Posted by Shaikh Shahnawaz on May 16
[+] Credits: Shahnawaz Shaikh, Security Researcher at Cybergate Defense LLCPosted by Sebastian AuwΓ€rter via Fulldisclosure on May 16
Advisory ID: SYSS-2025-006Posted by SEC Consult Vulnerability Lab via Fulldisclosure on May 16
SEC Consult Vulnerability Lab Security Advisory < 20250507-0 >Posted by SEC Consult Vulnerability Lab via Fulldisclosure on May 16
SEC Consult Vulnerability Lab Security Advisory < publishing date 20250429-0 >Posted by SEC Consult Vulnerability Lab via Fulldisclosure on May 16
SEC Consult Vulnerability Lab Security Advisory < 20250422-0 >Posted by Ron E on May 16
A session management vulnerability exists in gugoan's EconomizzerPosted by Ron E on May 16
A persistent cross-site scripting (XSS) vulnerability exists in gugoan'sPosted by Ron E on May 16
A persistent cross-site scripting (XSS) vulnerability exists in gugoan'sPosted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-9 Safari 18.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-8 visionOS 2.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-7 tvOS 18.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-6 watchOS 11.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-5 macOS Ventura 13.7.6Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-4 macOS Sonoma 14.7.6Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-3 macOS Sequoia 15.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-2 iPadOS 17.7.7Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-1 iOS 18.5 and iPadOS 18.5Posted by Egidio Romano on May 16
---------------------------------------------------------------------------Posted by Flo SchΓ€fer via Fulldisclosure on May 16
secuvera-SA-2025-01: Privilege EscalationPosted by CVE - VULSec Labs via Fulldisclosure on May 16
=== SUMMARY ===Posted by Paul Szabo via Fulldisclosure on May 06
=== Details ========================================================Posted by hyp3rlinx on May 01
[+] Credits: John Page (aka hyp3rlinx)Posted by Artur Janicki via Fulldisclosure on Apr 26
[APOLOGIES FOR CROSS-POSTING]Posted by Daniel Owens via Fulldisclosure on Apr 26
Inedo ProGet 2024.22 and below are vulnerable to unauthenticated denial of service and information disclosure attacksPosted by Daniel Owens via Fulldisclosure on Apr 26
Good morning. All current versions and all versions since the 2022/2023 "fix" to the Rails cross-site request forgeryPosted by hyp3rlinx on Apr 26
[-] Microsoft ".library-ms" File / NTLM Information DisclosurePosted by Marco Ivaldi on Apr 23
Hi,Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-4 visionOS 2.4.1Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-3 tvOS 18.4.1Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-2 macOS Sequoia 15.4.1Posted by Apple Product Security via Fulldisclosure on Apr 23
APPLE-SA-04-16-2025-1 iOS 18.4.1 and iPadOS 18.4.1Posted by Andrey Stoykov on Apr 23
# Exploit Title: Business Logic Flaw: Price Manipulation - alegrocartv1.2.9Posted by Andrey Stoykov on Apr 23
# Exploit Title: Stored XSS in "Message" Functionality - alegrocartv1.2.9Posted by Andrey Stoykov on Apr 23
# Exploit Title: XSS via SVG Image Upload - alegrocartv1.2.9Posted by Housma mardini on Apr 23
Hi Full Disclosure,Posted by Pierre Kim on Apr 13
No message preview for long message of 656780 bytes.Posted by Rafael Pedrero on Apr 13
<!--Posted by Nick Boyce on Apr 13
[Complete Apple product novice here (my devices all run a non-ApplePosted by Egidio Romano on Apr 13
------------------------------------------------------------------------------------Posted by Martin Heiland via Fulldisclosure on Apr 13
Dear subscribers,Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-04-01-2025-1 watchOS 11.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-11 visionOS 2.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-10 tvOS 18.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-9 macOS Ventura 13.7.5Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-8 macOS Sonoma 14.7.5Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-7 macOS Sequoia 15.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-6 iOS 15.8.4 and iPadOS 15.8.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-5 iOS 16.7.11 and iPadOS 16.7.11Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-4 iPadOS 17.7.6Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-3 iOS 18.4 and iPadOS 18.4Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-2 Xcode 16.3Posted by Apple Product Security via Fulldisclosure on Apr 02
APPLE-SA-03-31-2025-1 Safari 18.4Posted by Pierre Kim on Apr 02
## Advisory InformationPosted by Pierre Kim on Apr 02
## Advisory InformationPosted by Qualys Security Advisory via Fulldisclosure on Mar 27
Qualys Security AdvisoryPosted by Andrey Stoykov on Mar 24
# Exploit Title: SQL Injection in Admin Functionality - dolphin.prov7.4.2Posted by Andrey Stoykov on Mar 24
# Exploit Title: Stored XSS via Send Message Functionality -Posted by Apple Product Security via Fulldisclosure on Mar 20
APPLE-SA-03-11-2025-4 visionOS 2.3.2Posted by Apple Product Security via Fulldisclosure on Mar 20
APPLE-SA-03-11-2025-3 macOS Sequoia 15.3.2Posted by Apple Product Security via Fulldisclosure on Mar 20
APPLE-SA-03-11-2025-2 iOS 18.3.2 and iPadOS 18.3.2