Skip to main content

Free 30-min security demo  — We'll scan your real code and show live findings, no commitment Book Now

Offensive360
Real CVEs · Open Source · Updated Daily

ZeroDays

In-depth technical analysis of recently disclosed vulnerabilities in open-source software. Every post includes the vulnerable code, the fix, real-world impact, and how SAST catches it.

Severity:
22 vulnerabilities
Critical CVSS 9.8
CVE-2023-7221 Totolink T6 C January 12, 2024

Critical Buffer Overflow in Totolink T6 Router Login Handler

CVE-2023-7221 is a critical buffer overflow vulnerability in Totolink T6 4.1.9cu.5241_B20210923 affecting the HTTP POST login handler, enabling remote code execution with CVSS 9.8.

#buffer-overflow #remote-code-execution #network-device #authentication-bypass Read analysis →
Critical CVSS 9.8
CVE-2023-49237 TRENDnet TV-IP1314PI C January 10, 2024

OS Command Injection in TRENDnet TV-IP1314PI Language Pack Handler

CVE-2023-49237: Critical OS command injection vulnerability in TRENDnet IP camera firmware allows unauthenticated remote code execution via unfiltered URL parameters in language pack unpacking functionality.

#os-command-injection #embedded-systems #iot-security #remote-code-execution Read analysis →
Critical CVSS 10.0
CVE-2024-21650 XWiki Platform Java January 10, 2024

XWiki Platform RCE via User Registration Parameter Injection

CVE-2024-21650 is a critical remote code execution flaw in XWiki Platform affecting user registration. Attackers exploit unsanitized first/last name fields to execute arbitrary code on vulnerable instances.

#remote-code-execution #java #xwiki #parameter-injection Read analysis →
Critical CVSS 9.8
CVE-2023-51277 nbviewer-app Swift/Objective-C January 6, 2024

macOS Entitlement Privilege Escalation in nbviewer-app < 0.1.6

CVE-2023-51277 exposes a critical macOS entitlement vulnerability in Jupyter Notebook Viewer allowing unauthorized task access and potential privilege escalation in release builds.

#entitlement-misconfig #macOS #privilege-escalation #nbviewer-app Read analysis →

Find these vulnerabilities in your codebase

Offensive360 SAST detects the vulnerability patterns documented here — plus thousands more — across 60+ programming languages. See what's hiding in your source code.