Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

seclists.org

Full Disclosure

Get the latest updates from Full Disclosure directly as they happen.

Follow now 401 followers

Latest posts

Last updated 1 day ago

[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)

1 day ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)

1 day ago

Full Disclosure mailing list archives From: Surf free <surfv.free () gmail com>...

[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)

1 day ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)

1 day ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)

1 day ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)

1 day ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

1 day ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)

1 day ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)

1 day ago

Full Disclosure mailing list archives From: disclosure via Fulldisclosure <fulldisclosure () seclists...

CVE-2026-52307: Stored XSS in 1CMS v5.6

1 day ago

Full Disclosure mailing list archives From: 懒-癌-症~ via Fulldisclosure <fulldisclosure () seclists...

Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion

6 days ago

Full Disclosure mailing list archives From: Ron E <ronaldjedgerson () gmail com>...

O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script

6 days ago

Full Disclosure mailing list archives From: Ron E <ronaldjedgerson () gmail com>...