CVE-2023-37470 - Remote Code Execution in Metabase via H2 Connection String Injection
Metabase is a widely used open-source business intelligence (BI) and analytics platform, popular for helping users visualize and analyze their data with ease. In
CVE-2023-29505 - WebSocket Hijacking in Zoho ManageEngine Network Configuration Manager 12.6.165
In April 2023, a serious security vulnerability—CVE-2023-29505—was discovered in Zoho ManageEngine Network Configuration Manager (NCM) version 12.6.165. This flaw
CVE-2023-34038 - Deep Dive into VMware Horizon Server’s Information Disclosure Exploit
If you manage or use virtual desktops, you probably know about VMware Horizon Server. It’s a popular tool for delivering virtual desktops and applications.
CVE-2023-4002 - Deep Dive Into The GitLab EE Security Policy Linking Vulnerability
In August 2023, a new vulnerability—CVE-2023-4002—was disclosed in GitLab Enterprise Edition (EE), a popular self-hosted Git repository management tool. This
CVE-2023-38950 - Exploiting a Path Traversal Vulnerability in ZKTeco BioTime v8.5.5
*Last updated: June 2024*
Introduction
Security flaws in widely-used biometric and attendance systems can have huge consequences—especially when trusted by thousands of companies
Episode
00:00:00
00:00:00