A new flaw has appeared in the foundation of one of the web’s most popular Java frameworks....
ssrf
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting the widely used OSGeo...
The security team behind ZITADEL, the open-source identity management platform, has issued urgent advisories regarding three high-severity...
The Apache Software Foundation has rolled out a crucial update for the ubiquitous Apache HTTP Server, addressing...
The maintainers of GeoServer have issued an important security advisory regarding a high-severity vulnerability that could allow...
Elastic has issued two security advisories addressing two vulnerabilities in Kibana, the visualization and analytics dashboard component...
Zimbra has released an emergency security patch (version 10.1.12) to address a critical Server-Side Request Forgery (SSRF)...
Elastic has issued five security advisories addressing five vulnerabilities affecting its Kibana and Elasticsearch components, including three...
Splunk has released a series of security advisories addressing six vulnerabilities in Splunk Enterprise and Splunk Cloud...
The Apache Software Foundation has published a new security advisory disclosing three vulnerabilities in Apache Kylin, a...
The Astro project has disclosed a high-severity vulnerability in its Cloudflare adapter, tracked as CVE-2025-58179 (CVSS 7.2)....
A newly disclosed security flaw, tracked as CVE-2025-54370, has been identified in PhpSpreadsheet, a PHP-based library that...
Xerox has released a security update for FreeFlow Core, addressing two high-impact vulnerabilities that could allow attackers...
A severe server-side request forgery (SSRF) vulnerability has been disclosed in BentoML, a widely used Python framework...
Salesforce has released a security advisory addressing eight serious vulnerabilities affecting multiple versions of Tableau Server, the...
Samsung’s widely used MagicINFO 9 Server, a digital signage management platform, was found multi security vulnerabilities. Security...
A newly disclosed critical vulnerability in Manager.io, a free accounting software used by businesses across Australia and...
The Apache Software Foundation has issued a new release—Apache HTTP Server version 2.4.64—patching eight security vulnerabilities that...
Schneider Electric has issued a high-severity security advisory disclosing multiple vulnerabilities affecting its flagship infrastructure management platform,...
JPCERT/CC has issued a warning about two serious vulnerabilities in the Nimesa Backup and Recovery solution, a...