![]() 1 new exploits WordPress Multiple Versions - Pwnpress Exploitation Tookit (0.2pub) WordPress Core 1.5.1.1 <= 2.2.2 - Multiple Vulnerabilities WordPress and Pyrmont 2.x - SQL Injection WordPress Pyrmont 2.x Plugin - SQL Injection WordPress Copperleaf Photolog 0.16 - SQL injection WordPress Copperleaf Photolog 0.16 Plugin - SQL injection WordPress 3.3.1 - Multiple Vulnerabilities WordPress Core 3.3.1 - Multiple Vulnerabilities WordPress 2.x - PHP_Self Cross-Site Scripting WordPress Core 2.x - PHP_Self Cross-Site Scripting WordPress 2.2 - Request_URI Parameter Cross-Site Scripting WordPress Core 2.2 - Request_URI Parameter Cross-Site Scripting WordPress MailPoet - (wysija-newsletters) Unauthenticated File Upload WordPress MailPoet Newsletters 2.6.8 Plugin - (wysija-newsletters) Unauthenticated File Upload Drupal Core 7.32 - SQL Injection (1) Drupal Core 7.0 <= 7.31 - SQL Injection (SA-CORE-2014-005) (1) Drupal Core 7.32 - SQL Injection (2) Drupal Core 7.0 <= 7.31 - SQL Injection (SA-CORE-2014-005) (2) Drupal < 7.32 Pre Auth SQL Injection Drupal Core < 7.32 - Pre Auth SQL Injection Live Wire 2.3.1 For WordPress - Multiple Security Vulnerabilities Wordpress Live Wire 2.3.1 Theme - Multiple Security Vulnerabilities The Gazette Edition 2.9.4 For WordPress - Multiple Security Vulnerabilities WordPress The Gazette Edition 2.9.4 Theme - Multiple Security Vulnerabilities WordPress Webdorado Spider Event Calendar 1.4.9 - SQL Injection WordPress Webdorado Spider Event Calendar 1.4.9 Plugin - SQL Injection WordPress Trending 0.1 - 'cpage' Parameter Cross-Site Scripting WordPress Trending 0.1 Theme - 'cpage' Parameter Cross-Site Scripting WordPress WPML - Multiple Vulnerabilities WordPress WPML 3.1.9 Plugin - Multiple Vulnerabilities WordPress 4.2 - Stored XSS WordPress Core 4.2 - Stored XSS WordPress RevSlider File Upload and Execute WordPress RevSlider 3.0.95 Plugin - File Upload and Execute WordPress MailChimp Subscribe Forms 1.1 Remote Code Execution WordPress MailChimp Subscribe Forms 1.1 - Remote Code Execution WordPress Track That Stat 1.0.8 Cross-Site Scripting WordPress Track That Stat 1.0.8 - Cross-Site Scripting WordPress Aviary Image Editor Add On For Gravity Forms 3.0 Beta Shell Upload WordPress Aviary Image Editor Add On For Gravity Forms 3.0 Beta - Shell Upload WordPress Wp-ImageZoom 'file' Parameter Remote File Disclosure WordPress Wp-ImageZoom - 'file' Parameter Remote File Disclosure WordPress Flip Book 'php.php' Arbitrary File Upload WordPress Flip Book - 'php.php' Arbitrary File Upload WordPress PHPFreeChat 'url' Parameter Cross-Site Scripting WordPress PHPFreeChat - 'url' Parameter Cross-Site Scripting WordPress Finder 'order' Parameter Cross-Site Scripting WordPress Finder - 'order' Parameter Cross-Site Scripting WordPress Multiple Path Dislosure Vulnerabilities WordPress Core 3.4.2 - Multiple Path Dislosure Vulnerabilities WordPress Video Gallery 2.7 SQL Injection WordPress Video Gallery 2.7 - SQL Injection WordPress Cross Site Request Forgery WordPress - Cross Site Request Forgery WordPress CStar Design 'id' Parameter SQL Injection WordPress CStar Design Theme - 'id' Parameter SQL Injection WordPress White-Label Framework 2.0.6 - XSS WordPress White-Label Framework 2.0.6 Theme - XSS WordPress NextGEN Gallery 'upload.php' Arbitrary File Upload WordPress NextGEN Gallery - 'upload.php' Arbitrary File Upload WordPress Xorbin Digital Flash Clock 'widgetUrl' Parameter Cross-Site Scripting WordPress Xorbin Digital Flash Clock - 'widgetUrl' Parameter Cross-Site Scripting WordPress Lead Octopus Power 'id' Parameter SQL Injection WordPress Lead Octopus Power - 'id' Parameter SQL Injection WordPress Booking Calendar Contact Form 1.1.24 - Multiple Vulnerabilities WordPress Booking Calendar Contact Form 1.1.24 - addslashes SQL Injection WordPress Booking Calendar Contact Form 1.1.24 Plugin - Multiple Vulnerabilities WordPress Booking Calendar Contact Form 1.1.24 Plugin - addslashes SQL Injection Wordpress Ultimate Product Catalog 3.9.8 - (do_shortcode via ajax) Blind SQL Injection Wordpress Ultimate Product Catalog 3.9.8 Plugin - (do_shortcode via ajax) Blind SQL Injection Wireshark 1.12.0 - 1.12.12 - NDS Dissector Denial of Service Wireshark 2.0.0 to 2.0.4 - MMSE_ WAP_ WBXML_ and WSP Dissectors Denial of Service Wireshark 1.12.0-1.12.12 - NDS Dissector Denial of Service Wireshark 2.0.0 - 2.0.4 - MMSE_ WAP_ WBXML_ and WSP Dissectors Denial of Service Microsoft Office Word 2007_2010_2013_2016 - Out-of-Bounds Read Remote Code Execution (MS16-099) Microsoft Office Word 2007/2010/2013/2016 - Out-of-Bounds Read Remote Code Execution (MS16-099) WebNMS Framework Server 5.2 and 5.2 SP1 - Multiple Vulnerabilities WebNMS Framework Server 5.2 / 5.2 SP1 - Multiple Vulnerabilities ColoradoFTP 1.3 Prime Edition (Build 8) - Directory Traversal |
||
---|---|---|
.. | ||
dos | ||
remote | ||
webapps |