A critical security flaw has been discovered in Cherry Studio, a cross-platform desktop client that supports multiple...
Vulnerability Report
A critical authentication bypass vulnerability has been discovered in Better Auth, a popular framework-agnostic authentication and authorization...
A critical-severity vulnerability has been disclosed in Happy DOM, a popular JavaScript package used to emulate web...
The Zero Day Initiative (ZDI) has published details of two critical vulnerabilities in the popular open-source compression...
Google Threat Intelligence Group (GTIG) and Mandiant have jointly disclosed an extensive data theft and extortion campaign...
Huntress has sounded the alarm over active exploitation of a newly discovered Local File Inclusion (LFI) vulnerability...
NVIDIA has released an important software security update for its GPU Display Driver, addressing multiple vulnerabilities that...
MediaTek has released its October 2025 Product Security Bulletin, disclosing a set of high- and medium-severity vulnerabilities...
Security researcher Rocco Calvi detailed a critical flaw in the TP-Link AX1800 WiFi 6 Router (Archer AX21/AX20)...
The maintainers of Flowise, an open-source generative AI development platform for building AI agents and LLM workflows,...
GitLab has released important updates addressing two high-severity vulnerabilities that impact both its Community Edition (CE) and...
CrowdStrike has released security updates to address two vulnerabilities in its Falcon Sensor for Windows, identified as...
The Deno project has issued a new security advisory warning of a command injection vulnerability on Windows...
The Akka.NET team has issued a critical security advisory for a severe vulnerability in its Akka.Remote module...
Amazon Web Services (AWS) has released an important security bulletin warning users of a critical local privilege...
Security researchers have identified two critical vulnerabilities in Nagios Log Server, the enterprise log management solution widely...
A cross-site scripting (XSS) vulnerability in Synacor Zimbra Collaboration Suite (ZCS) β tracked as CVE-2025-27915 β has...
Security researcher David Leadbeater has disclosed a vulnerability in OpenSSH, identified as CVE-2025-61984, which highlights how even...
Google has released a new Stable Channel update for Chrome 141.0.7390.65/.66 on Windows and macOS and 141.0.7390.65...
Security researchers at Wordfence have issued an urgent warning about an actively exploited authentication bypass vulnerability in...