client DVR/NVR - 'SessionId' Brute Force
|
|
2021-01-04
|
Click2Magic 1.1.5 - Stored Cross-Site Scripting
|
|
2021-01-04
|
Subrion CMS 4.2.1 - 'avatar[path]' XSS
|
|
2021-01-04
|
CMS Made Simple 2.2.15 - RCE (Authenticated)
|
|
2021-01-04
|
sar2html 3.2.1 - 'plot' Remote Code Execution
|
|
2021-01-04
|
Advanced Comment System 1.0 - 'ACS_path' Path Traversal
|
|
2021-01-04
|
Knockpy 4.1.1 - CSV Injection
|
|
2021-01-04
|
A Hands-On Introduction to Insecure Deserialization - Paper
|
|
2021-01-04
|
Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
|
|
2021-01-04
|
4images v1.7.11 - 'Profile Image' Stored Cross-Site Scripting
|
|
2021-01-04
|
Wordpress Core 5.2.2 - 'post previews' XSS
|
|
2021-01-04
|
Easy CD & DVD Cover Creator 4.13 - Denial of Service (PoC)
|
|
2021-01-04
|
MiniTool ShadowMaker 3.2 - 'MTAgentService' Unquoted Service Path
|
|
2021-01-04
|
Apartment Visitors Management System 1.0 - Authentication Bypass
|
|
2020-12-24
|
GitLab 11.4.7 - RCE (Authenticated)
|
|
2020-12-24
|
WordPress Plugin WP-PostRatings 1.86 - 'postratings_image' Cross-Site Scripting
|
|
2020-12-24
|
WordPress Plugin Adning Advertising 1.5.5 - Arbitrary File Upload
|
|
2020-12-24
|
Baby Care System 1.0 - 'roleid' SQL Injection
|
|
2020-12-23
|
TerraMaster TOS 4.2.06 - Unauthenticated Remote Code Execution (Metasploit)
|
|
2020-12-23
|
Sales and Inventory System for Grocery Store 1.0 - Multiple Stored XSS
|
|
2020-12-23
|
Wordpress Epsilon Framework Multiple Themes - Unauthenticated Function Injection
|
|
2020-12-23
|
Online Learning Management System 1.0 - 'id' SQL Injection
|
|
2020-12-23
|
Online Learning Management System 1.0 - Multiple Stored XSS
|
|
2020-12-23
|
Online Learning Management System 1.0 - Authentication Bypass
|
|
2020-12-23
|
Class Scheduling System 1.0 - Multiple Stored XSS
|
|
2020-12-23
|
10-Strike Network Inventory Explorer Pro 9.05 - Buffer Overflow (SEH)
|
|
2020-12-22
|
TerraMaster TOS 4.2.06 - RCE (Unauthenticated)
|
|
2020-12-22
|
Faculty Evaluation System 1.0 - Stored XSS
|
|
2020-12-22
|
Artworks Gallery Management System 1.0 - 'id' SQL Injection
|
|
2020-12-22
|
Webmin 1.962 - 'Package Updates' Escape Bypass RCE (Metasploit)
|
|
2020-12-22
|
WordPress Plugin W3 Total Cache - Unauthenticated Arbitrary File Read (Metasploit)
|
|
2020-12-22
|
Multi Branch School Management System 3.5 - "Create Branch" Stored XSS
|
|
2020-12-22
|
Library Management System 3.0 - "Add Category" Stored XSS
|
|
2020-12-22
|
CSE Bookstore 1.0 - Multiple SQL Injection
|
|
2020-12-22
|
Pandora FMS 7.0 NG 750 - 'Network Scan' SQL Injection (Authenticated)
|
|
2020-12-22
|
Victor CMS 1.0 - File Upload To RCE
|
|
2020-12-22
|
Sony Playstation 4 (PS4) < 7.02 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code Execution (PoC)
|
|
2020-12-21
|
Sony Playstation 4 (PS4) < 6.72 - 'ValidationMessage::buildBubbleTree()' Use-After-Free WebKit Code Execution (PoC)
|
|
2020-12-21
|
Online Marriage Registration System 1.0 - 'searchdata' SQL Injection
|
|
2020-12-21
|