Skip to main content
🔍 Vulnerability Research & Disclosure

Security
Advisories

Extensive vulnerability research and responsible disclosure from KoreLogic's expert security researchers

105
Published Advisories

CVE discoveries and security bulletins

38
Vendors Affected

Major technology companies impacted

68
CVE Assignments

Coordinated vulnerability disclosures

105 advisories found

Jan 7, 2026 KL-001-2026-001
CVE-2025-15464

yintibao Fun Print Mobile Unauthorized Access via Context Hijacking

Felix Segoviano
yintibao • Fun Print Mobile
View
Jul 27, 2025 KL-001-2025-016
CVE-2025-54769

Xorux LPAR2RRD File Upload Directory Traversal

Jim Becher
Xorux • LPAR2RRD
View
Jul 27, 2025 KL-001-2025-015
CVE-2025-54768

Xorux LPAR2RRD Read Only User Log Download Exposing Sensitive Information

Jim Becher
Xorux • LPAR2RRD
View
Jul 27, 2025 KL-001-2025-014
CVE-2025-54767

Xorux LPAR2RRD Read Only User Denial of Service

Jim Becher
Xorux • LPAR2RRD
View
Jul 27, 2025 KL-001-2025-013
CVE-2025-54765

Xorux XorMon-NG Web Application Privilege Escalation to Administrator

Jim Becher
Xorux • XorMon-NG
View
Jul 27, 2025 KL-001-2025-012
CVE-2025-54766

Xorux XorMon-NG Read Only User Export Device Configuration Exposing Sensitive Information

Jim Becher
Xorux • XorMon-NG
View
Jul 8, 2025 KL-001-2025-011
CVE-2025-50125

Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Server-Side Request Forgery

Jaggar Henry, Jim Becher
Schneider Electric • EcoStruxure IT Data Center Expert
View
Jul 8, 2025 KL-001-2025-010
CVE-2025-50124

Schneider Electric EcoStruxure IT Data Center Expert Privilege Escalation

Jaggar Henry, Jim Becher
Schneider Electric • EcoStruxure IT Data Center Expert
View
Jul 8, 2025 KL-001-2025-009
CVE-2025-50123

Schneider Electric EcoStruxure IT Data Center Expert Remote Command Execution

Jaggar Henry, Jim Becher
Schneider Electric • EcoStruxure IT Data Center Expert
View
Jul 8, 2025 KL-001-2025-008
CVE-2025-50122

Schneider Electric EcoStruxure IT Data Center Expert Root Password Discovery

Jaggar Henry, Jim Becher
Schneider Electric • EcoStruxure IT Data Center Expert
View
Jul 8, 2025 KL-001-2025-007
CVE-2025-50121

Schneider Electric EcoStruxure IT Data Center Expert Unauthenticated Remote Code Execution

Jaggar Henry, Jim Becher
Schneider Electric • EcoStruxure IT Data Center Expert
View
Jul 8, 2025 KL-001-2025-006
CVE-2025-6438

Schneider Electric EcoStruxure IT Data Center Expert XML External Entities Injection

Jaggar Henry, Jim Becher
Schneider Electric • EcoStruxure IT Data Center Expert
View
May 21, 2025 KL-001-2025-005
CVE-2025-5100

Mobile Dynamix PrinterShare Mobile Print Double-Free Memory Write

Felix Segoviano
Mobile Dynamix • PrinterShare Mobile Print
View
May 21, 2025 KL-001-2025-004
CVE-2025-5099

Mobile Dynamix PrinterShare Mobile Print Out-of-bounds Write

Felix Segoviano
Mobile Dynamix • PrinterShare Mobile Print
View
May 21, 2025 KL-001-2025-003
CVE-2025-5098

Mobile Dynamix PrinterShare Mobile Print Gmail Oauth Token Disclosure

Felix Segoviano
Mobile Dynamix • PrinterShare Mobile Print
View
Feb 3, 2025 KL-001-2025-002
CVE-2024-13723

Checkmk NagVis Remote Code Execution

Jaggar Henry, Jim Becher
Checkmk • Checkmk/NagVis
View
Feb 3, 2025 KL-001-2025-001
CVE-2024-13722

Checkmk NagVis Reflected Cross-site Scripting

Jaggar Henry, Jim Becher
Checkmk • Checkmk/NagVis
View
Sep 9, 2024 KL-001-2024-012
CVE-2024-8504

VICIdial Authenticated Remote Code Execution

Jaggar Henry
VICIdial
View
Sep 9, 2024 KL-001-2024-011
CVE-2024-8503

VICIdial Unauthenticated SQL Injection

Jaggar Henry
VICIdial
View
Aug 6, 2024 KL-001-2024-010
CVE-2024-6893

Journyx Unauthenticated XML External Entities Injection

Jaggar Henry
Journyx • Journyx (jtime)
View
Aug 6, 2024 KL-001-2024-009
CVE-2024-6892

Journyx Reflected Cross Site Scripting

Jaggar Henry
Journyx • Journyx (jtime)
View
Aug 6, 2024 KL-001-2024-008
CVE-2024-6891

Journyx Authenticated Remote Code Execution

Jaggar Henry
Journyx • Journyx (jtime)
View
Aug 6, 2024 KL-001-2024-007
CVE-2024-6890

Journyx Unauthenticated Password Reset Bruteforce

Jaggar Henry
Journyx • Journyx (jtime)
View
Aug 6, 2024 KL-001-2024-006
CVE-2024-6707

Open WebUI Arbitrary File Upload + Path Traversal

Jaggar Henry, Sean Segreti
Open WebUI
View
Aug 6, 2024 KL-001-2024-005
CVE-2024-6706

Open WebUI Stored Cross-Site Scripting

Jaggar Henry, Sean Segreti
Open WebUI
View
Mar 4, 2024 KL-001-2024-004
CVE-2024-2056

Artica Proxy Loopback Services Remotely Accessible Unauthenticated

Jim Becher, Jaggar Henry
Artica • Artica Proxy
View
Mar 4, 2024 KL-001-2024-003
CVE-2024-2055

Artica Proxy Unauthenticated File Manager Vulnerability

Jim Becher
Artica • Artica Proxy
View
Mar 4, 2024 KL-001-2024-002
CVE-2024-2054

Artica Proxy Unauthenticated PHP Deserialization Vulnerability

Jaggar Henry
Artica • Artica Proxy
View
Mar 4, 2024 KL-001-2024-001
CVE-2024-2053

Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability

Jaggar Henry
Artica • Artica Proxy
View
Aug 16, 2023 KL-001-2023-003
CVE-2023-22809

Cisco ThousandEyes Enterprise Agent Virtual Appliance Arbitrary File Modification via sudoedit

Jim Becher
Cisco • ThousandEyes Enterprise Agent Virtual Appliance
View
Aug 16, 2023 KL-001-2023-002
CVE-2023-20224

Cisco ThousandEyes Enterprise Agent Virtual Appliance Privilege Escalation via tcpdump

Jim Becher
Cisco • ThousandEyes Enterprise Agent Virtual Appliance
View
Aug 16, 2023 KL-001-2023-001
CVE-2023-20217

Cisco ThousandEyes Enterprise Agent Virtual Appliance Arbitrary File Read via sudo dig

Jim Becher, Hank Leininger
Cisco • ThousandEyes Enterprise Agent Virtual Appliance
View
Jan 27, 2022 KL-001-2022-002
CVE-2021-46560

Moxa TN-5900 Post Authentication Command Injection Vulnerability

Matt Bergin, Josh Hardin
Moxa • TN-5900
View
Jan 27, 2022 KL-001-2022-001
CVE-2021-46559

Moxa TN-5900 Firmware Upgrade Checksum Validation Vulnerability

Matt Bergin, Josh Hardin
Moxa • TN-5900
View
Aug 31, 2021 KL-001-2021-010
CVE-2021-31798

CyberArk Credential Provider Local Cache Can Be Decrypted

Klayton Monroe
CyberArk • Application Access Manager/Credential Provider
View
Aug 31, 2021 KL-001-2021-009
CVE-2021-31797

CyberArk Credential Provider Race Condition And Authorization Bypass

Klayton Monroe
CyberArk • Application Access Manager/Credential Provider
View
Aug 31, 2021 KL-001-2021-008
CVE-2021-31796

CyberArk Credential File Insufficient Effective Key Space

Klayton Monroe
CyberArk • Application Access Manager/Credential Provider
View
May 25, 2021 KL-001-2021-007
CVE-2021-33216

CommScope Ruckus IoT Controller Undocumented Account

Jim Becher
CommScope • Ruckus IoT Controller
View
May 25, 2021 KL-001-2021-006
CVE-2021-33217

CommScope Ruckus IoT Controller Web Application Arbitrary Read/Write

Jim Becher
CommScope • Ruckus IoT Controller
View
May 25, 2021 KL-001-2021-005
CVE-2021-33215

CommScope Ruckus IoT Controller Web Application Directory Traversal

Jim Becher
CommScope • Ruckus IoT Controller
View
May 25, 2021 KL-001-2021-004
CVE-2021-33219

CommScope Ruckus IoT Controller Hard-coded Web Application Administrator Password

Jim Becher
CommScope • Ruckus IoT Controller
View
May 25, 2021 KL-001-2021-003
CVE-2021-33218

CommScope Ruckus IoT Controller Hard-coded System Passwords

Jim Becher
CommScope • Ruckus IoT Controller
View
May 25, 2021 KL-001-2021-002
CVE-2021-33220

CommScope Ruckus IoT Controller Hard-coded API Keys Exposed

Jim Becher
CommScope • Ruckus IoT Controller
View
May 25, 2021 KL-001-2021-001
CVE-2021-33221

CommScope Ruckus IoT Controller Unauthenticated API Endpoints

Jim Becher
CommScope • Ruckus IoT Controller
View
Nov 19, 2020 KL-001-2020-009
CVE-2020-28332

Barco wePresent Insecure Firmware Image

Jim Becher, Matt Bergin
Barco • wePresent WiPG-1600W
View
Nov 19, 2020 KL-001-2020-008
CVE-2020-28334

Barco wePresent Global Hardcoded Root SSH Password

Jim Becher
Barco • wePresent WiPG-1600W
View
Nov 19, 2020 KL-001-2020-007
CVE-2020-28331

Barco wePresent Undocumented SSH Interface Accessible Via Web UI

Jim Becher
Barco • wePresent WiPG-1600W
View
Nov 19, 2020 KL-001-2020-006
CVE-2020-28333

Barco wePresent Authentication Bypass

Jim Becher
Barco • wePresent WiPG-1600W
View
Nov 19, 2020 KL-001-2020-005
CVE-2020-28330

Barco wePresent Admin Credentials Exposed In Plain-text

Jim Becher
Barco • wePresent WiPG-1600W
View
Nov 19, 2020 KL-001-2020-004
CVE-2020-28329

Barco wePresent Hardcoded API Credentials

Jim Becher
Barco • wePresent WiPG-1600W
View
Jun 28, 2020 KL-001-2020-003
CVE-2020-14474

Cellebrite EPR Decryption Relies on Hardcoded AES Key Material

Matt Bergin
Cellebrite • UFED
View
May 13, 2020 KL-001-2020-002
CVE-2020-12798

Cellebrite Restricted Desktop Escape and Escalation of User Privilege

Matt Bergin
Cellebrite • UFED
View
Apr 12, 2020 KL-001-2020-001
CVE-2020-11723

Cellebrite Hardcoded ADB Authentication Keys

Matt Bergin
Cellebrite • UFED
View
Nov 4, 2018 KL-001-2018-009
CVE-2018-15767 CVE-2018-15768

Dell OpenManage Network Manager Multiple Vulnerabilities

Matt Bergin
Dell • OpenManage Network Manager
View
Jun 24, 2018 KL-001-2018-008

HPE VAN SDN Unauthenticated Remote Root Vulnerability

Matt Bergin
HP Enterprise • VAN SDN Controller
View
Mar 1, 2018 KL-001-2018-007

Sophos UTM 9 loginuser Privilege Escalation via confd Service

Matt Bergin
Sophos • UTM 9
View
Feb 7, 2018 KL-001-2018-006

Trend Micro IMSVA Management Portal Authentication Bypass

Matt Bergin
Trend Micro • InterScan Mail Security Virtual Apppliance
View
Feb 7, 2018 KL-001-2018-005

NetEx HyperIP Local File Inclusion Vulnerability

Matt Bergin
NetEx • HyperIP
View
Feb 7, 2018 KL-001-2018-004

NetEx HyperIP Privilege Escalation Vulnerability

Matt Bergin
NetEx • HyperIP
View
Feb 7, 2018 KL-001-2018-003

NetEx HyperIP Post-Auth Command Execution

Matt Bergin
NetEx • HyperIP
View
Feb 7, 2018 KL-001-2018-002

NetEx HyperIP Authentication Bypass

Matt Bergin
NetEx • HyperIP
View
Jan 25, 2018 KL-001-2018-001

Sophos Web Gateway Persistent Cross Site Scripting Vulnerability

Matt Bergin
Sophos • Web Gateway
View
Nov 2, 2017 KL-001-2017-022

Splunk Local Privilege Escalation

Hank Leininger
Splunk • Splunk Enterprise
View
Oct 23, 2017 KL-001-2017-021

Sophos UTM 9 Management Application Local File Inclusion

Matt Bergin
Sophos • UTM 9
View
Oct 23, 2017 KL-001-2017-020

Sophos UTM 9 loginuser Privilege Escalation via Insecure Directory Permissions

Matt Bergin
Sophos • UTM 9
View
Oct 23, 2017 KL-001-2017-019

Sonicwall WXA5000 Console Jail Escape and Privilege Escalation

Matt Bergin
Sonicwall • WXA5000 WAN Optimization Appliance
View
Oct 23, 2017 KL-001-2017-018

Infoblox NetMRI Administration Shell Factory Reset Persistence

Matt Bergin
Infoblox • NetMRI
View
Oct 23, 2017 KL-001-2017-017

Infoblox NetMRI Administration Shell Escape and Privilege Escalation

Matt Bergin, Hank Leininger
Infoblox • NetMRI
View
Sep 24, 2017 KL-001-2017-016

Solarwinds LEM Insecure Update Process

Hank Leininger
Solarwinds • Multiple
View
Jul 5, 2017 KL-001-2017-015

Solarwinds LEM Hardcoded Credentials

Matt Bergin
Solarwinds • Log and Event Manager Virtual Appliance
View
Jul 5, 2017 KL-001-2017-014

Barracuda WAF Support Tunnel Hijack

Matt Bergin
Barracuda • Web Application Firewall V360
View
Jul 5, 2017 KL-001-2017-013

Barracuda WAF Management Application Username and Session ID Leak

Matt Bergin
Barracuda • Web Application Firewall V360
View
Jul 5, 2017 KL-001-2017-012

Barracuda WAF Grub Password Complexity

Matt Bergin
Barracuda • Web Application Firewall V360
View
Jul 5, 2017 KL-001-2017-011

Barracuda WAF Internal Development Credential Disclosure

Matt Bergin
Barracuda • Web Application Firewall V360
View
Jul 5, 2017 KL-001-2017-010

Barracuda WAF Early Boot Root Shell

Matt Bergin
Barracuda • Web Application Firewall V360
View
Apr 23, 2017 KL-001-2017-009

Solarwinds LEM Database Listener with Hardcoded Credentials

Matt Bergin
Solarwinds • Log and Event Manager Virtual Appliance
View
Apr 23, 2017 KL-001-2017-008

Solarwinds LEM Management Shell Arbitrary File Read

Matt Bergin, Hank Leininger
Solarwinds • Log and Event Manager Virtual Appliance
View
Apr 23, 2017 KL-001-2017-007

Solarwinds LEM Management Shell Escape via Command Injection

Matt Bergin, Hank Leininger
Solarwinds • Log and Event Manager Virtual Appliance
View
Apr 23, 2017 KL-001-2017-006

Solarwinds LEM Privilege Escalation via Sudo Script Abuse

Hank Leininger, Matt Bergin
Solarwinds • Log and Event Manager Virtual Appliance
View
Apr 23, 2017 KL-001-2017-005

Solarwinds LEM Privilege Escalation via Controlled Sudo Path

Hank Leininger, Matt Bergin
Solarwinds • Log and Event Manager Virtual Appliance
View
Mar 9, 2017 KL-001-2017-004

WatchGuard XTMv User Management Cross-Site Request Forgery

Matt Bergin
WatchGuard • XTMv
View
Feb 14, 2017 KL-001-2017-003

Trendmicro InterScan Remote Root Access Vulnerability

Matt Bergin
Trendmicro • InterScan Web Security Virtual Appliance
View
Feb 14, 2017 KL-001-2017-002
CVE-2016-9315

Trendmicro InterScan Privilege Escalation Vulnerability

Matt Bergin
Trendmicro • InterScan Web Security Virtual Appliance
View
Feb 14, 2017 KL-001-2017-001

Trendmicro InterScan Arbitrary File Write

Matt Bergin
Trendmicro • InterScan Web Security Virtual Appliance
View
Nov 2, 2016 KL-001-2016-009

Sophos Web Appliance Remote Code Execution

Matt Bergin
Sophos • Web Apppliance
View
Nov 2, 2016 KL-001-2016-008

Sophos Web Appliance Privilege Escalation

Matt Bergin
Sophos • Web Apppliance
View
Oct 4, 2016 KL-001-2016-007
CVE-2016-6433

Cisco Firepower Threat Management Console Remote Command Execution Leading to Root Access

Matt Bergin
Cisco • Firepower Threat Management Console
View
Oct 4, 2016 KL-001-2016-006
CVE-2016-6435

Cisco Firepower Threat Management Console Local File Inclusion

Matt Bergin
Cisco • Firepower Threat Management Console
View
Oct 4, 2016 KL-001-2016-005
CVE-2016-6434

Cisco Firepower Threat Management Console Hard-coded MySQL Credentials

Matt Bergin
Cisco • Firepower Threat Management Console
View
Oct 4, 2016 KL-001-2016-004

Cisco Firepower Threat Management Console Authenticated Denial of Service

Matt Bergin
Cisco • Firepower Threat Management Console
View
Jun 30, 2016 KL-001-2016-003

SQLite Tempdir Selection Vulnerability

Hank Leininger
SQLite/Hwaci • SQLite
View
Jun 27, 2016 KL-001-2016-002

Ubiquiti Administration Portal CSRF to Remote Command Execution

Matt Bergin
Ubiquiti • AirGateway, AirFiber, mFi
View
Feb 11, 2016 KL-001-2016-001

Arris DG1670A Cable Modem Remote Command Execution

Matt Bergin, Hank Leininger
Arris • Cable Modem
View
Dec 17, 2015 KL-001-2015-008
CVE-2015-6856

Dell Pre-Boot Authentication Driver Uncontrolled Write to Arbitrary Address

Matt Bergin
Dell • Pre-Boot Authentication Driver
View
Dec 17, 2015 KL-001-2015-007
CVE-2015-2874

Seagate GoFlex Satellite Remote Telnet Default Password

Matt Bergin
Seagate • GoFlex Satellite
View
Dec 3, 2015 KL-001-2015-006

Linksys EA6100 Wireless Router Authentication Bypass

Matt Bergin
Linksys • EA6100 - EA6300 Wireless Router
View
Sep 15, 2015 KL-001-2015-005
CVE-2015-6923

VBox Satellite Express Arbitrary Write Privilege Escalation

Matt Bergin
VBox Communications • Satellite Express Protocol
View
Aug 31, 2015 KL-001-2015-004
CVE-2015-5466

XGI Windows VGA Display Manager Arbitrary Write Privilege Escalation

Matt Bergin
Silicon Integrated Systems Corporation • XGI VGA Display Manager
View
Aug 31, 2015 KL-001-2015-003
CVE-2015-5465

SiS Windows VGA Display Manager Multiple Privilege Escalation

Matt Bergin
Silicon Integrated Systems Corporation • Windows VGA Display Manager
View
May 17, 2015 KL-001-2015-002
CVE-2015-3999

Piriform CCleaner Wiped Filename Recovery

Don Allison
Piriform • CCleaner
View
Jan 28, 2015 KL-001-2015-001
CVE-2014-4076

Microsoft Windows Server 2003 SP2 Arbitrary Write Privilege Escalation

Matt Bergin
Microsoft • TCP/IP Protocol Driver
View
Nov 3, 2014 KL-001-2014-004

VMWare vmx86.sys Arbitrary Kernel Read

Matt Bergin
VMWare • Workstation
View
Jul 17, 2014 KL-001-2014-003
CVE-2014-4971

Microsoft XP SP3 MQAC.sys Arbitrary Write Privilege Escalation

Matt Bergin
Microsoft • MQ Access Control
View
Jul 17, 2014 KL-001-2014-002
CVE-2014-4971

Microsoft XP SP3 BthPan.sys Arbitrary Write Privilege Escalation

Matt Bergin
Microsoft • Bluetooth Personal Area Networking
View
Jul 15, 2014 KL-001-2014-001
CVE-2014-2477

Oracle VirtualBox Guest Additions Arbitrary Write Privilege Escalation

Matt Bergin
Oracle • VirtualBox Guest Additions
View
🛡️ Need Security Research?

Get Started
Today

Our security researchers can help identify vulnerabilities in your systems before attackers do