Vulnerability

Vulnerability In Angular HTTP Client Allows XSRF Token Exposure To Malicious Domains

A serious flaw in Angular's HTTP Client exposes users' XSRF tokens to attacker-controlled sites, enabling CSRF attacks that bypass built-in…

5 months ago

Critical Unauthenticated DoS Bug Can Take Down Next.js Servers Using Just One HTTP Request

A serious denial-of-service (DoS) flaw in Next.js lets attackers crash self-hosted servers with a single HTTP request, using almost no…

5 months ago

Apache Syncope Flaw Lets Attackers Dump Internal Database Contents

Security teams using Apache Syncope face a new risk. A flaw in this open-source identity management tool allows attackers to…

5 months ago

Critical Microsoft Update Health Tools Vulnerability Allows Remote Arbitrary Code Execution

A flaw in Microsoft's Update Health Tools exposed Windows devices to remote code execution by exploiting abandoned Azure Blob Storage…

5 months ago

HashiCorp Vault Flaw Enables Credential-Free Authentication Bypass

HashiCorp has disclosed a security flaw in its Vault Terraform Provider that allows attackers to bypass valid credentials and log…

5 months ago

NVIDIA Isaac-GROOT Robotics Platform Flaw Allows Malicious Code Injection

NVIDIA has patched serious security flaws in its Isaac-GR00T platform, a key tool for building AI-powered humanoid robots. Released on…

5 months ago

PoC Published for W3 Total Cache Flaw Putting 1M+ Websites At Risk Of Remote Code Execution

Security researchers released a proof-of-concept exploit for CVE-2025-9501, a critical unauthenticated remote code execution flaw in the W3 Total Cache…

5 months ago

Tenda N300 Vulnerabilities Allow Remote Attackers To Execute Commands As Root

Remote attackers can seize complete control of popular Tenda routers through serious command injection flaws, security researchers warn. Affecting the…

5 months ago

Remote Code Execution Enabled By Malicious Payloads Through vLLM Vulnerability

A serious flaw in the popular vLLM library could let attackers crash servers or even run malicious code remotely. Security…

5 months ago

Wireshark 4.6.1 Addresses Multiple Vulnerabilities That Could Cause Application Crashes

Wireshark, the leading open-source network protocol analyzer, released version 4.6.1 on November 19, 2025, to fix two security flaws in…

5 months ago