Vulnerabilities
The security defect allows unauthenticated attackers to execute arbitrary code remotely via malicious HTTP requests.
Hi, what are you looking for?
The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.
The security defect allows unauthenticated attackers to execute arbitrary code remotely via malicious HTTP requests.
CISA updated 59 KEV entries in 2025 to specify that the vulnerabilities have been exploited in ransomware attacks.
VS Code-integrated configuration files are automatically executed in Codespaces when the user opens a repository or pull request.
The vulnerability could allow attackers to execute arbitrary commands and steal credentials and other secrets.
The security defects can lead to DoS conditions, arbitrary command execution, and privilege escalation.
The flaws dubbed LookOut can be exploited for remote code execution and data exfiltration.
The critical vulnerability exists in the contextual trust in MCP Gateway architecture, as instructions are passed without validation.
Two IP addresses accounted for the majority of the 1.4 million exploitation attempts observed over the past week.
The critical-severity SolarWinds Web Help Desk flaw could lead to unauthenticated remote code execution.
Wiz and Permiso have analyzed the AI agent social network and found serious security issues and threats.
Albeit mainly considered a theoretical risk, the flaw has been exploited to disable protections and deliver malware.
The attacks targeting Europe were analyzed by Ukraine’s CERT-UA and the cybersecurity company Zscaler.
The critical-severity vulnerabilities could allow unauthenticated attackers to execute arbitrary code remotely.
The two bugs impacted n8n’s sandbox mechanism and could be exploited via weaknesses in the AST sanitization logic.
The four critical flaws could be exploited without authentication for remote code execution or authentication bypass.
Russian and Chinese state-sponsored threat actors have been exploiting CVE-2025-8088 since July 2025.
Tracked as CVE-2026-24858, the bug allows attackers to log into devices registered to other FortiCloud accounts.
A total of 12 vulnerabilities have been fixed in OpenSSL, all discovered by a single cybersecurity firm.
The flaws allow threat actors to obtain root privileges or bypass authentication via Telnet and gain shell access as root.
The vulnerability is tracked as CVE-2026-21509 and it can be exploited to bypass security features.