JioChat for Android has an issue where a caller can cause the callee device to send audio without user interaction.
Battle.Net 1.27.1.12428 – Insecure File Permissions
berliCRM 1.0.24 – ‘src_record’ SQL Injection
Cisco ASA and FTD 9.6.4.42 – Path Traversal
Liman 0.7 – Cross-Site Request Forgery (Change Password)
MedDream PACS Server 6.8.3.751 – Remote Code Execution (Unauthenticated)
Online Students Management System 1.0 – ‘username’ SQL Injections
Small CRM 2.0 – ’email’ SQL Injection
Twitter Analytics suffers from an open redirection vulnerability that can assist in phishing attacks.
Garfield Petshop versions through 2020-10-01 suffer from a cross site request forgery vulnerability.