CVE-2021-39090 - How a Missing HTTP Strict Transport Security Setting in IBM Cloud Pak for Security Leaked Sensitive Data
In 2021, a security flaw was discovered in IBM Cloud Pak for Security (CP4S), versions 1.10.. through 1.10.6.. This weakness, tracked as
CVE-2023-27545 - How IBM Watson CloudPak for Data Data Stores Exposes Sensitive Data Locally
In March 2023, IBM disclosed a new security vulnerability in its flagship data platform, IBM Watson CloudPak for Data. Tracked as CVE-2023-27545, this
CVE-2024-27516 - Server-Side Template Injection Vulnerability in LiveHelperChat Before v4.34 Allows Remote Code Execution
On February 2024, a new critical vulnerability—CVE-2024-27516—was discovered in LiveHelperChat, an open-source live support chat system. The issue, present in
CVE-2024-26458 - Memory Leak Vulnerability in Kerberos 5 (krb5) 1.21.2 Explored
Kerberos is one of the most crucial protocols in secure authentication. It is widely used in enterprise environments (like Active Directory) and open-source projects.
CVE-2024-25930 - Exploiting CSRF in Nuggethon Custom Order Statuses for WooCommerce (<= 1.5.2)
On February 21, 2024, a serious security vulnerability was disclosed in the Nuggethon Custom Order Statuses for WooCommerce plugin, affecting all versions up to 1.
Episode
00:00:00
00:00:00