CVE-2025-23006 - Pre-Auth Deserialization Flaw Exposes SMA100 AMC/CMC to Remote Command Execution
June 2024 Update: A new critical vulnerability, CVE-2025-23006, has been published for SonicWall SMA100 Series’ Appliance Management Console (AMC) and Central Management Console
CVE-2024-53299 - Apache Wicket 7.. Request Handling Gets Abused for Easy Denial-of-Service (DoS)
In Apache Wicket version 7.., there’s a serious problem: how it handles requests in the core can be misused by attackers to easily take
CVE-2024-52975 - How Sensitive Info Leaked from Fleet Server Logs and Why You Should Patch Now
Security vulnerabilities often come in all shapes and sizes. Sometimes, something as simple as a verbose log can end up being a huge data leak.
CVE-2024-52972 - Kibana API Vulnerability Lets Attackers Crash Your Instance with a Simple Request
On June 7, 2024, a new vulnerability was disclosed, tracked as CVE-2024-52972, affecting Kibana — the popular open-source analytics and visualization tool from
CVE-2024-43707 - Sensitive Information Disclosure in Kibana's Elastic Agent Policies
---
In June 2024, a new vulnerability was disclosed in Kibana, tracked as CVE-2024-43707. This security issue enables users _without_ proper Fleet access to
Episode
00:00:00
00:00:00