Wavlink WN530HG4 – Password Disclosure
Wavlink WN530HG4 – Password Disclosure
WordPress Plugin Duplicator 1.4.6 – Unauthenticated Backup Download
Webmin 1.996 – Remote Code Execution (RCE) (Authenticated)
NanoCMS v0.4 – Remote Code Execution (RCE) (Authenticated)
Omnia MPX 1.5.0+r1 – Path Traversal
mPDF 7.0 – Local File Inclusion
CuteEditor for PHP 6.6 – Directory Traversal
WordPress Plugin Duplicator 1.4.7 – Information Disclosure
WordPress WP-UserOnline plugin versions 2.87.6 and below suffer from a persistent cross site scripting vulnerability.
Transposh WordPress Translation versions 1.0.7 and below have an ajax action “tp_tp” that is vulnerable to an unauthenticated/authenticated reflected cross site scripting vulnerability when user-supplied input to the HTTP GET…