Posts tagged Vulnerability Disclosure

Vulnerabilities and Exploits
Vulnerability Found in InsightVM & Nexpose: CVE-2026-1814 (FIXED)
Rapid7

Vulnerabilities and Exploits
CVE-2025-10573: Ivanti EPM Unauthenticated Stored Cross-Site Scripting (Fixed)
Ryan Emmons

Vulnerabilities and Exploits
CVE-2025-13315, CVE-2025-13316: Critical Twonky Server Authentication Bypass (NOT FIXED)
Ryan Emmons

Vulnerabilities and Exploits
CVE-2025-10184: OnePlus OxygenOS Telephony provider permission bypass (FIXED as of October 11, 2025)
Rapid7

Vulnerabilities and Exploits
Securden Unified PAM: Multiple Critical Vulnerabilities (FIXED)
Aaron Herndon, Marcus Chang

Vulnerabilities and Exploits
CVE-2025-4365/CVE-2024-12284: NetScaler Console/SDX Authenticated Arbitrary File Read/Write (FIXED)
Calum Hutton

Vulnerabilities and Exploits
Konica Minolta bizhub Multifunction Printer: Pass-Back Attack Vulnerability (NOT FIXED)
Deral Heiland

Vulnerabilities and Exploits
CVE-2025-6759: Citrix Virtual Apps and Desktops - Local Privilege Escalation (FIXED)
Brandon Fisher

Vulnerabilities and Exploits
Multiple Brother Devices: Multiple Vulnerabilities (FIXED)
Stephen Fewer

Vulnerabilities and Exploits
CVE-2025-48045, CVE-2025-48046, CVE-2025-48047: MICI NetFax Server Product Vulnerabilities (NOT FIXED)
Anna Katarina Quinn

Threat Research
Multiple vulnerabilities in SonicWall SMA 100 series (FIXED)
Ryan Emmons

Vulnerabilities and Exploits
Xerox Versalink C7025 Multifunction Printer: Pass-Back Attack Vulnerabilities (FIXED)
Deral Heiland

Threat Research
CVE-2025-1094: PostgreSQL psql SQL injection (FIXED)
Stephen Fewer

Vulnerabilities and Exploits
Lorex 2K Indoor Wi-Fi Security Camera: Multiple Vulnerabilities (FIXED)
Stephen Fewer

Threat Research
Multiple Vulnerabilities in Wowza Streaming Engine (Fixed)
Ryan Emmons

Exposure Management
CVE-2024-45195: Apache OFBiz Unauthenticated Remote Code Execution (Fixed)
Ryan Emmons

Exposure Management
CVE-2024-6922: Automation Anywhere Automation 360 Server-Side Request Forgery
Ryan Emmons

Vulnerabilities and Exploits
CVE-2024-4978: Backdoored Justice AV Solutions Viewer Software Used in Apparent Supply Chain Attack
Rapid7

Threat Research
CVE-2024-27198 and CVE-2024-27199: JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities (FIXED)
Rapid7

Vulnerabilities and Exploits
CVE-2023-47218: QNAP QTS and QuTS Hero Unauthenticated Command Injection (FIXED)
Stephen Fewer

Vulnerabilities and Exploits
CVE-2023-5950 Rapid7 Velociraptor Reflected XSS
Dr. Mike Cohen