What This Vulnerability Research Portfolio Represents
Discoveries That Matter
Our vulnerability research team reverse engineers your enterprise software to find the 0-days that threaten your infrastructure - before attackers do.


Enterprise Focus
The vulnerabilities below affect systems organizations use: SAP. IBM. Check Point. F5. BMC. Microsoft. Rapid7. Cyberark.


Current Research
We identified a wide range of CVEs across various industries - each of the vulnerabilities have been assigned a threat level ranging from critical to low. We pride ourselves in beating others to identify critical CVEs in large infrastructure for orgasations such as IBM and Microsoft.
.webp)
Cross-site scripting with WAF bypass in Bitrix CRM allows script injection despite security controls





Remote command execution via unrestricted file upload in ExpressionEngine allows arbitrary code execution




.svg.webp)
Directory traversal in Apache Wicket allows reading Wicket markup source files from the server





Remote stored XSS via attachment name in Afterlogic WebMail Pro 8.3.11 allows persistent script injection





Arbitrary file upload leading to remote code execution in Energy Logserver allows server compromise




.svg.webp)
Stored cross-site scripting in Apache Atlas allows persistent malicious script injection





Local privilege escalation due to incorrect DLL permissions in KeeperChat on macOS allows local attackers to execute code with elevated privileges




We map your systems before testing how they break.
That's why critical findings usually show up outside the original scope - attackers don't respect scope documents.
Security Assessment Services FAQ
Questions enterprise security teams ask before partnering with AFINE for security assessments.



