Full Disclosure: by date
31 messages
starting Sep 03 26 and
ending Sep 03 26
Date index |
Thread index |
Author index
Thursday, 03 September
Acunetix 25.11.x - Local Privilege Escalation Vulnerability via OpenSSL Configuration (CVE-2026-6958) Andrea Intilangelo
[0day-rubbish] Akana API Platform 8.4.29 Unauthenticated RCE via path-normalization filter/dispatcher discrepancy (9.8) disclosure via Fulldisclosure
[0day-rubbish] Codoforum 5.4.1 Authenticated arbitrary file upload to PHP RCE (7.2) disclosure via Fulldisclosure
[0day-rubbish] DrayTek Vigor 2960 v1.5.1.6 Authenticated command injection to root RCE in uploadlangs (8.8) disclosure via Fulldisclosure
[0day-rubbish] GeoVision GV-TBL4700 V1.06 Authenticated command injection to root RCE via SNMPv3 user configuration (8.8) disclosure via Fulldisclosure
[0day-rubbish] Lantronix EDS3000PR 3.2.0.0R2 two vulnerabilities disclosure via Fulldisclosure
[0day-rubbish] Minuteman UPS Network Management Card 1.60.3 Unauthenticated OS command injection to root RCE (9.8) disclosure via Fulldisclosure
[0day-rubbish] NoMachine Terminal Server 10.0.57 two vulnerabilities disclosure via Fulldisclosure
[0day-rubbish] Puppet Enterprise 2025.10.0 Authenticated command injection to root RCE (patch-bypass variant of CVE-2025-5459) (8.8) disclosure via Fulldisclosure
[0day-rubbish] StreamSets DataCollector 6.4.1 (official Docker image) Default credentials plus unsandboxed Shell Executor to root RCE (9.8) disclosure via Fulldisclosure
[0day-rubbish] ZesleCP 3.1.21 Authenticated arbitrary file write to root RCE via cron (8.8) disclosure via Fulldisclosure
Paho v1.3.15 Arbitrary Code Execution via Shared Library Search Path Hijacking Ron E
Paho v1.3.15 Arbitrary Code Execution via Untrusted Dynamic Library Execution Ron E
Paho v1.3.15 Heap Use-After-Free in Eclipse Paho MQTT C Client via Message Retry Logi Ron E
lighttpd2 Signedness Error in li_chunkqueue_append_mem() Leads to Out-of-Bounds Memory Access Ron E
thttpd v2.26 Stack-Based Buffer Overflow in thttpd htpasswd Utility Allows Local Memory Corruption Ron E
thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirect CGI Program Ron E
WireGuard-Linux Stack-Based Buffer Overflow in lsiio (Linux IIO Userspace Tool) Due to Unbounded fscanf Ron E
Payara 7.2026.1.RC1 Arbitrary EJB Method Invocation via Insecure Reflection in Payara Server Ron E
Payara 7.2026.1.RC1 Remote Code Execution via Server-Side Includes #exec Directive in Payara Server Ron E
Flextype v1.0.0-alpha.3 Stored Arbitrary Expression Injection in ExpressionsDirective Allows Arbitrary File Read Ron E
Flextype v1.0.0-alpha.3 Server-Side Request Forgery via fetch() in Query API Ron E
Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure Ron E
Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass Ron E
Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution Ron E
Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read Ron E
Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery Ron E
Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion Ron E
O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script Ron E
Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists Ron E
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556 Nir Yehoshua
