SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Atlassian Critical Vulnerabilities of November 2022 in Atlassian Crowd and Bitbucket Products is addressed. Patch Now!
Atlassian Critical Vulnerabilities of November 2022 in Atlassian Crowd and Bitbucket Products is addressed. Patch Now!

CVE Research

Atlassian Critical Vulnerabilities of November 2022 in Atlassian Crowd and Bitbucket Products is addressed. Patch Now!

Atlassian released patches for two critical vulnerabilities of November 2022 affecting Bitbucket Server, Data Center, and Crowd products. Using a vulnerability management tool, these vulnerabilities are tracked as CVE-2022-43781 (Command Injection) and CVE-2022-43782 (Improper Authentication). A Vul...

Apr 30, 2026 • 3 min read

Open Oracle Critical Security Updates July 2021
Oracle Critical Security Updates July 2021

CVE Research

Oracle Critical Security Updates July 2021

Oracle Critical Security Updates July 2021 has released 342 new security patches for a wide range of product families. However, these include Oracle E-Business Suite, Oracle MySQL, Oracle Java SE, Oracle Hospitality Applications, Oracle Siebel CRM, Database Server, etc. Moreover, multiple products c...

Apr 30, 2026 • 7 min read

Open Heap-Based Buffer Overflow in Sudo Allows Attackers to Gain Root Privileges
Heap-Based Buffer Overflow in Sudo Allows Attackers to Gain Root Privileges

CVE Research

Heap-Based Buffer Overflow in Sudo Allows Attackers to Gain Root Privileges

The Vulnerability (CVE-2021-3156) exists in Sudo, a powerful utility to run programs with the security privileges of another user. The heap-based buffer overflow could allow an unprivileged local user to gain root privileges without any authentication on the affected systems. A vulnerability managem...

Apr 30, 2026 • 3 min read

Open Microsoft out-of-band Security Updates for Office and Paint 3D
Microsoft out-of-band Security Updates for Office and Paint 3D

CVE Research

Microsoft out-of-band Security Updates for Office and Paint 3D

Microsoft released an out-of-band security update addressing multiple vulnerabilities that plug remote code execution vulnerabilities in an Autodesk FBX library incorporated into Microsoft Office, Office 365 ProPlus and Paint 3D applications. A vulnerability management tool can detect multiple vulne...

Apr 30, 2026 • 3 min read

Open Lemon Duck Malware : Infecting outdated Windows systems using EternalBlue
Lemon Duck Malware : Infecting outdated Windows systems using EternalBlue

CVE Research

Lemon Duck Malware : Infecting outdated Windows systems using EternalBlue

Apr 30, 2026 • 4 min read

Open Gaining Root Shell in Linux (CVE-2016-4484)
Gaining Root Shell in Linux (CVE-2016-4484)

CVE Research

Gaining Root Shell in Linux (CVE-2016-4484)

Linux distributions are one of the most popular and commonly used operating systems. All Linux distributions including Debian, Ubuntu, Fedora, Red Hat Enterprise Linux (RHEL), and SUSE Linux Enterprise Server (SLES) suffer from a serious authentication bypass vulnerability that can allow anyone to b...

Apr 30, 2026 • 4 min read

Open Polarbear digs out a new Windows Zero-Day
Polarbear digs out a new Windows Zero-Day

CVE Research

Polarbear digs out a new Windows Zero-Day

Apr 30, 2026 • 4 min read

Open VMware addresses three critical flaws in Workspace ONE!
VMware addresses three critical flaws in Workspace ONE!

CVE Research

VMware addresses three critical flaws in Workspace ONE!

VMware has recently released patches to three critical severity vulnerabilities affecting the Workspace ONE assist solution. A good vulnerability management tool can solve these problems.

Apr 30, 2026 • 2 min read

Open Trend Micro Antivirus Products Exploited Wildly
Trend Micro Antivirus Products Exploited Wildly

CVE Research

Trend Micro Antivirus Products Exploited Wildly

A threat actor is actively exploiting a bug currently in Trend Micro’s security products to do privilege escalation on Windows systems. The vulnerability is tracked as CVE-2020-24557 and is affecting two major security products of the company – Apex One and OfficeScan. A good Vulnerability managemen...

Apr 30, 2026 • 2 min read