Friday, April 24, 2026
HomeTagsVulnerability

Tag: Vulnerability

Critical Flaw In Apache bRPC Framework Allows Remote Server Crash Exploits

Apache bRPC versions before 1.15.0 are vulnerable to a critical remote denial-of-service flaw that allows attackers to crash servers by exploiting uncontrolled recursion in the json2pb component. The vulnerability, tracked as CVE-2025-59789 and discovered by Tyler Zars, affects all platforms running vulnerable versions of...

PoC Exploit Now Public For Critical Microsoft Outlook “MonikerLink” RCE Vulnerability

A proof-of-concept (PoC) exploit for CVE-2024-21413, a critical remote code execution (RCE) flaw in Microsoft Outlook dubbed "MonikerLink," has been released publicly on GitHub, enabling researchers to test the vulnerability in controlled lab environments. This zero-click issue, with a CVSS v3.1 score of 9.8...

Vulnerability In Apache SkyWalking Exposes Users To Potential XSS Exploits

Apache SkyWalking, a popular open-source tool for application performance monitoring, faces a stored cross-site scripting vulnerability tracked as CVE-2025-54057. This flaw affects versions up to 10.2.0 and allows attackers to inject malicious scripts into web interfaces, potentially compromising user sessions and data. The Apache...

Critical NVIDIA DGX Spark Flaws Allow Malicious Code Execution and Denial-of-Service Attacks

NVIDIA disclosed 14 vulnerabilities in its DGX Spark GB10 AI workstation on November 25, 2025, affecting all DGX OS versions before OTA0. These flaws, mainly in the SROOT firmware and hardware resources, enable local attackers with privileged access to bypass protections, leading to remote...

Vulnerability In Angular HTTP Client Allows XSRF Token Exposure To Malicious Domains

A serious flaw in Angular's HTTP Client exposes users' XSRF tokens to attacker-controlled sites, enabling CSRF attacks that bypass built-in protections. Tracked as CVE-2025-66035 with a CVSS score of 7.5 (High severity), this issue affects the @angular/standard package. It stems from the mishandling of...

Critical Unauthenticated DoS Bug Can Take Down Next.js Servers Using Just One HTTP Request

A serious denial-of-service (DoS) flaw in Next.js lets attackers crash self-hosted servers with a single HTTP request, using almost no resources on their end. Security firm Harmony Intelligence found the issue while testing an AI tool, and it affects versions up to 15.5.4.​ Next.js powers...