Mail Thread Index
- [FD] Acunetix 25.11.x - Local Privilege Escalation Vulnerability via OpenSSL Configuration (CVE-2026-6958),
Andrea Intilangelo
- [FD] [0day-rubbish] Akana API Platform 8.4.29 Unauthenticated RCE via path-normalization filter/dispatcher discrepancy (9.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] Codoforum 5.4.1 Authenticated arbitrary file upload to PHP RCE (7.2),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] DrayTek Vigor 2960 v1.5.1.6 Authenticated command injection to root RCE in uploadlangs (8.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] GeoVision GV-TBL4700 V1.06 Authenticated command injection to root RCE via SNMPv3 user configuration (8.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] Lantronix EDS3000PR 3.2.0.0R2 two vulnerabilities,
disclosure via Fulldisclosure
- [FD] [0day-rubbish] Minuteman UPS Network Management Card 1.60.3 Unauthenticated OS command injection to root RCE (9.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] NoMachine Terminal Server 10.0.57 two vulnerabilities,
disclosure via Fulldisclosure
- [FD] [0day-rubbish] Puppet Enterprise 2025.10.0 Authenticated command injection to root RCE (patch-bypass variant of CVE-2025-5459) (8.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] StreamSets DataCollector 6.4.1 (official Docker image) Default credentials plus unsandboxed Shell Executor to root RCE (9.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] ZesleCP 3.1.21 Authenticated arbitrary file write to root RCE via cron (8.8),
disclosure via Fulldisclosure
- [FD] Paho v1.3.15 Arbitrary Code Execution via Shared Library Search Path Hijacking,
Ron E
- [FD] Paho v1.3.15 Arbitrary Code Execution via Untrusted Dynamic Library Execution,
Ron E
- [FD] Paho v1.3.15 Heap Use-After-Free in Eclipse Paho MQTT C Client via Message Retry Logi,
Ron E
- [FD] lighttpd2 Signedness Error in li_chunkqueue_append_mem() Leads to Out-of-Bounds Memory Access,
Ron E
- [FD] thttpd v2.26 Stack-Based Buffer Overflow in thttpd htpasswd Utility Allows Local Memory Corruption,
Ron E
- [FD] thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirect CGI Program,
Ron E
- [FD] WireGuard-Linux Stack-Based Buffer Overflow in lsiio (Linux IIO Userspace Tool) Due to Unbounded fscanf,
Ron E
- [FD] Payara 7.2026.1.RC1 Arbitrary EJB Method Invocation via Insecure Reflection in Payara Server,
Ron E
- [FD] Payara 7.2026.1.RC1 Remote Code Execution via Server-Side Includes #exec Directive in Payara Server,
Ron E
- [FD] Flextype v1.0.0-alpha.3 Stored Arbitrary Expression Injection in ExpressionsDirective Allows Arbitrary File Read,
Ron E
- [FD] Flextype v1.0.0-alpha.3 Server-Side Request Forgery via fetch() in Query API,
Ron E
- [FD] Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure,
Ron E
- [FD] Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass,
Ron E
- [FD] Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution,
Ron E
- [FD] Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read,
Ron E
- [FD] Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery,
Ron E
- [FD] Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion,
Ron E
- [FD] O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script,
Ron E
- [FD] Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists,
Ron E
- [FD] HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556,
Nir Yehoshua
- [FD] CVE-2026-52307: Stored XSS in 1CMS v5.6,
懒-癌-症~ via Fulldisclosure
- [FD] **Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8),
Surf free
- [FD] [0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8),
disclosure via Fulldisclosure
- [FD] [0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2),
disclosure via Fulldisclosure
Mail converted by MHonArc