DEWESoft X3 SP1 (64-bit) – Remote Command Execution
DEWESoft X3 SP1 (64-bit) – Remote Command Execution
Prisma Industriale Checkweigher PrismaWEB 1.21 – Hard-Coded Credentials
Advantech WebAccess < 8.3 – Directory Traversal / Remote Code Execution
TextPattern 4.6.2 – ‘qty’ SQL Injection
http://mukdahan.nfe.go.th/budget56/ notified by Romantic
Bacula-Web < 8.0.0-rc2 – SQL Injection
WebLog Expert Enterprise 9.4 – Authentication Bypass
WebLog Expert Enterprise 9.4 – Denial of Service
Redaxo CMS Addon MyEvents version 2.2.1 suffers from a remote SQL injection vulnerability.
antMan version 0.9.0c suffers from an authentication bypass vulnerability.