Travel Management System version 1.0 unauthenticated remote code execution exploit.
CMS Made Simple 2.2.14 – Authenticated Arbitrary File Upload
vBulletin 5.6.2 – ‘widget_tabbedContainer_tab_panel’ Remote Code Execution
http://suratpeo.go.th notified by Mr.Z
Fuel CMS 1.4.7 – ‘col’ SQL Injection (Authenticated)
BarcodeOCR 19.3.6 – ‘BarcodeOCR’ Unquoted Service Path
ManageEngine ADSelfService Build prior to 6003 – Remote Code Execution (Unauthenticated)
Warehouse Inventory System 1.0 – Cross-Site Request Forgery (Change Admin Password)
CodeMeter version 6.60 suffers from an unquoted service path vulnerability.
Tailor Management System version 1.0 suffers from multiple remote SQL injection vulnerabilities.