Posted by Usman Saeed via Fulldisclosure on Aug 18
#!/usr/bin/env python3Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Aug 18
Confidentiality class: Internal & PartnerPosted by SEC Consult Vulnerability Lab via Fulldisclosure on Aug 18
Confidentiality class: Internal & PartnerPosted by Ron E on Aug 18
nopCommerce is vulnerable to Insufficient Resource Allocation Limits whenPosted by Ron E on Aug 18
nopCommerce versions v4.10 and v4.80.3 are vulnerable to *C*SV InjectionPosted by Ron E on Aug 18
nopCommerce v4.10 and 4.80.3 is vulnerable to Insufficient Invalidation ofPosted by Ron E on Aug 18
The application does not issue a new session identifier (JSESSIONID) afterPosted by Ron E on Aug 18
A CSV Injection vulnerability exists in iDempiere WebUIPosted by Ron E on Aug 18
lcf2xml (part of liblcf) aborts when parsing specially crafted RPG MakerPosted by Ron E on Aug 18
A crafted RPG Maker save file (`.lsd`) can trigger an integer overflow inPosted by Georg Lukas on Aug 18
<PDF advisory:Posted by Georg Lukas on Aug 18
PDF advisory: https://rt-solutions.de/piciorgros/Piciorgros_TMO-100_IP-Logger_en.pdfPosted by Jozef Sudolsky on Aug 18
Dear community,Posted by josephgoyd via Fulldisclosure on Aug 18
TITLE: Undocumented TCC Access to Multiple Privacy Domains via 'preflight=yes' in iOS 18.6Posted by Security Explorations on Aug 12
Dear All,Posted by Security Explorations on Aug 12
Dear All,Posted by Stefan Kanthak via Fulldisclosure on Aug 04
Hi @ll,Posted by Sandro Gauci via Fulldisclosure on Aug 02
Rtpengine: RTP Inject and RTP Bleed vulnerabilities despite proper configuration (CVSS v4.0 Score: 9.3 / Critical)Posted by Apple Product Security via Fulldisclosure on Aug 02
APPLE-SA-07-30-2025-1 Safari 18.6Posted by Stefan Kanthak via Fulldisclosure on Jul 29
Hi @ll,Posted by Thomas Weber | CyberDanube via Fulldisclosure on Jul 29
St. PΓΆlten UAS 20250721-0Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-8 visionOS 2.6Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-7 tvOS 18.6Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-6 watchOS 11.6Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-5 macOS Ventura 13.7.7Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-4 macOS Sonoma 14.7.7Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-3 macOS Sequoia 15.6Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-2 iPadOS 17.7.9Posted by Apple Product Security via Fulldisclosure on Jul 29
APPLE-SA-07-29-2025-1 iOS 18.6 and iPadOS 18.6Posted by Egidio Romano on Jul 29
----------------------------------------------------------------------------Posted by Sanjay Singh on Jul 29
Hello Full Disclosure community,Posted by Egidio Romano on Jul 29
-----------------------------------------------------------------------------------------Posted by Palula Brasil on Jul 29
The following snippet in the text is associated to the wrong CVE number:Posted by Andrey Stoykov on Jul 29
# Exploit Title: Stored XSS "Edit General Info" Functionality -Posted by Andrey Stoykov on Jul 29
# Exploit Title: Stored XSS "Create Page" Functionality - seotoasterv2.5.0Posted by Andrey Stoykov on Jul 29
# Exploit Title: Open Redirect "Login Page" Functionality - seotoasterv2.5.0Posted by Andrey Stoykov on Jul 29
# Exploit Title: Stored XSS "Edit Header" Functionality - seotoasterv2.5.0Posted by Egidio Romano on Jul 29
------------------------------------------------------------------Posted by Marcus Krueppel on Jul 29
================== Overview ==================Posted by KoreLogic Disclosures via Fulldisclosure on Jul 28
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory TraversalPosted by KoreLogic Disclosures via Fulldisclosure on Jul 28
KL-001-2025-015: Xorux LPAR2RRD Read Only User Log Download Exposing Sensitive InformationPosted by KoreLogic Disclosures via Fulldisclosure on Jul 28
KL-001-2025-014: Xorux LPAR2RRD Read Only User Denial of ServicePosted by KoreLogic Disclosures via Fulldisclosure on Jul 28
KL-001-2025-013: Xorux XorMon-NG Web Application Privilege Escalation to AdministratorPosted by KoreLogic Disclosures via Fulldisclosure on Jul 28
KL-001-2025-012: Xorux XorMon-NG Read Only User Export Device Configuration Exposing Sensitive InformationPosted by Gabriel Augusto Vaz de Lima via Fulldisclosure on Jul 19
=====[Tempest SecurityPosted by Tifa Lockhart via Fulldisclosure on Jul 12
Advisory ID: OPENBLOW-2025-003Posted by Office nullFaktor GmbH on Jul 11
nullFaktor Security Advisory < 20250719 >Posted by Egidio Romano on Jul 09
----------------------------------------------------------------------------------Posted by KoreLogic Disclosures via Fulldisclosure on Jul 09
KL-001-2025-011: Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Server-Side Request ForgeryPosted by KoreLogic Disclosures via Fulldisclosure on Jul 09
KL-001-2025-010: Schneider Electric EcoStruxure IT Data Center Expert Privilege EscalationPosted by KoreLogic Disclosures via Fulldisclosure on Jul 09
KL-001-2025-009: Schneider Electric EcoStruxure IT Data Center Expert Remote Command ExecutionPosted by KoreLogic Disclosures via Fulldisclosure on Jul 09
KL-001-2025-008: Schneider Electric EcoStruxure IT Data Center Expert Root Password DiscoveryPosted by KoreLogic Disclosures via Fulldisclosure on Jul 09
KL-001-2025-007: Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Remote Code ExecutionPosted by KoreLogic Disclosures via Fulldisclosure on Jul 09
KL-001-2025-006: Schneider Electric EcoStruxure IT Data Center Expert XML External Entities InjectionPosted by Security Explorations on Jul 09
Dear All,Posted by Andrey Stoykov on Jul 07
# Exploit Title: Directory Traversal "Site Title" - bluditv3.16.2Posted by Andrey Stoykov on Jul 07
# Exploit Title: XSS via SVG File Upload - bluditv3.16.2Posted by Andrey Stoykov on Jul 07
# Exploit Title: Stored XSS "Add New Content" Functionality - bluditv3.16.2Posted by Andrey Stoykov on Jul 07
# Exploit Title: Session Fixation - bluditv3.16.2Posted by josephgoyd via Fulldisclosure on Jun 30
Title: iOS Activation Flaw Enables Pre-User Device Compromise