As part of our ongoing research and consulting efforts, we frequently discover vulnerabilities in third-party products. Committed to enhancing the security of the digital ecosystem, we publish detailed security advisories according our vulnerability disclosure policy. You can find the full security advisories with complete details in our Github repository.
Below is an overview of our latest security advisories:
-
MOKOSmart MKGW1 Gateway – Improper Session Management (CVE-2023-51059)
December 21, 2023 -
Vtiger CRM – Stored Cross-Site Scripting (CVE-2022-38335)
September 28, 2022 -
Shibboleth Identity Provider OIDC OP Plugin – Server-Side Request Forgery (CVE-2022-24129)
February 1, 2022 -
Monsta FTP – Stored Cross-Site Scripting (CVE-2020-14055)
July 1, 2020 -
Monsta FTP – Server-Side Request Forgery (CVE-2020-14056)
July 1, 2020 -
Monsta FTP – Arbitrary File Read and Write (CVE-2020-14057)
July 1, 2020 -
WordPress Plugin – All in One SEO Pack – Stored XSS (CVE-2019-16520)
October 23, 2019 -
WordPress Plugin – Broken Link Checker – Reflected XSS (CVE-2019-16521)
October 23, 2019