The team behind Memos, the privacy-first, self-hosted knowledge base platform, has issued a security advisory for CVE-2024-21635,...
Vulnerability
Researchers recently disclosed a path-traversal vulnerability (CVE-2025-11001) in the open-source archiver 7-Zip that allows attackers to craft...
SAP has released its October 2025 Security Patch Day, addressing 13 new security notes and 3 updates...
Splunk has released a series of security advisories addressing six vulnerabilities in Splunk Enterprise and Splunk Cloud...
Nvidia has issued an important security update addressing multiple high-severity vulnerabilities in its open-source Megatron-LM project, a...
Two vulnerabilities were found in WordPress Core, affecting all versions up to and including 6.8.2. Both flaws...
VDE CERT has issued a security advisory disclosing two vulnerabilities in WAGO Device Sphere and WAGO Solution...
CISA this week added CVE-2025-10585, a high-severity type-confusion flaw in Google’s V8 JavaScript engine, to its Known...
Salesforce has published a security advisory detailing a high-severity flaw in its Salesforce-CLI installer (sf-x64.exe). The vulnerability,...
Researchers at Rapid7 have disclosed a critical permission bypass vulnerability in OnePlus OxygenOS, tracked as CVE-2025-10184. The...
DNN Software has issued a security advisory warning of a critical stored cross-site scripting (XSS) vulnerability in...
Google has released a Stable Channel Update for Desktop with builds 140.0.7339.207/.208 for Windows and Mac and...
SolarWinds has released a hotfix for its Web Help Desk (WHD) software after the discovery of a...
The CERT Coordination Center (CERT/CC) has issued a vulnerability note warning of a cross-site scripting (XSS) flaw...
Libraesva has released an urgent security advisory addressing a command injection vulnerability (CVE-2025-59689) in its Email Security...
A new study from a ZeroSalarium security researcher sheds light on a new technique to bypass endpoint...
Security researcher Ezzer17 published a clear, methodical write-up that walks through the root cause, the partial fixes,...
CVE-2025-55241: Microsoft Entra ID Flaw with CVSS 10.0 Could Have Compromised Every Tenant Worldwide
CVE-2025-55241: Microsoft Entra ID Flaw with CVSS 10.0 Could Have Compromised Every Tenant Worldwide
In one of the most significant discoveries of 2025, security researcher Dirk-jan Mollema revealed a vulnerability in...
Security researchers at ByteRay have published a detailed exploitation write-up of CVE-2025-9961, a vulnerability in TP-Link’s CWMP...
Nokia has published a security advisory warning customers of two high-severity vulnerabilities affecting its CloudBand Infrastructure Software...