Adobe Magento Commerce versions prior to 2.4.2 suffer from a cross site scripting vulnerability.
Microsoft Windows has a privilege escalation vulnerability. When a process is running in a server silo, the checks for trusted hive registry key symbolic links is disabled leading to elevation…
This Metasploit module exploits an authenticated Java deserialization that affects a truckload of Micro Focus products: Operations Bridge Manager, Application Performance Management, Data Center Automation, Universal CMDB, Hybrid Cloud Management…
https://www.mayo.go.th/manis.htm notified by Dhen Bhocil
Openlitespeed WebServer 1.7.8 – Command Injection (Authenticated) (2)
b2evolution 6.11.6 – ‘tab3’ Reflected XSS
b2evolution 6.11.6 – ‘redirect_to’ Open Redirect
PEEL Shopping 9.3.0 – ‘address’ Stored Cross-Site Scripting
WordPress Supsystic Contact Form plugin version 1.7.5 suffers from remote SQL injection and persistent cross site scripting vulnerabilities.
Email-Worm.Win32.Sircam.eb malware suffers from an insecure permissions vulnerability.