Full Disclosure: by thread
89 messages
starting Sep 03 26 and
ending Sep 26 26
Date index |
Thread index |
Author index
- Acunetix 25.11.x - Local Privilege Escalation Vulnerability via OpenSSL Configuration (CVE-2026-6958) Andrea Intilangelo (Sep 03)
- [0day-rubbish] Akana API Platform 8.4.29 Unauthenticated RCE via path-normalization filter/dispatcher discrepancy (9.8) disclosure via Fulldisclosure (Sep 03)
- [0day-rubbish] Codoforum 5.4.1 Authenticated arbitrary file upload to PHP RCE (7.2) disclosure via Fulldisclosure (Sep 03)
- [0day-rubbish] DrayTek Vigor 2960 v1.5.1.6 Authenticated command injection to root RCE in uploadlangs (8.8) disclosure via Fulldisclosure (Sep 03)
- [0day-rubbish] GeoVision GV-TBL4700 V1.06 Authenticated command injection to root RCE via SNMPv3 user configuration (8.8) disclosure via Fulldisclosure (Sep 03)
- [0day-rubbish] Lantronix EDS3000PR 3.2.0.0R2 two vulnerabilities disclosure via Fulldisclosure (Sep 03)
- [0day-rubbish] Minuteman UPS Network Management Card 1.60.3 Unauthenticated OS command injection to root RCE (9.8) disclosure via Fulldisclosure (Sep 03)
- [0day-rubbish] NoMachine Terminal Server 10.0.57 two vulnerabilities disclosure via Fulldisclosure (Sep 03)
- [0day-rubbish] Puppet Enterprise 2025.10.0 Authenticated command injection to root RCE (patch-bypass variant of CVE-2025-5459) (8.8) disclosure via Fulldisclosure (Sep 03)
- [0day-rubbish] StreamSets DataCollector 6.4.1 (official Docker image) Default credentials plus unsandboxed Shell Executor to root RCE (9.8) disclosure via Fulldisclosure (Sep 03)
- [0day-rubbish] ZesleCP 3.1.21 Authenticated arbitrary file write to root RCE via cron (8.8) disclosure via Fulldisclosure (Sep 03)
- Paho v1.3.15 Arbitrary Code Execution via Shared Library Search Path Hijacking Ron E (Sep 03)
- Paho v1.3.15 Arbitrary Code Execution via Untrusted Dynamic Library Execution Ron E (Sep 03)
- Paho v1.3.15 Heap Use-After-Free in Eclipse Paho MQTT C Client via Message Retry Logi Ron E (Sep 03)
- lighttpd2 Signedness Error in li_chunkqueue_append_mem() Leads to Out-of-Bounds Memory Access Ron E (Sep 03)
- thttpd v2.26 Stack-Based Buffer Overflow in thttpd htpasswd Utility Allows Local Memory Corruption Ron E (Sep 03)
- thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirect CGI Program Ron E (Sep 03)
- WireGuard-Linux Stack-Based Buffer Overflow in lsiio (Linux IIO Userspace Tool) Due to Unbounded fscanf Ron E (Sep 03)
- Payara 7.2026.1.RC1 Arbitrary EJB Method Invocation via Insecure Reflection in Payara Server Ron E (Sep 03)
- Payara 7.2026.1.RC1 Remote Code Execution via Server-Side Includes #exec Directive in Payara Server Ron E (Sep 03)
- Flextype v1.0.0-alpha.3 Stored Arbitrary Expression Injection in ExpressionsDirective Allows Arbitrary File Read Ron E (Sep 03)
- Flextype v1.0.0-alpha.3 Server-Side Request Forgery via fetch() in Query API Ron E (Sep 03)
- Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure Ron E (Sep 03)
- Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass Ron E (Sep 03)
- Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution Ron E (Sep 03)
- Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read Ron E (Sep 03)
- Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery Ron E (Sep 03)
- Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion Ron E (Sep 03)
- O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script Ron E (Sep 03)
- Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists Ron E (Sep 03)
- HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556 Nir Yehoshua (Sep 03)
- CVE-2026-52307: Stored XSS in 1CMS v5.6 懒-癌-症~ via Fulldisclosure (Sep 08)
- **Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8) Surf free (Sep 08)
- [0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8) disclosure via Fulldisclosure (Sep 08)
- [0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8) disclosure via Fulldisclosure (Sep 08)
- [0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8) disclosure via Fulldisclosure (Sep 08)
- [0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2) disclosure via Fulldisclosure (Sep 08)
- [0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8) disclosure via Fulldisclosure (Sep 08)
- [0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8) disclosure via Fulldisclosure (Sep 08)
- [0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8) disclosure via Fulldisclosure (Sep 08)
- [0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2) disclosure via Fulldisclosure (Sep 08)
- SCHUTZWERK-SA-2024-007: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education David Brown via Fulldisclosure (Sep 22)
- UAF in XMEye Security Camera evan (Sep 22)
- Teams meeting audio and roster data remain accessible via ACS Call Automation connectCall after a participant is removed from the meeting Jacob Greenway (Sep 22)
- [0day-rubbish] PrizmDoc for Java (VirtualViewer) 5.22.1 Unauthenticated uploadDocument write into the webapp root to JSP webshell (9.8) disclosure via Fulldisclosure (Sep 22)
- [0day-rubbish] CaptureBites MetaServer Anonymous WCF SOAP workflow leading to RunPrograms code execution (9.8) disclosure via Fulldisclosure (Sep 22)
- [0day-rubbish] Devolutions Server (DVLS) 2026.2.14.0 PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (9.1) disclosure via Fulldisclosure (Sep 22)
- [0day-rubbish] Ecava IntegraXor IGX 16.0.701.10 Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (9.8) disclosure via Fulldisclosure (Sep 22)
- [0day-rubbish] LCDS Laquis SCADA Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (9.8) disclosure via Fulldisclosure (Sep 22)
- [0day-rubbish] Opengear NGCS 25.11.8 Authenticated PDU name command injection to root via io.popen (8.8) disclosure via Fulldisclosure (Sep 22)
- APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27 Apple Product Security via Fulldisclosure (Sep 22)
- APPLE-SA-09-14-2026-2 iOS 26.7 and iPadOS 26.7 Apple Product Security via Fulldisclosure (Sep 22)
- APPLE-SA-09-14-2026-3 macOS Golden Gate 27 Apple Product Security via Fulldisclosure (Sep 22)
- APPLE-SA-09-14-2026-4 macOS Tahoe 26.7 Apple Product Security via Fulldisclosure (Sep 22)
- APPLE-SA-09-14-2026-5 macOS Sequoia 15.8 Apple Product Security via Fulldisclosure (Sep 22)
- APPLE-SA-09-14-2026-6 tvOS 27 Apple Product Security via Fulldisclosure (Sep 22)
- APPLE-SA-09-14-2026-7 watchOS 27 Apple Product Security via Fulldisclosure (Sep 22)
- APPLE-SA-09-14-2026-8 visionOS 27 Apple Product Security via Fulldisclosure (Sep 22)
- APPLE-SA-09-14-2026-9 Safari 27 Apple Product Security via Fulldisclosure (Sep 22)
- APPLE-SA-09-14-2026-10 Xcode 27 Apple Product Security via Fulldisclosure (Sep 22)
- [0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8) disclosure via Fulldisclosure (Sep 22)
- [0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8) disclosure via Fulldisclosure (Sep 22)
- CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work) Raschin Tavakoli via Fulldisclosure (Sep 22)
- CVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2) Louis Sanchez via Fulldisclosure (Sep 22)
- CFP No cON Name 2k26 - Palma, Mallorca - Spain Jose Nicolas Castellano (Sep 22)
- HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084) Joe via Fulldisclosure (Sep 22)
- Code Security Review tool E. Kellinis (Sep 22)
- [NotCVE-2026-0014] Input Leap 3.0.3 Drag-and-Drop File Transfer Path Traversal Allows Arbitrary File Write Outside the Drop Directory advisories (Sep 26)
- [NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM advisories (Sep 26)
- SCHUTZWERK-SA-2024-006: Stored Cross-Site Scripting via text fields in H5P module (h5p-nodejs-library) of Lumi Education David Brown via Fulldisclosure (Sep 26)
- [0day-rubbish] Cambium cnMatrix EX3024F 6.2.1-r4 SSL CSR COMMON_NAME command injection to root RCE (7.2) disclosure via Fulldisclosure (Sep 26)
- [0day-rubbish] FME Flow 2026.2 Zip-Slip arbitrary file write to code execution as LocalSystem (8.8) disclosure via Fulldisclosure (Sep 26)
- [0day-rubbish] Lantronix SGX5150 9.13.0.0R7 Authenticated FsBrowseClean command injection to root RCE (7.2) disclosure via Fulldisclosure (Sep 26)
- [0day-rubbish] Lightstreamer Server 7.4.8 Shipped placeholder JMX/RMI credentials plus MLet remote class loading to root RCE (9.8) disclosure via Fulldisclosure (Sep 26)
- [0day-rubbish] Lightstreamer Server 7.4.8 Unauthenticated JMX jvmtiAgentLoad native code execution (8.1) disclosure via Fulldisclosure (Sep 26)
- [0day-rubbish] MultiTech Conduit AEP 6.3.6 Authenticated import_config filename command injection to root RCE (7.2) disclosure via Fulldisclosure (Sep 26)
- [0day-rubbish] Netsis NetOpenX REST 2.0.6.9 Unauthenticated SQL injection to xp_cmdshell SYSTEM command execution (9.8) disclosure via Fulldisclosure (Sep 26)
- [0day-rubbish] Server Technology PRO3X PDU 030600 port_mux listener program override to root command execution (7.2) disclosure via Fulldisclosure (Sep 26)
- openEQUELLA authenticated RCE chain(s) evan via Fulldisclosure (Sep 26)
- usvg SVGZ decompression bomb in `Tree::from_data` Khashayar Fereidani (Sep 26)
- dive tar-slip in image file extraction Khashayar Fereidani (Sep 26)
- harness(gitness) registry webhook sort_order blind SQL injection Khashayar Fereidani (Sep 26)
- harness Gitspace hardcoded password for every user account Khashayar Fereidani (Sep 26)
- [SYSS-2026-067]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121) Matthias Deeg via Fulldisclosure (Sep 26)
- [SYSS-2026-068]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121) Matthias Deeg via Fulldisclosure (Sep 26)
- [SYSS-2026-069]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190) Matthias Deeg via Fulldisclosure (Sep 26)
- [SYSS-2026-070]: GDCM (Grassroots DICOM) - Integer Overflow (CWE-190) Matthias Deeg via Fulldisclosure (Sep 26)
- [SYSS-2026-071]: GDCM (Grassroots DICOM) - Format String (CWE-134) Matthias Deeg via Fulldisclosure (Sep 26)
- SEC Consult SA-20260923-0 :: Local Privilege Escalation in Honeywell IQ MultiAccess Update Service #CVE-2026-13742 SEC Consult Vulnerability Lab via Fulldisclosure (Sep 26)
