A pair of critical security vulnerabilities has been disclosed in the Ruby SAML library, a foundational tool...
Authentication Bypass
A severe security vulnerability has been uncovered in Cal.com, the popular open-source scheduling platform positioned as the...
A critical security vulnerability has been identified in Step CA, a popular online Certificate Authority tool used...
CISA Warns: Critical Iskra iHUB Flaw (CVE-2025-13510) Allows Unauthenticated Smart Metering Takeover
CISA Warns: Critical Iskra iHUB Flaw (CVE-2025-13510) Allows Unauthenticated Smart Metering Takeover
A critical security vacuum has been discovered in smart metering infrastructure, potentially leaving utility networks exposed to...
GitLab has released an important security update today affecting both its Community Edition (CE) and Enterprise Edition...
ASUS has released an urgent security update to address a sweeping list of eight potential vulnerabilities in...
HashiCorp has released an important security advisory addressing a misconfiguration flaw in the Vault Terraform Provider that...
A newly disclosed vulnerability in R.V.R Elettronica’s TEX broadcast hardware has been assigned CVE-2025-63207, scoring 9.8 Critical...
ABB has issued an urgent cybersecurity advisory warning customers of a critical authentication bypass vulnerability in the...
METZ CONNECT GmbH, in coordination with CERT@VDE, has issued an urgent security advisory warning of multiple critical...
Critical Flowise Flaw Allows Unauthenticated Remote Admin Takeover via Exposed Registration Endpoint
Critical Flowise Flaw Allows Unauthenticated Remote Admin Takeover via Exposed Registration Endpoint
The team behind Flowise—a popular open-source platform for building AI agents and LLM workflows—has issued an urgent...
Cybersecurity firms are sounding the alarm over a critical vulnerability in Fortinet FortiWeb, the company’s Web Application...
Milvus, a leading open-source vector database that powers AI and large-scale search applications, has disclosed a critical...
Researchers at Mandiant Threat Defense, part of Google Cloud Security Operations, have revealed that a critical unauthenticated...
Devolutions, a leading provider of privileged access management (PAM) and remote connection solutions, has released an urgent...
GE Vernova’s Electrification Software division has released a critical security advisory addressing a high-severity authentication vulnerability (CVE-2025-3222)...
Cisco has released urgent security updates to address two critical vulnerabilities in its Unified Contact Center Express...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory warning about a critical vulnerability affecting...
Researchers at Wordfence have disclosed a critical vulnerability (CVE-2025-11749, CVSS 9.8) in the popular AI Engine WordPress...
An extremely severe security vulnerability has been discovered and is being actively exploited in the Jobmonster –...