Source
CVE
A reflected XSS vulnerability was discovered in the Quickform component for Joomla.
A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.
A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.
A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.
SQLi vulnerability in LMS Lite component for Joomla.
A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.
In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.
There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.
There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.
There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.