CVE-2024-55160 - SQL Injection in GFast v2 to v3.2 via the `OrderBy` Parameter
In the ongoing battle for cybersecurity, SQL injection vulnerabilities remain a top threat for web applications. In this blog post, we focus on a newly
CVE-2024-51138 - Remote Code Execution in DrayTek Vigor Routers via TR-069 STUN URL Parsing (Exploit and Technical Deep-Dive)
---
A new critical vulnerability, CVE-2024-51138, has been identified in several popular DrayTek Vigor router models (source). This security flaw could let a remote
CVE-2024-41334 - DrayTek Vigor Certificate Validation Bypass Leads to Remote Code Execution
---
Overview
A newly discovered vulnerability tracked as CVE-2024-41334 affects a wide range of DrayTek Vigor devices, allowing attackers to upload and execute malicious
CVE-2025-21765 - Linux Kernel ipv6 RCU Protection Bypass Exploit Detailed
In early 2024, security professionals noticed a subtle but significant vulnerability in the Linux kernel's IPv6 networking stack. Officially cataloged as CVE-2025-
CVE-2025-21715 - How a Linux Kernel Use-After-Free in dm900 Network Driver Was Fixed
---
TL;DR
A critical use-after-free (UAF) bug was found and patched in the Linux kernel’s dm900 network driver, officially tracked as CVE-
Episode
00:00:00
00:00:00