Vulnerability

Kohler’s Encrypted Smart Toilet Camera Lacks True End-to-End Encryption

Kohler Health launched Dekoda in October 2025, a $600 device (plus a monthly subscription) that clips onto your toilet rim.…

5 months ago

Critical Elementor Security Breach Leaves WordPress Sites Open To Admin Takeovers

Attackers exploit a critical privilege escalation flaw in the King Addons for Elementor WordPress plugin, allowing unauthenticated users to create…

5 months ago

CISA Issues Warning About Iskra iHUB Authentication Flaw Allowing Remote Device Reconfiguration

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory warning of a high-severity authentication flaw in…

5 months ago

Flaw In Microsoft Azure API Management Allows Cross-Tenant Account Creation, Bypassing Admin Controls

A security flaw in Microsoft Azure API Management's Developer Portal allows attackers to register accounts across tenants, bypassing admin controls…

5 months ago

Google Addresses Android 0-Day Vulnerabilities Being Actively Exploited

Google released the Android Security Bulletin for December 2025 on December 1, with an update on December 4 the advisory…

5 months ago

PoC Exploit Now Public For Critical Microsoft Outlook “MonikerLink” RCE Vulnerability

A proof-of-concept (PoC) exploit for CVE-2024-21413, a critical remote code execution (RCE) flaw in Microsoft Outlook dubbed "MonikerLink," has been…

5 months ago

Vulnerability In Apache SkyWalking Exposes Users To Potential XSS Exploits

Apache SkyWalking, a popular open-source tool for application performance monitoring, faces a stored cross-site scripting vulnerability tracked as CVE-2025-54057. This…

5 months ago

Critical NVIDIA DGX Spark Flaws Allow Malicious Code Execution and Denial-of-Service Attacks

NVIDIA disclosed 14 vulnerabilities in its DGX Spark GB10 AI workstation on November 25, 2025, affecting all DGX OS versions…

5 months ago

Critical Microsoft Update Health Tools Vulnerability Allows Remote Arbitrary Code Execution

A flaw in Microsoft's Update Health Tools exposed Windows devices to remote code execution by exploiting abandoned Azure Blob Storage…

5 months ago

PoC Published for W3 Total Cache Flaw Putting 1M+ Websites At Risk Of Remote Code Execution

Security researchers released a proof-of-concept exploit for CVE-2025-9501, a critical unauthenticated remote code execution flaw in the W3 Total Cache…

5 months ago