A newly disclosed vulnerability in the Linux kernel’s KSMBD subsystem has been assigned CVE-2025-38501, allowing remote attackers...
Vulnerability
The Spring team has disclosed two related vulnerabilities—CVE-2025-41248 and CVE-2025-41249—that affect Spring Security and the Spring Framework....
In a recent deep-dive analysis, security researcher BitsByWill examined two critical Linux kernel vulnerabilities—CVE-2023-52440 and CVE-2023-4130—both impacting...
Samsung has released security updates to patch a critical zero-day vulnerability actively exploited against Android devices. Tracked...
The open-source generative AI development platform FlowiseAI, widely used for building AI agents and LLM workflows, has...
The Taiwan Computer Emergency Response Team (TWCERT/CC) has issued a vulnerability note warning of two critical security...
The rise of large language model (LLM) applications has made frameworks like LangChain and its ports foundational...
Security researchers at ETH Zurich have published a study revealing how attackers can break through virtualization boundaries...
OpenPrinting has released patches addressing two significant security flaws in the Common Unix Printing System (CUPS), a...
The Axios project has released a security advisory for a newly discovered vulnerability affecting its popular promise-based...
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw in Dassault Systèmes DELMIA Apriso...
The PyInstaller project has released fixes for a local privilege escalation vulnerability that affected applications packaged with...
The Angular team has issued a security advisory addressing a high-severity flaw in server-side rendering (SSR) that...
The CERT Coordination Center (CERT/CC) has issued a vulnerability note warning of two critical local security flaws...
The Internet Systems Consortium (ISC) has issued a security advisory addressing a high-severity flaw in Stork UI,...
The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has issued an alert on the active...
The CoreDNS project has disclosed a vulnerability in its etcd plugin, tracked as CVE-2025-58063 (CVSS 7.1), which...
NVIDIA has released a software update for its NVDebug tool, addressing three high-severity vulnerabilities (CVE-2025-23342, CVE-2025-23343, and...
GitLab has released new versions of its Community and Enterprise Editions to address several security vulnerabilities, including...
The Django Software Foundation has patched a high-severity SQL injection vulnerability in Django’s FilteredRelation feature. Tracked as...
Sophos has released a fix for a critical authentication bypass vulnerability (CVE-2025-10159) affecting its AP6 Series Wireless...
Microsoft’s September 2025 Patch Tuesday addresses 86 vulnerabilities across its product ecosystem, including two zero-days and nine...