❌

Normal view

Code Security Review tool

22 September 2026 at 18:34

Posted by E. Kellinis on Sep 22

Karma Pro is an open source code review tool that can assist code reviewers with a multitude of useful tools. Karma Pro
is a macOS source-code security scanner (AST base and Heuristics) that statically analyses projects in multiple
languages. It's backed by an ML classifier trained on real patches to catch subtle issues. Beyond scanning, it offers
interactive call graphs and data-flow diagrams, a bug tracker, a private research wiki,...

CFP No cON Name 2k26 - Palma, Mallorca - Spain

22 September 2026 at 18:32

Posted by Jose Nicolas Castellano on Sep 22

No cON Name 2026 - Palma, Mallorca - Balearic Islands

************************************
*****Β  Call For PapersΒ  Β  Β  Β  ******
************************************

https://www.noconname.org/call-for-papers/

Exact place not disclosed until a few weeks before due celebration.

Β  Β  * INTRODUCTIONfulldisclosure () seclists org
The organization hasΒ  opened CFP proposals. No cON Name is the eldest
Hacking
and Security Conference in Span....

CVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2)

22 September 2026 at 18:32

Posted by Louis Sanchez via Fulldisclosure on Sep 22

Posting this as an update rather than a first disclosure. The advisory
went public on 2026-08-04 with no vendor fix. Penpot has shipped two
releases since then, 2.17.1 and 2.17.2 -- the latter 14 days ago, on
2026-08-27 -- and I re-checked the code this morning: the missing
permission check is still missing in both, and in every release before
them. It was fixed on develop the day after this advisory went public.
That fix has never shipped....

APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27

22 September 2026 at 18:31

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27

iOS 27 and iPadOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149034.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch...

[0day-rubbish] Opengear NGCS 25.11.8 Authenticated PDU name command injection to root via io.popen (8.8)

22 September 2026 at 18:31

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Opengear NGCS 25.11.8.

Type: Authenticated PDU name command injection to root via io.popen (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact: root command execution on the out-of-band console manager
Authentication: authenticated administrator

Full technical analysis and a reproducible proof-of-concept:...

[0day-rubbish] LCDS Laquis SCADA Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (9.8)

22 September 2026 at 18:31

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
LCDS Laquis SCADA.

Type: Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (CWE-434)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary native code execution inside the SCADA web and HMI process, which also hosts the Modbus TCP listener
Authentication: unauthenticated (no password configured is the default)

Full technical analysis and a...

[0day-rubbish] Ecava IntegraXor IGX 16.0.701.10 Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (9.8)

22 September 2026 at 18:31

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Ecava IntegraXor IGX 16.0.701.10.

Type: Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary command execution as Administrator on a Web SCADA HMI host
Authentication: unauthenticated

Full technical analysis and a reproducible proof-of-concept:...

[0day-rubbish] Devolutions Server (DVLS) 2026.2.14.0 PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (9.1)

22 September 2026 at 18:31

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Devolutions Server (DVLS) 2026.2.14.0.

Type: PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (CWE-862)
CVSS: 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Impact: arbitrary PowerShell execution as NT AUTHORITY\SYSTEM on the Devolutions Server host
Authentication: authenticated administrator (no PAM licence, no PAM role)

Full technical analysis and a...

[0day-rubbish] CaptureBites MetaServer Anonymous WCF SOAP workflow leading to RunPrograms code execution (9.8)

22 September 2026 at 18:31

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
CaptureBites MetaServer.

Type: Anonymous WCF SOAP workflow leading to RunPrograms code execution (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary command execution as NT AUTHORITY\SYSTEM on the MetaServer host
Authentication: unauthenticated

Full technical analysis and a reproducible proof-of-concept:...

[0day-rubbish] PrizmDoc for Java (VirtualViewer) 5.22.1 Unauthenticated uploadDocument write into the webapp root to JSP webshell (9.8)

22 September 2026 at 18:31

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
PrizmDoc for Java (VirtualViewer) 5.22.1.

Type: Unauthenticated uploadDocument write into the webapp root to JSP webshell (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: JSP webshell execution with the JVM privileges, uid 0 (root) in the verified deployment
Authentication: unauthenticated

Full technical analysis and a reproducible proof-of-concept:...

Teams meeting audio and roster data remain accessible via ACS Call Automation connectCall after a participant is removed from the meeting

22 September 2026 at 18:31

Posted by Jacob Greenway on Sep 22

Hi Full Disclosure team,

I'm not a traditional security researcher by background - I found this
while working with the ACS and Teams SDKs and followed it through to a full
writeup and PoC. I've done my best to be accurate and responsible
throughout (reporting to MSRC first, giving advance notice of this
disclosure date, and only testing against meetings/tenants I own), but if
anything here is imprecise or doesn't match community...

UAF in XMEye Security Camera

22 September 2026 at 18:29

Posted by evan on Sep 22

checksec:

$ checksec --file Sofia
[*] '/redacted/Sofia'
Arch: arm-32-little
RELRO: No RELRO
Stack: Canary found
NX: NX unknown - GNU_STACK missing
PIE: No PIE (0x8000)
Stack: Executable
RWX: Has RWX segments

this ones interesting. sofia uses an internal flash fs called WFS. per
an online search:

WFS is a proprietary filesystem developed by Hikvision for its...

SCHUTZWERK-SA-2024-007: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education

22 September 2026 at 18:25

Posted by David Brown via Fulldisclosure on Sep 22

A stored cross-site scripting (XSS) vulnerability has been identified in
the H5P module
h5p-nodejs-library by Lumi Education UG in versions up to and including
10.0.4. The
library allows users to upload H5P content that contains malicious
JavaScript. This code
is then executed in the browsers of other users who view the affected
H5P content.

Metadata
========

- Affected product: h5p-nodejs-library
- Affected version: All versions up to and...

[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path
without credential override (7.2)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
Royal Server 5.04.50529.0.

Type: Local privilege escalation to LocalSystem on the execution path without credential override (CWE-250)
CVSS: 7.2...

[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote
escaping (8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
core-admin 1.0.164 (build 16468).

Type: Systemic shell command injection via ineffective quote escaping (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)...

[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective)
(8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
OP5 Monitor 9.20.

Type: Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact:...

[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field
(8.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
QuantaStor 6.8.3.018.

Type: Command injection in the alert-mail command via the smtpPassword field (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact:...

[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT
AUTHORITY\SYSTEM (7.2)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
SmarterMail 100.0.9693 (Build 9693).

Type: Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (CWE-250)
CVSS: 7.2...

[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded
credentials leading to OS command execution (9.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6).

Type: Unauthenticated SOAP with hard-coded credentials leading...

[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)

8 September 2026 at 17:31

Posted by disclosure via Fulldisclosure on Sep 08

TO: fulldisclosure () seclists org
SUBJECT: [0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading
to JNDI remote class loading (9.8)
FROM: disclosure () 0day-rubbish com
----BODY----
0day Rubbish Research Team is publicly disclosing a vulnerability in
Accurate Online Private Cloud on-prem (current).

Type: Unauthenticated Hessian deserialization leading to JNDI remote class loading...
❌