Overview
News
Technologies
Salaries
Products
People
Growth
Financials

Overview

0day Rubbish is an autonomous, multi-LLM vulnerability research project publishing full root-cause analyses and reproducible PoCs for 0-day RCE chains in enterprise, ICS/SCADA, ERP, and NMS products. Responsible disclosure, full technical writeups.

News

Blog 20 days ago
MidVision RapidDeploy: Remote Agent Unauthenticated Arbitrary File Write Root RCE
MidVision RapidDeploy 5.2.2's remote agent (bisocket 20000) ships with host=0.0.0.0 and an empty auth.servers; isAuthorised returns true when authServers is empty. An unauthenticated attacker invokes RapidDeployCopyHandler and writes attacker-controlled b
Read more
Report
Blog 20 days ago
Cinegy Cinegize: Unauthenticated BinaryFormatter Deserialization LocalSystem RCE
Cinegy Cinegize runs CinegizeService as LocalSystem on TCP 51140. The DotNetty pipeline deserializes client input with BinaryFormatter before authorization, and the client-controlled Encryptor=None branch skips the password path. A TypeConfuseDelegate gad
Read more
Report
Blog 20 days ago
Output Messenger Server: Unauthenticated Zip-Slip Plugin Planting SYSTEM RCE
Output Messenger Server 2.0.x exposes an unauthenticated XMPP control plane (14121) and SOCKS5 file listener (14135). An anonymous attacker pushes a crafted ZIP extracted by an old SharpZipLib that permits .. entries, planting a plugin DLL; the next servi
Read more
Report
Blog 20 days ago
Telaeris XPressEntry: Unauthenticated SQL Injection to xp_cmdshell RCE
Telaeris XPressEntry 3.7.7454 exposes an unauthenticated HTTP API (RequireReaderCredentials=False by default). SaveVerifyActivity concatenates message_content raw into an INSERT; on SQL Server backends a COMMIT-breakout stacked query enables xp_cmdshell a
Read more
Report
Blog 20 days ago
Plixer Scrutinizer: Authenticated ORDER BY SQL Injection to pg_cron COPY TO PROGRAM RCE
Plixer Scrutinizer 19.7.0 adminEditLang passes the orderBy parameter raw into an ORDER BY clause. The plixer DB user is PostgreSQL SUPERUSER and pg_cron is installed by default, so an attacker schedules a COPY TO PROGRAM job and executes OS commands as po
Read more
Report
Pro access
Upgrade to see all 40 mentions
Upgrade to a paid plan to read every media mention of this company - funding news, awards, product launches and press releases from all the outlets writing about it.
Every media mention and press release
Funding news, awards and product launches
Fresh coverage from every outlet writing about the company
Upgrade now
Cancel anytime. Secure checkout. Instant activation.