The TP-Link TL-WA855RE V5_200415 suffers from a flow where an unauthenticated attacker can reset the device and then set a new administrator password.
>> ARCHIVE: 2020-11
LifeRay version 7.2.1 GA2 suffers from a persistent cross site scripting vulnerability.
http://www.sa-aat.go.th notified by Xyp3r2667
http://www.muangphoe.go.th notified by Xyp3r2667
http://jaroensuk.go.th notified by Xyp3r2667
http://www.sajorakhea.go.th notified by Xyp3r2667
OpenCart 3.0.3.6 – ‘subject’ Stored Cross-Site Scripting
Apache OpenMeetings 5.0.0 – ‘hostname’ Denial of Service
nopCommerce Store 4.30 – ‘name’ Stored Cross-Site Scripting
http://plai.go.th notified by Xyp3r2667