An attacker with administrative access to a Windows machine with UEFI Secure Boot enabled may bypass code signing policy checks by putting intentionally-malformed configuration options in the boot configuration database…
ZyXEL PMG5318-B20A suffers from a command injection vulnerability via the ping function.
A mitigation added to Windows 10 to prevent NTFS Mount Reparse Points being created at integrity levels below medium can be bypassed.
A session fixation web vulnerability has been discovered in the official PayPal Inc online service web application.
Freemake Video Downloader version 3.7.1 suffers from a code execution vulnerability.
CakePHP version 3.0.5 suffers from server-side request forgery attacks that can cause a denial of service condition.
Kentico CMS version 8.2 suffers from cross site scripting and open redirection vulnerabilities.
PROLiNK H5004NK ADSL routers with firmware version R76S Slt 4WNE1 6.1R suffer from cross site request forgery, backdoor accounts, and weak RBAC control vulnerabilities.
netis RealTek routers with firmware version 2.1.1 suffer from cross site request forgery, backdoor accounts, and weak RBAC control vulnerabilities.
The Google generic TLD and ccTLD suffer from an open redirection vulnerability.