ProtonVPN 1.26.0 – Unquoted Service Path
>> TAG: #0day
ProtonVPN 1.26.0 – Unquoted Service Path
WordPress Plugin amministrazione-aperta 3.7.3 – Local File Read – Unauthenticated
ICEHRM 31.0.0.0S – Cross-site Request Forgery (CSRF) to Account Takeover
iRZ Mobile Router – CSRF to RCE
Ivanti Endpoint Manager 4.6 – Remote Code Execution (RCE)
Sysax FTP Automation 6.9.0 – Privilege Escalation
ICT Protege GX/WX 2.08 – Stored Cross-Site Scripting (XSS)
ICT Protege GX/WX 2.08 – Client-Side SHA1 Password Hash Disclosure
WordPress Plugin iQ Block Country 1.2.13 – Arbitrary File Deletion via Zip Slip (Authenticated)
Moodle 3.11.5 – SQLi (Authenticated)