Monday, April 27, 2026
HomeVulnerabilities

Vulnerabilities

Critical Grafana Vulnerabilities Allow Malicious Redirects and Arbitrary Code Execution

Grafana Labs has released critical security patches addressing two significant vulnerabilities that could allow attackers to redirect users to malicious websites and execute arbitrary JavaScript code. The company issued fixes for CVE-2025-6023 (high severity) and CVE-2025-6197 (medium severity) across multiple versions of the popular...

CISA Publishes 13 ICS Security Alerts on Vulnerabilities and Exploits

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a comprehensive set of Industrial Control Systems (ICS) advisories on July 17, 2025, addressing critical security vulnerabilities across multiple vendor platforms. These advisories represent a significant effort to protect critical infrastructure by providing timely information...

New BIND 9 Vulnerabilities Put Organizations at Risk of Cache Poisoning and DoS Attacks

Two critical vulnerabilities in BIND 9, one of the most widely deployed DNS server software solutions globally. Released on July 16, 2025, these security vulnerabilities pose significant risks to organizations running affected versions, potentially exposing them to cache poisoning attacks and denial-of-service incidents...

NVIDIA Container Toolkit Vulnerabilities Enables Attackers to Run Code with Elevated Privileges

NVIDIA has released critical security updates for its Container Toolkit and GPU Operator following the discovery of two high-severity vulnerabilities that could allow attackers to execute arbitrary code with elevated permissions and cause system disruption. The vulnerabilities, tracked as CVE-2025-23266 and CVE-2025-23267, affect all...

Samsung WLAN AP Vulnerabilities Enable Remote Root Command Execution

A critical vulnerabilities in Samsung's WEA453e WLAN Access Point in August 2020, revealing a chain of exploits that culminate in unauthenticated remote code execution with root privileges. The vulnerabilities represent a significant security risk, allowing attackers to completely compromise affected devices without requiring valid...

Oracle Addresses 309 Security Vulnerabilities in Latest Critical Patch Update

Oracle has released its quarterly Critical Patch Update (CPU) for July 2025, addressing a substantial 309 security vulnerabilities across its comprehensive product portfolio. This release represents one of the most significant security updates from Oracle, spanning database systems, middleware, enterprise applications, and cloud native...