Six Apart Ltd. has issued an urgent security advisory for Movable Type, a long-standing content management system...
rce
Welcome to this week’s vulnerability digest. As we close out the first full week of April, security...
A critical security vulnerability in Axios, the ubiquitous promise-based HTTP client for Node.js and the browser, has...
Security researchers have unmasked three critical vulnerabilities in goshs, a popular high-performance replacement for Python’s SimpleHTTPServer. The...
Everest Forms, a popular WordPress plugin trusted by over 100,000 websites for building everything from simple contact...
Flatpak, the widely-used system for building, distributing, and running sandboxed desktop applications on Linux, has been hit...
A technical analysis from the Microsoft Defender Security Research Team has revealed that threat actors are increasingly...
The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical code injection vulnerability in Ivanti...
In the world of secure software development, sandboxing is the ultimate safety net—a controlled environment designed to...
A critical security vulnerability, tracked as CVE-2026-22679, has been identified in Weaver (Fanwei) E-cology 10.0, one of...
A critical security vulnerability, tracked as CVE-2021-4473, has been identified in the Tianxin Internet Behavior Management System....
A highly-sophisticated zero-day exploit has been discovered targeting Adobe Reader users, allowing attackers to steal local files...
Budibase, the popular open-source low-code platform used by engineers to rapidly build internal tools, has released urgent...
A critical security vulnerability has been unmasked in Kestra, the popular open-source, event-driven orchestration platform. The flaw,...
In a major alert for the WordPress community, a critical security flaw has been disclosed in the...
In a significant discovery for enterprises and public sector organizations, a critical security vulnerability has been unmasked...
In a significant alert for the industrial automation sector, CERT@VDE has disclosed a series of high-severity vulnerabilities...
A severe security failure has been unearthed in Control Web Panel (CWP)—formerly known as CentOS Web Panel—that...
As organizations race to integrate autonomous systems into their workflows, a new and subtle threat is emerging...