Knowledge Base
Threat Encyclopedia
99 researched entries covering vulnerabilities, attack techniques, malware, tools and glossary terms — written so you can understand a finding, not just see a red flag.
- Entries
- 99
- Threat guides
- 70
- Attack flows
- 7
- Categories
- 5
How to read an entry
-
1
Start with the summary
The card and severity badge tell you what it is and how badly it ends when it lands.
-
2
Follow the attack steps
Each entry walks the chain in order — foothold, escalation, objective — so you can see where you sit.
-
3
Work the fix list
The green checklist is ordered: complete it top to bottom and the exposure is closed.
Vulnerabilities
Weaknesses an attacker can exploit — 19 entries.
Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
Read entry →Broken Access Control
Users can reach records, routes or functions that belong to someone else.
Read entry →Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
Read entry →Citrix NetScaler Improper Input Validation Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
Read entry →Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
Read entry →Cross-Site Request Forgery (CSRF)
A logged-in browser is tricked into submitting an action the user never intended.
Read entry →Cross-Site Scripting (XSS)
Attacker-supplied script runs in another user's browser, stealing sessions and rewriting the page.
Read entry →Directory Traversal
Path segments such as ../../ escape the intended folder and expose system files.
Read entry →Exposed Source Control Metadata
A reachable .git directory hands an attacker the entire repository history, including rotated secrets.
Read entry →Exposed XML-RPC Endpoint
The WordPress xmlrpc.php endpoint is reachable, enabling brute force amplification and remote pingback abuse.
Read entry →Insecure Deserialization
Trusting serialized objects from the client allows remote code execution through gadget chains.
Read entry →Missing Security Headers
Absent CSP, HSTS, X-Frame-Options and Referrer-Policy leave the browser with no guard rails.
Read entry →