SUPERAntiSpyware Professional X Trial versions prior to 10.0.1206 suffer from a local privilege escalation vulnerability.
WordPress Autoptimize plugin version 2.7.6 suffers from an authenticated remote shell upload vulnerability.
Symphony CMS version 3.0.0 suffers from a persistent cross site scripting vulnerability.
Eikon Thomson Reuters version 4.0.42144 suffers from a weak permissions issue that can lead to code execution.
ZTE Mobile Hotspot MS910S version DL_MF910S_CN_EUV1.00.01 suffers from having a hard-coded administrative password, busybox vulnerabilities, and having a known backdoor in the GoAhead webserver.
Eibiz i-Media Server Digital Signage 3.8.0 – Privilege Escalation
SymphonyCMS 3.0.0 – Persistent Cross-Site Scripting
Nagios Log Server 2.1.6 – Persistent Cross-Site Scripting
Online Shopping Alphaware 1.0 – ‘id’ SQL Injection
WordPress Plugin Autoptimize 2.7.6 – Arbitrary File Upload (Authenticated)