NC450 version 1.5.0 Build 181022 Rel.3A033D contains a hardcoded root credential within its Linux distribution image.
0b2d21ebae3e02d4fafe82f12e358ca5c9551b67ec031bcfdac6fb19d6678076
WordPress Form Maker plugin version 1.13.2 suffers from cross site request forgery and local file inclusion vulnerabilities.
1b3bf215939ed0af3a3170b5bd54568907757b57bdbe0a60f59f37dc35209cd3
Dell EMC IsilonSD Management Server version 1.1.1 contains fixes for two cross site scripting (XSS) security vulnerabilities, which could potentially be exploited by malicious users to compromise the affected system.
ea9700de214b1f06e9cf2cca030f0fb03efd55b6a13f59c0dea8bc4fcf79cd46
hardwear is seeking innovative research on hardware security. If you have done interesting research on attacks or mitigation on any Hardware and want to showcase it to the security community, just submit your research paper. A conference in the USA will take place June 11th through the 14th, 2019 and another will take place in the Netherlands September 23rd through the 27th.
6118d3a214a32756e5b6b327f0b5caef81e9542aaf609117cea86aebf4a638ab
Open-Xchange AppSuite versions 7.10.1 and below suffer from information exposure and improper access control vulnerabilities.
a722921e6fddc3e83ee1b00bdf589f283a0af7624c6b56c8422fdc8435786cc9
The c0c0n 2019 call for papers has been announced. It will take place September 25th through the 28th, 2019 at the Grand Hyatt, Kochi (Cochin), Kerala, India.
be8843635d53aade8031d3091d8811f1ca770e66cc38dbc3a43c4447928bf48d
Debian Linux Security Advisory 4424-1 - Adam Dobrawy, Frederico Silva and Gregory Brzeski from HyperOne.com discovered that pdns, an authoritative DNS server, did not properly validate user-supplied data when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend. This would allow a remote user to cause either a denial-of-service, or information disclosure.
a6c78fc67efbb442cf102ef8de19a438f5068b2d1c71e0ad435ed20a619c7706
Tradebox CryptoCurrency version 5.4 suffers from a remote SQL injection vulnerability.
ca72a107a5895c9e5f455263fc336cfd54fa2e156ff5a30b3734b90e6d130bd6
Administrative credentials submitted to the Arris Touchstone TG1672 are sent over HTTP base64 encoded in a GET request.
e48c054b3486698da29dbc101e457d21bb8aac0ce639aa8505dade2aa0907a27
Uniqkey Password Manager version 1.14 suffers from a credential disclosure vulnerability.
74a9d5a6cd42b3cf5502deaed5ee5abfef3eb39b1b75f9de2df6ab29e1baba27
ManageEngine ServiceDesk Plus version 9.3 suffers from a user enumeration vulnerability.
0ba7779153798bbb8993d4ec7b527cb2a4a3256481ea9167ab101140a4eb7c6e
QNAP Netatalk versions prior to 3.1.12 suffer from an authentication bypass vulnerability.
8726f3f9ab38929e4a013f5be7d72ab568578d6f058e4d2bc011093bdde53d91
Uniqkey Password Manager version 1.14 suffers from a denial of service vulnerability.
cc8ad4fc898175303e703eae485e37d43635dca0650f51fbbe2914247c97e6c0
Download Accelerator Plus (DAP) version 10.0.6.0 SEH buffer overflow exploit.
992d55606a8caf652bb1bd0922524e61c749c48673c46d100d4402308f0f0896
SaLICru -SLC-20-cube3(5) suffers from an html injection vulnerability.
f084464dba8b8951813c2af00518de63a5d48fbc2195a6386b82c04516e2f1c5