Posted by josephgoyd via Fulldisclosure on Jun 17
"Glass Cage" β Sophisticated Zero-Click iMessage Exploit ChainEnabling Persistent iOS Compromise and Device BrickingPosted by SEC Consult Vulnerability Lab via Fulldisclosure on Jun 17
SEC Consult Vulnerability Lab Security Advisory < 20250612-0 >Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Jun 17
SEC Consult Vulnerability Lab Security Advisory < 20250611-0 >Posted by 0610648533 on Jun 17
========================================================================Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Jun 09
SEC Consult Vulnerability Lab Security Advisory < 20250604-0 >Posted by josephgoyd via Fulldisclosure on Jun 09
Hello Full Disclosure,Posted by Stefan Kanthak on Jun 03
Hi @ll,Posted by Sanjay Singh on Jun 03
Hello Full Disclosure list,Posted by Ron E on Jun 03
An authenticated attacker can inject JavaScript into the bio field of theirPosted by Ron E on Jun 03
An authenticated user can inject malicious JavaScript into the user_imagePosted by Qualys Security Advisory via Fulldisclosure on Jun 03
Qualys Security AdvisoryPosted by Andrey Stoykov on Jun 03
# Exploit Title: Stored XSS via File Upload - adaptcmsv3.0.3Posted by Andrey Stoykov on Jun 03
# Exploit Title: IDOR "Change Password" Functionality - adaptcmsv3.0.3Posted by Andrey Stoykov on Jun 03
# Exploit Title: Stored XSS "Send Message" Functionality - adaptcmsv3.0.3Posted by Andrey Stoykov on Jun 03
# Exploit Title: Authenticated File Upload to RCE - adaptcmsv3.0.3Posted by Andrey Stoykov on Jun 03
# Exploit Title: Stored XSS in "Description" Functionality - cubecartv6.5.9Posted by MichaΕ Majchrowicz via Fulldisclosure on Jun 03
Security AdvisoryPosted by Juho ForsΓ©n via Fulldisclosure on Jun 03
The PSF requests library (https://github.com/psf/requests & https://pypi.org/project/requests/) leaks .netrcPosted by Housma mardini on Jun 03
Hi,Posted by Jacek Lipkowski via Fulldisclosure on Jun 03
Hi,Posted by SEC Consult Vulnerability Lab via Fulldisclosure on May 27
SEC Consult Vulnerability Lab Security Advisory < 20250521-0 >Posted by Ron E on May 27
ο»ΏPosted by Shaikh Shahnawaz on May 16
[+] Credits: Shahnawaz Shaikh, Security Researcher at Cybergate Defense LLCPosted by Sebastian AuwΓ€rter via Fulldisclosure on May 16
Advisory ID: SYSS-2025-006Posted by SEC Consult Vulnerability Lab via Fulldisclosure on May 16
SEC Consult Vulnerability Lab Security Advisory < 20250507-0 >Posted by SEC Consult Vulnerability Lab via Fulldisclosure on May 16
SEC Consult Vulnerability Lab Security Advisory < publishing date 20250429-0 >Posted by SEC Consult Vulnerability Lab via Fulldisclosure on May 16
SEC Consult Vulnerability Lab Security Advisory < 20250422-0 >Posted by Ron E on May 16
A session management vulnerability exists in gugoan's EconomizzerPosted by Ron E on May 16
A persistent cross-site scripting (XSS) vulnerability exists in gugoan'sPosted by Ron E on May 16
A persistent cross-site scripting (XSS) vulnerability exists in gugoan'sPosted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-9 Safari 18.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-8 visionOS 2.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-7 tvOS 18.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-6 watchOS 11.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-5 macOS Ventura 13.7.6Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-4 macOS Sonoma 14.7.6Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-3 macOS Sequoia 15.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-2 iPadOS 17.7.7Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-1 iOS 18.5 and iPadOS 18.5Posted by Egidio Romano on May 16
---------------------------------------------------------------------------Posted by Flo SchΓ€fer via Fulldisclosure on May 16
secuvera-SA-2025-01: Privilege EscalationPosted by CVE - VULSec Labs via Fulldisclosure on May 16
=== SUMMARY ===Posted by Paul Szabo via Fulldisclosure on May 06
=== Details ========================================================Posted by hyp3rlinx on May 01
[+] Credits: John Page (aka hyp3rlinx)Posted by Artur Janicki via Fulldisclosure on Apr 26
[APOLOGIES FOR CROSS-POSTING]Posted by Daniel Owens via Fulldisclosure on Apr 26
Inedo ProGet 2024.22 and below are vulnerable to unauthenticated denial of service and information disclosure attacksPosted by Daniel Owens via Fulldisclosure on Apr 26
Good morning. All current versions and all versions since the 2022/2023 "fix" to the Rails cross-site request forgeryPosted by hyp3rlinx on Apr 26
[-] Microsoft ".library-ms" File / NTLM Information DisclosurePosted by Marco Ivaldi on Apr 23
Hi,Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-4 visionOS 2.4.1Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-3 tvOS 18.4.1Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-2 macOS Sequoia 15.4.1Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-1 iOS 18.4.1 and iPadOS 18.4.1Posted by Andrey Stoykov on Apr 23
# Exploit Title: Business Logic Flaw: Price Manipulation - alegrocartv1.2.9Posted by Andrey Stoykov on Apr 23
# Exploit Title: Stored XSS in "Message" Functionality - alegrocartv1.2.9Posted by Andrey Stoykov on Apr 23
# Exploit Title: XSS via SVG Image Upload - alegrocartv1.2.9Posted by Housma mardini on Apr 23
Hi Full Disclosure,Posted by Pierre Kim on Apr 13
No message preview for long message of 656780 bytes.Posted by Rafael Pedrero on Apr 13
<!--Posted by Nick Boyce on Apr 13
[Complete Apple product novice here (my devices all run a non-Apple