Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

seclists.org

Full Disclosure

Get the latest updates from Full Disclosure directly as they happen.

Follow now 402 followers

Latest posts

Last updated 14 days ago

[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)

14 days ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)

14 days ago

Full Disclosure mailing list archives From: Surf free <surfv.free () gmail com>...

[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)

14 days ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)

14 days ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)

14 days ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)

14 days ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

14 days ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)

14 days ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)

14 days ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

CVE-2026-52307: Stored XSS in 1CMS v5.6

14 days ago

Full Disclosure mailing list archives From: 懒-癌-症~ via Fulldisclosure <fulldisclosure () seclists...

Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion

19 days ago

Full Disclosure mailing list archives From: Ron E <ronaldjedgerson () gmail com>...

O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script

19 days ago

Full Disclosure mailing list archives From: Ron E <ronaldjedgerson () gmail com>...