Friday, November 14, 2025
HomeVulnerabilities

Vulnerabilities

CISA Alerts On Exploited WatchGuard Firebox Out-of-Bounds Write Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in WatchGuard Firebox firewalls to its Known Exploited Vulnerabilities (KEV) catalog, highlighting active exploitation in the wild. Tracked as CVE-2025-9242, this out-of-bounds write flaw in the Fireware OS ike process enables...

Citrix NetScaler ADC and Gateway Vulnerability Exposes Systems To Cross-Site Scripting Attacks

In a recent security bulletin, Cloud Software Group (formerly Citrix) disclosed a medium-severity vulnerability affecting NetScaler ADC and NetScaler Gateway products. Identified as CVE-2025-12101, this cross-site scripting (XSS) flaw could allow attackers to inject malicious scripts into web pages viewed by users, potentially leading...

CISA Alerts on Active Exploitation of Citrix Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on August 25, 2025, highlighting active exploitation of critical vulnerabilities affecting Citrix Session Recording and Git systems. The additions include CVE-2024-8069 and CVE-2024-8068 in Citrix...

Critical Mozilla Vulnerabilities Allow Remote Code Execution

Mozilla released Firefox 142 on August 19, 2025, addressing multiple critical security vulnerabilities that could enable remote code execution and sandbox escape attacks. The security update patches nine CVEs, with three classified as high-severity vulnerabilities that could allow attackers to execute arbitrary code on...

ShinyHunters Hackers Allegedly Release New Exploit for SAP 0-Day Vulnerabilities

Cybersecurity researchers and organizations worldwide were alerted to the public release of a weaponized exploit targeting critical SAP vulnerabilities, marking a significant escalation in threats against enterprise SAP environments. The exploit, which combines two previously zero-day vulnerabilities in SAP NetWeaver Visual Composer, represents a...

Critical PostgreSQL Vulnerabilities Allow Remote Code Execution During Restoration

The PostgreSQL Global Development Group has released urgent security updates on August 14, 2025, addressing three critical vulnerabilities that affect all supported versions of the world's most advanced open-source relational database. The update covers PostgreSQL versions 17.6, 16.10, 15.14, 14.19, and 13.22, along with...