ManageEngine DeviceExpert 5.9 – User Credential Disclosure
>> TAG: #0day
ManageEngine DeviceExpert 5.9 – User Credential Disclosure
ActualAnalyzer Lite 2.81 – Unauthenticated Command Execution
Plogger 1.0-RC1 – Authenticated Arbitrary File Upload
Firefox WebIDL Privileged Javascript Injection
glibc Off-by-One NUL Byte gconv_translit_find Exploit
WooCommerce Store Exporter 1.7.5 – SXSS and RXSS
VTLS Virtua InfoStation.cgi – SQL Injection
ntopng 1.2.0 – XSS Injection
ManageEngine Password Manager MetadataServlet.dat SQL Injection
Innovaphone PBX Admin-GUI – CSRF Vulnerability