Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Apple macOS MOV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2025-24124)

CVE-2025-24124 – This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS.

Read More
NewsSecurity Vulnerabilities

IROAD Dash Cam X5 critical vulnerability (CVE-2025-2345)

CVE-2025-2345 – The IROAD X5 dashcam allows unauthorized users to modify critical system settings once connected to its network.

Read More
NewsSecurity Vulnerabilities

Cisco IOS XR Software Release 7.9.2 Denial of Service Vulnerability (CVE-2025-20141)

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.

Read More
NewsSecurity Vulnerabilities

NVIDIA Riva Triton Inference Server Missing Authentication Vulnerability (CVE-2025-23242)

CVE-2025-23242 – This vulnerability allows remote attackers to access protected functionality on affected installations of NVIDIA Riva.

Read More
NewsSecurity Vulnerabilities

Remote code execution when loading a crafted GraphQL schema (CVE-2025-27407)

Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution.

Read More
NewsSecurity Vulnerabilities

Cisco IOS XR Software Internet Key Exchange Version 2 Denial of Service Vulnerability (CVE-2025-20209)

CVE-2025-20209 – A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent an affected device from processing any control plane UDP packets.

Read More
NewsSecurity Vulnerabilities

Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability (CVE-2025-2233)

CVE-2025-2233 allows attackers to bypass authentication on Samsung SmartThings due to improper signature verification.

Read More
NewsSecurity Vulnerabilities

Veritas Arctera InfoScale Critical Vulnerability (CVE-2025-27816)

CVE-2025-27816 is a critical vulnerability that was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of potentially untrusted messages.

Read More
NewsSecurity Vulnerabilities

Trimble SketchUp SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability (CVE-2025-2024)

CVE-2025-2024 – This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp.

Read More
NewsSecurity Vulnerabilities

Cisco Small Business Routers Vulnerabilities (CVE-2023-20025 and CVE-2023-20026 and CVE-2023-20118)

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow a remote attacker to bypass authentication or execute arbitrary commands on the underlying operating system of an affected device.

Read More