Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Cisco Smart Licensing Utility Vulnerabilities (CVE-2024-20439 and CVE-2024-20440)

CVE-2024-20439 and CVE-2024-20440 – Multiple vulnerabilities in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to collect sensitive information or administer Cisco Smart Licensing Utility services on a system while the software is running.

Read More
NewsSecurity Vulnerabilities

Authorisation bypass vulnerability in Next.js web development framework (CVE-2025-29927)

Next.js has published a security advisory detailing an authorisation bypass vulnerability present in Next.js, a popular and open-source React-based web development framework that is used to build full-stack web applications in use in the UK and around the world.

Read More
NewsSecurity Vulnerabilities

Cisco Catalyst SD-WAN Manager Cross-Site Scripting Vulnerability (CVE-2024-20475)

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.

Read More
NewsSecurity Vulnerabilities

Four vulnerabilities found in Devolutions Remote Desktop Manager

Four vulnerabilities have been reported in Devolutions Remote Desktop Manager software.

Read More
NewsSecurity Vulnerabilities

BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability (CVE-2025-2773)

CVE number – CVE-2025-2773 This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers.

Read More
NewsSecurity Vulnerabilities

70mai A510 Use of Default Password Authentication Bypass Vulnerability (CVE-2025-2766)

CVE number = CVE-2025-2766 – This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of 70mai A510.

Read More
NewsSecurity Vulnerabilities

OpenSlides Improper Neutralization of Input During Web Page Generation (CVE-2025-30345)

CVE number – CVE-2025-30345 An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action,

Read More
NewsSecurity Vulnerabilities

Apple macOS MOV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2025-24124)

CVE-2025-24124 – This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS.

Read More
NewsSecurity Vulnerabilities

IROAD Dash Cam X5 critical vulnerability (CVE-2025-2345)

CVE-2025-2345 – The IROAD X5 dashcam allows unauthorized users to modify critical system settings once connected to its network.

Read More
NewsSecurity Vulnerabilities

Cisco IOS XR Software Release 7.9.2 Denial of Service Vulnerability (CVE-2025-20141)

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.

Read More