Tailor MS 1.0 – Reflected Cross-Site Scripting
Tailor MS 1.0 – Reflected Cross-Site Scripting
ThinkAdmin 6 – Arbitrarily File Read
Pearson Vue VTS 2.3.1911 Installer – ‘VUEApplicationWrapper’ Unquoted Service Path
Rapid7 Nexpose Installer 6.6.39 – ‘nexposeengine’ Unquoted Service Path
RAD SecFlow-1v SF_0290_2.3.01.26 – Cross-Site Request Forgery (Reboot)
RAD SecFlow-1v SF_0290_2.3.01.26 – Persistent Cross-Site Scripting
CuteNews version 2.1.2 remote code execution exploit.
Tiandy IPC and NVR version 9.12.7 suffer from a credential disclosure vulnerability.
The ZTE F602W router suffers from a CAPTCHA bypass vulnerability.
Mobile Shop System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.