As part of our ongoing research and consulting efforts, we frequently discover vulnerabilities in third-party products. Committed to enhancing the security of the digital ecosystem, we publish detailed security advisories according our vulnerability disclosure policy. You can find the full security advisories with complete details in our Github repository.
Below is an overview of our latest security advisories:
-
Mediatek Modem – Selection of less-secure algorithm during negotiation ‘algorithm downgrade’ (CVE-2024-20069)
July 31, 2024 -
ZTE ZXUN-ePDG – Use of non-unique cryptographic keys under default configuration (CVE-2024-22064)
July 31, 2024 -
Craft CMS – TOTP Token Stays Valid After Use (CVE-2024-41800)
July 26, 2024 -
Paradox IP150 Internet Module – Cross-Site Request Forgery (CVE-2024-5676)
June 19, 2024 -
CraftCMS Plugin – Two-Factor Authentication – TOTP token Stays Valid After Use (CVE-2024-5658)
June 6, 2024 -
CraftCMS Plugin – Two-Factor Authentication – Password Hash Disclosure (CVE-2024-5657)
June 6, 2024 -
CloudLinux CageFS – Insufficiently Restricted Proxy Command (CVE-2020-36772)
January 26, 2024 -
CloudLinux CageFS – Token Disclosure (CVE-2020-36771)
January 26, 2024