Vulnerability-Lab
343 exploits
Active since Jan 2008
WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting
CVSS 6.4
uBidAuction 2.0.1 mailingLog manage Reflected XSS
CVSS 6.1
uBidAuction 2.0.1 auctions manage Reflected XSS
CVSS 6.1
uBidAuction 2.0.1 tickets manage Reflected XSS
CVSS 6.1
uBidAuction 2.0.1 news manage Reflected XSS
CVSS 6.1
uBidAuction 2.0.1 posts manage Reflected XSS
CVSS 6.1
uBidAuction 2.0.1 myAuctions loose Reflected XSS
CVSS 6.1
uBidAuction 2.0.1 myAuctions active Reflected XSS
CVSS 6.1
uBidAuction 2.0.1 myOrders Reflected XSS
CVSS 6.1
Rocket LMS 1.1 Persistent Cross-Site Scripting via Support Tickets
CVSS 6.4
Ametys CMS 4.4.1 - Stored Cross-Site Scripting in Link Directory Input Fields
CVSS 6.1
Easy Transfer Wifi Transfer v1.7 - XSS
Easy Transfer 1.7 iOS - Path Traversal
CVSS 6.2
Fishing Reservation System 7.5 - SQL Injection
CVSS 7.1
OpenZ ERP 3.6.60 - Stored Cross-Site Scripting in Employee Module Parameters
CVSS 6.4
RDP Manager 4.9.9.3 - Denial of Service via Oversized Connection Input Fields
CVSS 5.5
Isshue Shopping Cart 3.5 - Stored Cross-Site Scripting in Title Input Fields
CVSS 4.8
ImportExportTools NG 10.0.4 - Stored Cross-Site Scripting in Email Export Module
CVSS 6.1
Tryton < 5.4 - Stored Cross-Site Scripting via User Profile Name Input
CVSS 6.4
Sellacious eCommerce < 4.6 - Stored Cross-Site Scripting in Manage Your Addresses Module
CVSS 6.4
Froxlor Server Management Panel <0.10.16 - XSS
CVSS 6.4
VestaCP 0.9.8-26 - Incorrect Authorization via LoginAs Session Token Manipulation
CVSS 9.8
ManageEngine SupportCenter Plus 7.90 - Path Traversal & Arbitrary File Write via Attachment.jsp
Olat 7.8.0.1 - Cross-Site Scripting via Calendar Event Name or Date Field
diy-cms 1.0 - Cross-Site Request Forgery via Poll Module