CVE-2021-30153 - VisualEditor in MediaWiki Leaks Existence of Hidden Users
CVE-2021-30153 is a security vulnerability found in the VisualEditor extension for MediaWiki. MediaWiki is the open-source software that runs Wikipedia and many
CVE-2023-29202 - Critical XSS in XWiki Commons RSS Macro—How It Works, Exploit, and Fixes
A critical security vulnerability—CVE-2023-29202—was discovered in XWiki Commons, affecting the bundled RSS macro. Attackers could inject malicious HTML and JavaScript content
CVE-2023-29193 - Exposing Sensitive gRPC Preshared Keys via SpiceDB Metrics Endpoint
SpiceDB is a powerful, open-source permissions database inspired by Google's Zanzibar design. As more organizations use SpiceDB to handle critical application permissions,
CVE-2022-45173 - Exploiting LIVEBOX Collaboration vDesk 2FA Bypass via Broken API Challenge
In late 2022, a critical vulnerability was discovered in the LIVEBOX Collaboration vDesk product (through version v018), tracked as CVE-2022-45173. This flaw exposes
CVE-2023-20863 - How a Simple Spring SpEL Expression Can Take Down Your App (With Exploit Code and Details)
Spring Framework is everywhere in the Java world, powering millions of web applications, APIs, and enterprise systems. Sometimes, though, even trusted frameworks like Spring develop
Episode
00:00:00
00:00:00