Full Disclosure: by author

67 messages starting Sep 03 26 and ending Sep 08 26
Date index | Thread index | Author index


Andrea Intilangelo

Acunetix 25.11.x - Local Privilege Escalation Vulnerability via OpenSSL Configuration (CVE-2026-6958) Andrea Intilangelo (Sep 03)

Apple Product Security via Fulldisclosure

APPLE-SA-09-14-2026-3 macOS Golden Gate 27 Apple Product Security via Fulldisclosure (Sep 22)
APPLE-SA-09-14-2026-2 iOS 26.7 and iPadOS 26.7 Apple Product Security via Fulldisclosure (Sep 22)
APPLE-SA-09-14-2026-8 visionOS 27 Apple Product Security via Fulldisclosure (Sep 22)
APPLE-SA-09-14-2026-4 macOS Tahoe 26.7 Apple Product Security via Fulldisclosure (Sep 22)
APPLE-SA-09-14-2026-5 macOS Sequoia 15.8 Apple Product Security via Fulldisclosure (Sep 22)
APPLE-SA-09-14-2026-6 tvOS 27 Apple Product Security via Fulldisclosure (Sep 22)
APPLE-SA-09-14-2026-7 watchOS 27 Apple Product Security via Fulldisclosure (Sep 22)
APPLE-SA-09-14-2026-10 Xcode 27 Apple Product Security via Fulldisclosure (Sep 22)
APPLE-SA-09-14-2026-9 Safari 27 Apple Product Security via Fulldisclosure (Sep 22)
APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27 Apple Product Security via Fulldisclosure (Sep 22)

David Brown via Fulldisclosure

SCHUTZWERK-SA-2024-007: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education David Brown via Fulldisclosure (Sep 22)

disclosure via Fulldisclosure

[0day-rubbish] CaptureBites MetaServer Anonymous WCF SOAP workflow leading to RunPrograms code execution (9.8) disclosure via Fulldisclosure (Sep 22)
[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2) disclosure via Fulldisclosure (Sep 08)
[0day-rubbish] Lantronix EDS3000PR 3.2.0.0R2 two vulnerabilities disclosure via Fulldisclosure (Sep 03)
[0day-rubbish] Akana API Platform 8.4.29 Unauthenticated RCE via path-normalization filter/dispatcher discrepancy (9.8) disclosure via Fulldisclosure (Sep 03)
[0day-rubbish] Devolutions Server (DVLS) 2026.2.14.0 PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (9.1) disclosure via Fulldisclosure (Sep 22)
[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8) disclosure via Fulldisclosure (Sep 08)
[0day-rubbish] LCDS Laquis SCADA Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (9.8) disclosure via Fulldisclosure (Sep 22)
[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8) disclosure via Fulldisclosure (Sep 08)
[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8) disclosure via Fulldisclosure (Sep 08)
[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2) disclosure via Fulldisclosure (Sep 08)
[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8) disclosure via Fulldisclosure (Sep 08)
[0day-rubbish] ZesleCP 3.1.21 Authenticated arbitrary file write to root RCE via cron (8.8) disclosure via Fulldisclosure (Sep 03)
[0day-rubbish] Ecava IntegraXor IGX 16.0.701.10 Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (9.8) disclosure via Fulldisclosure (Sep 22)
[0day-rubbish] StreamSets DataCollector 6.4.1 (official Docker image) Default credentials plus unsandboxed Shell Executor to root RCE (9.8) disclosure via Fulldisclosure (Sep 03)
[0day-rubbish] Opengear NGCS 25.11.8 Authenticated PDU name command injection to root via io.popen (8.8) disclosure via Fulldisclosure (Sep 22)
[0day-rubbish] GeoVision GV-TBL4700 V1.06 Authenticated command injection to root RCE via SNMPv3 user configuration (8.8) disclosure via Fulldisclosure (Sep 03)
[0day-rubbish] NoMachine Terminal Server 10.0.57 two vulnerabilities disclosure via Fulldisclosure (Sep 03)
[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8) disclosure via Fulldisclosure (Sep 08)
[0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8) disclosure via Fulldisclosure (Sep 22)
[0day-rubbish] PrizmDoc for Java (VirtualViewer) 5.22.1 Unauthenticated uploadDocument write into the webapp root to JSP webshell (9.8) disclosure via Fulldisclosure (Sep 22)
[0day-rubbish] DrayTek Vigor 2960 v1.5.1.6 Authenticated command injection to root RCE in uploadlangs (8.8) disclosure via Fulldisclosure (Sep 03)
[0day-rubbish] Minuteman UPS Network Management Card 1.60.3 Unauthenticated OS command injection to root RCE (9.8) disclosure via Fulldisclosure (Sep 03)
[0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8) disclosure via Fulldisclosure (Sep 22)
[0day-rubbish] Puppet Enterprise 2025.10.0 Authenticated command injection to root RCE (patch-bypass variant of CVE-2025-5459) (8.8) disclosure via Fulldisclosure (Sep 03)
[0day-rubbish] Codoforum 5.4.1 Authenticated arbitrary file upload to PHP RCE (7.2) disclosure via Fulldisclosure (Sep 03)
[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8) disclosure via Fulldisclosure (Sep 08)

E. Kellinis

Code Security Review tool E. Kellinis (Sep 22)

evan

UAF in XMEye Security Camera evan (Sep 22)

Jacob Greenway

Teams meeting audio and roster data remain accessible via ACS Call Automation connectCall after a participant is removed from the meeting Jacob Greenway (Sep 22)

Joe via Fulldisclosure

HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084) Joe via Fulldisclosure (Sep 22)

Jose Nicolas Castellano

CFP No cON Name 2k26 - Palma, Mallorca - Spain Jose Nicolas Castellano (Sep 22)

Louis Sanchez via Fulldisclosure

CVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2) Louis Sanchez via Fulldisclosure (Sep 22)

Nir Yehoshua

HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556 Nir Yehoshua (Sep 03)

Raschin Tavakoli via Fulldisclosure

CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work) Raschin Tavakoli via Fulldisclosure (Sep 22)

Ron E

Flextype v1.0.0-alpha.3 Stored Arbitrary Expression Injection in ExpressionsDirective Allows Arbitrary File Read Ron E (Sep 03)
Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists Ron E (Sep 03)
Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read Ron E (Sep 03)
Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass Ron E (Sep 03)
O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script Ron E (Sep 03)
thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirect CGI Program Ron E (Sep 03)
Paho v1.3.15 Arbitrary Code Execution via Shared Library Search Path Hijacking Ron E (Sep 03)
Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion Ron E (Sep 03)
Paho v1.3.15 Heap Use-After-Free in Eclipse Paho MQTT C Client via Message Retry Logi Ron E (Sep 03)
Flextype v1.0.0-alpha.3 Server-Side Request Forgery via fetch() in Query API Ron E (Sep 03)
Payara 7.2026.1.RC1 Remote Code Execution via Server-Side Includes #exec Directive in Payara Server Ron E (Sep 03)
Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery Ron E (Sep 03)
lighttpd2 Signedness Error in li_chunkqueue_append_mem() Leads to Out-of-Bounds Memory Access Ron E (Sep 03)
Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure Ron E (Sep 03)
Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution Ron E (Sep 03)
Payara 7.2026.1.RC1 Arbitrary EJB Method Invocation via Insecure Reflection in Payara Server Ron E (Sep 03)
WireGuard-Linux Stack-Based Buffer Overflow in lsiio (Linux IIO Userspace Tool) Due to Unbounded fscanf Ron E (Sep 03)
thttpd v2.26 Stack-Based Buffer Overflow in thttpd htpasswd Utility Allows Local Memory Corruption Ron E (Sep 03)
Paho v1.3.15 Arbitrary Code Execution via Untrusted Dynamic Library Execution Ron E (Sep 03)

Surf free

**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8) Surf free (Sep 08)

懒-癌-症~ via Fulldisclosure

CVE-2026-52307: Stored XSS in 1CMS v5.6 懒-癌-症~ via Fulldisclosure (Sep 08)