JumpStart 0.6.0.0 – ‘jswpbapi’ Unquoted Service Path
JumpStart 0.6.0.0 – ‘jswpbapi’ Unquoted Service Path
waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 – ‘description’ Cross-Site Scripting
waldronmatt FullCalendar-BS4-PHP-MySQL-JSON 1.21 – ‘start’ SQL Injection
Part-DB 0.4 – Authentication Bypass
Intelbras Router WRN150 1.0.18 – Cross-Site Request Forgery
This is a newer method to exploit php-fpm to achieve remote code execution when certain nginx with php-fpm configurations exist.
AUO SunVeillance Monitoring System version 1.1.9e suffers from an incorrect access control vulnerability.
AUO SunVeillance Monitoring System version 1.1.9e suffers from a remote SQL injection vulnerability.
ClonOs WEB UI 19.09 – Improper Access Control
Moxa EDR-810 suffers from command injection and information disclosure vulnerabilities.