Vulnerability

Persistent XSS Vulnerability in IPFire Web Interface via Authenticated Administrator

In a critical security advisory, researchers have disclosed a stored cross-site scripting (XSS) vulnerability in IPFire 2.29’s web-based firewall interface…

8 months ago

Critical 0-Day RCE Vulnerability in Citrix NetScaler ADC & Gateway Under Active Exploitation

A critical security bulletin warning that attackers are actively exploiting a zero-day remote code execution vulnerability in NetScaler ADC and…

8 months ago

PhpSpreadsheet Library Vulnerability Allows Injection of Malicious HTML

A critical Server-Side Request Forgery (SSRF) vulnerability has been discovered in the popular PHP library PhpSpreadsheet, allowing attackers to inject…

8 months ago

Apple 0-Day RCE Vulnerability: PoC Exploit and Analysis Released

A detailed proof-of-concept exploit and vulnerability analysis for CVE-2025-43300, a critical zero-click remote code execution vulnerability affecting Apple devices. The…

8 months ago

New QUIC-LEAK Vulnerability Exposes Servers to Memory Exhaustion and Denial-of-Service

A critical vulnerability in the widely-used LSQUIC QUIC implementation that allows attackers to crash servers through memory exhaustion before any…

8 months ago

Copilot Vulnerability Exposes Audit Logs and Grants Secret Access to Attackers

A critical security vulnerability in Microsoft's M365 Copilot allowed users to access sensitive files without generating audit log entries, effectively…

8 months ago

Lenovo AI Chatbot Vulnerability Allows Attackers to Execute Remote Scripts on Corporate Machines

A critical security vulnerability in Lenovo's AI-powered chatbot "Lena" has exposed the company's corporate systems to potential cyberattacks, allowing malicious…

8 months ago

Linux Kernel Netfilter Vulnerability Allows Attackers to Gain Elevated Privileges

A critical security vulnerability in the Linux kernel's netfilter ipset subsystem has been disclosed, allowing attackers to achieve privilege escalation…

8 months ago

FortiWeb Vulnerability Enables Attackers to Impersonate Any User

Fortinet has disclosed a critical authentication bypass vulnerability in its FortiWeb web application firewall that allows unauthenticated attackers to log…

9 months ago

Critical FortiSIEM Vulnerability Exploited in the Wild: PoC Enables Remote Command Execution

Fortinet has issued an urgent security advisory for a critical vulnerability in FortiSIEM that allows unauthenticated attackers to execute arbitrary…

9 months ago