SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open EmbedThis GoAhead Web Server Critical Vulnerabilities
EmbedThis GoAhead Web Server Critical Vulnerabilities

CVE Research

EmbedThis GoAhead Web Server Critical Vulnerabilities

Apr 30, 2026 • 3 min read

Open Oracle WebLogic WLS-WSAT Component Deserialisation RCE
Oracle WebLogic WLS-WSAT Component Deserialisation RCE

CVE Research

Oracle WebLogic WLS-WSAT Component Deserialisation RCE

Apr 30, 2026 • 3 min read

Open Google patches new Chrome zero-day flaw exploited in Wild
Google patches new Chrome zero-day flaw exploited in Wild

CVE Research

Google patches new Chrome zero-day flaw exploited in Wild

Google has released security fixes for the desktop Chrome app on Windows, Linux, and Mac. This consists of Ten vulnerabilities that include one Zero-day vulnerability with High severity. Google can fix the vulnerabilities by auto patching. This is the fifth Zero-day vulnerability fixed by Google thi...

Apr 30, 2026 • 3 min read

Open Follina: Microsoft Support Diagnostic Tool RCE Vulnerability Under Active Exploitation
Follina: Microsoft Support Diagnostic Tool RCE Vulnerability Under Active Exploitation

CVE Research

Follina: Microsoft Support Diagnostic Tool RCE Vulnerability Under Active Exploitation

A remote code execution vulnerability was discovered in MSDT (Microsoft Support Diagnostic Tool), which is tracked with CVE-2022-30190. Vulnerability exploitation is active in the wild. MSDT is a Windows 11/10/8.1/7 and Windows Server service. Microsoft support personnel can use the tool to evaluate...

Apr 30, 2026 • 3 min read

Open Why Is It Important To Manage Vulnerabilities Beyond CVEs?
Why Is It Important To Manage Vulnerabilities Beyond CVEs?

CVE Research

Why Is It Important To Manage Vulnerabilities Beyond CVEs?

CVE stands for Common Vulnerabilities and Exposures. It is the database of publicly disclosed information on security issues. All organizations use CVEs to identify and track the number of vulnerabilities. However, not all the vulnerabilities discovered have a CVE number. For instance, the CVE datab...

Apr 30, 2026 • 5 min read

Open ALERT: SQLite database Remote Code Execution Vulnerability
ALERT: SQLite database Remote Code Execution Vulnerability

CVE Research

ALERT: SQLite database Remote Code Execution Vulnerability

SQLite is a cross-platform relational database management system. It is known to be the most used database engine in the world. The vendor claims that several applications, like Skype, Firefox, Chrome, Safari, etc., use billions of deployments of SQLite. Researchers showcased how SQL language can ex...

Apr 30, 2026 • 3 min read

Open F5 BIG-IP Critical Remote Code Execution Vulnerability Getting Exploited. Patch Now!
F5 BIG-IP Critical Remote Code Execution Vulnerability Getting Exploited. Patch Now!

CVE Research

F5 BIG-IP Critical Remote Code Execution Vulnerability Getting Exploited. Patch Now!

A Remote Code Execution vulnerability was detected (CVE-2022-1388) in F5 BIG-IP. This flaw affects the BIG-IP iControl REST authentication component. Successful exploitation allows remote attackers to bypass authentication and execute commands on the vulnerable device with the highest privileges. Va...

Apr 30, 2026 • 4 min read

Open WordPress ‘REST API Endpoint’ Zero-Day Content Injection Vulnerability
WordPress ‘REST API Endpoint’ Zero-Day Content Injection Vulnerability

CVE Research

WordPress ‘REST API Endpoint’ Zero-Day Content Injection Vulnerability

Apr 30, 2026 • 4 min read

Open Discover The Extremely Critical Apache Log4j Vulnerability (CVE-2021-44228)
Discover The Extremely Critical Apache Log4j Vulnerability (CVE-2021-44228)

CVE Research

Discover The Extremely Critical Apache Log4j Vulnerability (CVE-2021-44228)

All Java applications come with Log4j, a logging library/facade that allows programmers to release output logs to numerous output targets. Log4j is an integral part of Apache Logging Services, which cybercriminals can use to launch RCE attacks due to a vulnerability.

Apr 30, 2026 • 9 min read