Security researcher Morris Richman has disclosed a new privilege escalation vulnerability, CVE-2025-43472, which could allow an attacker...
Vulnerability
While most Android users can breathe a sigh of relief, a newly analyzed Bluetooth vulnerability presents a...
cPanel, the industry-standard control panel software that powers a vast portion of the web hosting market, has...
A significant crack has been discovered in the armor of Windows Administrator Protection, potentially allowing low-privileged attackers...
Just when administrators thought NTLM relay attacks were becoming a thing of the past, a dangerous new...
Critical Flowise Flaw Allows Unauthenticated Remote Admin Takeover via Exposed Registration Endpoint
Critical Flowise Flaw Allows Unauthenticated Remote Admin Takeover via Exposed Registration Endpoint
The team behind Flowiseβa popular open-source platform for building AI agents and LLM workflowsβhas issued an urgent...
Microsoft has patched a newly disclosed local privilege escalation (LPE) vulnerability affecting the Host Process for Windows...
Zimbra has issued a critical security patch, Zimbra Daffodil (v10.1.13), to address a host of vulnerabilities in...
Dell Technologies has issued a critical security advisory addressing multiple vulnerabilities in its CloudLink encryption management software,...
Security researcher Hyeonjin Choi has detailed a serious privilege escalation vulnerability (CVE-2025-50168) in Microsoft Windowsβ Win32K subsystem,...
The strongSwan Team has disclosed a critical heap-based buffer overflow vulnerability (CVE-2025-62291) in the EAP-MSCHAPv2 plugin used...
Ubiquiti has released a security update to address a critical authentication bypass vulnerability (CVE-2025-52665) in its UniFi...
Security researcher Jordan Jay has published an extensive technical breakdown of CVE-2025-24990, a high-severity Elevation of Privilege...
Researchers Ivan Fratric and Natalie Silvanovich from Google Project Zero have disclosed a critical 0-click vulnerability (CVE-2025-54957,...
A cybersecurity researcher at Cymulate Research Labs, Ruben Enkaoua, has discovered yet another zero-click NTLM credential leakage...
Security researcher Chino Kafuu details a flaw buried deep within the Transport Layer Security (TLS) subsystem of...
Esri has released a critical security patch addressing a SQL injection vulnerability (CVE-2025-57870) in ArcGIS Server, a...
A detailed exploit analysis of CVE-2023-4921 (CVSS 7.8) reveals how a subtle use-after-free flaw in the Linux...
A newly discovered vulnerability in HAProxy, the widely used open-source reverse proxy and load balancer, could allow...
Security researcher Huyinhao has published a deep-dive analysis of CVE-2025-21701, a newly disclosed Linux kernel vulnerability rated...