Vulnerabilities
SAP has released patches for 16 vulnerabilities, including a critical-severity SSRF bug in NetWeaver (Adobe Document Services).
Hi, what are you looking for?
Akamai documents a privilege escalation flaw in Windows Server 2025 after Redmond declines to ship an immediate patch.
SAP has released patches for 16 vulnerabilities, including a critical-severity SSRF bug in NetWeaver (Adobe Document Services).
Cisco Talos has disclosed the details of apparently unpatched vulnerabilities in MC Technologies industrial routers and the GoCast BGP tool.
The CVE-2024-54143 vulnerability affects the OpenWrt sysupgrade server and exposes users to risks of installing malicious firmware images.
QNAP has released patches for multiple high-severity QTS and QuTS Hero vulnerabilities disclosed at the Pwn2Own Ireland 2024 hacking contest.
SonicWall has released patches for multiple high-severity flaws in the SMA100 SSL-VPN secure access gateway.
WatchTowr has published proof-of-concept (PoC) code for an unpatched vulnerability in the Mitel MiCollab enterprise collaboration platform.
A critical directory traversal vulnerability in the SailPoint IdentityIQ IAM platform exposes restricted files to attackers.
Japanese device maker confirms zero-day router exploitation and warn that full patches won’t be available for a few weeks.
More than 100 Cisco products are affected by an NX-OS vulnerability that allows attackers to bypass image signature verification.
Veeam releases patches for two vulnerabilities in Service Provider Console, including a critical-severity remote code execution bug.
A second vulnerability in Zyxel firewalls has been exploited in Helldown ransomware attacks over the past weeks.
Cisco has updated an advisory for CVE-2014-2120 to warn customers that the vulnerability has been exploited in the wild.
The 'Bootkitty' prototype UEFI bootkit contains an exploit for LogoFAIL and was created in a South Korea university program.
A critical-severity vulnerability in open source enterprise network monitoring tool Zabbix could lead to full system compromise.
Microsoft informed customers that vulnerabilities affecting cloud, AI and other services have been patched, including an exploited flaw.
ESET warns of a new reality: “UEFI bootkits are no longer confined to Windows systems alone.”
VulnCheck warns of widespread exploitation of a year-and-a-half-old ProjectSend vulnerability for which multiple public exploits exist.
Palo Alto Networks and SonicWall VPNs affected by vulnerabilities allowing remote code execution and privilege escalation.
The company warns that malicious hackers can craft exploits to elevate privileges or launch cross-site scripting attacks.
IBM has released patches for two high-severity remote code execution vulnerabilities in Data Virtualization Manager and Security SOAR.