Full Disclosure: by date
67 messages
starting Sep 03 26 and
ending Sep 22 26
Date index |
Thread index |
Author index
Thursday, 03 September
Acunetix 25.11.x - Local Privilege Escalation Vulnerability via OpenSSL Configuration (CVE-2026-6958) Andrea Intilangelo
[0day-rubbish] Akana API Platform 8.4.29 Unauthenticated RCE via path-normalization filter/dispatcher discrepancy (9.8) disclosure via Fulldisclosure
[0day-rubbish] Codoforum 5.4.1 Authenticated arbitrary file upload to PHP RCE (7.2) disclosure via Fulldisclosure
[0day-rubbish] DrayTek Vigor 2960 v1.5.1.6 Authenticated command injection to root RCE in uploadlangs (8.8) disclosure via Fulldisclosure
[0day-rubbish] GeoVision GV-TBL4700 V1.06 Authenticated command injection to root RCE via SNMPv3 user configuration (8.8) disclosure via Fulldisclosure
[0day-rubbish] Lantronix EDS3000PR 3.2.0.0R2 two vulnerabilities disclosure via Fulldisclosure
[0day-rubbish] Minuteman UPS Network Management Card 1.60.3 Unauthenticated OS command injection to root RCE (9.8) disclosure via Fulldisclosure
[0day-rubbish] NoMachine Terminal Server 10.0.57 two vulnerabilities disclosure via Fulldisclosure
[0day-rubbish] Puppet Enterprise 2025.10.0 Authenticated command injection to root RCE (patch-bypass variant of CVE-2025-5459) (8.8) disclosure via Fulldisclosure
[0day-rubbish] StreamSets DataCollector 6.4.1 (official Docker image) Default credentials plus unsandboxed Shell Executor to root RCE (9.8) disclosure via Fulldisclosure
[0day-rubbish] ZesleCP 3.1.21 Authenticated arbitrary file write to root RCE via cron (8.8) disclosure via Fulldisclosure
Paho v1.3.15 Arbitrary Code Execution via Shared Library Search Path Hijacking Ron E
Paho v1.3.15 Arbitrary Code Execution via Untrusted Dynamic Library Execution Ron E
Paho v1.3.15 Heap Use-After-Free in Eclipse Paho MQTT C Client via Message Retry Logi Ron E
lighttpd2 Signedness Error in li_chunkqueue_append_mem() Leads to Out-of-Bounds Memory Access Ron E
thttpd v2.26 Stack-Based Buffer Overflow in thttpd htpasswd Utility Allows Local Memory Corruption Ron E
thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirect CGI Program Ron E
WireGuard-Linux Stack-Based Buffer Overflow in lsiio (Linux IIO Userspace Tool) Due to Unbounded fscanf Ron E
Payara 7.2026.1.RC1 Arbitrary EJB Method Invocation via Insecure Reflection in Payara Server Ron E
Payara 7.2026.1.RC1 Remote Code Execution via Server-Side Includes #exec Directive in Payara Server Ron E
Flextype v1.0.0-alpha.3 Stored Arbitrary Expression Injection in ExpressionsDirective Allows Arbitrary File Read Ron E
Flextype v1.0.0-alpha.3 Server-Side Request Forgery via fetch() in Query API Ron E
Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure Ron E
Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass Ron E
Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution Ron E
Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read Ron E
Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery Ron E
Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion Ron E
O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script Ron E
Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists Ron E
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556 Nir Yehoshua
Tuesday, 08 September
CVE-2026-52307: Stored XSS in 1CMS v5.6 懒-癌-症~ via Fulldisclosure
**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8) Surf free
[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8) disclosure via Fulldisclosure
[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8) disclosure via Fulldisclosure
[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8) disclosure via Fulldisclosure
[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2) disclosure via Fulldisclosure
[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8) disclosure via Fulldisclosure
[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8) disclosure via Fulldisclosure
[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8) disclosure via Fulldisclosure
[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2) disclosure via Fulldisclosure
Tuesday, 22 September
SCHUTZWERK-SA-2024-007: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education David Brown via Fulldisclosure
UAF in XMEye Security Camera evan
Teams meeting audio and roster data remain accessible via ACS Call Automation connectCall after a participant is removed from the meeting Jacob Greenway
[0day-rubbish] PrizmDoc for Java (VirtualViewer) 5.22.1 Unauthenticated uploadDocument write into the webapp root to JSP webshell (9.8) disclosure via Fulldisclosure
[0day-rubbish] CaptureBites MetaServer Anonymous WCF SOAP workflow leading to RunPrograms code execution (9.8) disclosure via Fulldisclosure
[0day-rubbish] Devolutions Server (DVLS) 2026.2.14.0 PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (9.1) disclosure via Fulldisclosure
[0day-rubbish] Ecava IntegraXor IGX 16.0.701.10 Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (9.8) disclosure via Fulldisclosure
[0day-rubbish] LCDS Laquis SCADA Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (9.8) disclosure via Fulldisclosure
[0day-rubbish] Opengear NGCS 25.11.8 Authenticated PDU name command injection to root via io.popen (8.8) disclosure via Fulldisclosure
APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27 Apple Product Security via Fulldisclosure
APPLE-SA-09-14-2026-2 iOS 26.7 and iPadOS 26.7 Apple Product Security via Fulldisclosure
APPLE-SA-09-14-2026-3 macOS Golden Gate 27 Apple Product Security via Fulldisclosure
APPLE-SA-09-14-2026-4 macOS Tahoe 26.7 Apple Product Security via Fulldisclosure
APPLE-SA-09-14-2026-5 macOS Sequoia 15.8 Apple Product Security via Fulldisclosure
APPLE-SA-09-14-2026-6 tvOS 27 Apple Product Security via Fulldisclosure
APPLE-SA-09-14-2026-7 watchOS 27 Apple Product Security via Fulldisclosure
APPLE-SA-09-14-2026-8 visionOS 27 Apple Product Security via Fulldisclosure
APPLE-SA-09-14-2026-9 Safari 27 Apple Product Security via Fulldisclosure
APPLE-SA-09-14-2026-10 Xcode 27 Apple Product Security via Fulldisclosure
[0day-rubbish] Teltonika RutOS 00.07.06.21 Authenticated ipsec.lua logread command injection with reflected output (8.8) disclosure via Fulldisclosure
[0day-rubbish] TigerGraph Community Edition 4.2.4 Default credentials plus GSQL TO_CSV arbitrary file write to SSH code execution (9.8) disclosure via Fulldisclosure
CVE-2026-44756: Pre-Auth RCE in SAP EPP Processing (ICM, Web Dispatcher, disp+work) Raschin Tavakoli via Fulldisclosure
CVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2) Louis Sanchez via Fulldisclosure
CFP No cON Name 2k26 - Palma, Mallorca - Spain Jose Nicolas Castellano
HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084) Joe via Fulldisclosure
Code Security Review tool E. Kellinis
