WordPress WooCommerce plugin with GloBee cryptocurrency payment gateway versions 1.1.1 and below suffer from payment bypass and unauthorized order status spoofing vulnerabilities.
Typo3 CMS T3 EasyEvent tx_easyevent_pi1 version 0.37.3 suffers from a remote SQL injection vulnerability.
Webiness Inventory version 2.3 suffers from an arbitrary file upload vulnerability.
This write up contains details on how to perform remote code execution within Jenkins.
Typo3 CMS Shop System tt_products version 2.9.4 suffers from a remote SQL injection vulnerability.
MaxxAudio Drivers WavesSysSvc64.exe version 1.6.2.0 suffers from a file permission privilege escalation vulnerability that results in SYSTEM level access.
On Android, a ptrace hold makes the seccomp filter useless on devices with a kernel with a version lower than 4.8.
FaceTime suffers from a memory corruption vulnerability in texture processing.
This Metasploit module has been tested on a Wemo-enabled Crock-Pot, but other Wemo devices are known to be affected, albeit on a different RPORT (49153).
http://mattayom31.go.th/web1/file_editor/db.txt notified by SeRaVo BlackHaT