Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, allowing attackers with Item/Configure permission to capture passwords of the jobs ...……
A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server using attacker-specified credentials.……
A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials.……
A vulnerability has been identified in SINEMA Remote Connect Server (All versions V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user t ...……
A vulnerability has been identified in Spectrum Power 4 (All versions V4.70 SP9 Security Patch 1). The integrated web application Online Help in affected product contains a Cross-Site Scripting (XSS) ...……
A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated vic ...……