Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Delta Electronics CNCSoft-G2 DOPSoft DPAX File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics CNCSoft-G2.

Read More
NewsSecurity Vulnerabilities

Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities (CVE-2025-20354 and CVE-2025-20358)

– Multiple vulnerabilities in the Java Remote Method Invocation (RMI) process of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to upload arbitrary files, bypass authentication, execute arbitrary commands, and elevate privileges to root.

Read More
NewsSecurity Vulnerabilities

Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability

– Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions.

Read More
NewsSecurity Vulnerabilities

Heimdall Data Database Proxy Cross-Site Scripting Remote Code Execution Vulnerability (CVE-2025-12486)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy.

Read More
NewsSecurity Vulnerabilities

evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability (CVE-2025-12489)

– This vulnerability allows local attackers to escalate privileges on affected installations of evernote-mcp-server.

Read More
NewsSecurity Vulnerabilities

Krita TGA File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2025-59820)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Krita.

Read More
NewsSecurity Vulnerabilities

Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability (CVE-2025-62591)

– This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox.

Read More
NewsSecurity Vulnerabilities

Oracle VirtualBox Virtio-net Uninitialized Memory Information Disclosure Vulnerability (CVE-2025-61759)

– This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox.

Read More
NewsSecurity Vulnerabilities

Microsoft issues emergency Windows Server updates to patch WSUS vulnerability with proof-of-concept exploit

– Microsoft has issued out-of-band (OOB) security updates to address a critical vulnerability in Windows Server Update Services (WSUS), following the release of publicly available proof-of-concept (PoC) exploit code.

Read More
NewsSecurity Vulnerabilities

Critical Vulnerabilities in Veeam Backup

– On October 14th 2025, Veeam released a security advisory addressing multiple vulnerabilities including 2 critical in its Veeam Backup product.

Read More