56,966 blogs · [ { "id": "01a0b0bb-b3c1-726c-8158-703e8135c730", "title": "Three Injections and a Rootkit: How the lurves PyPI typosquat attacks the AI in your toolchain", "url": "https://ctrsec.io/research/lurves-pypi-typosquat-ai-toolchain/", "published_at": "2026-09-13T04:00:00+00:00" }, { "id": "01a0b0bb-b3c1-726c-8158-703e81398526", "title": "CVE-2024-45719: Predictable Authorization Token Vulnerability in Apache Answer", "url": "https://ctrsec.io/research/apache-answer-weak-uuid/", "published_at": "2024-11-23T05:00:00+00:00" }, { "id": "01a0b0bb-b3c1-726c-8158-703e8167b860", "title": "CVE-2024-46911: Uncovering CSRF vulnerabilities in Apache Roller", "url": "https://ctrsec.io/research/apache-roller-csrf/", "published_at": "2024-10-12T04:00:00+00:00" }, { "id": "01a0b0bb-b3c1-726c-8158-703e81a24e5f", "title": "How I nabbed a new CVE from a Cookie-Munching, Scam-Slinging Browser Extension", "url": "https://ctrsec.io/research/pwning-the-scammer-new-zero-day/", "published_at": "2023-06-24T04:00:00+00:00" }, { "id": "01a0b0bb-b3c1-726c-8158-703e81c5839f", "title": "[Pwn2Own 2022] CVE-2023-0855: Canon imageClass MF743CDW IPP BOF", "url": "https://ctrsec.io/research/pwn2own-canon-bof-mf743cdw/", "published_at": "2023-05-22T04:00:00+00:00" }, { "id": "01a0b0bb-b3c1-726c-8158-703e81fcc11d", "title": "Pwning the Samsung TV", "url": "https://ctrsec.io/research/pwning-the-samsung-tv/", "published_at": "2022-01-28T05:00:00+00:00" }, { "id": "01a0b0bb-b3c1-726c-8158-703e82a23041", "title": "Pwning the Facebook Portal", "url": "https://ctrsec.io/research/pwning-facebook-portal/", "published_at": "2022-01-21T05:00:00+00:00" }, { "id": "01a0b0bb-b3c1-726c-8158-703e82e5582d", "title": "How I faked tons of COVID passes — Weak Key Cryptography in real world", "url": "https://ctrsec.io/research/weak-key-cryptography-in-real-world/", "published_at": "2021-09-29T04:00:00+00:00" }, { "id": "01a0b0bb-b3c1-726c-8158-703e832a8fde", "title": "[ZDI-21-977] D-Link DAP-2020 webproc Stack-based BOF RCE", "url": "https://ctrsec.io/research/zdi-21-977-d-link-dap-2020-webproc-stack-based-bof-rce/", "published_at": "2021-08-21T04:00:00+00:00" }, { "id": "01a0b0bb-b3c1-726c-8158-703e8338ccf0", "title": "[CVE-2020-8962] D-LINK DIR-842 Stack-based Buffer-overflow", "url": "https://ctrsec.io/research/cve-2020-8962-d-link-dir-842-stack-based-buffer-overflow/", "published_at": "2020-02-13T05:00:00+00:00" }, { "id": "01a0c657-65f2-70fe-88c2-b00301e57ac7", "title": "[CVE-2020-7237] Remote Code Execution in Cacti RRDTool", "url": "https://ctrsec.io/research/cve-2020-7237-remote-code-execution-in-cacti-rrdtool/", "published_at": "2020-01-26T05:00:00+00:00" }, { "id": "01a0c657-65f2-70fe-88c2-b003006aaa88", "title": "[Google CTF 2019] Web Challenge - bnv", "url": "https://ctrsec.io/ctf/google-ctf-2019-web-challenge-bnv/", "published_at": "2019-06-25T04:00:00+00:00" }, { "id": "01a0c657-65f2-70fe-88c2-b0030146b4bb", "title": "[Google CTF 2019] Web Challenge - gphotos", "url": "https://ctrsec.io/ctf/google-ctf-2019-web-challenge-gphotos/", "published_at": "2019-06-25T04:00:00+00:00" }, { "id": "01a0c657-65f2-70fe-88c2-b002ff82e6a7", "title": "Arbitrary Command Execution in latest OrangeHRM platform", "url": "https://ctrsec.io/research/ace-orangehrm/", "published_at": "2019-06-12T04:00:00+00:00" }, { "id": "01a0c657-65f1-7307-ae74-75a2692480a8", "title": "CVE-2019-[12584-12585] : Command Injection Vulnerability on pfSense 2.4.4-RELEASE-p3", "url": "https://ctrsec.io/research/cve-2019-12584-12585-command-injection-vulnerability-on-pfsense-2-4-4-release-p3/", "published_at": "2019-05-29T04:00:00+00:00" }, { "id": "01a0c657-65f1-7307-ae74-75a269d664b7", "title": "CVE-2019-12347: Stored Cross-site Scripting on pfSense 2.4.4-RELEASE-p3", "url": "https://ctrsec.io/research/stored-xss-acme-pfsense-2-4-4-p3/", "published_at": "2019-05-29T04:00:00+00:00" }, { "id": "01a0c657-65f1-7307-ae74-75a268117f9a", "title": "CVE-2019-10017: CMS Made Simple 2.2.10 XSS via File Picker Extension", "url": "https://ctrsec.io/research/cmsmadesimple-xss-filepicker/", "published_at": "2019-03-25T04:00:00+00:00" }, { "id": "01a0c657-65f1-7307-ae74-75a2682d1af3", "title": "CVE-2019-10016: GForge Advanced Server Input validation error in ‘commonsearch.php’", "url": "https://ctrsec.io/research/gforge-advanced-server-xss-commonsearch-php/", "published_at": "2019-03-25T04:00:00+00:00" }, { "id": "01a0c657-65f2-70fe-88c2-b003071565ba", "title": "About | iam.chi", "url": "https://ctrsec.io/about", "published_at": null }, { "id": "01a0c657-65f2-70fe-88c2-b003071994f4", "title": "iam.chi", "url": "https://ctrsec.io/categories/", "published_at": null }, { "id": "01a0c657-65f2-70fe-88c2-b00307214c1c", "title": "iam.chi", "url": "https://ctrsec.io/", "published_at": null }, { "id": "01a0c657-65f2-70fe-88c2-b00307851297", "title": "All Posts", "url": "https://ctrsec.io/posts/", "published_at": null }, { "id": "01a0c657-65f2-70fe-88c2-b0030839b3e0", "title": "iam.chi", "url": "https://ctrsec.io/page2/", "published_at": null } ] posts Claim your blog
Back to ctrsec.io
Blog · corpus.blog/blogs/ctrsec.io/posts

ctrsec.io

ctrsec.io

2026

2024

2023

2022

2021

2020

2019

Undated