CVEs
Current vulnerabilities that matter: who is affected and what to do now.
- CWE-22A01:2021FortiOS SSL VPN (CVE-2018-13379)CVE-2018-13379 explained: how a path traversal in FortiOS SSL VPN exposed plaintext passwords, and why it was still being exploited years later.
- CWE-917A03:2021Log4Shell (CVE-2021-44228)Log4Shell explained: how one line of text in a log file ran code on your server, who exploited it, and what you should still be checking today.
- CWE-420A05:2021Cisco IOS XE Web UI (CVE-2023-20198)CVE-2023-20198 explained: how an internet-exposed management interface in Cisco IOS XE let attackers create a full administrator account.
- CWE-89A03:2021MOVEit Transfer (CVE-2023-34362)CVE-2023-34362 explained: how a SQL injection in MOVEit Transfer gave the Cl0p extortion group access to the data of thousands of organisations.
- CWE-119A07:2021Citrix Bleed (CVE-2023-4966)Citrix Bleed explained: how attackers read session tokens out of NetScaler memory, bypassed MFA with them, and why patching alone was not enough.
- CWE-77A03:2021PAN-OS GlobalProtect (CVE-2024-3400)CVE-2024-3400 explained: how a command injection in the PAN-OS GlobalProtect gateway handed attackers root on the firewall itself.