writeups.xyz writeups.xyz / Security Code Review

Title Vulnerabilities Programs Authors
CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster
Dangerous Import: SourceForge Patches Critical Code Vulnerability
Hacking Swisscom’s End-to-End Encrypted Cloud Storage for $4,000
Apache Dubbo Consumer Risks: The Road Not Taken
Micro Services, Major Headaches: Detecting Vulnerabilities in Erxes' Microservices
Java Deserialization Tricks
Broken access control in GoAnywhere Admin portal
OpenOlat - XML external entity (XXE) injection (CVE-2024-28198)
Security Implications of net/textproto.Reader Misuse
CVE-2024-27198 and CVE-2024-27199: JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities
Judge0 Sandbox Escape
OpenNMS Vulnerabilities: Securing Code against Attackers’ Unexpected Ways
Leaking ObjRefs to Exploit HTTP .NET Remoting
SSD Advisory – TP-LINK NCXXX Authentication Bypass
Continuing the Citrix Saga: CVE-2023-5914 & CVE-2023-6184
Joomla: PHP Bug Introduces Multiple XSS Vulnerabilities (CVE-2024-21726)
Hello Lucee! Let us hack Apple again?
CVE-2024-0685 Ninja Contact Forms Data Export SQLi
Form Tools Remote Code Execution: We Need To Talk About PHP
Azure HDInsight: The Sequel – Unveiling 3 New Vulnerabilities That Could Have Led to Privilege Escalations and Denial of Service
Pitfalls of Desanitization: Leaking Customer Data from osTicket
Back to the (Clip)board with Microsoft Whiteboard and Excalidraw in Meta (CVE-2023-26140)
Auth Bypass Round Two
Jumpserver Preauth RCE Exploit Chain
Relution Remote Code Execution via Java Deserialization Vulnerability