Tiny Tiny RSS – Remote Code Execution
>> AUTHOR: deepcore
Tiny Tiny RSS – Remote Code Execution
Zen Cart 1.5.7b – Remote Code Execution (Authenticated)
WiFi Mouse 1.7.8.5 – Remote Code Execution
FortiLogger 4.4.2.2 – Unauthenticated Arbitrary File Upload (Metasploit)
VMware vCenter Server 7.0 – Unauthenticated File Upload
WordPress Under Construction, Coming Soon, and Maintenance Mode plugin version 1.1.1 suffers from cross site scripting and server-side request forgery vulnerabilities.
Simple Employee Records System version 1.0 suffers from an unauthenticated remote shell upload vulnerability.
Yeastar TG400 GSM Gateway version 91.3.0.3 suffers from a path traversal vulnerability.
Nagios XI version 5.7.5 suffers from a cross site scripting and multiple remote code execution vulnerabilities.
LightCMS version 1.3.4 suffers from a persistent cross site scripting vulnerability.