Who am I ?

Mehmet Ince is a co-founder of PRODAFT, a company specializing in cyber intelligence. His journey in cybersecurity began around 2002, focusing on vulnerability research, particularly in open-source applications. Over the years, he has identified and disclosed over 300 security vulnerabilities, contributing significantly to the enhancement of global software security. Ince has led 0-day vulnerability research projects across various industries, including aviation, military, and maritime sectors. His work in these areas has involved in-depth analysis of security vulnerabilities in specialized appliances and systems, aiming to bolster defenses against potential cyber threats. Through these initiatives, he has provided critical insights into the unique security challenges faced by these industries, enhancing their resilience against cyber-attacks.

Overview

179

total CVE

CRITICAL
18
HIGH
119
MEDIUM
41
LOW
1
NONE
0

Latest CVEs

9.3

CVSS4.0

CVE-2025-20061 - mySCADA myPRO Manager OS Command Injection

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.

📅 Published: Jan. 29, 2025, 7:52 p.m. 🔄 Last Modified: Feb. 12, 2025, 7:51 p.m.

9.3

CVSS4.0

CVE-2025-20014 - mySCADA myPRO Manager OS Command Injection

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.

📅 Published: Jan. 29, 2025, 7:46 p.m. 🔄 Last Modified: Jan. 29, 2025, 8:15 p.m.

8.8

CVSS3.1

CVE-2024-9188 - Specially constructed queries cause cross platform scripting leaking administrator tokens

Specially constructed queries cause cross platform scripting leaking administrator tokens

📅 Published: Jan. 10, 2025, 10:05 p.m. 🔄 Last Modified: Jan. 13, 2025, 8:07 p.m.

7.6

CVSS3.1

CVE-2024-47520 - A user with advanced report application access rights can perform actions for which they are not au…

A user with advanced report application access rights can perform actions for which they are not authorized

📅 Published: Jan. 10, 2025, 10 p.m. 🔄 Last Modified: Jan. 13, 2025, 8:11 p.m.

8.3

CVSS3.1

CVE-2024-47519 - Backup uploads to ETM subject to man-in-the-middle interception

Backup uploads to ETM subject to man-in-the-middle interception

📅 Published: Jan. 10, 2025, 9:56 p.m. 🔄 Last Modified: Jan. 13, 2025, 8:12 p.m.