Vulnerabilities
The flaws can be exploited remotely to impersonate users or execute arbitrary commands on the underlying OS.
Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
The flaws can be exploited remotely to impersonate users or execute arbitrary commands on the underlying OS.
Hackers are exploiting CVE-2026-33032, a critical remote takeover vulnerability in the Nginx UI management tool.
Researchers warn that a flaw in Anthropic’s Model Context Protocol allows unsanitized commands to execute silently, enabling full system compromise across widely used AI...
The flaws could allow a remote attacker to maintain access after their account has been disabled and to access information from other user sessions.
The flaws could allow attackers to bypass authentication or execute arbitrary code or commands via HTTP requests.
Experts say this is the second-largest Microsoft Patch Tuesday ever based on CVE count.
Critical ColdFusion vulnerabilities are the most at risk of being exploited in attacks, according to the software giant.
CISOs face a shrinking window to prepare as AI models like Mythos collapse the gap between vulnerability discovery and exploitation, driving a new era...
The company has released 19 new security notes addressing flaws in over a dozen enterprise products.
The security defects allow attackers to escalate privileges and execute arbitrary code remotely.
The vulnerability is tracked as CVE-2026-34621 and Adobe has confirmed that it can be exploited for arbitrary code execution.
A critical-severity flaw could be exploited remotely, without authentication, to take over a vulnerable device.
Attackers could exploit these vulnerabilities in denial-of-service, information disclosure, and arbitrary code execution attacks.
The critical vulnerabilities affect Chrome’s WebML component and they have been reported by anonymous researchers.
Within nine hours, a hacker built an exploit from the unauthenticated bug’s advisory and started using it in the wild.
The security hole affected an EngageLab SDK and it was reported by Microsoft to the vendor one year ago.
The bugs could allow attackers to modify protected resources and escalate their privileges to administrator.
Reputable researcher Haifei Li has come across what appears to be a PDF designed to exploit an unpatched vulnerability.
A total of seven vulnerabilities, most of which can be exploited for DoS attacks, have been patched in OpenSSL.
The vulnerability requires authentication for successful exploitation, but another flaw exposes the Jolokia API without authentication.