Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 – Remote Code Execution
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 – Remote Code Execution
WordPress Plugin Gift Voucher 1.0.5 – ‘template_id’ SQL Injection
ManageEngine ADManager Plus 6.5.7 – Cross-Site Scripting
NEC Aterm WG2600HP2 suffers from an information disclosure vulnerability due to missing authentication.
PLANEX CS-QR20 suffers from a remote command execution vulnerability due to a hidden management page existing.
PLANEX CS-QR20 suffers from a hardcoded administrative login credential vulnerability.
StyleWriter 4 version 1.0 suffers from a denial of service vulnerability.
Seagate Personal Cloud model SRN21C running firmware versions 4.3.16.0 and 4.3.18.0 suffer from remote SQL injection vulnerabilities in the media server.
Couchbase Server allows for authenticated users to send arbitrary erlang code to diag/eval.
Adobe Flash suffers from an out-of-bounds read vulnerability during AVC processing.