Warp Terminal
Read my full technical breakdown
| CVE ID | Description | 
|---|
| CVE-2024-41997 | Warp Protocol Handler RCE (Command Injection) | 
OpenText NetIQ iManager
Read my full technical breakdown
| CVE ID | Description | 
|---|
| CVE-2024-4429 | iManager CSRF Validation Bypass | 
| CVE-2024-3970 | iManager Create eGuide Blind SSRF | 
| CVE-2024-3969 | iManager Unsafe Stylesheet Parsing RCE | 
| CVE-2024-3968 | iManager Plugin Studio Installer RCE | 
| CVE-2024-3967 | iManager Email Config Deserialization RCE | 
| CVE-2024-3488 | iManager Autoparse Arbitrary File Upload | 
| CVE-2024-3487 | iManager fw_authState Authentication Bypass | 
| CVE-2024-3486 | iManager ModulesToInstall XXE | 
| CVE-2024-3485 | iManager Multiple data handler directory traversal file disclosure | 
| CVE-2024-3484 | iManager OctetStringUpload path traversal -> privesc + file disclosure | 
| CVE-2024-3483 | iManager checkForLocaleDirectory command injection RCE | 
Ivanti Endpoint Manager
Read my full technical breakdown
| CVE ID | Description | 
|---|
| CVE-2023-28323 | Ivanti EPM Unsafe Deserialization Leading to RCE | 
| CVE-2023-28324 | Ivanti EPM Insufficient Client Validation Leading to Privilege Escalation | 
| CVE-2023-38343 | Ivanti EPM XXE Leading to File Disclosure and SSRF | 
| CVE-2023-38344 | Ivanti EPM Authenticated Arbitrary File Read | 
PrinterLogic
Read my full technical breakdown
| CVE ID | Description | 
|---|
| CVE-2021-42631 | Printerlogic Object Injection leading to RCE | 
| CVE-2021-42635 | Printerlogic Hardcoded APP_KEY leading to RCE | 
| CVE-2021-42638 | Printerlogic Misc command injections leading to RCE | 
| CVE-2021-42633 | Printerlogic SQLi may disclose audit logs | 
| CVE-2021-42637 | Printerlogic Blind SSRF | 
| CVE-2021-42639 | Printerlogic Misc reflected XSS | 
| CVE-2021-42640 | Printerlogic Driver assignment IDOR | 
| CVE-2021-42641 | Printerlogic Username/email info disclosure | 
| CVE-2021-42642 | Printerlogic Printer console username/password info disclosure | 
Apple ImageIO
ruby-jss
| CVE ID | Description | 
|---|
| CVE-2021-33575 | Pixar ruby-jss gem Arbitrary Code Exec | 
Obsidian
| CVE ID | Description | 
|---|
| CVE-2021-38148 | Obsidian remote code exec |