2021-05-25 |
wordpress plugin cookie law bar 1.2.1 - 'clb_bar_msg' stored cross-site scripting (xss)
|
webapps exploit |
php vulnerability |
2021-05-25 |
gadget works online ordering system 1.0 - 'category' persistent cross-site scripting (xss)
|
webapps exploit |
php vulnerability |
2021-05-24 |
wordpress plugin redi restaurant reservation 21.0307 - 'comment' stored cross-site scripting (xss)
|
webapps exploit |
php vulnerability |
2021-05-24 |
codiad 2.8.4 - remote code execution (authenticated) (2)
|
webapps exploit |
multiple vulnerability |
2021-05-24 |
shopizer 2.16.0 - 'multiple' cross-site scripting (xss)
|
webapps exploit |
java vulnerability |
2021-05-24 |
epowersvc 6.0.3008.0 - 'epowersvc.exe' unquoted service path
|
local exploit |
windows vulnerability |
2021-05-24 |
diskboss service 12.2.18 - 'diskbsa.exe' unquoted service path
|
local exploit |
windows vulnerability |
2021-05-24 |
idailydiary 4.30 - denial of service (poc)
|
dos exploit |
windows vulnerability |
2021-05-24 |
schlix cms 2.2.6-6 - arbitary file upload and directory traversal leads to rce (authenticated)
|
webapps exploit |
multiple vulnerability |
2021-05-21 |
solaris sunssh 11.0 x86 - libpam remote root (2)
|
remote exploit |
solaris vulnerability |
2021-05-21 |
microsoft exchange 2019 - unauthenticated email download (metasploit)
|
webapps exploit |
windows vulnerability |
2021-05-21 |
dell dbutil_2_3.sys 2.3 - arbitrary write to local privilege escalation (lpe)
|
local exploit |
windows vulnerability |
2021-05-21 |
mozilla firefox 88.0.1 - file extension execution of arbitrary code
|
local exploit |
windows vulnerability |
2021-05-21 |
spotweb 1.4.9 - dom based cross-site scripting (xss)
|
webapps exploit |
multiple vulnerability |
2021-05-20 |
acer updater service 1.2.3500.0 - 'updaterservice.exe'unquoted service path
|
local exploit |
windows vulnerability |
2021-05-20 |
backup manager module 3.0.0.99 - 'ischedulesvc.exe' unquoted service path
|
local exploit |
windows vulnerability |
2021-05-20 |
asus hid access service 1.0.94.0 - 'ashidsrv.exe' unquoted service path
|
local exploit |
windows vulnerability |
2021-05-19 |
covid19 testing management system 1.0 - 'admin name' cross-site scripting (xss)
|
webapps exploit |
php vulnerability |
2021-05-19 |
covid19 testing management system 1.0 - sql injection (auth bypass)
|
webapps exploit |
php vulnerability |
2021-05-19 |
manageengine adselfservice plus 6.1 - csv injection
|
webapps exploit |
multiple vulnerability |
2021-05-19 |
in4suit erp 3.2.74.1370 - 'txtloginid' sql injection
|
webapps exploit |
multiple vulnerability |
2021-05-19 |
webssh for ios 14.16.10 - 'mashrepl' denial of service (poc)
|
dos exploit |
ios vulnerability |
2021-05-19 |
visual studio code 1.47.1 - denial of service (poc)
|
local exploit |
windows vulnerability |
2021-05-19 |
wordpress plugin stop spammers 2021.8 - 'log' reflected cross-site scripting (xss)
|
webapps exploit |
php vulnerability |
2021-05-18 |
microsoft exchange 2019 - unauthenticated email download
|
webapps exploit |
windows vulnerability |
2021-05-18 |
egavilanmedia phpcrud 1.0 - 'first name' sql injection
|
webapps exploit |
php vulnerability |
2021-05-17 |
printable staff id card creator system 1.0 - sqli & rce via arbitrary file upload
|
webapps exploit |
php vulnerability |
2021-05-17 |
subrion cms 4.2.1 - file upload bypass to rce (authenticated)
|
webapps exploit |
php vulnerability |
2021-05-17 |
advanced guestbook 2.4.4 - 'smilies' persistent cross-site scripting (xss)
|
webapps exploit |
php vulnerability |
2021-05-17 |
billing management system 2.0 - union based sql injection (authenticated)
|
webapps exploit |
php vulnerability |
2021-05-17 |
simple chatbot application 1.0 - 'category' stored cross site scripting
|
webapps exploit |
php vulnerability |
2021-05-17 |
microsoft internet explorer 8 - 'setmousecapture ' use after free
|
local exploit |
windows vulnerability |
2021-05-17 |
dental clinic appointment reservation system 1.0 - cross site request forgery (add admin)
|
webapps exploit |
php vulnerability |
2021-05-17 |
dental clinic appointment reservation system 1.0 - 'firstname' persistent cross site scripting (authenticated)
|
webapps exploit |
php vulnerability |
2021-05-17 |
ipfire 2.25 - remote code execution (authenticated)
|
webapps exploit |
cgi vulnerability |
2021-05-17 |
customer relationship management (crm) system 1.0 - 'category' persistent cross site scripting
|
webapps exploit |
php vulnerability |
2021-05-14 |
chamilo lms 1.11.14 - remote code execution (authenticated)
|
webapps exploit |
php vulnerability |
2021-05-14 |
podcast generator 3.1 - 'long description' persistent cross-site scripting (xss)
|
webapps exploit |
php vulnerability |
2021-05-14 |
student management system 1.0 - 'message' persistent cross-site scripting (authenticated)
|
webapps exploit |
php vulnerability |
2021-05-13 |
firefox 72 ionmonkey - jit type confusion
|
local exploit |
windows_x86-64 vulnerability |
2021-05-13 |
microsoft internet explorer 8/11 and wpad service 'jscript.dll' - use-after-free
|
local exploit |
windows_x86-64 vulnerability |
2021-05-13 |
zeroshell 3.9.0 - remote command execution
|
webapps exploit |
linux vulnerability |
2021-05-13 |
dental clinic appointment reservation system 1.0 - 'date' union based sql injection (authenticated)
|
webapps exploit |
php vulnerability |
2021-05-13 |
dental clinic appointment reservation system 1.0 - authentication bypass (sqli)
|
webapps exploit |
php vulnerability |
2021-05-12 |
chevereto 3.17.1 - cross site scripting (stored)
|
webapps exploit |
multiple vulnerability |
2021-05-12 |
splinterware system scheduler professional 5.30 - privilege escalation
|
local exploit |
windows vulnerability |
2021-05-11 |
odoo 12.0.20190101 - 'nssm.exe' unquoted service path
|
local exploit |
windows vulnerability |
2021-05-10 |
microweber cms 1.1.20 - remote code execution (authenticated)
|
webapps exploit |
php vulnerability |
2021-05-10 |
linux/x86 - setreuid(0) + execve("/bin/sh") shellcode (29 bytes)
|
shellcode exploit |
linux_x86 vulnerability |
2021-05-10 |
human resource information system0.1- 'first name' persistent cross-site scripting (authenticated)
|
webapps exploit |
php vulnerability |