A security vulnerability affecting GoAhead versions 2 to 5 has been identified when using Digest authentication over HTTP. The HTTP Digest Authentication in the GoAhead web server does not completely…
D-Link DSR-250N 3.12 – Denial of Service (PoC)
SEO Panel 4.6.0 – Remote Code Execution
Krpano Panorama Viewer versions 1.20.8 and below suffer from a cross site scripting vulnerability.
HashiCorp Vault’s AWS IAM authentication method can be bypassed by sending a serialized request to the STS AssumeRoleWithWebIdentity method as part of the authentication flow. The request triggers a JSON…
HashiCorp Vault’s GCP authentication method can be bypassed on gce type roles that do not specify bound_service_accounts. Vault does not enforce that the compute_engine data in a signed JWT token…
http://www.klonghok.go.th notified by Tev3R
BACnet Test Server 1.01 – Remote Denial of Service (PoC)
Textpattern CMS 4.6.2 – ‘body’ Persistent Cross-Site Scripting