SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open High-Risk Vulnerability in TeamViewer Could be Exploited to Crack Users’ Password
High-Risk Vulnerability in TeamViewer Could be Exploited to Crack Users’ Password

CVE Research

High-Risk Vulnerability in TeamViewer Could be Exploited to Crack Users’ Password

The discovery of a high-risk vulnerability was in TeamViewer for Windows. It has a tracking as “CVE-2020-13699“, with a CVSS base score of “8.8,” in which exploits can happen by remote attacks to crack users’ passwords and, thereupon, lead to further system exploitation. Vulnerability Management Sof...

Apr 30, 2026 • 3 min read

Open Warning: Atlassian Critical Vulnerabilities Being Actively Exploited- Patch Now!
Warning: Atlassian Critical Vulnerabilities Being Actively Exploited- Patch Now!

CVE Research

Warning: Atlassian Critical Vulnerabilities Being Actively Exploited- Patch Now!

Atlassian released patches for three critical vulnerabilities (CVE-2022-26136, CVE-2022-26137, CVE-2022-26138). Out of the three flaws, two impacts Confluence Server, Confluence Data Center, and some other products, as well as Bamboo, BitBucket, Fisheye, and Jira, and one of the flaws impacts only C...

Apr 30, 2026 • 4 min read

Open PwnKit Linux vulnerability Jan-2022: Local Privilege Escalation Vulnerability In Major Linux Distributions
PwnKit Linux vulnerability Jan-2022: Local Privilege Escalation Vulnerability In Major Linux Distributions

CVE Research

PwnKit Linux vulnerability Jan-2022: Local Privilege Escalation Vulnerability In Major Linux Distributions

Most of the Linux distributions have the pkexec binary. The vulnerability (CVE-2021-4034) lies in that binary. The pkexec is a part PwnKit Linux vulnerability Jan-2022, which affects the Polkit open-source application framework used for interaction between privileged and unprivileged processes. Furt...

Apr 30, 2026 • 6 min read

Open WordPress Plugin Contact Form 7 Critical File Upload Vulnerability (CVE-2020-35489)
WordPress Plugin Contact Form 7 Critical File Upload Vulnerability (CVE-2020-35489)

CVE Research

WordPress Plugin Contact Form 7 Critical File Upload Vulnerability (CVE-2020-35489)

Contact Form 7 is a popular WordPress plugin that is used to create, customize, and manage multiple contact forms on WordPress sites. A critical file upload vulnerability (CVE-2020-35489) has an identity in the WordPress Contact Form 7 plugin, allowing an attacker to execute arbitrary code on affect...

Apr 30, 2026 • 2 min read

Open Watch out for Alpine Linux Docker Image Root login Vulnerability
Watch out for Alpine Linux Docker Image Root login Vulnerability

CVE Research

Watch out for Alpine Linux Docker Image Root login Vulnerability

Apr 30, 2026 • 3 min read

Open Apple’s June 2023 Updates Addresses Multiple Security Vulnerabilities And 3 Zero-Days!
Apple’s June 2023 Updates Addresses Multiple Security Vulnerabilities And 3 Zero-Days!

CVE Research

Apple’s June 2023 Updates Addresses Multiple Security Vulnerabilities And 3 Zero-Days!

Apples Security Alert June 2023 recently released multiple updates to patch various Apple products affected by multiple vulnerabilities. A total of three vulnerabilities were fixed in nine of its products on June 21st. An attacker who successfully exploits these flaws could therefore compromise the ...

Apr 30, 2026 • 2 min read

Open Cisco AnyConnect Vulnerabilities are Being Exploited in the Wild!
Cisco AnyConnect Vulnerabilities are Being Exploited in the Wild!

CVE Research

Cisco AnyConnect Vulnerabilities are Being Exploited in the Wild!

Cisco AnyConnect Secure Mobility Client allows users to connect to remote systems through a VPN. On October 26, 2022, Cisco issued a warning to its customers, stating that security vulnerabilities in the Cisco AnyConnect Secure Mobility Client for Windows, which are two years old, are currently bein...

Apr 30, 2026 • 4 min read

Open Oracle WebLogic Server Under Active Exploitation (CVE-2020-14882)
Oracle WebLogic Server Under Active Exploitation (CVE-2020-14882)

CVE Research

Oracle WebLogic Server Under Active Exploitation (CVE-2020-14882)

Critical Remote Code Execution (RCE) vulnerability CVE-2020-14882 in the console component of the Oracle WebLogic Server Exploitation allows unauthenticated, remote attackers to execute commands on the affected servers. Oracle has assigned this vulnerability a CVSSv3 score of 9.8 out of 10, clearly ...

Apr 30, 2026 • 3 min read

Open Dirty COW Vulnerability (Kernel Local Privilege Escalation)
Dirty COW Vulnerability (Kernel Local Privilege Escalation)

CVE Research

Dirty COW Vulnerability (Kernel Local Privilege Escalation)

Dirty COW vulnerability(CVE-2016-5195) is a privilege escalation in the Linux Kernel, which allows an unprivileged local user to gain write access to otherwise read-only memory mappings. Thus increases their privileges on the system. Vulnerability management tool are essential to detect such critica...

Apr 30, 2026 • 4 min read