Exploiting CVEs

Our Latest Research Around Critical CVEs: Understanding, Exploiting & Defending against
Exploiting CVEs
July 4, 2024

Unlocking the World of CVEs: CVE Cipher Lab

Start by studying known critical CVEs, understanding their impact, and exploring how they can be exploited. Welcome to CVE Cipher Lab by Enciphers
Exploiting CVEs
June 30, 2024

Critical Authentication Bypass Vulnerability in InfiniteWP Client Plugin

The InfiniteWP Client plugin versions 1.9.4.4 and earlier have a critical authentication bypass vulnerability (CVE-2020-8772) that allows attackers to access and control WordPress sites without proper credentials.
Exploiting CVEs
July 1, 2024

Cacti’s Thorn: Unveiling the CVE-2022-46169 Vulnerability

A critical vulnerability (CVE-2022-46169) in Cacti versions 1.2.22 and below allows remote attackers to execute arbitrary code via the remote_client_authorized function in cacti/remote_agent.php.
Exploiting CVEs
July 1, 2024

In the Crosshairs: Understanding CVE-2024-23897's Technical Implications

Exploring a critical vulnerability (CVE-2024-23897) allowing malicious users to read files and potentially execute remote code; this blog post explores its impact, exploits, and mitigation strategies.
Exploiting CVEs
June 27, 2024

Apache ActiveMQ Under Siege: Understanding CVE-2023-46604

CVE-2023-46604 is a critical remote code execution vulnerability in Apache ActiveMQ, caused by improper input validation, allowing malicious payloads to execute arbitrary code on affected servers, leading to unauthorized access
Exploiting CVEs
June 28, 2024

Apache HTTPD Remote Code Execution (CVE-2021-42013)

CVE-2021-42013 is a significant vulnerability in Apache HTTP Server versions 2.4.49 and 2.4.50, arising from an inadequate fix for CVE-2021-41773, allowing attackers to exploit path traversal attacks and potentially achieve remote code execution if CGI scripts are enabled.
Exploiting CVEs
April 1, 2024

Text4Shell(CVE-2022-42889)

Blog on CVE-2022-42889 explores a critical vulnerability found in Apache commons text in October 2022. Let's jump into its technicality.
Exploiting CVEs
March 29, 2024

RCE on MobSF(CVE-2024-21633)

This CVE exposes a critical security vulnerability in Apktool, a widely-used tool for reverse engineering closed-source, third-party Android apps.
Exploiting CVEs

Path Traversal in Openfire Admin Console

Enter CVE-2023-32315, an authentication bypass vulnerability discovered in Openfire, a popular XMPP server. This exploit grants malicious actors unrestricted access to the Openfire administrative console.
Exploiting CVEs
February 27, 2024

AI Engine WordPress Plugin(CVE-2023-51409)

Delve into CVE-2023-51409, a severe security flaw that affected the AI Engine plugin—a widely used AI-related WordPress plugin with over 50,000 active installations.
Exploiting CVEs
March 25, 2024

Apache Spark Command Injection Vulnerability

Join us as we investigate CVE-2022-33891, a critical vulnerability discovered in Apache Spark, a widely-used distributed computing framework. This flaw, involving command injection, poses severe risks of unauthorized access and control.
Exploiting CVEs
March 22, 2024

Ultimate Member plugin(CVE-2024-1071)

This blog addresses CVE-2024-1071, a critical security vulnerability found in the Ultimate Member plugin for WordPress. With over 200,000 active installations affected, it's essential to comprehend the intricacies of this issue.
Exploiting CVEs
March 20, 2024

Confluence Template Injection (CVE-2023-22527)

This blog takes a deep dive into the intricacies of the Atlassian Confluence CVE-2023-22527 vulnerability. It aims to illuminate the inner workings of the exploit and provide actionable defense strategies that organizations can implement effectively.
Exploiting CVEs
July 19, 2023

Office and Windows HTML Remote Code Execution (CVE-2023-36884)

CVE-2023-36884: Lets discuss the attack method, the elements that contributed to its success, and potential mitigation strategies
Exploiting CVEs
May 31, 2023

Spring4Shell (CVE-2022-22965)

Dive into the details of Spring4Shell CVE-2022-22965, a critical vulnerability that was discovered in the Spring Framework
Exploiting CVEs
June 22, 2023

Confluence (CVE-2022-26134)

Explore the vulnerability, how to exploit it, its potential impact, and the essential steps organisations can take to protect their virtual infrastructure
Exploiting CVEs
July 2, 2023

VMware vSphere (CVE-2021-21972)

Explore the vulnerability, how to exploit it, its potential impact, and the essential steps organisations can take to protect their virtual infrastructure
Exploiting CVEs
May 24, 2023

Exploiting Log4Shell or Log4j (CVE 2021-44229)

A critical vulnerability known as CVE 2021-44228 was discovered in the popular logging tool Log4j. This vulnerability allowed attackers to execute remote code on servers and gain unauthorized access to sensitive data.