[dos] QNap QVR Client 5.1.1.30070 – 'Password' Denial of Service (PoC)

QNap QVR Client 5.1.1.30070 – ‘Password’ Denial of Service (PoC)

Davolink DVW 3200 Router Password Disclosure

The Davolink DVW 32000 router suffers from a password disclosure vulnerability.

Shopclues.com Cross Site Request Forgery

Shopclues.com suffers from a cross site request forgery vulnerability.

McAfee.com Redirect Cross Site Scripting

A URL redirect at mcafee.com suffers from a cross site scripting vulnerability.

SMPlayer 18.6.0 Memory Corruption

SMPlayer version 18.6.0 suffers from a memory corruption vulnerability that allows for denial of service.

NUUO NVRmini upgrade_handle.php Remote Command Execution

NUUO NVRmini suffers from a remote command execution vulnerability in upgrade_handle.php.

GeoVision GV-SNVR0811 Directory Traversal

GeoVision GV-SNVR0811 suffers from a directory traversal vulnerability.

Microsoft Windows Kernel Malformed GPOS Table Buffer Overflow

The Microsoft Windows kernel suffers from an OTF font processing pool-based buffer overflow via a malformed GPOS table in ATMFD.DLL.

[dos] Core FTP 2.0 – 'XRMD' Denial of Service (PoC)

Core FTP 2.0 – ‘XRMD’ Denial of Service (PoC)

[webapps] Trivum Multiroom Setup Tool 8.76 – Corss-Site Request Forgery (Admin Bypass)

Trivum Multiroom Setup Tool 8.76 – Corss-Site Request Forgery (Admin Bypass)