A newly disclosed vulnerability in the Spirit Framework plugin for WordPress has put thousands of websites at...
Authentication Bypass
The Termix project has disclosed a critical authentication bypass vulnerability in its official Docker image, exposing sensitive...
The Apache Software Foundation has published a new security advisory disclosing three vulnerabilities in Apache Kylin, a...
The Formbricks project, an open-source platform for building in-app and website surveys, has released an urgent patch...
Nokia has published a security advisory warning customers of two high-severity vulnerabilities affecting its CloudBand Infrastructure Software...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a new security advisory warning about two serious...
Hackers are exploiting a critical authentication bypass vulnerability in the Case Theme User plugin, a WordPress plugin...
OpenPrinting has released patches addressing two significant security flaws in the Common Unix Printing System (CUPS), a...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a security advisory about a critical flaw in...
Sophos has released a fix for a critical authentication bypass vulnerability (CVE-2025-10159) affecting its AP6 Series Wireless...
Siemens has disclosed a critical security vulnerability (CVE-2025-40804) in its SIMATIC Virtualization as a Service (SIVaaS) platform....
Siemens has disclosed multiple vulnerabilities in its User Management Component (UMC), which is used in products like...
ABB has issued a cybersecurity advisory disclosing multiple vulnerabilities affecting its ASPECT Building Management System (BMS), including...
The ESPHome project, a popular open-source firmware framework for ESP32- and ESP8266-based smart home devices, has disclosed...
watchTowr Labs has released a detailed analysis of CVE-2025-54309, a zero-day authentication bypass vulnerability in CrushFTP, the...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-severity alert for a missing authentication...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a security advisory warning about a critical authentication...
Dell Technologies has released an urgent security advisory addressing multiple vulnerabilities affecting its PowerProtect Data Domain Operating...
SUSE has issued a high-severity security advisory for CVE-2025-46811, a critical vulnerability in SUSE Manager that allows...
A critical vulnerability in the popular OAuth2-Proxy open-source authentication tool has been discovered, allowing attackers to bypass...
Critical Flaw in Wix’s New AI Platform Base44 Allowed Unauthorized Access to Private Enterprise Apps
Critical Flaw in Wix’s New AI Platform Base44 Allowed Unauthorized Access to Private Enterprise Apps
In a significant finding that highlights the risks associated with emerging AI development platforms, Wiz Research has...
A newly disclosed critical vulnerability in Node-SAML, a widely used SAML 2.0 authentication provider for Node.js, could...