Vulnerabilities
Google has released a Chrome 138 security update that patches a zero-day, the fifth resolved in the browser this year.
Hi, what are you looking for?
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.
Google has released a Chrome 138 security update that patches a zero-day, the fifth resolved in the browser this year.
CISA considers the recently disclosed CitrixBleed 2 vulnerability an unacceptable risk and has added it to the KEV catalog.
Two Gravity Forms WordPress plugin versions available on the official download page were injected with malware in a supply chain attack.
Wing FTP Server vulnerability CVE-2025-47812 can be exploited for arbitrary command execution with root or system privileges.
Researchers demonstrated GPUHammer — a Rowhammer attack against GPUs — by degrading the accuracy of machine learning models.
Ivanti, Fortinet, and Splunk have released patches for critical- and high-severity vulnerabilities in their products.
Adobe patches were also released for medium-severity flaws in After Effects, Audition, Dimension, Experience Manager Screens, FrameMaker, Illustrator, Substance 3D Stager, and Substance 3D...
Patch Tuesday July 2025: Microsoft rolled out fixes for 130 vulnerabilities, including a zero-day in SQL Server.
SAP has released patches for multiple insecure deserialization vulnerabilities in NetWeaver that could lead to full system compromise.
Researchers released technical information and exploit code targeting a critical vulnerability (CVE-2025-5777) in Citrix NetScaler.
CVE-2025-6554 and three other Chromium vulnerabilities could allow attackers to execute code and corrupt memory remotely.
Hardcoded SSH credentials in Cisco Unified CM and Unified CM SME could allow attackers to execute commands as root.
A vulnerability in the Forminator WordPress plugin allows attackers to delete arbitrary files and take over impacted websites.
CISA says two more vulnerabilities in the messaging application TeleMessage TM SGNL have been exploited in the wild.
Many Citrix NetScaler systems are exposed to attacks exploiting the vulnerabilities tracked as CVE-2025-5777 and CVE-2025-6543.
Google has released a Chrome 138 update that patches a high-severity vulnerability with an exploit in the wild.
The Citrix NetScaler vulnerability tracked as CitrixBleed 2 and CVE-2025–5777 may be exploited in the wild for initial access.
A vulnerability in the extension publishing mechanism of Open VSX could have allowed attackers to tamper with any repository.
CISA is urging federal agencies to patch a recent AMI BMC vulnerability and a half-a-decade-old bug in FortiOS by July 17.
Two critical vulnerabilities in Cisco ISE could allow remote attackers to execute arbitrary code with root privileges.