Grocy version 2.7.1 suffers from a persistent cross site scripting vulnerability.
Rapid7 Nexpose Installer version 6.6.39 suffers from a local privilege escalation vulnerability.
This Metasploit module exploits an arbitrary file write in cfprefsd on macOS versions 10.15.4 and below in order to run a payload as root. The CFPreferencesSetAppValue function, which is reachable…
ShareMouse 5.0.43 – ‘ShareMouse Service’ Unquoted Service Path
ManageEngine Applications Manager 14700 – Remote Code Execution (Authenticated)
grocy 2.7.1 – Persistent Cross-Site Scripting
Cabot 0.11.12 – Persistent Cross-Site Scripting
https://www.pattawee.go.th/U72.html notified by Unravel72
http://www.roiet.go.th notified by TAHU PETIS
The COVR 3902 REVA router with firmware 1.01B0 has hardcoded telnet credentials.