Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion (CVE-2026-59234)

– Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3.

Read More
NewsSecurity VulnerabilitiesUncategorized

Cisco Catalyst Center Arbitrary File Read Vulnerability (CVE-2026-20191)

– A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.

Read More
NewsSecurity Vulnerabilities

X.Org Server CreateSaverWindow Use-After-Free Information Disclosure Vulnerability (CVE-2026-50263)

– This vulnerability allows local attackers to disclose sensitive information on affected installations of X.Org Server.

Read More
NewsSecurity Vulnerabilities

Cisco Finesse Remote File Inclusion Vulnerability (CVE-2026-20175)

– A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks.

Read More
NewsSecurity Vulnerabilities

MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2026-10043)

CVE number – CVE-2026-10043 This vulnerability allows remote attackers to execute arbitrary code on affected installations of MosaicML Composer. User

Read More
NewsSecurity Vulnerabilities

Oracle PeopleSoft Remote Code Execution Vulnerability (CVE-2026-35273)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft.

Read More
NewsSecurity Vulnerabilities

Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

– Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device.

Read More
NewsSecurity Vulnerabilities

Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability (CVE-2026-8916)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie.

Read More
NewsSecurity Vulnerabilities

NVIDIA Transformers4Rec Model.load Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2026-24162)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec.

Read More
NewsSecurity Vulnerabilities

Microsoft Edge Origin Validation Error Security Bypass Vulnerability (CVE-2026-45492)

– This vulnerability allows remote attackers to access restricted functionality on affected installations of Microsoft Edge.

Read More