Full Disclosure: by author
116 messages
starting Aug 06 26 and
ending Aug 26 26
Date index |
Thread index |
Author index
0xReadingSteiner via Fulldisclosure
Silent;Call — Pre-Authentication Remote Root in Cisco CUCM 15.x (SKYLINE-2026-001/002/003) 0xReadingSteiner via Fulldisclosure (Aug 06)
Abhinav Agarwal
NVIDIA Linux GPU driver: unprivileged Xid 31 MMU fault via undocumented peer-teardown ordering, no CVE (vendor: intended) Abhinav Agarwal (Aug 26)
NVIDIA Linux GPU driver: cross-UID GPU process telemetry via NVML, no CVE (vendor: expected behavior) Abhinav Agarwal (Aug 26)
advisories
[NotCVE-2026-0012] EmpManageX Hardcoded Administrative Credentials in Login API Allow Full Access to Employee Records advisories (Aug 26)
[NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial of Service advisories (Aug 26)
[NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM advisories (Aug 26)
[NotCVE-2026-0009] NitroShare Desktop 0.3.4 Path Traversal Allows LAN-Adjacent Arbitrary File Write advisories (Aug 26)
[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File advisories (Aug 26)
Apple Product Security via Fulldisclosure
APPLE-SA-08-18-2026-1 Safari 26.6.1 Apple Product Security via Fulldisclosure (Aug 19)
APPLE-SA-07-27-2026-2 macOS Tahoe 26.6 Apple Product Security via Fulldisclosure (Aug 06)
APPLE-SA-07-27-2026-6 watchOS 26.6 Apple Product Security via Fulldisclosure (Aug 06)
APPLE-SA-07-27-2026-7 visionOS 26.6 Apple Product Security via Fulldisclosure (Aug 06)
APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9 Apple Product Security via Fulldisclosure (Aug 13)
APPLE-SA-08-17-2026-1 iOS 26.6.1 and iPadOS 26.6.1 Apple Product Security via Fulldisclosure (Aug 17)
APPLE-SA-07-27-2026-1 iOS 26.6 and iPadOS 26.6 Apple Product Security via Fulldisclosure (Aug 06)
APPLE-SA-07-27-2026-8 Safari 26.6 Apple Product Security via Fulldisclosure (Aug 06)
APPLE-SA-08-17-2026-2 iOS 18.7.10 and iPadOS 18.7.10 Apple Product Security via Fulldisclosure (Aug 17)
APPLE-SA-07-27-2026-5 tvOS 26.6 Apple Product Security via Fulldisclosure (Aug 06)
APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9 Apple Product Security via Fulldisclosure (Aug 13)
APPLE-SA-08-17-2026-3 macOS Tahoe 26.6.2 Apple Product Security via Fulldisclosure (Aug 17)
APPLE-SA-08-17-2026-2 iOS 18.7.10 and iPadOS 18.7.10 Apple Product Security via Fulldisclosure (Aug 17)
APPLE-SA-07-27-2026-3 macOS Sequoia 15.7.8 Apple Product Security via Fulldisclosure (Aug 06)
APPLE-SA-07-27-2026-4 macOS Sonoma 14.8.8 Apple Product Security via Fulldisclosure (Aug 06)
Banks Tools
CVE-2026-20079 - Cisco Secure Firewall Management Center Authentication Bypass to Root RCE Banks Tools (Aug 26)
disclosure via Fulldisclosure
[0day-rubbish] VLink Virtual Matrix 6.60 (other versions with the same unquoted openssl command construction are likely affected) Authenticated RCE (OpenSSL argument injection to SYSTEM) (8.8) disclosure via Fulldisclosure (Aug 26)
Security advisory: Pre-authentication SYSTEM RCE in iMonnit Express 4.0.5.5 (Monnit / iMonnit) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] NCache Enterprise 5.3.6 (other versions with the same default-disabled security and handler logic are likely affected) Pre-authentication RCE (missing auth + attacker assembly load) (9.8) disclosure via Fulldisclosure (Aug 26)
Security advisory: multiple vulnerabilities including Pre-authentication root RCE in Xeams 10.3 build 6449 (Synametrics Technologies) disclosure via Fulldisclosure (Aug 06)
[0day-Rubbish] SonicWall SMA 1000 — Pre-Auth Deserialization RCE (CVSS 9.8) via Struts 1 Property Injection and Auth-Filter Rewrite disclosure via Fulldisclosure (Aug 06)
[0day-rubbish] HiveMQ Platform 4.54.0 Pre-authentication RCE (default credentials + Zip-Slip) (9.8) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] mySCADA PRO Runtime 9.4.0 (container deployment msxrun; earlier versions with the same upgrade branch are likely affected) Unauthenticated OS command injection to root RCE (9.4) disclosure via Fulldisclosure (Aug 26)
Security advisory: Pre-authentication RCE in vMix 29 v29.0.0.48 (Studio Coast Pty Ltd) disclosure via Fulldisclosure (Aug 06)
[0day-rubbish] RoboTask 11.0.5.1229 Unauthenticated REST API remote task execution (9.8) disclosure via Fulldisclosure (Aug 19)
[0day-rubbish] Tornado 2.11.3 Unauthenticated arbitrary file write to root RCE (storeTo=file: to cron) (9.8) disclosure via Fulldisclosure (Aug 19)
Security advisory: multiple vulnerabilities including JWT forgery / authentication bypass, Pre-authentication SYSTEM RCE in CIRCUTOR PowerStudio SCADA WAVE 24.11.6.0 (CIRCUTOR S.A.) disclosure via Fulldisclosure (Aug 06)
[0day-rubbish] Brekeke PBX 3.19.1.8 (other versions with the same Bean dispatch model are likely affected) Pre-authentication RCE (fail-open auth gate + reflection to exec) (9.8) disclosure via Fulldisclosure (Aug 26)
Security advisory: Pre-authentication RCE in Apache Struts 2 2.6.11.0 (Apache Software Foundation) disclosure via Fulldisclosure (Aug 06)
[0day-rubbish] ActiveFax Server 10.70 Unauthenticated LPD Ghostscript %pipe% SYSTEM RCE (9.8) disclosure via Fulldisclosure (Aug 19)
[0day-rubbish] Scan2x ScanWebClient 2.3.3.0 (other versions with the same handler are likely affected) Pre-authentication RCE (unrestricted upload to executable webroot) (9.8) disclosure via Fulldisclosure (Aug 26)
[0day-rubbish] myDBR 7.5.4 (build 5454) (other versions with the same file-editor are likely affected) Authenticated RCE (admin file editor + default credentials) (8.8) disclosure via Fulldisclosure (Aug 26)
[0day-rubbish] Microsip 2026 (ASD data-service agent) 2026 Eval (other builds with the same backup-runner path handling are likely affected) Pre-authentication RCE (attacker-controlled binary path, LocalSystem) (9.8) disclosure via Fulldisclosure (Aug 26)
batch-2: 15 vulnerabilities incl. multiple pre-auth RCE across 10 enterprise/SCADA products - full analyses + reproducible exploits disclosure via Fulldisclosure (Aug 06)
[0day-rubbish] Gemini 7.3.0 Authenticated SQL injection to xp_cmdshell RCE (8.8) disclosure via Fulldisclosure (Aug 19)
[0day-rubbish] Workflow Enterprise 9.1.0.1 Pre-authentication RCE (expression injection) (9.8) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] Leostream Connection Broker 9.1.37.0 two vulnerabilities (SQLi to root RCE, unauth SSRF) disclosure via Fulldisclosure (Aug 26)
Security advisory: Pre-authentication RCE in Ontotext GraphDB 11.4.3 Free edition (Ontotext / Graphwise) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] IceWarp Server 14.3.0 Authenticated config write + unauthenticated trigger (UNC DLL loading) (9.0) disclosure via Fulldisclosure (Aug 17)
Security advisory: Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax Software (Output Technology)) disclosure via Fulldisclosure (Aug 17)
Security advisory: Pre-authentication SYSTEM RCE in Vicon Valerus ViconNet Gateway 25.200.46.0 (Vicon Industries) disclosure via Fulldisclosure (Aug 06)
Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] webMethods Microservices Runtime (MSR) 10.x (other versions with the same XSLT module are likely affected) Pre-authentication RCE (default factory credentials + XSLT extension functions) (9.8) disclosure via Fulldisclosure (Aug 26)
Security advisory: multiple vulnerabilities including Default-credential RCE, Pre-authentication root RCE in atvise SCADA 3.13.0 (atvise GmbH / Bachmann Visutec) disclosure via Fulldisclosure (Aug 06)
Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH) disclosure via Fulldisclosure (Aug 17)
Security advisory: Pre-authentication RCE (arbitrary file write) in RapidDeploy 5.2.2 (MidVision) disclosure via Fulldisclosure (Aug 17)
Security advisory: Pre-authentication RCE in Confluent Platform (ksqlDB) 7.9.1-ce (Confluent, Inc.) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] Raritan EMX firmware emx_ecx_3.6.1_46982 (EMX/ECX gateway) Authenticated config injection to root RCE (8.8) disclosure via Fulldisclosure (Aug 26)
[0day-rubbish] CFEngine Enterprise Nova Hub 3.27.1 (other versions with the same generateScriptFromTemplates quoting are likely affected) Authenticated RCE (command injection via VCS settings, root) (8.8) disclosure via Fulldisclosure (Aug 26)
[0day-rubbish] Vocia MS-1 Firmware 1.2.27 Pre-authentication RCE (hardcoded credentials + supervisor execution) (9.8) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] Delta DIAEnergie IEMS V1.11 Authenticated (conditional) SQL injection to VBScript RCE (8.8) disclosure via Fulldisclosure (Aug 26)
Security advisory: Pre-authentication RCE in Wyn Enterprise 9.1.00145.0 (Mescius (GrapeCity)) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] LogicalDOC Enterprise Edition 9.3 (the incomplete CVE-2024-54448 fix suggests earlier 9.x versions are likely affected) Authenticated RCE (automation sandbox bypass + default credentials) (8.8) disclosure via Fulldisclosure (Aug 26)
[0day-rubbish] VMS 6.48.809 Authenticated command injection to root RCE (8.8) disclosure via Fulldisclosure (Aug 19)
Security advisory: Pre-authentication SYSTEM RCE in Stimulsoft Server 2026.3.1 (Stimulsoft) disclosure via Fulldisclosure (Aug 06)
[0day-rubbish] Datalore On-Premises 2026.2.3 Unauthenticated RCE via InteractiveReport access-mapping flaw (9.8) disclosure via Fulldisclosure (Aug 19)
Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] InsightEdge Enterprise (XAP IMDg) 16.1.1 Pre-authentication RCE (path traversal + JSP webshell) (9.8) disclosure via Fulldisclosure (Aug 17)
Security advisory: Pre-authentication RCE (default credentials + path traversal) in PulseNET Enterprise 6.0.3 (build 6975) (GE Vernova) disclosure via Fulldisclosure (Aug 17)
Security advisory: Pre-authentication SYSTEM RCE in MAPS SCADA 4.0.5.5 (Adroit Technologies) disclosure via Fulldisclosure (Aug 17)
Security advisory: Pre-authentication RCE (default credentials) in ObjectDB 2.9.5 server mode (ObjectDB Software) disclosure via Fulldisclosure (Aug 17)
Security advisory: Pre-authentication RCE in AOMEI Cyber Backup v2.3.0 (AOMEI) disclosure via Fulldisclosure (Aug 06)
Security advisory: Authenticated RCE (command injection) in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI Software) disclosure via Fulldisclosure (Aug 17)
Security advisory: Pre-authentication RCE in DataStax Enterprise (DSE) 6.8.49 (DataStax) disclosure via Fulldisclosure (Aug 17)
Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] ONE Reporter 13.1 Authenticated RCE / privilege escalation via CommandExecutor (8.8) disclosure via Fulldisclosure (Aug 19)
[0day-rubbish] Biamp Devio SCR-20/25 firmware 2.3.1 Unauthenticated remote root RCE (DTP protocol quote injection) (9.8) disclosure via Fulldisclosure (Aug 26)
[0day-rubbish] KeyHelp 26.0 (Build 3624) Authenticated RCE (command injection via Apache directive) (7.2) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] CacheGuard OS UF-2.5.2 Authenticated RCE via config-import eval injection (8.8) disclosure via Fulldisclosure (Aug 26)
[0day-rubbish] Enterprise ADC 8.13.8 Authenticated RCE (command injection + passwordless sudo) (8.8) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] Seeq Server R65.2.3 (default deployment with Data Lab installed via the official CLI) Unauthenticated RCE (open self-registration + Data Lab Jupyter missing authorization) (9.8) disclosure via Fulldisclosure (Aug 26)
Security advisory: Pre-authentication RCE in nanoDLP stable build #10729 (Nano3Dtech) disclosure via Fulldisclosure (Aug 17)
[0day-rubbish] SpiraTeam 9.3.0.0 (other versions with the same RetrieveByIndentLevel implementation are likely affected) Authenticated SQL injection to RCE (sysadmin + xp_cmdshell) (8.8) disclosure via Fulldisclosure (Aug 26)
[0day-rubbish] VitalPBX 4.5.2 (Asterisk 20.20.1) Authenticated root RCE via asterisk_cli to dialplan System() (8.8) disclosure via Fulldisclosure (Aug 26)
Security advisory: multiple vulnerabilities including Authenticated RCE (property injection), Hardcoded credentials, Pre-authentication root RCE in CatDV Server 10.7.8 (Square Box Systems) disclosure via Fulldisclosure (Aug 06)
Security advisory: Pre-authentication RCE in Plastic SCM (Unity Version Control On-Prem) 11.0.16.10303 (Unity Technologies) disclosure via Fulldisclosure (Aug 06)
[0day-rubbish] Maian Gallery v2.1 Authenticated unrestricted file upload to PHP RCE (7.2) disclosure via Fulldisclosure (Aug 26)
[0day-rubbish] Call Center Suite 10.10.1 Pre-authentication RCE (auth bypass + webroot write) (9.8) disclosure via Fulldisclosure (Aug 17)
Egidio Romano
[KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability Egidio Romano (Aug 06)
[KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability Egidio Romano (Aug 06)
[KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability Egidio Romano (Aug 06)
[KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability Egidio Romano (Aug 06)
Erica Windisch
OpenZFS Linux open zpool manipulation and escapes via unprivileged userns Erica Windisch (Aug 17)
evan
Cisco Catalyst SD-WAN C8000V Authenticated Heap Buffer Overflow evan (Aug 06)
Evan Tang
FD - Half-click unauthenticated remote code execution on Horde Groupware IMP (from a stored XSS) Evan Tang (Aug 26)
Intilangelo, Andrea
CVE-2026-78331 / CVE-2026-78332: Multiple Vulnerabilities in NethServer Intilangelo, Andrea (Aug 26)
Jacob Nowak
Skullcandy Dime 3 unauthorized Bluetooth pairing behavior Jacob Nowak (Aug 06)
LOMOSITS.Daniel via Fulldisclosure
Re: Security advisory: multiple vulnerabilities including Default-credential RCE, Pre-authentication root RCE in atvise SCADA 3.13.0 (atvise GmbH / Bachmann Visutec) LOMOSITS.Daniel via Fulldisclosure (Aug 17)
Matthias Deeg via Fulldisclosure
[SYSS-2026-049]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190) Matthias Deeg via Fulldisclosure (Aug 06)
[SYSS-2026-048]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190) Matthias Deeg via Fulldisclosure (Aug 06)
[SYSS-2026-047]: DICOM Toolkit (DCMTK) - Path traversal (CWE-22) Matthias Deeg via Fulldisclosure (Aug 06)
[SYSS-2026-050]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190) Matthias Deeg via Fulldisclosure (Aug 06)
[SYSS-2026-046]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190) Matthias Deeg via Fulldisclosure (Aug 06)
Nir Yehoshua
Cudy WR3000: Hard-coded JWT Secret to Root Command Injection Nir Yehoshua (Aug 19)
Öner Efe Güngör
CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC) Öner Efe Güngör (Aug 06)
Ron E
Escargot v4.3.0-214-gfaee4437 Unauthenticated Remote Debugger Allows Arbitrary JavaScript Evaluation and Local File Disclosure Ron E (Aug 26)
Escargot v4.3.0-214-gfaee4437 Debugger WebSocket Off-by-One Stack Buffer Overflow Ron E (Aug 26)
Chronicle Wire v2026.8 Arbitrary Class Instantiation During YAML Deserialization via Externally Controlled YAML Type Tags Ron E (Aug 26)
UltraJSON v5.13.0-6-g733f9e1 Length-Boundary Violation Causes Out-of-Bounds Read During Incomplete JSON Parsing Ron E (Aug 26)
Realtek edimax 52fc10d19 In-Band Ioctl Response Length Confusion Causes Heap Buffer Overflow Ron E (Aug 26)
Escargot v4.3.0-214-gfaee4437 OS Command Injection in Crash Handler via Unsanitized Executable Path Ron E (Aug 26)
Chronicle Wire v2026.8 Insecure Reflection Allows Unvalidated Method Invocation Ron E (Aug 26)
WatsonWebserver v7.1.0 HTTP/1 Chunked Request Processing Bypasses MaxRequestBodySize Ron E (Aug 26)
Chronicle Wire v2026.8 FileMarshallableOut Append Operations Follow Symbolic Links and Allow File Write Redirection Ron E (Aug 26)
shed riot
Dangling DNS record for bastion.certb.cdp.bethesda.net shed riot (Aug 06)
CL.0 desync in www.microsoft.com shed riot (Aug 06)
Shrikant Bhosale
The DCHECK Illusion: Chrome's "Trusted Path" Policy Creates Vulnerabilities Shrikant Bhosale (Aug 06)
Thomas Weber | CyberDanube via Fulldisclosure
Multiple Vulnerabilities in TBEA TLogger Communication Box 3rd Generation Thomas Weber | CyberDanube via Fulldisclosure (Aug 26)
