Vulnerability

Critical Elementor Security Breach Leaves WordPress Sites Open To Admin Takeovers

Attackers exploit a critical privilege escalation flaw in the King Addons for Elementor WordPress plugin, allowing unauthenticated users to create…

5 months ago

Angular Platform Flaw Enables Malicious Code Execution Through Weaponized SVG Animations

Security researchers have uncovered a stored cross-site scripting (XSS) vulnerability in Angular's Template Compiler that lets attackers inject and execute…

5 months ago

CISA Issues Warning About Iskra iHUB Authentication Flaw Allowing Remote Device Reconfiguration

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory warning of a high-severity authentication flaw in…

5 months ago

Multiple Vulnerabilities In Django Facilitate SQL Injection and Denial-of-Service Attacks

The Django project released security patches on December 2, 2025, addressing two vulnerabilities in versions 5.2.9, 5.1.15, and 4.2.27. Posted…

5 months ago

Chrome 143 Released With Patch For 13 Vulnerabilities Allowing Arbitrary Code Execution

Google has rolled out Chrome 143 to the stable channel for Windows, Mac, and Linux, addressing 13 security vulnerabilities in…

5 months ago

nopCommerce Vulnerability Lets Attackers Access Application Using Captured Cookie

A critical flaw in the popular open-source eCommerce platform nopCommerce exposes users to session hijacking attacks. Security researchers at CERT…

5 months ago

Flaw In Microsoft Azure API Management Allows Cross-Tenant Account Creation, Bypassing Admin Controls

A security flaw in Microsoft Azure API Management's Developer Portal allows attackers to register accounts across tenants, bypassing admin controls…

5 months ago

OpenVPN Vulnerabilities Allow Hackers To Trigger DDoS Attacks and Bypass Security Measures

OpenVPN, a popular open-source VPN solution, has patched multiple flaws in its recent releases that expose users to denial-of-service (DoS)…

5 months ago

Google Addresses Android 0-Day Vulnerabilities Being Actively Exploited

Google released the Android Security Bulletin for December 2025 on December 1, with an update on December 4 the advisory…

5 months ago

Critical Apache Struts Vulnerability Lets Hackers Overwhelm System Storage

A new denial-of-service vulnerability in Apache Struts exposes web applications to disk exhaustion attacks, in which hackers flood servers with…

5 months ago