Posted by Shaikh Shahnawaz on May 16
[+] Credits: Shahnawaz Shaikh, Security Researcher at Cybergate Defense LLCPosted by Sebastian Auwärter via Fulldisclosure on May 16
Advisory ID: SYSS-2025-006Posted by SEC Consult Vulnerability Lab via Fulldisclosure on May 16
SEC Consult Vulnerability Lab Security Advisory < 20250507-0 >Posted by SEC Consult Vulnerability Lab via Fulldisclosure on May 16
SEC Consult Vulnerability Lab Security Advisory < publishing date 20250429-0 >Posted by SEC Consult Vulnerability Lab via Fulldisclosure on May 16
SEC Consult Vulnerability Lab Security Advisory < 20250422-0 >Posted by Ron E on May 16
A session management vulnerability exists in gugoan's EconomizzerPosted by Ron E on May 16
A persistent cross-site scripting (XSS) vulnerability exists in gugoan'sPosted by Ron E on May 16
A persistent cross-site scripting (XSS) vulnerability exists in gugoan'sPosted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-9 Safari 18.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-8 visionOS 2.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-7 tvOS 18.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-6 watchOS 11.5Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-5 macOS Ventura 13.7.6Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-4 macOS Sonoma 14.7.6Posted by Apple Product Security via Fulldisclosure on May 16
APPLE-SA-05-12-2025-3 macOS Sequoia 15.5Posted by Paul Szabo via Fulldisclosure on May 06
=== Details ========================================================Posted by hyp3rlinx on May 01
[+] Credits: John Page (aka hyp3rlinx)Posted by Artur Janicki via Fulldisclosure on Apr 26
[APOLOGIES FOR CROSS-POSTING]Posted by Daniel Owens via Fulldisclosure on Apr 26
Inedo ProGet 2024.22 and below are vulnerable to unauthenticated denial of service and information disclosure attacksPosted by Daniel Owens via Fulldisclosure on Apr 26
Good morning. All current versions and all versions since the 2022/2023 "fix" to the Rails cross-site request forgery