Spring Framework developers have issued a security advisory addressing a vulnerability that could lead to unauthorized access...
Vulnerability
RAGFlow, the open-source Retrieval-Augmented Generation (RAG) platform developed by Infiniflow, has been found vulnerable to a serious...
Security researcher Navy Titanium have released a technical deep-dive uncovering three severe vulnerabilities affecting pfSense, the popular...
Imperva researchers have disclosed a newly discovered vulnerability in WordPress that could expose sensitive draft and private...
Mozilla has moved swiftly to patch two critical zero-day vulnerabilities in Firefox, both of which were exploited...
A patched kernel vulnerability, CVE-2025-24203, has attracted great attention in the security community as well as the...
Okta has issued a critical security advisory warning developers and enterprises using the Auth0-PHP SDK about a...
A newly disclosed vulnerability in the Tornado Python web framework, tracked as CVE-2025-47287, exposes applications to a...
Researchers have disclosed a reflected cross-site scripting (XSS) vulnerability in Label Studio, an open-source data labeling tool...
A newly reported vulnerability within the GNU C Library (glibc), a fundamental component of countless Linux applications,...
A newly disclosed vulnerability in Microsoftβs Remote Desktop Gateway (RD Gateway) reveals a dangerous race condition that...
A serious security flaw has been identified in the Reflex open-source framework, a tool used to build...
OpenText has issued a critical security advisory addressing two significant vulnerabilities in its Operations Bridge Manager (OBM)...
Rockwell Automation has issued a critical security advisory affecting the FactoryTalk Historian-ThingWorx Connector, due to a third-party...
A high-severity vulnerability in a popular WordPress event management plugin has been disclosed and patched, raising alarms...
A newly surfaced proof of concept (PoC) has reignited attention around a critical iOS kernel vulnerabilityβCVE-2023-41992βthat Apple...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new security vulnerabilities to its Known...
A critical XML External Entity (XXE) injection vulnerability has been identified in WebDriverManager, an essential Java library...
The PgPool Global Development Group has issued a high-severity security advisory for Pgpool-II, a widely used middleware...
Jenkins, a popular open-source automation server, is a crucial tool for many development and operations teams. A...