Posted by Stefan Kanthak on Jun 03
Hi @ll,Posted by Sanjay Singh on Jun 03
Hello Full Disclosure list,Posted by Ron E on Jun 03
An authenticated attacker can inject JavaScript into the bio field of theirPosted by Ron E on Jun 03
An authenticated user can inject malicious JavaScript into the user_imagePosted by Qualys Security Advisory via Fulldisclosure on Jun 03
Qualys Security AdvisoryPosted by Andrey Stoykov on Jun 03
# Exploit Title: Stored XSS via File Upload - adaptcmsv3.0.3Posted by Andrey Stoykov on Jun 03
# Exploit Title: IDOR "Change Password" Functionality - adaptcmsv3.0.3Posted by Andrey Stoykov on Jun 03
# Exploit Title: Stored XSS "Send Message" Functionality - adaptcmsv3.0.3Posted by Andrey Stoykov on Jun 03
# Exploit Title: Authenticated File Upload to RCE - adaptcmsv3.0.3Posted by Andrey Stoykov on Jun 03
# Exploit Title: Stored XSS in "Description" Functionality - cubecartv6.5.9Posted by Michał Majchrowicz via Fulldisclosure on Jun 03
Security AdvisoryPosted by Juho Forsén via Fulldisclosure on Jun 03
The PSF requests library (https://github.com/psf/requests & https://pypi.org/project/requests/) leaks .netrcPosted by Housma mardini on Jun 03
Hi,Posted by Jacek Lipkowski via Fulldisclosure on Jun 03
Hi,Posted by Jordan Wiens via Dailydave on May 30
Worth pointing out that the RE//verse videos are also online though I don'tPosted by SEC Consult Vulnerability Lab via Fulldisclosure on May 27
SEC Consult Vulnerability Lab Security Advisory < 20250521-0 >Posted by Ron E on May 27
Posted by Dave Aitel via Dailydave on May 27
https://www.linkedin.com/mwlite/feed/posts/daveaitel_for-the-offensive-information-professionals-activity-7331470514927865856-Posted by Andrew Case via Dailydave on May 27
The Volatility Team is very excited to announce the official ParityPosted by Dave Aitel via Dailydave on May 27
https://www.linkedin.com/jobs/view/4233405535/