Vulnerabilities
Tracked as CVE-2025-37164, the critical flaw could allow unauthenticated, remote attackers to execute arbitrary code.
Hi, what are you looking for?
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.
Tracked as CVE-2025-37164, the critical flaw could allow unauthenticated, remote attackers to execute arbitrary code.
Tracked as CVE-2025-59374, the issue is a software backdoor implanted in Asus Live Update in a supply chain attack.
The medium-severity flaw has been exploited in combination with a critical bug for remote code execution.
The critical zero-day is tracked as CVE-2025-20393 and it impacts Secure Email Gateway and Secure Email and Web Manager appliances.
The startup takes an agentic approach to preventing vulnerability exploitation by uncovering exposure across assets.
From open source libraries to AI-powered coding assistants, speed-driven development is introducing new third-party risks that threat actors are increasingly exploiting.
The issue allows attackers to write arbitrary data to any file, or delete arbitrary files to obtain System privileges.
Threat actors are exploiting the two critical authentication bypass vulnerabilities against FortiGate appliances.
Atlassian has released software updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira.
Apple has released macOS and iOS updates to patch two WebKit zero-days exploited in an “extremely sophisticated” attack.
Threat actors have hacked at least nine organizations by exploiting the recently patched Gladinet CentreStack flaw.
Because user input is not sufficiently sanitized, attackers could exploit the flaw to define external entities within an XML request.
XSS remains the top software weakness, followed by SQL injection and CSRF. Buffer overflow issues and improper access control make it to top 25.
All critical vulnerabilities in Microsoft, third-party, and open source code are eligible for rewards if they impact Microsoft services.
Participants earned rewards at the hacking competition for Grafana, Linux Kernel, Redis, MariaDB, and PostgreSQL vulnerabilities.
The exploited flaw allows attackers to overwrite files outside the repository, leading to remote code execution.
Most of the 100 vulnerabilities resolved this week, including critical flaws, were in third-party dependencies.
The Chrome zero-day does not have a CVE and it's unclear who reported it and which browser component it affects.
The two security defects impact FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager with FortiCloud SSO login authentication enabled.
The XSS vulnerability could allow remote attackers to execute arbitrary JavaScript code with administrator privileges.