SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Microsoft’s November 2023 Patch Tuesday Fixes 75 Vulnerabilities, Including 5 Zero Days
This Patch Tuesday November 2023, Microsoft fixed 75 vulnerabilities, with three rated as critical and 57 rated as important. Elevation of Privilege and Remote Code Execution vulnerabilities are tied for the most common categories at 17 each, with one in each category being critical. The third criti...

CVE Research
Critical RCE Flaw Discovered In Confluence: CVE-2023-22522
A new remote code execution vulnerability has been found in Confluence Data Center and Server. CVE-2023-22522, exploited using template injection, allows authenticated attackers (including those with anonymous access) to inject malicious user input into Confluence pages. What’s more, this vulnerabil...
Avaya IP Office Manager TFTP Server Directory Traversal Vulnerability
CVE Research
Avaya IP Office Manager TFTP Server Directory Traversal Vulnerability
SecPod Research Team member (Veerendra G.G) has found a Directory Traversal Vulnerability in Avaya IP Office Manager TFTP Server. The vulnerability is caused due to improper validation of TFTP READ requests containing ‘../’ sequences, which allows attackers to read arbitrary files via directory trav...

CVE Research
Oracle Critical Security Updates October 2021
Oracle Critical Updates October 2021 has finally released 419 new security patches for various product families, including Oracle Mysql, Oracle Java SE, Oracle Essbase, Database server, Oracle Golden Gate, etc. However, This advisory covers multiple products which are prone to many vulnerabilities. ...

CVE Research
New Windows Installer Zero-Day Flaw exploited in the Wild
Microsoft recently patched a Windows Installer Elevation of Privilege vulnerability tracked as CVE-2021-41379 in its November Patch Tuesday. As we know, the security researcher Abdelhamid Naceri discovered and reported this vulnerability. But surprisingly, recently, he also found that the fix releas...

CVE Research
Oracle Micros Point-Of-Sale Systems Critical Vulnerability (CVE-2018-2636)
Oracle Micros POS is a hospitality management platform providing enterprise point-of-sale (POS) and back-office functionality to support a wide range of food and beverage operations. Oracle’s MICROS has more than 330,000 cash registers worldwide and currently. Oracle is the third-largest provider of...



