Vulnerability

Tenda N300 Vulnerabilities Allow Remote Attackers To Execute Commands As Root

Remote attackers can seize complete control of popular Tenda routers through serious command injection flaws, security researchers warn. Affecting the…

5 months ago

Critical Azure Bastion Flaw Enables Authentication Bypass and Privilege Escalation

Microsoft patched a severe flaw in Azure Bastion on November 20, 2025, tracked as CVE-2025-49752, that allows attackers to bypass…

5 months ago

Severe Grafana Flaw Allows Attackers To Gain Elevated Privileges

Grafana released emergency patches for a critical SCIM vulnerability (CVE-2025-41115) that allows attackers to escalate privileges or impersonate admins in…

5 months ago

Severe Windows Graphics Flaw Allows Full System Takeover via A Single Image

Zscaler ThreatLabz uncovered CVE-2025-50165 in May 2025, a critical remote code execution flaw in the Windows Graphics Component with a…

5 months ago

Milvus Proxy Vulnerability Enables Forged Headers and Full Authorization Circumvention

A critical authentication bypass flaw in Milvus Proxy (CVE-2025-64513) allows attackers to bypass all security checks. Discovered by the HelixGuard…

5 months ago

Severe Vulnerabilities In N-able N-central Enable Unauthorized Legacy API Access and Sensitive File Disclosure

N-able N-central, a popular remote monitoring and management (RMM) platform used by enterprises and managed service providers (MSPs), faces severe…

5 months ago

Critical Twonky Server Vulnerabilities Expose Authentication Bypass Path

Twonky Server version 8.5.2 contains two serious flaws that allow attackers to bypass authentication and steal admin credentials on Linux…

5 months ago

Ollama Parsing Vulnerabilities Could Let Attackers Execute Arbitrary Code Through Crafted Model Files

Ollama versions before 0.7.0 contain parsing flaws that allow attackers to execute arbitrary code by loading a crafted GGUF model…

5 months ago

Active Exploitation Detected for 7-Zip Remote Code Execution Vulnerability

A critical vulnerability in 7-Zip, tracked as CVE-2025-11001, has raised alarms in the cybersecurity community due to its potential for…

5 months ago

Hackers Can Leverage Default ServiceNow AI Assistant Settings To Carry Out Prompt Injection Attacks

Earlier this year, cybersecurity researcher Aaron Costello uncovered a critical flaw in ServiceNow's Now Assist AI platform that enables hackers…

5 months ago