A severe server-side request forgery (SSRF) vulnerability has been disclosed in BentoML, a widely used Python framework...
Vulnerability
Critical Flaw in Wix’s New AI Platform Base44 Allowed Unauthorized Access to Private Enterprise Apps
Critical Flaw in Wix’s New AI Platform Base44 Allowed Unauthorized Access to Private Enterprise Apps
In a significant finding that highlights the risks associated with emerging AI development platforms, Wiz Research has...
A critical-severity vulnerability in the popular Alone – Charity Multipurpose Non-profit WordPress Theme has left thousands of...
The CERT Coordination Center (CERT/CC) has issued a vulnerability note concerning a flaw in the TP-Link Archer...
BeyondTrust, a global leader in intelligent identity and access security, has issued two advisories addressing two local...
SonicWall, a prominent provider of cybersecurity solutions, has disclosed a critical vulnerability—CVE-2025-40600—affecting the SSL VPN interface of...
Google has announced a Stable Channel update for Chrome Desktop, pushing version 138.0.7204.183/.184 to users on Windows...
Microsoft Threat Intelligence has unveiled a critical macOS vulnerability that exploits Spotlight plugins to bypass the system’s...
ASUS has issued security updates to patch two vulnerabilities in its MyASUS software, a pre-installed utility application...
A newly discovered vulnerability in Python’s tarfile module, identified as CVE-2025-8194, threatens to hang applications that process...
A newly disclosed critical vulnerability in Node-SAML, a widely used SAML 2.0 authentication provider for Node.js, could...
Developers relying on CodeIgniter, one of the most widely adopted PHP full-stack web frameworks with over 2.9...
A critical command injection vulnerability has been disclosed in the widely used GitHub Action tj-actions/branch-names, affecting over...
Salesforce has released a security advisory addressing eight serious vulnerabilities affecting multiple versions of Tableau Server, the...
The CERT Coordination Center (CERT/CC) has issued a Vulnerability Note detailing a critical privilege escalation flaw affecting...
A critical vulnerability has been discovered in the popular open-source Node.js library Node-SAML, used to implement SAML...
NVIDIA has released software security updates for its GPU Display Drivers and vGPU software across Windows, Linux,...
Axios, the popular promise-based HTTP client for Node.js and browsers, has been found vulnerable through a critical...
High-Severity SQL Injection (CVE-2025-52914) in Mitel MiCollab Allows Data Access, Command Execution
High-Severity SQL Injection (CVE-2025-52914) in Mitel MiCollab Allows Data Access, Command Execution
Mitel has released a security advisory addressing a high-severity SQL injection vulnerability in its MiCollab platform—an issue...
A critical vulnerability in several Bitnami Helm charts has exposed sensitive Kubernetes secrets to unauthenticated web access,...
Mitel has issued a security advisory addressing a critical-severity vulnerability in the Provisioning Manager component of its...
Amazon Web Services (AWS) has released a security patch for a high-severity local privilege escalation vulnerability (CVE-2025-8069)...