Exploits (Total: 98348)

    
    
    
ICE Hrm 29.0.0.OS - 'xml upload' Stored Cross-Site Scripting (XSS)
2021-06-18
ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Request Forgery (CSRF)
2021-06-18
ICE Hrm 29.0.0.OS - 'Account Takeover' Cross-Site Scripting and Session Fixation
2021-06-18
Online Shopping Portal 3.1 - Remote Code Execution (Unauthenticated)
2021-06-17
Workspace ONE Intelligent Hub 20.3.8.0 - 'VMware Hub Health Monitoring Service' Unquoted Service Path
2021-06-17
Zoho ManageEngine ServiceDesk Plus MSP 9.4 - User Enumeration
2021-06-17
VX Search 13.5.28 - 'Multiple' Unquoted Service Path
2021-06-17
Dup Scout 13.5.28 - 'Multiple' Unquoted Service Path
2021-06-17
Disk Savvy 13.6.14 - 'Multiple' Unquoted Service Path
2021-06-17
Sync Breeze 13.6.18 - 'Multiple' Unquoted Service Path
2021-06-17
Unified Office Total Connect Now 1.0 - 'data' SQL Injection
2021-06-17
CKEditor 3 - Server-Side Request Forgery (SSRF)
2021-06-16
Penetration testing Web Storage (User Experience) - Paper (Arabic)
2021-06-16
Teachers Record Management System 1.0 - 'email' Stored Cross-site Scripting (XSS)
2021-06-16
Teachers Record Management System 1.0 - 'Multiple' SQL Injection (Authenticated)
2021-06-16
OpenEMR 5.0.1.3 - '/portal/account/register.php' Authentication Bypass
2021-06-16
Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting
2021-06-16
Disk Sorter Server 13.6.12 - 'Disk Sorter Server' Unquoted Service Path
2021-06-16
DiskPulse 13.6.14 - 'Multiple' Unquoted Service Path
2021-06-16
Polkit 0.105-26 0.117-2 - Local Privilege Escalation
2021-06-15
Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path
2021-06-15
SysGauge 7.9.18 - ' SysGauge Server' Unquoted Service Path
2021-06-15
Client Management System 1.1 - 'Search' SQL Injection
2021-06-15
Client Management System 1.1 - 'username' Stored Cross-Site Scripting (XSS)
2021-06-15
XML External Entity via MP3 File Upload on WordPress - Paper
2021-06-15
Brother BRPrint Auditor - 'Multiple' Unquoted Service Path
2021-06-15
Tftpd64 4.64 - 'Tftpd32_svc' Unquoted Service Path
2021-06-14
Notex the best notes 6.4 - Denial of Service (PoC)
2021-06-14
Post-it 5.0.1 - Denial of Service (PoC)
2021-06-14
Secure Notepad Private Notes 3.0.3 - Denial of Service (PoC)
2021-06-14
WibuKey Runtime 6.51 - 'WkSvW32.exe' Unquoted Service Path
2021-06-14
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated)
2021-06-14
Spy Emergency 25.0.650 - 'Multiple' Unquoted Service Path
2021-06-14
TextPattern CMS 4.8.7 - Remote Command Execution (Authenticated)
2021-06-14
Small CRM 3.0 - 'Authentication Bypass' SQL Injection
2021-06-14
Stock Management System 1.0 - 'user_id' Blind SQL injection (Authenticated)
2021-06-14
COVID19 Testing Management System 1.0 - 'State' Stored Cross-Site-Scripting (XSS)
2021-06-14
GLPI 9.4.5 - Remote Code Execution (RCE)
2021-06-14
Accela Civic Platform 21.1 - 'contactSeqNumber' Insecure Direct Object References (IDOR)
2021-06-14
Accela Civic Platform 21.1 - 'successURL' Cross-Site-Scripting (XSS)
2021-06-14
WoWonder Social Network Platform 3.1 - Authentication Bypass
2021-06-13
Zenario CMS 8.8.52729 - 'cID' Blind & Error based SQL injection (Authenticated)
2021-06-13
Solar-Log 500 2.8.2 - Unprotected Storage of Credentials
2021-06-13
Solar-Log 500 2.8.2 - Incorrect Access Control
2021-06-13
Grocery crud 1.6.4 - 'order_by' SQL Injection
2021-06-13
WordPress Plugin Database Backups 1.2.2.6 - 'Database Backup Download' CSRF
2021-06-13
OpenEMR 5.0.0 - Remote Code Execution (Authenticated)
2021-06-13
Microsoft SharePoint Server 16.0.10372.20060 - 'GetXmlDataFromDataSource' Server-Side Request Forgery (SSRF)
2021-06-13
Cerberus FTP Web Service 11 - 'svg' Stored Cross-Site Scripting (XSS)
2021-06-13
Accela Civic Platform 21.1 - 'servProvCode' Cross-Site-Scripting (XSS)
2021-06-13
Exploits/page:


Page:
1-4-2 (www02)