Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Path traversal vulnerability in Commvault Command Center Innovation Release (CVE-2025-34028)

A critical security vulnerability has been identified in the Commvault Command Center installation, allowing remote attackers to execute arbitrary code without authentication. 

Read More
NewsSecurity Vulnerabilities

SAP NetWeaver Visual Composer Metadata Uploader High Risk Vulnerability (CVE-2025-31324)

This vulnerability affects the platform’s visual composer, it lets a remote and unauthenticated attacker upload malicious files directly to the system without authorisation.

Read More
NewsSecurity Vulnerabilities

SonicWALL Connect Tunnel Link Following Denial-of-Service Vulnerability (CVE-2025-32817)

CVE-2025-32817 – This vulnerability allows local attackers to create a denial-of-service condition on affected installations of SonicWALL Connect Tunnel.

Read More
NewsSecurity Vulnerabilities

Unauthenticated Remote Code Execution in Erlang/OTP SSH (CVE-2025-32433)

A serious vulnerability (CVE-2025-32433) has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE).

Read More
NewsSecurity Vulnerabilities

Multiple Cisco Products Unauthenticated Remote Code Execution in Erlang/OTP SSH Server (CVE-2025-32433)

On April 16th 2025, a critical vulnerability in the Erlang/OTP SSH server was disclosed. This vulnerability could allow an unauthenticated, remote attacker to perform remote code execution (RCE) on an affected device.

Read More
NewsSecurity Vulnerabilities

Cisco Webex App Client-Side Remote Code Execution Vulnerability (CVE-2025-20236)

A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user.

Read More
NewsSecurity Vulnerabilities

SonicWall Authenticated SMA100 Arbitrary Command Injection Vulnerability Is Been Exploited (CVE-2021-20035)

CVE number – CVE-2021-20035 Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to

Read More
NewsSecurity Vulnerabilities

Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability (CVE-2025-24054)

CVE number = CVE-2025-24054 This is a spoofing vulnerability involving the Windows New Technology LAN Manager (NTLM) hash, which Microsoft

Read More
NewsSecurity Vulnerabilities

Cisco Nexus Dashboard LDAP Username Enumeration Vulnerability (CVE-2025-20150)

CVE-2025-20150 – A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts.

Read More
NewsSecurity Vulnerabilities

Jenkins Host key reuse in SSH build agent Docker images (CVE-2025-32754 and CVE-2025-32755)

CVE numbers CVE-2025-32754 and CVE-2025-32755. In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation

Read More