SALTO ProAccess SPACE versions 5.5 and below suffer from path traversal, arbitrary file write, persistent cross site scripting, privilege escalation, and clear text transmission of sensitive data vulnerabilities.
http://www.silalang.go.th/o.htm notified by chinafans
Intelbras Router RF1200 1.1.3 – Cross-Site Request Forgery
Online Invoicing System 2.6 – ‘description’ Persistent Cross-Site Scripting
http://ncd.ddc.moph.go.th notified by Zeerx7
Microsoft Excel 2016 1901 – XML External Entity Injection
Max Secure Anti Virus Plus 19.0.4.020 – Insecure File Permissions
Nsauditor 3.1.8.0 – ‘Key’ Denial of Service (PoC)
Dokuwiki 2018-04-22b – Username Enumeration
Visual Studio 2008 – XML External Entity Injection