Full Disclosure Mailing List

A public, vendor-neutral forum for detailed discussion of vulnerabilities and exploitation techniques, as well as tools, papers, news, and events of interest to the community. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. More importantly, fresh vulnerabilities sometimes hit this list many hours or days before they pass through the Bugtraq moderation queue.

List Archives

Latest Posts

[0day-rubbish] VMS 6.48.809 Authenticated command injection to root RCE (8.8) disclosure via Fulldisclosure (Aug 19)
0day Rubbish Research Team is publicly disclosing a vulnerability in
VMS 6.48.809.

Type: Authenticated command injection to root RCE (CWE-78)
CVSS: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Impact: Authenticated attacker executes arbitrary commands as root via unsanitized command injection
Authentication: authenticated

Full technical analysis and a reproducible proof-of-concept:...

[0day-rubbish] ONE Reporter 13.1 Authenticated RCE / privilege escalation via CommandExecutor (8.8) disclosure via Fulldisclosure (Aug 19)
0day Rubbish Research Team is publicly disclosing a vulnerability in
ONE Reporter 13.1.

Type: Authenticated RCE / privilege escalation via CommandExecutor (CWE-78)
CVSS: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Impact: Low-privilege user executes arbitrary commands as local-admin service account
Authentication: authenticated

Full technical analysis and a reproducible proof-of-concept:...

[0day-rubbish] Gemini 7.3.0 Authenticated SQL injection to xp_cmdshell RCE (8.8) disclosure via Fulldisclosure (Aug 19)
0day Rubbish Research Team is publicly disclosing a vulnerability in
Gemini 7.3.0.

Type: Authenticated SQL injection to xp_cmdshell RCE (CWE-89)
CVSS: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Impact: Authenticated user executes OS commands via stacked SQL and xp_cmdshell as sa/sysadmin
Authentication: authenticated

Full technical analysis and a reproducible proof-of-concept:...

[0day-rubbish] RoboTask 11.0.5.1229 Unauthenticated REST API remote task execution (9.8) disclosure via Fulldisclosure (Aug 19)
0day Rubbish Research Team is publicly disclosing a vulnerability in
RoboTask 11.0.5.1229.

Type: Unauthenticated REST API remote task execution (CWE-306)
CVSS: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: Unauthenticated attacker enumerates and triggers pre-existing tasks with Administrator privileges
Authentication: unauthenticated / pre-auth

Full technical analysis and a reproducible proof-of-concept:...

[0day-rubbish] ActiveFax Server 10.70 Unauthenticated LPD Ghostscript %pipe% SYSTEM RCE (9.8) disclosure via Fulldisclosure (Aug 19)
0day Rubbish Research Team is publicly disclosing a vulnerability in
ActiveFax Server 10.70.

Type: Unauthenticated LPD Ghostscript %pipe% SYSTEM RCE (CWE-78)
CVSS: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: Unauthenticated attacker executes arbitrary commands as SYSTEM via an LPD print job
Authentication: unauthenticated / pre-auth

Full technical analysis and a reproducible proof-of-concept:...

[0day-rubbish] Tornado 2.11.3 Unauthenticated arbitrary file write to root RCE (storeTo=file: to cron) (9.8) disclosure via Fulldisclosure (Aug 19)
0day Rubbish Research Team is publicly disclosing a vulnerability in
Tornado 2.11.3.

Type: Unauthenticated arbitrary file write to root RCE (storeTo=file: to cron) (CWE-22)
CVSS: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Impact: Unauthenticated attacker writes arbitrary files and achieves root command execution via cron
Authentication: unauthenticated / pre-auth

Full technical analysis and a reproducible proof-of-concept:...

[0day-rubbish] Datalore On-Premises 2026.2.3 Unauthenticated RCE via InteractiveReport access-mapping flaw (9.8) disclosure via Fulldisclosure (Aug 19)
0day Rubbish Research Team is publicly disclosing a vulnerability in
Datalore On-Premises 2026.2.3.

Type: Unauthenticated RCE via InteractiveReport access-mapping flaw (CWE-306)
CVSS: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Impact: Anonymous attacker executes arbitrary code in the notebook agent container
Authentication: unauthenticated / pre-auth

Full technical analysis and a reproducible proof-of-concept:...

APPLE-SA-08-18-2026-1 Safari 26.6.1 Apple Product Security via Fulldisclosure (Aug 19)
APPLE-SA-08-18-2026-1 Safari 26.6.1

Safari 26.6.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/148286.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

WebKit
Available for: macOS Sonoma and macOS Sequoia
Impact: Processing maliciously crafted web content may lead to an
unexpected...

Cudy WR3000: Hard-coded JWT Secret to Root Command Injection Nir Yehoshua (Aug 19)
Hello Full Disclosure list,

Cipher Security Labs has published details for two vulnerabilities
affecting Cudy WR3000 hardware revision 2.0 running firmware before
version 2.5.24.

CVE-2026-71960 - Hard-coded JWT Secret Authentication Bypass
Severity: Critical, CVSS 9.3

The device firmware contains a hard-coded HMAC signing secret used by
the Mosquitto MQTT JWT authentication plugin. Because the secret can
be recovered from the firmware image,...

Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc) disclosure via Fulldisclosure (Aug 17)
0day Rubbish Research Team is publicly disclosing a vulnerability in XPressEntry 3.7.7454 (Telaeris Inc). The research
is published and a proof-of-concept is available.

Pre-authentication RCE (SQL injection) (CVSS 9.8, pre-authentication)

Telaeris XPressEntry 3.7.7454 runs its main HTTP API without authentication when RequireReaderCredentials is False,
which is the default. The SaveVerifyActivity handler concatenates the sNotes parameter into...

Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer) disclosure via Fulldisclosure (Aug 17)
0day Rubbish Research Team is publicly disclosing a vulnerability in Scrutinizer 19.7.0 (Plixer). The research is
published and a proof-of-concept is available.

Authenticated RCE (SQL injection) (CVSS 8.8, authenticated)

Plixer Scrutinizer 19.7.0 concatenates the HTTP orderBy parameter directly into a SQL ORDER BY clause with no escaping
in the adminEditLang handler. The default configuration includes the pg_cron extension and a PostgreSQL...

Security advisory: Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax Software (Output Technology)) disclosure via Fulldisclosure (Aug 17)
0day Rubbish Research Team is publicly disclosing a vulnerability in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax
Software (Output Technology)). The research is published and a proof-of-concept is available.

Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) (CVSS 9.8, pre-authentication)

Output Messenger Server 2.0.x accepts XMPP connections on TCP 14121 with no SASL and no credentials; every connection
is treated as...

Security advisory: Pre-authentication RCE (arbitrary file write) in RapidDeploy 5.2.2 (MidVision) disclosure via Fulldisclosure (Aug 17)
0day Rubbish Research Team is publicly disclosing a vulnerability in RapidDeploy 5.2.2 (MidVision). The research is
published and a proof-of-concept is available.

Pre-authentication RCE (arbitrary file write) (CVSS 9.8, pre-authentication)

MidVision RapidDeploy 5.2.2 ships a remote-agent template (midvision-remoting-server.xml) with host=0.0.0.0 and
auth.servers commented out, making the JBoss Remoting layer network-reachable with no...

Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper) disclosure via Fulldisclosure (Aug 17)
0day Rubbish Research Team is publicly disclosing a vulnerability in Lansweeper 12.2.1.0 (web reports 12.2.1.6)
(Lansweeper). The research is published and a proof-of-concept is available.

Authenticated RCE (second-order SQL injection) (CVSS 8.8, authenticated)

Lansweeper 12.2.1.0 contains a second-order SQL injection in the LicenseActions console. A SQL Server sub-server name
containing a single quote is stored and later concatenated...

Security advisory: Authenticated RCE (command injection) in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI Software) disclosure via Fulldisclosure (Aug 17)
0day Rubbish Research Team is publicly disclosing a vulnerability in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI
Software). The research is published and a proof-of-concept is available.

Authenticated RCE (command injection) (CVSS 8.8, authenticated)

Kerio Connect 10.0.9 Patch 2 contains a command-injection vulnerability in the WebAdmin JSON-RPC method
Server.startEncryption. The password parameter is double-quoted and concatenated...

More Lists

Dozens of other network security lists are archived at SecLists.Org.