D-LINK Central WifiManager CWM-100 – Server-Side Request Forgery
D-LINK Central WifiManager CWM-100 – Server-Side Request Forgery
ServerZilla 1.0 – ’email’ SQL Injection
GPS Tracking System 2.12 – ‘username’ SQL Injection
CuteFTP 9.3.0.3 – Denial of Service (PoC)
Easyndexer 1.0 – Cross-Site Request Forgery (Add Admin)
Facturation System 1.0 – ‘modid’ SQL Injection
HeidiSQL 9.5.0.5196 – Denial of Service (PoC)
Data Center Audit 2.6.2 – ‘username’ SQL Injection
TufinOS 2.17 Build 1193 – XML External Entity Injection
The Everus.org Android application version 1.0.7 has a fundamental design flaw where the client can send a random phone number during the second factor flow and the server will update…