Socket’s Threat Research Team has uncovered two malicious npm packages—naya-flore and nvlore-hsc—designed to target developers building WhatsApp...
Remote Code Execution
Security researcher Juan Jose Lopez Jaimez published the technical details and proof-of-concept exploit code for a vulnerability...
A critical vulnerability—CVE-2025-54594 (CVSS 9.1)—has been identified in the React Native Bottom Tabs project, exposing the repository...
Adobe has released urgent patches for two critical vulnerabilities affecting Adobe Experience Manager (AEM) Forms on JEE,...
Rockwell Automation has issued a security advisory addressing three memory abuse vulnerabilities in its Arena Simulation software,...
Trend Micro has issued an urgent advisory for two critical command injection vulnerabilities affecting its Apex One...
Google has released the August 2025 Android Security Bulletin, addressing multiple critical and high-severity vulnerabilities affecting Android...
NVIDIA has released urgent software updates to address a set of critical vulnerabilities discovered in its popular...
A critical vulnerability has been uncovered in the @nestjs/devtools-integration package—a component of the popular NestJS framework for...
Cursor, an AI-powered code editor that promises to “understand your codebase and help you code faster,” has...
The Squid Project has issued an urgent advisory for CVE-2025-54574 (CVSS 9.3), a heap buffer overflow bug...
In a recently disclosed advisory, HashiCorp has patched a critical vulnerability—CVE-2025-6000—in Vault, its industry-standard secrets management solution....
SUSE has issued a high-severity security advisory for CVE-2025-46811, a critical vulnerability in SUSE Manager that allows...
A critical-severity vulnerability in the popular Alone – Charity Multipurpose Non-profit WordPress Theme has left thousands of...
A critical command injection vulnerability has been disclosed in the widely used GitHub Action tj-actions/branch-names, affecting over...
Salesforce has released a security advisory addressing eight serious vulnerabilities affecting multiple versions of Tableau Server, the...
The lightweight JavaScript utility library is is a widely popular project on the NPM platform, boasting over...
SonicWall has released a security updates for its Secure Mobile Access (SMA) 100 series appliances, addressing three...
Dahua Technology has issued a security advisory addressing two high-severity vulnerabilities in its IP camera product line,...
Samsung’s widely used MagicINFO 9 Server, a digital signage management platform, was found multi security vulnerabilities. Security...