CVE-2023-36388 - How Improper REST API Permission in Apache Superset (≤ 2.1.) Can Lead to SSRF for Authenticated Gamma Users
Apache Superset is a popular open-source data visualization platform, used by businesses and data teams everywhere. But even the best tools sometimes have dangerous
CVE-2023-4761 - Out of Bounds Memory Access in FedCM in Google Chrome – What Happened, How It Works, and How Attackers Could Exploit It
In August 2023, Google patched a high-severity vulnerability in Chrome known as CVE-2023-4761. This flaw affected Chrome’s FedCM (Federated Credential Management)
CVE-2023-40918 - KnowStreaming 3.3. Privilege Escalation – How Attackers Get Admin Access (with Proof of Concept)
KnowStreaming is an open-source distributed data platform that’s getting a lot of buzz in the world of real-time data processing. But recently,
CVE-2023-40743 - Dangerous Service Lookups in Apache Axis 1.x Can Lead to RCE, SSRF, and DOS
In August 2023, a high-impact vulnerability was disclosed affecting applications based on Apache Axis 1.x, a Java-based SOAP engine. Identified as CVE-
CVE-2023-4614 - How Remote Attackers Can Take Over LG LED Assistant via setThumbnailRc Endpoint
---
LG’s LED Assistant is a tool used to control and customize large screen displays, especially in commercial environments. In mid-2023, a critical vulnerability
Episode
00:00:00
00:00:00