Vulnerability Alerts

Vulnerability Alerts

CVEs, zero-days, exploits, and security advisories

VULNcriticalFull Disclosureabout 16 hours ago

[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)

VULNcriticalFull Disclosureabout 16 hours ago

[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)

VULNcriticalCVE-2025-34115Full Disclosureabout 16 hours ago

[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)

VULNcriticalFull Disclosureabout 16 hours ago

[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

VULNcriticalFull Disclosureabout 16 hours ago

[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)

VULNcriticalFull Disclosureabout 16 hours ago

[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)

FD
VULNcriticalFull Disclosureabout 16 hours ago

[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)

FD
VULNcriticalFull Disclosureabout 16 hours ago

[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)

FD
VULNhighCVE-2026-2035703Full Disclosureabout 16 hours ago

**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)

FD
VULNhighCVE-2026-52307Full Disclosureabout 16 hours ago

CVE-2026-52307: Stored XSS in 1CMS v5.6

VULNCheck Point Researchabout 21 hours ago

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

VULNGoogle Project Zero1 day ago

Testing race conditions with memory access tracing and stack-based delay injection

ZD
VULNhighCVE-2026-506967.5 HIGHZero Day Initiative1 day ago

ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

ZD
VULNhighCVE-2026-627127.8 HIGHZero Day Initiative1 day ago

ZDI-26-621: Microsoft Windows UMPDDrvRealizeBrush Improper Object Management Local Privilege Escalation Vulnerability

ZD
VULNhighCVE-2026-627127.8 HIGHZero Day Initiative1 day ago

ZDI-26-620: Microsoft Windows UMPDDrvPlgBlt Improper Object Management Local Privilege Escalation Vulnerability

ZD
VULNhighCVE-2026-627127.8 HIGHZero Day Initiative1 day ago

ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerability

ZD
VULNhighCVE-2026-627127.8 HIGHZero Day Initiative1 day ago

ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability

ZD
VULNhighCVE-2026-668047.8 HIGHZero Day Initiative1 day ago

ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability

ZD
VULNhighCVE-2026-19780Zero Day Initiative1 day ago

ZDI-26-616: Koha Eval Code Injection Remote Code Execution Vulnerability

VULNCheck Point Research2 days ago

7th September – Threat Intelligence Report

VULNMicrosoft Security5 days ago

How to secure edge AI in customer-owned environments

VULNhighCVE-2026-12554Full Disclosure5 days ago

HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556

VULNFull Disclosure5 days ago

Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists

VULNFull Disclosure5 days ago

O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script

VULNFull Disclosure5 days ago

Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion

VULNFull Disclosure5 days ago

Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery

VULNFull Disclosure5 days ago

Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read

VULNFull Disclosure5 days ago

Flextype v1.0.0-alpha.3 Stored Expression Injection Enables PHP Remote Code Execution

FD
VULNFull Disclosure5 days ago

Flextype v1.0.0-alpha.3 NULL access_token Authentication Bypass

FD
VULNFull Disclosure5 days ago

Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure