Posted by Paul Szabo via Fulldisclosure on May 06
=== Details ========================================================Posted by hyp3rlinx on May 01
[+] Credits: John Page (aka hyp3rlinx)Posted by Artur Janicki via Fulldisclosure on Apr 26
[APOLOGIES FOR CROSS-POSTING]Posted by Daniel Owens via Fulldisclosure on Apr 26
Inedo ProGet 2024.22 and below are vulnerable to unauthenticated denial of service and information disclosure attacksPosted by Daniel Owens via Fulldisclosure on Apr 26
Good morning. All current versions and all versions since the 2022/2023 "fix" to the Rails cross-site request forgeryPosted by hyp3rlinx on Apr 26
[-] Microsoft ".library-ms" File / NTLM Information DisclosurePosted by Marco Ivaldi on Apr 23
Hi,Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-4 visionOS 2.4.1Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-3 tvOS 18.4.1Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-2 macOS Sequoia 15.4.1Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-1 iOS 18.4.1 and iPadOS 18.4.1Posted by Andrey Stoykov on Apr 23
# Exploit Title: Business Logic Flaw: Price Manipulation - alegrocartv1.2.9Posted by Andrey Stoykov on Apr 23
# Exploit Title: Stored XSS in "Message" Functionality - alegrocartv1.2.9Posted by Andrey Stoykov on Apr 23
# Exploit Title: XSS via SVG Image Upload - alegrocartv1.2.9Posted by Housma mardini on Apr 23
Hi Full Disclosure,Posted by Pierre Kim on Apr 13
No message preview for long message of 656780 bytes.Posted by Rafael Pedrero on Apr 13
<!--Posted by Nick Boyce on Apr 13
[Complete Apple product novice here (my devices all run a non-ApplePosted by Egidio Romano on Apr 13
------------------------------------------------------------------------------------Posted by Martin Heiland via Fulldisclosure on Apr 13
Dear subscribers,Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-04-01-2025-1 watchOS 11.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-11 visionOS 2.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-10 tvOS 18.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-9 macOS Ventura 13.7.5Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-8 macOS Sonoma 14.7.5Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-7 macOS Sequoia 15.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-6 iOS 15.8.4 and iPadOS 15.8.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-5 iOS 16.7.11 and iPadOS 16.7.11Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-4 iPadOS 17.7.6Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-3 iOS 18.4 and iPadOS 18.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-2 Xcode 16.3Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-1 Safari 18.4Posted by Pierre Kim on Apr 02
## Advisory InformationPosted by Pierre Kim on Apr 02
## Advisory InformationPosted by Qualys Security Advisory via Fulldisclosure on Mar 27
Qualys Security AdvisoryPosted by Andrey Stoykov on Mar 24
# Exploit Title: SQL Injection in Admin Functionality - dolphin.prov7.4.2Posted by Andrey Stoykov on Mar 24
# Exploit Title: Stored XSS via Send Message Functionality -Posted by Apple Product Security via Fulldisclosure on Mar 20
APPLE-SA-03-11-2025-4 visionOS 2.3.2Posted by Apple Product Security via Fulldisclosure on Mar 20
APPLE-SA-03-11-2025-3 macOS Sequoia 15.3.2Posted by Apple Product Security via Fulldisclosure on Mar 20
APPLE-SA-03-11-2025-2 iOS 18.3.2 and iPadOS 18.3.2Posted by Apple Product Security via Fulldisclosure on Mar 20
APPLE-SA-03-11-2025-1 Safari 18.3.1Posted by Lucas Lalumière on Mar 20
[Author]: Lucas LalumierePosted by areca-palm via Fulldisclosure on Mar 11
[CVE pending]Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Feb 27
SEC Consult Vulnerability Lab Security Advisory < 20250226-0 >Posted by Jordy Zomer on Feb 27
Hey all,Posted by Qualys Security Advisory via Fulldisclosure on Feb 20
Qualys Security AdvisoryPosted by Andrey Stoykov on Feb 20
# Exploit Title: Self Stored XSS - acp2sev7.2.2Posted by Georgi Guninski on Feb 20
Python's official documentation contains textbook example of insecure code (XSS)Posted by Gynvael Coldwind on Feb 17
Hi,Posted by upper.underflow via Fulldisclosure on Feb 16
Hello,Posted by Ryan Delaney via Fulldisclosure on Feb 16
<!--Posted by Gabriel Valachi via Fulldisclosure on Feb 15
In GZDoom 4.13.1 and below, there is a vulnerability involving array sizes in ZScript, the game engine's primaryPosted by David Fifield on Feb 15
Today at about 2025-02-13 19:00 I noticed the "β " is back, but now thePosted by SEC Consult Vulnerability Lab via Fulldisclosure on Feb 12
SEC Consult Vulnerability Lab Security Advisory < 20250211-0 >Posted by Apple Product Security via Fulldisclosure on Feb 10
APPLE-SA-02-10-2025-2 iPadOS 17.7.5Posted by Apple Product Security via Fulldisclosure on Feb 10
APPLE-SA-02-10-2025-1 iOS 18.3.1 and iPadOS 18.3.1Posted by Jeroen Hermans via Fulldisclosure on Feb 10
CloudAware Security AdvisoryPosted by Georgi Guninski on Feb 10
Summary: On 2025-02-09 ChatGPT AI found "security concern" (XSS) inPosted by KoreLogic Disclosures via Fulldisclosure on Feb 04
KL-001-2025-002: Checkmk NagVis Remote Code ExecutionPosted by KoreLogic Disclosures via Fulldisclosure on Feb 04
KL-001-2025-001: Checkmk NagVis Reflected Cross-site Scripting