The Exploit

Notes from the Front Lines of Penetration Testing

Category: Exploits

Discover expert insights on the latest exploits, penetration testing tactics, and real-world vulnerabilities to strengthen your cybersecurity defenses.
  • OPENSSL v3.0.x: Critical Threat Alert
  • CVE-2022-35739: PRTG Network Monitor Cascading Style Sheets (CSS) Injection
  • CVE-2022-26653 & CVE-2022-26777: ManageEngine Remote Access Plus Guest User Insecure Direct Object References
  • CVE-2022-25373: ManageEngine Support Center Plus Stored Cross-Site Scripting (XSS)
  • CVE-2022-25245: ManageEngine Asset Explorer Information Leakage
  • Exploiting Dirty Pipe (CVE-2022-0847)
  • CVE-2022-24681: ManageEngine AD SelfService Plus Stored Cross-Site Scripting (XSS)
  • Submit Button
  • Cross-Site Scripting: Filter Evasion & Sideloading Payloads
  • 2021 OWASP Top 10
  • 2021 OWASP Top 10
  • Unescaped JavaScript Tags