A Server-Side Request Forgery (SSRF) vulnerability has been discovered in the @opennextjs/cloudflare package, potentially allowing unauthenticated users...
Vulnerability Report
A critical vulnerability has been disclosed in KAON’s KCM3100 Wi-Fi gateway devices that could allow attackers to...
The Qualys Threat Research Unit (TRU) has unveiled two interconnected privilege escalation vulnerabilities—CVE-2025-6018 and CVE-2025-6019—that can allow...
A dangerous Linux privilege escalation vulnerability, CVE-2023-0386, has officially entered the CISA Known Exploited Vulnerabilities (KEV) Catalog...
The Cloud Software Group has issued a security bulletin addressing two critical vulnerabilities in NetScaler ADC (formerly...
Veeam, a global leader in data protection and disaster recovery solutions, has issued a critical security update...
Google has rolled out an important security update for the Stable Channel of Chrome, bringing the version...
German industrial automation manufacturer WAGO GmbH & Co. KG has released critical security updates for its WAGO...
Facial recognition technology is increasingly prevalent across a variety of scenarios; however, cases of identity fraud continue...
Gamers and PC enthusiasts relying on ASUS Armoury Crate to manage their high-performance systems are urged to...
In a major revelation, the Threat Intelligence Department of the Positive Technologies Expert Security Center (PT ESC)...
A newly disclosed security flaw in the MCP Inspector, a tool designed to test and debug Machine...
In June 2025, the SUSE Security Team disclosed critical vulnerabilities in sslh, a lightweight protocol multiplexer used...
The Apache Software Foundation has disclosed four security vulnerabilities affecting multiple versions of Apache Tomcat, the widely...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two high-risk vulnerabilities to its Known Exploited...
A recent investigation by SpecterOps has uncovered a chain of critical vulnerabilities in OneLogin’s Active Directory (AD)...
A tool named PoCGen is revolutionizing how the security community generates Proof-of-Concept (PoC) exploits for vulnerabilities in...
A sudden and coordinated wave of exploit attempts targeting a critical vulnerability in Zyxel firewalls has been...
Trend Micro has uncovered an active and sophisticated campaign exploiting a critical remote code execution (RCE) vulnerability...
Five critical vulnerabilities—each scoring a CVSS of 9.8—have been disclosed in multiple models of Blink routers BL,...
An independent hardware security researcher Danilo Erazo has unveiled two critical-severity vulnerabilities—CVE-2025-6029 and CVE-2025-6030—affecting smart keyless entry...
IBM has disclosed a high-severity vulnerability affecting its Backup, Recovery, and Media Services (BRMS) for IBM i...