Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Apache Parquet Java – Potential malicious code execution from trusted packages (CVE-2025-46762)

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code.

Read More
NewsSecurity Vulnerabilities

Cisco IOS XE SNMP GET-NEXT ciscoFlashFileSize Unexpected Sign Extension Denial-of-Service Vulnerability (CVE-2025-20169)

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Cisco IOS XE.

Read More
NewsSecurity Vulnerabilities

Synology BeeStation BST150-4T Unnecessary Privileges Remote Code Execution Vulnerability (CVE-2024-10445)

CVE number = CVE-2024-10445 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology BeeStation BST150-4T

Read More
NewsSecurity Vulnerabilities

Apache ActiveMQ NMS Body Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-29953)

CVE-2025-29953 – This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apache ActiveMQ NMS.

Read More
NewsSecurity Vulnerabilities

Oracle VirtualBox OHCI USB Controller Race Condition Local Privilege Escalation Vulnerability (CVE-2024-21113)

CVE-2024-21113 – This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox.

Read More
NewsSecurity Vulnerabilities

Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability (CVE-2025-24054)

CVE-2025-24054 is a vulnerability involving NTLM hash disclosure through spoofing, triggered by specially crafted .library-ms files.

Read More
NewsSecurity Vulnerabilities

Path traversal vulnerability in Commvault Command Center Innovation Release (CVE-2025-34028)

A critical security vulnerability has been identified in the Commvault Command Center installation, allowing remote attackers to execute arbitrary code without authentication. 

Read More
NewsSecurity Vulnerabilities

SAP NetWeaver Visual Composer Metadata Uploader High Risk Vulnerability (CVE-2025-31324)

This vulnerability affects the platform’s visual composer, it lets a remote and unauthenticated attacker upload malicious files directly to the system without authorisation.

Read More
NewsSecurity Vulnerabilities

SonicWALL Connect Tunnel Link Following Denial-of-Service Vulnerability (CVE-2025-32817)

CVE-2025-32817 – This vulnerability allows local attackers to create a denial-of-service condition on affected installations of SonicWALL Connect Tunnel.

Read More
NewsSecurity Vulnerabilities

Unauthenticated Remote Code Execution in Erlang/OTP SSH (CVE-2025-32433)

A serious vulnerability (CVE-2025-32433) has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE).

Read More