Posts tagged Vulnerability Disclosure

Vulnerabilities and Exploits
CVE-2025-10573: Ivanti EPM Unauthenticated Stored Cross-Site Scripting (Fixed)
Ryan Emmons

Vulnerabilities and Exploits
CVE-2025-13315, CVE-2025-13316: Critical Twonky Server Authentication Bypass (NOT FIXED)
Ryan Emmons

Vulnerabilities and Exploits
CVE-2025-10184: OnePlus OxygenOS Telephony provider permission bypass (FIXED as of October 11, 2025)
Rapid7

Vulnerabilities and Exploits
Securden Unified PAM: Multiple Critical Vulnerabilities (FIXED)
Aaron Herndon, Marcus Chang

Vulnerabilities and Exploits
CVE-2025-4365/CVE-2024-12284: NetScaler Console/SDX Authenticated Arbitrary File Read/Write (FIXED)
Calum Hutton

Vulnerabilities and Exploits
Konica Minolta bizhub Multifunction Printer: Pass-Back Attack Vulnerability (NOT FIXED)
Deral Heiland

Vulnerabilities and Exploits
CVE-2025-6759: Citrix Virtual Apps and Desktops - Local Privilege Escalation (FIXED)
Brandon Fisher

Vulnerabilities and Exploits
Multiple Brother Devices: Multiple Vulnerabilities (FIXED)
Stephen Fewer

Vulnerabilities and Exploits
CVE-2025-48045, CVE-2025-48046, CVE-2025-48047: MICI NetFax Server Product Vulnerabilities (NOT FIXED)
Anna Katarina Quinn

Threat Research
Multiple vulnerabilities in SonicWall SMA 100 series (FIXED)
Ryan Emmons

Vulnerabilities and Exploits
Xerox Versalink C7025 Multifunction Printer: Pass-Back Attack Vulnerabilities (FIXED)
Deral Heiland

Threat Research
CVE-2025-1094: PostgreSQL psql SQL injection (FIXED)
Stephen Fewer

Vulnerabilities and Exploits
Lorex 2K Indoor Wi-Fi Security Camera: Multiple Vulnerabilities (FIXED)
Stephen Fewer

Threat Research
Multiple Vulnerabilities in Wowza Streaming Engine (Fixed)
Ryan Emmons

Exposure Management
CVE-2024-45195: Apache OFBiz Unauthenticated Remote Code Execution (Fixed)
Ryan Emmons

Exposure Management
CVE-2024-6922: Automation Anywhere Automation 360 Server-Side Request Forgery
Ryan Emmons

Vulnerabilities and Exploits
CVE-2024-4978: Backdoored Justice AV Solutions Viewer Software Used in Apparent Supply Chain Attack
Rapid7

Threat Research
CVE-2024-27198 and CVE-2024-27199: JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities (FIXED)
Rapid7

Vulnerabilities and Exploits
CVE-2023-47218: QNAP QTS and QuTS Hero Unauthenticated Command Injection (FIXED)
Stephen Fewer

Vulnerabilities and Exploits
CVE-2023-5950 Rapid7 Velociraptor Reflected XSS
Dr. Mike Cohen
![Multiple Vulnerabilities in South River Technologies Titan MFT and Titan SFTP [FIXED]](/_next/image/?url=https%3A%2F%2Fimages.contentstack.io%2Fv3%2Fassets%2Fblte4f029e766e6b253%2Fblt1de2821d1eac3ffb%2F683ddc6570aa95f50bfe2f13%2Fvuln-disclosure-banner.jpeg%3Fauto%3Davif&w=1920&q=75)
Vulnerabilities and Exploits
Multiple Vulnerabilities in South River Technologies Titan MFT and Titan SFTP [FIXED]
Ron Bowes