Vulnerability

OpenAI Codex CLI Command Injection Flaw Allows Arbitrary Command Execution

OpenAI Codex CLI serves developers by integrating AI reasoning into terminal workflows. This tool reads, edits, and runs code via…

5 months ago

Qualcomm Discloses Critical Vulnerabilities Affecting Secure Boot Mechanisms

Qualcomm Technologies released its December 2025 Security Bulletin on December 1, 2025, revealing multiple high-severity flaws in proprietary and open-source…

5 months ago

Severe WatchGuard Firebox Vulnerabilities Enable Attackers To Bypass Integrity Checks and Inject Malicious Code

WatchGuard disclosed multiple high-severity vulnerabilities in Firebox appliances on December 4, 2025, including flaws that let privileged attackers execute arbitrary…

5 months ago

SQL Injection Vulnerability In Devolutions Server Enables Data Exfiltration Attacks

Devolutions Server, a platform for secure remote connection management, faces serious security risks from multiple flaws disclosed in advisory DEVO-2025-0018…

5 months ago

Massive OAST Exploit Unleashes Attacks Across 200 CVEs Using Google Cloud Infrastructure

Security researchers at VulnCheck have uncovered a sophisticated exploit campaign leveraging a private out-of-band application security testing (OAST) service hosted…

5 months ago

Linux 6.18 Released With Improved Hardware Support, Updated Drivers, and File System Enhancements

Linus Torvalds released Linux kernel 6.18 on November 30, 2025, after addressing last-minute driver bugs in areas like Bluetooth, Ceph,…

5 months ago

Critical Flaw In Apache bRPC Framework Allows Remote Server Crash Exploits

Apache bRPC versions before 1.15.0 are vulnerable to a critical remote denial-of-service flaw that allows attackers to crash servers by…

5 months ago

PoC Exploit Now Public For Critical Microsoft Outlook “MonikerLink” RCE Vulnerability

A proof-of-concept (PoC) exploit for CVE-2024-21413, a critical remote code execution (RCE) flaw in Microsoft Outlook dubbed "MonikerLink," has been…

5 months ago

Vulnerability In Apache SkyWalking Exposes Users To Potential XSS Exploits

Apache SkyWalking, a popular open-source tool for application performance monitoring, faces a stored cross-site scripting vulnerability tracked as CVE-2025-54057. This…

5 months ago

Critical NVIDIA DGX Spark Flaws Allow Malicious Code Execution and Denial-of-Service Attacks

NVIDIA disclosed 14 vulnerabilities in its DGX Spark GB10 AI workstation on November 25, 2025, affecting all DGX OS versions…

5 months ago