Openfire 4.6.0 - 'groupchatJID' Stored XSS
|
|
2020-12-19
|
Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting
|
|
2020-12-19
|
WordPress Plugin Popup Builder 3.69.6 - Multiple Stored Cross Site Scripting
|
|
2020-12-19
|
Library Management System 2.0 - Auth Bypass SQL Injection
|
|
2020-12-19
|
Openfire 4.6.0 - 'path' Stored XSS
|
|
2020-12-19
|
OpenCart 3.0.3.6 - Cross Site Request Forgery
|
|
2020-12-19
|
Barcodes generator 1.0 - 'name' Stored Cross Site Scripting
|
|
2020-12-19
|
PDF Complete 3.5.310.2002 - 'pdfsvc.exe' Unquoted Service Path
|
|
2020-12-19
|
Task Management System 1.0 - 'id' SQL Injection
|
|
2020-12-19
|
Task Management System 1.0 - Unrestricted File Upload to Remote Code Execution
|
|
2020-12-19
|
Task Management System 1.0 - 'First Name and Last Name' Stored XSS
|
|
2020-12-19
|
Tibco ObfuscationEngine 5.11 - Fixed Key Password Decryption
|
|
2020-12-19
|
VestaCP 0.9.8-26 - 'backup' Information Disclosure
|
|
2020-12-19
|
VestaCP 0.9.8-26 - 'LoginAs' Insufficient Session Validation
|
|
2020-12-19
|
Huawei HedEx Lite 200R006C00SPC005 - Path Traversal
|
|
2020-12-19
|
Dup Scout Enterprise 10.0.18 - 'sid' Remote Buffer Overflow (SEH)
|
|
2020-12-19
|
SmarterMail Build 6985 - Remote Code Execution
|
|
2020-12-19
|
Employee Performance Evaluation System 1.0 - 'Task and Description' Persistent Cross Site Scripting
|
|
2020-12-08
|
Online Bus Ticket Reservation 1.0 - SQL Injection
|
|
2020-12-08
|
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell)
|
|
2020-12-07
|
Dup Scout Enterprise 10.0.18 - 'online_registration' Remote Buffer Overflow
|
|
2020-12-07
|
vBulletin 5.6.3 - 'group' Cross Site Scripting
|
|
2020-12-07
|
Savsoft Quiz 5 - 'Skype ID' Stored XSS
|
|
2020-12-07
|
RarmaRadio 2.72.5 - Denial of Service (PoC)
|
|
2020-12-07
|
TapinRadio 2.13.7 - Denial of Service (PoC)
|
|
2020-12-07
|
Kite 1.2020.1119.0 - 'KiteService' Unquoted Service Path
|
|
2020-12-07
|
User Registration & Login and User Management System 2.1 - Cross Site Request Forgery
|
|
2020-12-07
|
Employee Record Management System 1.1 - Login Bypass SQL Injection
|
|
2020-12-07
|
Realtek Andrea RT Filters 1.0.64.7 - 'AERTSr64.EXE' Unquoted Service Path
|
|
2020-12-07
|
Joomla Plugin Simple Image Gallery Extended (SIGE) 3.5.3 - Multiple Vulnerabilities
|
|
2020-12-07
|
Realtek Audio Service 1.0.0.55 - 'RtkAudioService64.exe' Unquoted Service Path
|
|
2020-12-07
|
PandoraFMS NG747 7.0 - 'filename' Persistent Cross-Site Scripting
|
|
2020-12-07
|
Eaton Intelligent Power Manager 1.6 - Directory Traversal
|
|
2020-12-07
|
Cyber Cafe Management System Project (CCMS) 1.0 - Persistent Cross-Site Scripting
|
|
2020-12-07
|
Rumble Mail Server 0.51.3135 - 'rumble_win32.exe' Unquoted Service Path
|
|
2020-12-07
|
Zabbix 5.0.0 - Stored XSS via URL Widget Iframe
|
|
2020-12-04
|
CMS Made Simple 2.2.15 - Stored Cross-Site Scripting via SVG File Upload (Authenticated)
|
|
2020-12-04
|
Laravel Nova 3.7.0 - 'range' DoS
|
|
2020-12-04
|
Forma LMS 2.3 - 'First & Last Name' Stored Cross-Site Scripting
|
|
2020-12-04
|
Savsoft Quiz 5 - 'field_title' Stored Cross-Site Scripting
|
|
2020-12-04
|
Chromium 83 - Full CSP Bypass
|
|
2020-12-04
|
Testa Online Test Management System 3.4.7 - 'q' SQL Injection
|
|
2020-12-04
|
MiniCMS 1.10 - 'content box' Stored XSS
|
|
2020-12-04
|
Phpscript-sgh 0.1.0 - Time Based Blind SQL Injection
|
|
2020-12-04
|
IDT PC Audio 1.0.6499.0 - 'STacSV' Unquoted Service Path
|
|
2020-12-04
|
Composr CMS 10.0.34 - 'banners' Persistent Cross Site Scripting
|
|
2020-12-04
|
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
|
|
2020-12-04
|
Invision Community 4.5.4 - 'Field Name' Stored Cross-Site Scripting
|
|
2020-12-03
|
Sony BRAVIA Digital Signage 1.7.8 - System API Information Disclosure
|
|
2020-12-03
|
Sony BRAVIA Digital Signage 1.7.8 - Unauthenticated Remote File Inclusion
|
|
2020-12-03
|
mojoPortal forums 2.7.0.0 - 'Title' Persistent Cross-Site Scripting
|
|
2020-12-03
|
Online Matrimonial Project 1.0 - Authenticated Remote Code Execution
|
|
2020-12-03
|
EgavilanMedia Address Book 1.0 Exploit - SQLi Auth Bypass
|
|
2020-12-03
|
Coastercms 5.8.18 - Stored XSS
|
|
2020-12-03
|
Microsoft Windows - Win32k Elevation of Privilege
|
|
2020-12-02
|
WordPress Plugin Wp-FileManager 6.8 - RCE
|
|
2020-12-02
|
Car Rental Management System 1.0 - SQL Injection / Local File include
|
|
2020-12-02
|
Mitel mitel-cs018 - Call Data Information Disclosure
|
|
2020-12-02
|
Simple College Website 1.0 - 'page' Local File Inclusion
|
|
2020-12-02
|
Anuko Time Tracker 1.19.23.5311 - Password Reset leading to Account Takeover
|
|
2020-12-02
|
Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality
|
|
2020-12-02
|
ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)
|
|
2020-12-02
|
ChurchCRM 4.2.0 - CSV/Formula Injection
|
|
2020-12-02
|
WebDamn User Registration & Login System with User Panel - SQLi Auth Bypass
|
|
2020-12-02
|
Ksix Zigbee Devices - Playback Protection Bypass (PoC)
|
|
2020-12-02
|
DotCMS 20.11 - Stored Cross-Site Scripting
|
|
2020-12-02
|
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile
|
|
2020-12-02
|
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Add Artwork
|
|
2020-12-02
|
WonderCMS 3.1.3 - 'Menu' Persistent Cross-Site Scripting
|
|
2020-12-02
|
Local Service Search Engine Management System 1.0 - SQLi Authentication Bypass
|
|
2020-12-02
|
Online News Portal System 1.0 - 'Title' Stored Cross Site Scripting
|
|
2020-12-02
|
Bakeshop Online Ordering System 1.0 - 'Owner' Persistent Cross-site scripting
|
|
2020-12-02
|
NewsLister - Authenticated Persistent Cross-Site Scripting
|
|
2020-12-02
|
Online Voting System Project in PHP - 'username' Persistent Cross-Site Scripting
|
|
2020-12-02
|
IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path
|
|
2020-12-02
|
PRTG Network Monitor 20.4.63.1412 - 'maps' Stored XSS
|
|
2020-12-02
|
WonderCMS 3.1.3 - Authenticated Remote Code Execution
|
|
2020-12-02
|
WonderCMS 3.1.3 - Authenticated SSRF to Remote Remote Code Execution
|
|
2020-12-02
|
EgavilanMedia User Registration & Login System with Admin Panel 1.0 - Stored Cross Site Scripting
|
|
2020-12-02
|
Student Result Management System 1.0 - Authentication Bypass SQL Injection
|
|
2020-12-02
|
User Registration & Login System with Admin Panel - CSRF
|
|
2020-12-02
|
Under Construction Page with CPanel 1.0 - SQL injection
|
|
2020-12-02
|
Pharmacy Store Management System 1.0 - 'id' SQL Injection
|
|
2020-12-02
|
ILIAS Learning Management System 4.3 - SSRF
|
|
2020-12-02
|
aSc TimeTables 2021.6.2 - Denial of Service (PoC)
|
|
2020-12-02
|
Expense Management System - 'description' Stored Cross Site Scripting
|
|
2020-12-02
|
Tendenci 12.3.1 - CSV/ Formula Injection
|
|
2020-12-01
|
Intel(r) Management and Security Application 5.2 - User Notification Service Unquoted Service Path
|
|
2020-12-01
|
Pearson Vue VTS 2.3.1911 Installer - VUEApplicationWrapper Unquoted Service Path
|
|
2020-12-01
|
Global Registration Service 1.0.0.3 - 'GREGsvc.exe' Unquoted Service Path
|
|
2020-12-01
|
EPSON Status Monitor 3 'EPSON_PM_RPCV4_06' - Unquoted Service Path
|
|
2020-12-01
|
Social Networking Site - Authentication Bypass (SQli)
|
|
2020-12-01
|
Pandora FMS 7.0 NG 749 - Multiple Persistent Cross-Site Scripting Vulnerabilities # Date: 11-14-2020
|
|
2020-12-01
|
Medical Center Portal Management System 1.0 - 'login' SQL Injection
|
|
2020-12-01
|
LEPTON CMS 4.7.0 - 'URL' Persistent Cross-Site Scripting
|
|
2020-12-01
|
Tailor Management System 1.0 - Unrestricted File Upload to Remote Code Execution
|
|
2020-12-01
|
Multi Restaurant Table Reservation System 1.0 - Multiple Persistent XSS
|
|
2020-12-01
|
10-Strike Network Inventory Explorer 8.65 - Buffer Overflow (SEH)
|
|
2020-12-01
|
Setelsa Conacwin 3.7.1.2 - Local File Inclusion
|
|
2020-12-01
|
Pharmacy/Medical Store & Sale Point 1.0 - 'email' SQL Injection
|
|
2020-12-01
|