<?xml version="1.0" encoding="UTF-8" ?>
<rss
    version="2.0"
    xmlns:atom="http://www.w3.org/2005/Atom"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:webfeeds="http://webfeeds.org/rss/1.0"
    xmlns:media="http://search.yahoo.com/mrss/"
    >
    <channel>
        <title>Cve Tag - Viblo</title>
        <link>https://viblo.asia/rss</link>
        <description><![CDATA[Free service for technical knowledge sharing]]></description>
        <atom:link href="https://viblo.asia/rss/tags/cve.rss" rel="self"></atom:link>
                <copyright>Sun* Inc.</copyright>
                                                <webfeeds:logo>https://viblo.asia/logo_full.svg</webfeeds:logo>
        <image>
            <url>https://viblo.asia/logo_full.svg</url>
            <title>Cve Tag - Viblo</title>
            <link>https://viblo.asia/rss</link>
        </image>
                                <language>vi-vn</language>
        <lastBuildDate>2026-07-13T09:59:15+07:00</lastBuildDate>
                <item>
            <title><![CDATA[CVE-2026-0073: Android 0-Click RCE]]></title>
                        <link>https://viblo.asia/p/cve-2026-0073-android-0-click-rce-ym4007N5491</link>
            <guid isPermaLink="true">https://viblo.asia/p/cve-2026-0073-android-0-click-rce-ym4007N5491</guid>
            <description><![CDATA[
Tóm tắt

Đầu tháng 5 này, Google đã phát hành bản vá bảo mật cho hệ điều hành Android, trong đó đã vá lỗ hổng CVE-2026-0073 — một lỗi logic khi hệ th...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tran Minh Nhat</dc:creator>
            <pubDate>2026-05-07 17:07:23</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Phát hiện RCE nhưng... bạn phải đăng nhập trước đã: Câu chuyện CVE của mình với 56.000 host!]]></title>
                        <link>https://viblo.asia/p/phat-hien-rce-nhung-ban-phai-dang-nhap-truoc-da-cau-chuyen-cve-cua-minh-voi-56000-host-MkNLrQaOJgA</link>
            <guid isPermaLink="true">https://viblo.asia/p/phat-hien-rce-nhung-ban-phai-dang-nhap-truoc-da-cau-chuyen-cve-cua-minh-voi-56000-host-MkNLrQaOJgA</guid>
            <description><![CDATA[Sumary
Bạn có biết rằng có những lỗ hổng nghe có vẻ rất nguy hiểm nhưng lại có một điều kiện 'bé xíu' là bạn phải đăng nhập không? Hôm nay, mình sẽ kể...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bách Trần</dc:creator>
            <pubDate>2024-10-02 16:26:28</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Roudncube XSS qua thuộc tính SVG]]></title>
                        <link>https://viblo.asia/p/roudncube-xss-qua-thuoc-tinh-svg-BQyJKGG7JMe</link>
            <guid isPermaLink="true">https://viblo.asia/p/roudncube-xss-qua-thuoc-tinh-svg-BQyJKGG7JMe</guid>
            <description><![CDATA[0. Bla bla

- Dạo gần đây mình muốn tìm hiểu thêm các kiến thức về lỗ hổng phía client-side, bypass WAF và filter. Vô tình thấy Roundcube phát hành bả...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">NeLeet</dc:creator>
            <pubDate>2024-08-05 01:10:28</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Một vài những vulnerable gần đây của Whatsup Gold]]></title>
                        <link>https://viblo.asia/p/mot-vai-nhung-vulnerable-gan-day-cua-whatsup-gold-W13VMy1GVY7</link>
            <guid isPermaLink="true">https://viblo.asia/p/mot-vai-nhung-vulnerable-gan-day-cua-whatsup-gold-W13VMy1GVY7</guid>
            <description><![CDATA[Đợt vừa rồi mình cùng @lengocanh cũng target vào Whatsup Gold, tuy kết quả chưa thật sự tốt nhưng cũng có để lại một vài bài học cho ae trong team

TL...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Minh Tuấn Ngụy</dc:creator>
            <pubDate>2024-07-31 15:50:57</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Vài ghi chú về CVE-2024-34351: Server-Side Request Forgery in NextJS Server Actions]]></title>
                        <category>Development</category>
                        <link>https://viblo.asia/p/vai-ghi-chu-ve-cve-2024-34351-server-side-request-forgery-in-nextjs-server-actions-gwd43jKrVX9</link>
            <guid isPermaLink="true">https://viblo.asia/p/vai-ghi-chu-ve-cve-2024-34351-server-side-request-forgery-in-nextjs-server-actions-gwd43jKrVX9</guid>
            <description><![CDATA[Giới thiệu

Tuần vừa rồi, các researcher của Assetnote.io có công bố bài viết liên quan đến lỗi SSRF ở Server Actions của NextJS phiên bản < 14.1.1 ở ...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nguyen Anh Tien</dc:creator>
            <pubDate>2024-05-13 17:07:35</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[CVE-2024-4142 Privilege Escalation in Jfrog Artifactory]]></title>
                        <link>https://viblo.asia/p/cve-2024-4142-privilege-escalation-in-jfrog-artifactory-0gdJzDbvVz5</link>
            <guid isPermaLink="true">https://viblo.asia/p/cve-2024-4142-privilege-escalation-in-jfrog-artifactory-0gdJzDbvVz5</guid>
            <description><![CDATA[When I was feeling bored and scrolling down the twitter, suddenly I catched up a status https://twitter.com/matthias_kaiser/status/1786264686146560251...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">realalphaman dot substack dot com</dc:creator>
            <pubDate>2024-05-06 16:48:47</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Phân tích CVE-2023-39476 Inductive Automation Ignition Deserialization và vấn đề với Gadget Jython2]]></title>
                        <link>https://viblo.asia/p/phan-tich-cve-2023-39476-inductive-automation-ignition-deserialization-va-van-de-voi-gadget-jython2-obA46M60VKv</link>
            <guid isPermaLink="true">https://viblo.asia/p/phan-tich-cve-2023-39476-inductive-automation-ignition-deserialization-va-van-de-voi-gadget-jython2-obA46M60VKv</guid>
            <description><![CDATA[Một CVE mới từ một pháp sư trung hoa nào đó. Mình sẽ viết lại vì quá trình reproduce nó khá hay và trắc trở. Trong đó trung tâm bài này là Gadget Jyth...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">realalphaman dot substack dot com</dc:creator>
            <pubDate>2023-09-07 16:37:19</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Phân tích CVE-2017-3066 - AMF Deserialization trong Adobe ColdFusion]]></title>
                        <link>https://viblo.asia/p/phan-tich-cve-2017-3066-amf-deserialization-trong-adobe-coldfusion-EoW4oROAVml</link>
            <guid isPermaLink="true">https://viblo.asia/p/phan-tich-cve-2017-3066-amf-deserialization-trong-adobe-coldfusion-EoW4oROAVml</guid>
            <description><![CDATA[1. Giới thiệu

Adobe ColdFusion là một nền tảng phát triển ứng dụng web nhanh chóng, ngôn ngữ lập trình được sử dụng với nền tảng Adobe ColdFusion cũn...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">realalphaman dot substack dot com</dc:creator>
            <pubDate>2023-06-29 15:24:43</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Redteam 0x01: Làm gì khi đã chiếm được quyền điều khiển hệ thống Source code management]]></title>
                        <link>https://viblo.asia/p/redteam-0x01-lam-gi-khi-da-chiem-duoc-quyen-dieu-khien-he-thong-source-code-management-E1XVOa8GJMz</link>
            <guid isPermaLink="true">https://viblo.asia/p/redteam-0x01-lam-gi-khi-da-chiem-duoc-quyen-dieu-khien-he-thong-source-code-management-E1XVOa8GJMz</guid>
            <description><![CDATA[*/ Lưu ý: Tất cả những gì mình làm và ghi lại trong bài post này đều đã được đơn vị chủ quản đồng ý và fix các lỗ hổng trước khi bài viết được public....]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">realalphaman dot substack dot com</dc:creator>
            <pubDate>2023-08-02 10:40:13</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Adobe Coldfusion from LFI to RCE (CVE-2023-26359 / CVE-2023-26360)]]></title>
                        <link>https://viblo.asia/p/adobe-coldfusion-from-lfi-to-rce-cve-2023-26359-cve-2023-26360-aAY4q8QDVPw</link>
            <guid isPermaLink="true">https://viblo.asia/p/adobe-coldfusion-from-lfi-to-rce-cve-2023-26359-cve-2023-26360-aAY4q8QDVPw</guid>
            <description><![CDATA[As the description from this CVE,

I will download two versions 2018.0.15 and 2018.0.16 to diff. We can easily install Adobe Coldfusion with docker vi...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">realalphaman dot substack dot com</dc:creator>
            <pubDate>2023-06-15 17:30:49</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Phân tích lỗ hổng CVE 2022 36804 trong Bitbucket]]></title>
                        <link>https://viblo.asia/p/phan-tich-lo-hong-cve-2022-36804-trong-bitbucket-PwlVmjp145Z</link>
            <guid isPermaLink="true">https://viblo.asia/p/phan-tich-lo-hong-cve-2022-36804-trong-bitbucket-PwlVmjp145Z</guid>
            <description><![CDATA[Lại một lần nữa là CVE của Bitbucket.  Mình hay làm thằng này đơn giản là vì nó setup dễ.

1. Đọc mô tả
Đây là mô tả của Atlatssian về CVE này

Có thể...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">realalphaman dot substack dot com</dc:creator>
            <pubDate>2022-12-19 22:13:55</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Phân tích lỗ hổng Deserialization trong Bitbucket CVE-2022-26133]]></title>
                        <link>https://viblo.asia/p/phan-tich-lo-hong-deserialization-trong-bitbucket-cve-2022-26133-W13VMgEGJY7</link>
            <guid isPermaLink="true">https://viblo.asia/p/phan-tich-lo-hong-deserialization-trong-bitbucket-cve-2022-26133-W13VMgEGJY7</guid>
            <description><![CDATA[Về desialization là gì thì anh em có thể tham khảo thêm ở đây.

1. Tìm hiểu về lỗi
Trên Jira của Atlassian đã mô tả về lỗi như sau:

Lỗ hổng này là lỗ...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">realalphaman dot substack dot com</dc:creator>
            <pubDate>2022-12-17 15:51:21</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[[Phân tích CVE] any23 (Phần 1)]]></title>
                        <link>https://viblo.asia/p/phan-tich-cve-any23-phan-1-Qbq5Q6a4KD8</link>
            <guid isPermaLink="true">https://viblo.asia/p/phan-tich-cve-any23-phan-1-Qbq5Q6a4KD8</guid>
            <description><![CDATA[I. Giới thiệu về any23
Any23 (Any To Triples) là một thư viện, một dịch vụ web và một command line tool nhằm trích xuất định dạng RDF từ các tài liệu ...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dong Vu Viet</dc:creator>
            <pubDate>2021-09-18 18:34:01</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Phân tích CVE-2019-20042 WordPress và BuddyPress (phần 2)]]></title>
                        <link>https://viblo.asia/p/phan-tich-cve-2019-20042-wordpress-va-buddypress-phan-2-gGJ597w9ZX2</link>
            <guid isPermaLink="true">https://viblo.asia/p/phan-tich-cve-2019-20042-wordpress-va-buddypress-phan-2-gGJ597w9ZX2</guid>
            <description><![CDATA[1. Giới thiệu
Tiếp tục với series về phân tích CVE wordpress, Hôm nay mình sẽ đi phân tích  CVE về lỗ hổng XSS: CVE-2019-20042.

Phiên bản bị ảnh hưởn...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nguyen Xuan Chien</dc:creator>
            <pubDate>2021-06-09 16:44:27</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Phân tích CVE-2019-8942 của wordpress]]></title>
                        <link>https://viblo.asia/p/phan-tich-cve-2019-8942-cua-wordpress-bWrZnVrYZxw</link>
            <guid isPermaLink="true">https://viblo.asia/p/phan-tich-cve-2019-8942-cua-wordpress-bWrZnVrYZxw</guid>
            <description><![CDATA[1. Giới thiệu
CVE-2019-8942 lợi dụng lỗi hổng LFI + File Upload để thực hiện RCE đến máy chủ web với quyền author. Phiên bản bị ảnh hưởng bao gồm trướ...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nguyen Xuan Chien</dc:creator>
            <pubDate>2021-05-21 10:24:20</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Lỗ hổng PHP-FPM (CVE-2019-11043) với máy chủ NGINX khiến nhiều trang web bị ảnh hưởng]]></title>
                        <link>https://viblo.asia/p/lo-hong-php-fpm-cve-2019-11043-voi-may-chu-nginx-khien-nhieu-trang-web-bi-anh-huong-3Q75wxxMKWb</link>
            <guid isPermaLink="true">https://viblo.asia/p/lo-hong-php-fpm-cve-2019-11043-voi-may-chu-nginx-khien-nhieu-trang-web-bi-anh-huong-3Q75wxxMKWb</guid>
            <description><![CDATA[![](https://images.viblo.asia/1e9642a2-ef48-4006-a96f-ae4084f33fcf.png)


Một lỗ hổng được báo cáo gần đây, có mã là CVE-2019-11043, có thể ảnh hưởng ...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Minh Tuấn Ngụy</dc:creator>
            <pubDate>2019-11-01 09:15:42</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Linux: broken permission and object lifetime handling for PTRACE_TRACEME - Chiếm quyền root hầu hết các máy chạy Linux]]></title>
                        <link>https://viblo.asia/p/linux-broken-permission-and-object-lifetime-handling-for-ptrace-traceme-chiem-quyen-root-hau-het-cac-may-chay-linux-4P8564M3ZY3</link>
            <guid isPermaLink="true">https://viblo.asia/p/linux-broken-permission-and-object-lifetime-handling-for-ptrace-traceme-chiem-quyen-root-hau-het-cac-may-chay-linux-4P8564M3ZY3</guid>
            <description><![CDATA[Mở đầu
- Ngày hôm qua, 1 thành viên trong đội của tôi đã gửi cho tôi 1 bài post trên facebook nói về con CVE-2019-13272 này. Sau một hồi tìm hiểu thì ...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Minh Tuấn Ngụy</dc:creator>
            <pubDate>2019-07-26 09:08:58</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[CVE-2019-7164: Lỗ hổng trong SQLALchemy (version 1.2.17 và 1.3.x đến 1.3.0b2) cho phép SQL injection thông qua tham số order_by]]></title>
                        <link>https://viblo.asia/p/cve-2019-7164-lo-hong-trong-sqlalchemy-version-1217-va-13x-den-130b2-cho-phep-sql-injection-thong-qua-tham-so-order-by-bJzKmwxYl9N</link>
            <guid isPermaLink="true">https://viblo.asia/p/cve-2019-7164-lo-hong-trong-sqlalchemy-version-1217-va-13x-den-130b2-cho-phep-sql-injection-thong-qua-tham-so-order-by-bJzKmwxYl9N</guid>
            <description><![CDATA[CVE-2019-7164: Lỗ hổng trong SQLALchemy (version 1.2.17 và 1.3.x đến 1.3.0b2) cho phép SQL injection thông qua tham số order_by.

Lời mở đầu

Câu chuy...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ManhNV</dc:creator>
            <pubDate>2019-07-11 09:10:11</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Tìm hiểu về lỗ hổng CVE 2017-0016 (Phần cuối)]]></title>
                        <link>https://viblo.asia/p/tim-hieu-ve-lo-hong-cve-2017-0016-phan-cuoi-XL6lAoQNKek</link>
            <guid isPermaLink="true">https://viblo.asia/p/tim-hieu-ve-lo-hong-cve-2017-0016-phan-cuoi-XL6lAoQNKek</guid>
            <description><![CDATA[Phần III: Thiết lập môi trường kiểm thử
1. Phương pháp khai thác

Phần II, mình đã trình bày sơ lược về một số phương pháp khai thác lỗ hổng CVE 2017 ...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Phan Đức Bảo</dc:creator>
            <pubDate>2019-05-16 09:12:12</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Tìm hiểu về lỗ hổng CVE 2017-0016 (Phần II)]]></title>
                        <link>https://viblo.asia/p/tim-hieu-ve-lo-hong-cve-2017-0016-phan-ii-XL6lAoEgKek</link>
            <guid isPermaLink="true">https://viblo.asia/p/tim-hieu-ve-lo-hong-cve-2017-0016-phan-ii-XL6lAoEgKek</guid>
            <description><![CDATA[Phần II: Một số phương pháp khai thác lỗ hổng CVE – 2017 – 0016
1. Cơ chế của lỗ hổng
Để truy cập vào tài nguyên được chia sẻ trên máy chủ SMB, client...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Phan Đức Bảo</dc:creator>
            <pubDate>2019-04-18 10:05:27</pubDate>
                                                                                                        </item>
                <item>
            <title><![CDATA[Tìm hiểu  về lỗ hổng CVE 2017-0016 (Phần I)]]></title>
                        <link>https://viblo.asia/p/tim-hieu-ve-lo-hong-cve-2017-0016-phan-i-WAyK8QDoZxX</link>
            <guid isPermaLink="true">https://viblo.asia/p/tim-hieu-ve-lo-hong-cve-2017-0016-phan-i-WAyK8QDoZxX</guid>
            <description><![CDATA[LỜI NÓI ĐẦU
Hiện nay, với sự phát triển mạnh mẽ của công nghệ đã và đang tác động sâu sắc đến mọi lĩnh vực của đời sống xã hội, cũng như sự phát triển...]]></description>
                        <dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Phan Đức Bảo</dc:creator>
            <pubDate>2019-03-18 09:50:40</pubDate>
                                                                                                        </item>
            </channel>
</rss>
