RAD SecFlow-1v version SF_0290_2.3.01.26 suffers from a cross site request forgery vulnerability.
The installer in Pearson Vue VTS version 2.3.1911 suffers from an unquoted service path vulnerability.
Joomla! paGO Commerce component 2.5.9.0 suffers from an authenticated remote SQL injection vulnerability.
Tailor MS 1.0 – Reflected Cross-Site Scripting
ThinkAdmin 6 – Arbitrarily File Read
Pearson Vue VTS 2.3.1911 Installer – ‘VUEApplicationWrapper’ Unquoted Service Path
Rapid7 Nexpose Installer 6.6.39 – ‘nexposeengine’ Unquoted Service Path
RAD SecFlow-1v SF_0290_2.3.01.26 – Cross-Site Request Forgery (Reboot)
RAD SecFlow-1v SF_0290_2.3.01.26 – Persistent Cross-Site Scripting
CuteNews version 2.1.2 remote code execution exploit.