SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Patch Tuesday: Microsoft Security Bulletin Summary for February 2021
Microsoft has roll-out its February 2021 patch Tuesday security updates on this month’s for 56 vulnerabilities, including a zero-day in its product line. Released patches include products such as Windows operating system, Edge browser, Microsoft Office, and services. Out of these, 11 are classified ...

CVE Research
Netgear Patches High Severity Flaws In Its Smart Switches
Netgear is a multinational computer networking company that produces networking hardware for consumers, businesses, and service providers. Netgear identified three high severity vulnerabilities and patched them recently, affecting its wide range of products. Most of these affected products are smart...

CVE Research
Google Chrome Patches Another High Severity Zero-Day Flaw Exploited in the Wild
Google has released an emergency fix for its Chrome browser app in Windows, Linux, and Mac. This consists of four vulnerabilities that include one Zero-day vulnerability with High severity. This is the eighth Zero-day vulnerability which is fixed by Google this year and is assigned with CVE-2021-305...

CVE Research
Microsoft July 2021 Patch Tuesday Addresses 117 CVEs Including 9 Zero-Days
Microsoft has released July Patch Tuesday security updates with a total of 117 vulnerabilities in the family of Windows, Mac, and Android operating systems and related products. In the release by Microsoft, 13 were rated as Critical, 1 as moderate, and 103 as Important. The products covered in the J...
Ipswitch TFTP Server Directory Traversal Vulnerability
CVE Research
Ipswitch TFTP Server Directory Traversal Vulnerability
SecPod Research Team member (Prabhu S Angadi) has found a Directory Traversal vulnerability in Ipswitch TFTP Server. The vulnerability is caused due to improper validation of ‘Read’ request containing ‘../’ sequences. The flaw can be exploited to read arbitrary files via directory traversal attacks.

CVE Research
Security Admin’s Savannah
Austin was waiting, and he was worried. It had been 16 hours since he had initiated a vulnerability scan, and it wasn’t complete yet. The talks of a zero-day vulnerability were flying around in the media, and he didn’t even know if it was detected in his network.

CVE Research
Severe Vulnerabilities Patched in WooCommerce and Google Chrome
A critical SQL injection vulnerability was recently fixed in the WordPress plug-in, WooCommerce. The vulnerability poses a threat to over 5 million WordPress websites and can be exploited to obtain access to information stored in the databases of online stores. On a different but related subject, a ...

CVE Research
VMware Releases Security Update for Multiple Products
VMware, the virtualization giant, has patched six vulnerabilities, including 4 high severity vulnerabilities, in its recent security update VMSA-2021-0018. The vulnerabilities tracked as CVE-2021-22022, CVE-2021-22023, CVE-2021-22024, CVE-2021-22025, CVE-2021-22026, CVE-2021-22027 are affecting the ...

CVE Research
Critical 21Nails Flaws Affect Millions of Exim Servers
A series of critical vulnerabilities were recently disclosed to reside in the popular internet mailer, Exim. The vulnerabilities, collectively termed as 21Nails, were brought to light by researchers at Qualys. The advisory includes 21 vulnerabilities, some of which can be used to gain elevated privi...
