Full Disclosure·3h ago highharness Gitspace hardcoded password for every user account#harness#gitspaces#hardcoded-passwordVulnerability
Full Disclosure·3h ago highharness(gitness) registry webhook sort_order blind SQL injection#harness#gitness#sql-injectionVulnerability
Full Disclosure·3h agodive tar-slip in image file extraction#dive#tar-slip#path-traversalVulnerability
Full Disclosure·3h ago highopenEQUELLA authenticated RCE chain(s)#openequella#rce#deserializationVulnerability
Full Disclosure·3h ago[0day-rubbish] Server Technology PRO3X PDU 030600 port_mux listener program override to root command execution (7.2)#server-technology#legrand#pduVulnerability 5 sources
Full Disclosure·3h agoSCHUTZWERK-SA-2024-007: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education#xss#stored-xss#h5pVulnerability 2 sources
Full Disclosure·4d agoTeams meeting audio and roster data remain accessible via ACS Call Automation connectCall after a participant is removed from the meeting#microsoft#teams#azure-communication-servicesVulnerability
Full Disclosure·18d ago high[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)#cwe-306#dbxtra#full-disclosureVulnerability 2 sources
Full Disclosure·18d ago high[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)#accurate-online-private-cloud#deserialization#full-disclosureVulnerability
Full Disclosure·18d agoCVE-2026-52307: Stored XSS in 1CMS v5.6#1cms#classcms#full-disclosureCVE-2026-52307