The Astro project has disclosed a high-severity vulnerability in its Cloudflare adapter, tracked as CVE-2025-58179 (CVSS 7.2)....
ssrf
A newly disclosed security flaw, tracked as CVE-2025-54370, has been identified in PhpSpreadsheet, a PHP-based library that...
Xerox has released a security update for FreeFlow Core, addressing two high-impact vulnerabilities that could allow attackers...
A severe server-side request forgery (SSRF) vulnerability has been disclosed in BentoML, a widely used Python framework...
Salesforce has released a security advisory addressing eight serious vulnerabilities affecting multiple versions of Tableau Server, the...
Samsung’s widely used MagicINFO 9 Server, a digital signage management platform, was found multi security vulnerabilities. Security...
A newly disclosed critical vulnerability in Manager.io, a free accounting software used by businesses across Australia and...
The Apache Software Foundation has issued a new release—Apache HTTP Server version 2.4.64—patching eight security vulnerabilities that...
Schneider Electric has issued a high-severity security advisory disclosing multiple vulnerabilities affecting its flagship infrastructure management platform,...
JPCERT/CC has issued a warning about two serious vulnerabilities in the Nimesa Backup and Recovery solution, a...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a risk advisory on three newly discovered vulnerabilities...
Elastic has published a security advisory addressing two significant vulnerabilities in Kibana, the visualization and dashboarding layer...
A Server-Side Request Forgery (SSRF) vulnerability has been discovered in the @opennextjs/cloudflare package, potentially allowing unauthenticated users...
The Apache Kafka Project has released security advisories addressing three important vulnerabilities affecting various versions of the...
Esri has issued a critical security patch for its widely used Portal for ArcGIS software, addressing a...
A critical XML External Entity (XXE) injection vulnerability has been identified in WebDriverManager, an essential Java library...
A newly disclosed Server-Side Request Forgery (SSRF) vulnerability in SonicWall’s SMA1000 series appliances could allow remote attackers...
JPCERT/CC has issued a vulnerability note disclosing multiple security flaws in a-blog cms, a popular content management...
Microsoft has addressed a cluster of critical vulnerabilities affecting several of its core cloud services—including Azure Automation,...
SonicWall’s Product Security Incident Response Team (PSIRT) has issued an important update for its SMA1000 series appliances...
CrushFTP, a popular file transfer server, is facing increased scrutiny following the discovery of two significant security...
LNbits, the modular and extendable Lightning Network wallet server, has patched a critical Server-Side Request Forgery (SSRF)...