WordPress Plugin Multi-Scheduler 1.0.0 – Cross-Site Request Forgery (Delete User)
>> AUTHOR: deepcore
WordPress Plugin Multi-Scheduler 1.0.0 – Cross-Site Request Forgery (Delete User)
Crystal Shard http-protection 0.2.0 – IP Spoofing Bypass
BIND TSIG denial of service exploit.
WordPress Drag and Drop File Upload Contact Form plugin version 1.3.3.2 suffers from a remote shell upload vulnerability.
StreamRipper32 version 2.6 buffer overflow proof of concept exploit.
Pi-hole version 4.4.0 suffers from a remote code execution vulnerability.
http://www3.djop.moj.go.th/X-m3n.html notified by X-m3n
http://www.tambonbandua.go.th/activity/images/ notified by laZy hAcker
http://www.thayai.go.th/activity/images/ notified by laZy hAcker
NOKIA VitalSuite SPM 2020 – ‘UserName’ SQL Injection