ManageEngine Service Desk 10.0 - Cross-Site Scripting
|
|
2020-05-23
|
vBulletin 5.6.1 - 'nodeId' SQL Injection
|
|
2020-05-23
|
E-Commerce System 1.0 - Unauthenticated Remote Code Execution
|
|
2020-05-23
|
Netlink XPON 1GE WiFi V2801RGW - Remote Command Execution
|
|
2020-05-23
|
Dameware Remote Support 12.1.1.273 - Buffer Overflow (SEH)
|
|
2020-05-23
|
Complaint Management System 1.0 - 'username' SQL Injection
|
|
2020-05-23
|
Sellacious eCommerce 4.6 - Persistent Cross-Site Scripting
|
|
2020-05-13
|
Tryton 5.4 - Persistent Cross-Site Scripting
|
|
2020-05-13
|
Remote Desktop Audit 2.3.0.157 - Buffer Overflow (SEH)
|
|
2020-05-13
|
MacOS 320.whatis Script - Privilege Escalation
|
|
2020-05-12
|
TylerTech Eagle 2018.3.11 - Remote Code Execution
|
|
2020-05-12
|
LanSend 3.2 - Buffer Overflow (SEH)
|
|
2020-05-12
|
qdPM 9.1 - Arbitrary File Upload
|
|
2020-05-12
|
Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site Scripting
|
|
2020-05-12
|
CuteNews 2.1.2 - Authenticated Arbitrary File Upload
|
|
2020-05-12
|
ChopSlider3 Wordpress Plugin3.4 - 'id' SQL Injection
|
|
2020-05-12
|
Orchard Core RC1 - Persistent Cross-Site Scripting
|
|
2020-05-12
|
Phase Botnet - Blind SQL Injection
|
|
2020-05-12
|
LibreNMS 1.46 - 'search' SQL Injection
|
|
2020-05-11
|
Complaint Management System 1.0 - Authentication Bypass
|
|
2020-05-11
|
Victor CMS 1.0 - 'post' SQL Injection
|
|
2020-05-11
|
OpenZ ERP 3.6.60 - Persistent Cross-Site Scripting
|
|
2020-05-11
|
SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
|
|
2020-05-11
|
CuteNews 2.1.2 - Arbitrary File Deletion
|
|
2020-05-11
|
Sentrifugo CMS 3.2 - Persistent Cross-Site Scripting
|
|
2020-05-11
|
Kartris 1.6 - Arbitrary File Upload
|
|
2020-05-11
|
Online AgroCulture Farm Management System 1.0 - 'uname' SQL Injection
|
|
2020-05-11
|
Pi-hole < 4.4 - Remote Code Execution / Privileges Escalation
|
|
2020-05-11
|
Pi-hole < 4.4 - Remote Code Execution
|
|
2020-05-11
|
Extreme Networks Aerohive HiveOS 11.0 - Remote Denial of Service (PoC)
|
|
2020-05-08
|
Online AgroCulture Farm Management System 1.0 - 'pid' SQL Injection
|
|
2020-05-07
|
Pisay Online E-Learning System 1.0 - Remote Code Execution
|
|
2020-05-07
|
Online Clothing Store 1.0 - Arbitrary File Upload
|
|
2020-05-07
|
School File Management System 1.0 - 'username' SQL Injection
|
|
2020-05-07
|
Draytek VigorAP 1000C - Persistent Cross-Site Scripting
|
|
2020-05-07
|
Car Park Management System 1.0 - Authentication Bypass
|
|
2020-05-07
|
FlashGet 1.9.6 - Denial of Service (PoC)
|
|
2020-05-07
|
MPC Sharj 3.11.1 - Arbitrary File Download
|
|
2020-05-06
|
YesWiki cercopitheque 2020.04.18.1 - 'id' SQL Injection
|
|
2020-05-06
|
GitLab 12.9.0 - Arbitrary File Read
|
|
2020-05-06
|
webTareas 2.0.p8 - Arbitrary File Deletion
|
|
2020-05-06
|
Online Clothing Store 1.0 - 'username' SQL Injection
|
|
2020-05-06
|
Booked Scheduler 2.7.7 - Authenticated Directory Traversal
|
|
2020-05-06
|
i-doit Open Source CMDB 1.14.1 - Arbitrary File Deletion
|
|
2020-05-06
|
Online Clothing Store 1.0 - Persistent Cross-Site Scripting
|
|
2020-05-06
|
NEC Electra Elite IPK II WebPro 01.03.01 - Session Enumeration
|
|
2020-05-05
|
SimplePHPGal 0.7 - Remote File Inclusion
|
|
2020-05-05
|
PhreeBooks ERP 5.2.5 - Remote Command Execution
|
|
2020-05-05
|
BlogEngine 3.3 - 'syndication.axd' XML External Entity Injection
|
|
2020-05-05
|
Saltstack 3000.2 - Remote Code Execution
|
|
2020-05-05
|
webERP 4.15.1 - Unauthenticated Backup File Access
|
|
2020-05-05
|
Online Scheduling System 1.0 - 'username' SQL Injection
|
|
2020-05-05
|
Oracle Database 11g Release 2 - 'OracleDBConsoleorcl' Unquoted Service Path
|
|
2020-05-05
|
Fishing Reservation System 7.5 - 'uid' SQL Injection
|
|
2020-05-05
|
addressbook 9.0.0.1 - 'id' SQL Injection
|
|
2020-05-04
|
Frigate 3.36 - Buffer Overflow (SEH)
|
|
2020-05-04
|
Outline Service 1.3.3 - 'Outline Service ' Unquoted Service Path
|
|
2020-05-04
|
osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting
|
|
2020-05-04
|
BoltWire 6.03 - Local File Inclusion
|
|
2020-05-04
|
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
|
|
2020-05-01
|
Online Scheduling System 1.0 - Authentication Bypass
|
|
2020-05-01
|
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
|
|
2020-05-01
|
HardDrive 2.1 for iOS - Arbitrary File Upload
|
|
2020-05-01
|
Super Backup 2.0.5 for iOS - Directory Traversal
|
|
2020-05-01
|
php-fusion 9.03.50 - Persistent Cross-Site Scripting
|
|
2020-05-01
|
Online Scheduling System 1.0 - Persistent Cross-Site Scripting
|
|
2020-05-01
|
VirtualTablet Server 3.0.2 - Denial of Service (PoC)
|
|
2020-05-01
|
ChemInv 1.0 - Authenticated Persistent Cross-Site Scripting
|
|
2020-05-01
|
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
|
|
2020-04-29
|
hits script 1.0 - 'item_name' SQL Injection
|
|
2020-04-29
|
EmEditor 19.8 - Insecure File Permissions
|
|
2020-04-29
|
Internet Download Manager 6.37.11.1 - Stack Buffer Overflow (PoC)
|
|
2020-04-29
|
Andrea ST Filters Service 1.0.64.7 - 'Andrea ST Filters Service ' Unquoted Service Path
|
|
2020-04-29
|
Easy Transfer 1.7 for iOS - Directory Traversal
|
|
2020-04-29
|
School ERP Pro 1.0 - Arbitrary File Read
|
|
2020-04-29
|
Open-AudIT Professional 3.3.1 - Remote Code Execution
|
|
2020-04-29
|
School ERP Pro 1.0 - Remote Code Execution
|
|
2020-04-29
|
NVIDIA Update Service Daemon 1.0.21 - 'nvUpdatusService' Unquoted Service Path
|
|
2020-04-29
|
School ERP Pro 1.0 - 'es_messagesid' SQL Injection
|
|
2020-04-29
|
CloudMe 1.11.2 - Buffer Overflow (PoC)
|
|
2020-04-29
|
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
|
|
2020-04-29
|
Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
|
|
2020-04-29
|
Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)
|
|
2020-04-29
|
Online Course Registration 2.0 - Authentication Bypass
|
|
2020-04-29
|
Netis E1+ V1.2.32533 - Unauthenticated WiFi Password Leak
|
|
2020-04-29
|
Online shopping system advanced 1.0 - 'p' SQL Injection
|
|
2020-04-29
|
Netis E1+ 1.2.32533 - Backdoor Account (root)
|
|
2020-04-29
|
PHP-Fusion 9.03.50 - 'Edit Profile' Arbitrary File Upload
|
|
2020-04-29
|
Furukawa Electric ConsciusMAP 2.8.1 - Remote Code Execution
|
|
2020-04-29
|
Linux/x64 - Password Protected Bindshell + Null-free Shellcode (272 Bytes)
|
|
2020-04-29
|
Popcorn Time 6.2 - 'Update service' Unquoted Service Path
|
|
2020-04-29
|
Edimax EW-7438RPn 1.13 - Remote Code Execution
|
|
2020-04-29
|
EspoCRM 5.8.5 - Privilege Escalation
|
|
2020-04-29
|
Sky File 2.1.0 iOS - Directory Traversal
|
|
2020-04-29
|
Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)
|
|
2020-04-23
|
Complaint Management System 4.2 - Cross-Site Request Forgery (Delete User)
|
|
2020-04-23
|
Complaint Management System 4.2 - Authentication Bypass
|
|
2020-04-23
|
Complaint Management System 4.2 - Persistent Cross-Site Scripting
|
|
2020-04-23
|
User Management System 2.0 - Authentication Bypass
|
|
2020-04-23
|
User Management System 2.0 - Persistent Cross-Site Scripting
|
|
2020-04-23
|
Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
|
|
2020-04-22
|
Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)
|
|
2020-04-22
|
Edimax EW-7438RPn - Information Disclosure (WiFi Password)
|
|
2020-04-22
|
RM Downloader 3.1.3.2.2010.06.13 - 'Load' Buffer Overflow (SEH)
|
|
2020-04-22
|
Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
|
|
2020-04-21
|
P5 FNIP-8x16A FNIP-4xSH 1.0.20 - Cross-Site Request Forgery (Add Admin)
|
|
2020-04-21
|
jizhi CMS 1.6.7 - Arbitrary File Download
|
|
2020-04-21
|
NSClient++ 0.5.2.35 - Authenticated Remote Code Execution
|
|
2020-04-21
|
Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
|
|
2020-04-21
|
IQrouter 3.3.1 Firmware - Remote Code Execution
|
|
2020-04-21
|
CSZ CMS 1.2.7 - 'title' HTML Injection
|
|
2020-04-21
|
PMB 5.6 - 'logid' SQL Injection
|
|
2020-04-21
|
Windows/x86 - MSVCRT System + Dynamic Null-free + Add RDP Admin + Disable Firewall + Enable RDP Shellcode (644 Bytes)
|
|
2020-04-21
|
CSZ CMS 1.2.7 - Persistent Cross-Site Scripting
|
|
2020-04-21
|
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
|
|
2020-04-20
|
Atomic Alarm Clock x86 6.3 - 'AtomicAlarmClock' Unquoted Service Path
|
|
2020-04-20
|
Rubo DICOM Viewer 2.0 - Buffer Overflow (SEH)
|
|
2020-04-20
|
Nsauditor 3.2.1.0 - Buffer Overflow (SEH+ASLR bypass (3 bytes overwrite))
|
|
2020-04-20
|
Fork CMS 5.8.0 - Persistent Cross-Site Scripting
|
|
2020-04-20
|
Atomic Alarm Clock 6.3 - Stack Overflow (Unicode+SEH)
|
|
2020-04-20
|
Centreon 19.10.5 - 'id' SQL Injection
|
|
2020-04-20
|
Code Blocks 16.01 - Buffer Overflow (SEH) UNICODE
|
|
2020-04-18
|
Nexus Repository Manager - Java EL Injection RCE (Metasploit)
|
|
2020-04-18
|
Cisco IP Phone 11.7 - Denial of service (PoC)
|
|
2020-04-18
|
TAO Open Source Assessment Platform 3.3.0 RC02 - HTML Injection
|
|
2020-04-18
|
Playable 9.18 iOS - Persistent Cross-Site Scripting
|
|
2020-04-18
|
Easy MPEG to DVD Burner 1.7.11 - Buffer Overflow (SEH + DEP)
|
|
2020-04-18
|
Apache Solr - Remote Code Execution via Velocity Template (Metasploit)
|
|
2020-04-18
|
VMware Fusion - USB Arbitrator Setuid Privilege Escalation (Metasploit)
|
|
2020-04-18
|
DotNetNuke - Cookie Deserialization Remote Code Execution (Metasploit)
|
|
2020-04-18
|
PlaySMS - index.php Unauthenticated Template Injection Code Execution (Metasploit)
|
|
2020-04-18
|
Pandora FMS - Ping Authenticated Remote Code Execution (Metasploit)
|
|
2020-04-18
|
ThinkPHP - Multiple PHP Injection RCEs (Metasploit)
|
|
2020-04-18
|
Liferay Portal - Java Unmarshalling via JSONWS RCE (Metasploit)
|
|
2020-04-18
|
TP-Link Archer A7/C7 - Unauthenticated LAN Remote Code Execution (Metasploit)
|
|
2020-04-18
|
BlazeDVD 7.0.2 - Buffer Overflow (SEH)
|
|
2020-04-15
|
Xeroneit Library Management System 3.0 - 'category' SQL Injection
|
|
2020-04-15
|
File Transfer iFamily 2.1 - Directory Traversal
|
|
2020-04-15
|
DedeCMS 7.5 SP2 - Persistent Cross-Site Scripting
|
|
2020-04-15
|
Macs Framework 1.14f CMS - Persistent Cross-Site Scripting
|
|
2020-04-15
|
SeedDMS 5.1.18 - Persistent Cross-Site Scripting
|
|
2020-04-15
|
Pinger 1.0 - Remote Code Execution
|
|
2020-04-15
|
SuperBackup 2.0.5 for iOS - Persistent Cross-Site Scripting
|
|
2020-04-15
|
AirDisk Pro 5.5.3 for iOS - Persistent Cross-Site Scripting
|
|
2020-04-15
|
Oracle WebLogic Server 12.2.1.4.0 - Remote Code Execution
|
|
2020-04-14
|
WSO2 3.1.0 - Persistent Cross-Site Scripting
|
|
2020-04-14
|
Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution
|
|
2020-04-14
|
B64dec 1.1.2 - Buffer Overflow (SEH Overflow + Egg Hunter)
|
|
2020-04-14
|
MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection
|
|
2020-04-13
|
Wordpress Plugin Media Library Assistant 2.81 - Local File Inclusion
|
|
2020-04-13
|
Free Desktop Clock x86 Venetian Blinds Zipper 3.0 - Unicode Stack Overflow (SEH)
|
|
2020-04-13
|
WSO2 3.1.0 - Arbitrary File Delete
|
|
2020-04-13
|
Webtateas 2.0 - Arbitrary File Read
|
|
2020-04-13
|
TVT NVMS 1000 - Directory Traversal
|
|
2020-04-13
|
Huawei HG630 2 Router - Authentication Bypass
|
|
2020-04-13
|
Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal
|
|
2020-04-10
|
Windscribe 1.83 - 'WindscribeService' Unquoted Service Path
|
|
2020-04-10
|
AbsoluteTelnet 11.12 - 'SSH1/username' Denial of Service (PoC)
|
|
2020-04-10
|
Amcrest Dahua NVR Camera IP2M-841 - Denial of Service (PoC)
|
|
2020-04-08
|
Django 3.0 - Cross-Site Request Forgery Token Bypass
|
|
2020-04-08
|
dnsmasq-utils 2.79-1 - 'dhcp_release' Denial of Service (PoC)
|
|
2020-04-07
|
ZOC Terminal 7.25.5 - 'Script' Denial of Service (PoC)
|
|
2020-04-07
|
pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
|
|
2020-04-06
|
Microsoft NET USE win10 - Insufficient Authentication Logic
|
|
2020-04-06
|
LimeSurvey 4.1.11 - 'File Manager' Path Traversal
|
|
2020-04-06
|
Bolt CMS 3.7.0 - Authenticated Remote Code Execution
|
|
2020-04-06
|
WhatsApp Desktop 0.3.9308 - Persistent Cross-Site Scripting
|
|
2020-04-06
|
Vesta Control Panel 0.9.8-26 - Authenticated Remote Code Execution (Metasploit)
|
|
2020-04-06
|
Triologic Media Player 8 - '.m3l' Buffer Overflow (Unicode) (SEH)
|
|
2020-04-06
|
ZOC Terminal v7.25.5 - 'Private key file' Denial of Service (PoC)
|
|
2020-04-06
|
UltraVNC Viewer 1.2.4.0 - 'VNCServer' Denial of Service (PoC)
|
|
2020-04-06
|
UltraVNC Launcher 1.2.4.0 - 'Password' Denial of Service (PoC)
|
|
2020-04-06
|
LimeSurvey 4.1.11 - 'Survey Groups' Persistent Cross-Site Scripting
|
|
2020-04-06
|
UltraVNC Launcher 1.2.4.0 - 'RepeaterHost' Denial of Service (PoC)
|
|
2020-04-06
|
Frigate 3.36 - Denial of Service (PoC)
|
|
2020-04-06
|
Nsauditor 3.2.0.0 - 'Name' Denial of Service (PoC)
|
|
2020-04-06
|
SpotAuditor 5.3.4 - 'Name' Denial of Service (PoC)
|
|
2020-04-06
|
Product Key Explorer 4.2.2.0 - 'Key' Denial of Service (PoC)
|
|
2020-04-06
|
Memu Play 7.1.3 - Insecure Folder Permissions
|
|
2020-04-06
|
AIDA64 Engineer 6.20.5300 - 'Report File' filename Buffer Overflow (SEH)
|
|
2020-04-03
|
Pandora FMS 7.0NG - 'net_tools.php' Remote Code Execution
|
|
2020-04-03
|
DiskBoss 7.7.14 - 'Input Directory' Local Buffer Overflow (PoC)
|
|
2020-04-02
|
10Strike LANState 9.32 - 'Force Check' Buffer Overflow (SEH)
|
|
2020-04-01
|
DiskBoss 7.7.14 - Denial of Service (PoC)
|
|
2020-04-01
|
SharePoint Workflows - XOML Injection (Metasploit)
|
|
2020-03-31
|
DLINK DWL-2600 - Authenticated Remote Command Injection (Metasploit)
|
|
2020-03-31
|
IBM TM1 / Planning Analytics - Unauthenticated Remote Code Execution (Metasploit)
|
|
2020-03-31
|
Redis - Replication Code Execution (Metasploit)
|
|
2020-03-31
|
Grandstream UCM6200 Series WebSocket 1.0.20.20 - 'user_password' SQL Injection
|
|
2020-03-31
|
Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection
|
|
2020-03-31
|
FlashFXP 4.2.0 Build 1730 - Denial of Service (PoC)
|
|
2020-03-31
|
Multiple DrayTek Products - Pre-authentication Remote Root Code Execution
|
|
2020-03-30
|
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation
|
|
2020-03-30
|
Zen Load Balancer 3.10.1 - Remote Code Execution
|
|
2020-03-30
|
10-Strike Network Inventory Explorer 9.03 - 'Read from File' Buffer Overflow (SEH)(ROP)
|
|
2020-03-30
|
Joomla! com_fabrik 3.9.11 - Directory Traversal
|
|
2020-03-30
|
Odin Secure FTP Expert 7.6.3 - 'Site Info' Denial of Service (PoC)
|
|
2020-03-30
|
rConfig 3.9.4 - 'searchField' Unauthenticated Root Remote Code Execution
|
|
2020-03-27
|
Jinfornet Jreport 15.6 - Unauthenticated Directory Traversal
|
|
2020-03-27
|
Everest 5.50.2100 - 'Open File' Denial of Service (PoC)
|
|
2020-03-27
|
ECK Hotel 1.0 - Cross-Site Request Forgery (Add Admin)
|
|
2020-03-27
|
Easy RM to MP3 Converter 2.7.3.700 - 'Input' Local Buffer Overflow (SEH)
|
|
2020-03-27
|
Centreo 19.10.8 - 'DisplayServiceStatus' Remote Code Execution
|
|
2020-03-26
|
TP-Link Archer C50 3 - Denial of Service (PoC)
|
|
2020-03-26
|
10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)
|
|
2020-03-25
|
Windows/x64 - WinExec Add-Admin Dynamic Null-Free Shellcode (210 Bytes)
|
|
2020-03-25
|
10-Strike Network Inventory Explorer - 'srvInventoryWebServer' Unquoted Service Path
|
|
2020-03-25
|
LeptonCMS 4.5.0 - Persistent Cross-Site Scripting
|
|
2020-03-25
|
AVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service Path
|
|
2020-03-25
|
Joomla! Component GMapFP 3.30 - Arbitrary File Upload
|
|
2020-03-25
|
UCM6202 1.0.18.13 - Remote Command Injection
|
|
2020-03-24
|
Veyon 4.3.4 - 'VeyonService' Unquoted Service Path
|
|
2020-03-24
|
Wordpress Plugin WPForms 1.5.9 - Persistent Cross-Site Scripting
|
|
2020-03-24
|
UliCMS 2020.1 - Persistent Cross-Site Scripting
|
|
2020-03-24
|
Linux\x86 - 'reboot' polymorphic Shellcode (26 bytes)
|
|
2020-03-23
|
Joomla! com_hdwplayer 4.2 - 'search.php' SQL Injection
|
|
2020-03-23
|
rConfig 3.9.4 - 'search.crud.php' Remote Command Injection
|
|
2020-03-23
|
FIBARO System Home Center 5.021 - Remote File Include
|
|
2020-03-23
|
CyberArk PSMP 10.9.1 - Policy Restriction Bypass
|
|
2020-03-23
|
Google Chrome 80.0.3987.87 - Heap-Corruption Remote Denial of Service (PoC)
|
|
2020-03-23
|
ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service (PoC)
|
|
2020-03-23
|
VMware Fusion 11.5.2 - Privilege Escalation
|
|
2020-03-20
|
Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)
|
|
2020-03-20
|
Broadcom Wi-Fi Devices - 'KR00K Information Disclosure
|
|
2020-03-19
|
VMWare Fusion - Local Privilege Escalation
|
|
2020-03-18
|
Microsoft VSCode Python Extension - Code Execution
|
|
2020-03-18
|
Windows\x64 - Dynamic MessageBoxA or MessageBoxW PEB & Import Table Method Shellcode (232 bytes)
|
|
2020-03-18
|
Microtik SSH Daemon 6.44.3 - Denial of Service (PoC)
|
|
2020-03-18
|
NetBackup 7.0 - 'NetBackup INET Daemon' Unquoted Service Path
|
|
2020-03-18
|
Netlink GPON Router 1.0.11 - Remote Code Execution
|
|
2020-03-18
|
ManageEngine Desktop Central - Java Deserialization (Metasploit)
|
|
2020-03-17
|
Rconfig 3.x - Chained Remote Code Execution (Metasploit)
|
|
2020-03-17
|
PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution
|
|
2020-03-16
|
PHPKB Multi-Language 9 - Authenticated Directory Traversal
|
|
2020-03-16
|
PHPKB Multi-Language 9 - Authenticated Remote Code Execution
|
|
2020-03-16
|
MiladWorkShop VIP System 1.0 - 'lang' SQL Injection
|
|
2020-03-16
|
Enhanced Multimedia Router 3.0.4.27 - Cross-Site Request Forgery (Add Admin)
|
|
2020-03-16
|
Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)
|
|
2020-03-14
|
Horde Groupware Webmail Edition 5.2.22 - Remote Code Execution
|
|
2020-03-14
|
Drobo 5N2 4.1.1 - Remote Command Injection
|
|
2020-03-13
|
Centos WebPanel 7 - 'term' SQL Injection
|
|
2020-03-13
|
AnyBurn 4.8 - Buffer Overflow (SEH)
|
|
2020-03-13
|
Horde Groupware Webmail Edition 5.2.22 - PHAR Loading
|
|
2020-03-12
|
Horde Groupware Webmail Edition 5.2.22 - PHP File Inclusion
|
|
2020-03-12
|
rConfig 3.9 - 'searchColumn' SQL Injection
|
|
2020-03-12
|
rConfig 3.93 - 'ajaxAddTemplate.php' Authenticated Remote Code Execution
|
|
2020-03-12
|
ASUS AAHM 1.00.22 - 'asHmComSvc' Unquoted Service Path
|
|
2020-03-12
|
HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)
|
|
2020-03-12
|
Wordpress Plugin Appointment Booking Calendar 1.3.34 - CSV Injection
|
|
2020-03-12
|
WatchGuard Fireware AD Helper Component 5.8.5.10317 - Credential Disclosure
|
|
2020-03-12
|