Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

RSA Security SecureID Software Token for Microsoft Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of RSA Security SecureID Software Token for Microsoft

Read More
NewsSecurity Vulnerabilities

Zhelin NUS-M9 ERP Management Software – Arbitrary file download vulnerability [CVE-2024-44759]

CVE number – CVE-2024-44759 An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows

Read More
NewsSecurity Vulnerabilities

Palo Alto Networks PAN-OS – cross-site scripting (XSS) vulnerability [CVE-2024-5920]

CVE number – CVE-2024-5920 A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama

Read More
NewsSecurity Vulnerabilities

Microsoft Office PowerPoint PPTX File Parsing Use-After-Free Remote Code Execution Vulnerability [CVE-2024-49032]

CVE number = CVE-2024-49032 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Office PowerPoint.

Read More
NewsSecurity Vulnerabilities

Cisco IOS XR Software Bootloader Unauthenticated Information Disclosure Vulnerability [Updated – CVE-2023-20064]

CVE number = CVE-2023-20064 (Updated 13/11/2024) A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could

Read More
NewsSecurity Vulnerabilities

Veeam Backup Enterprise Manager AuthorizeByVMwareSsoToken Improper Certificate Validation Authentication Bypass Vulnerability

CVE number = CVE-2024-40715 This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Veeam Backup Enterprise Manager.

Read More
NewsSecurity Vulnerabilities

Panda Security Dome PSANHost Link Following Local Privilege Escalation Vulnerability [CVE-2024-8424]

CVE number = CVE-2024-8424 This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An

Read More
NewsSecurity Vulnerabilities

Cisco Nexus Dashboard Fabric Controller SQL Injection Vulnerability [CVE-2024-20536]

CVE number = CVE-2024-20536 A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller

Read More
NewsSecurity Vulnerabilities

Cisco Unified Industrial Wireless Software for Ultra-Reliable Wireless Backhaul Access Point Command Injection Vulnerability

CVE number = CVE-2024-20418 A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable

Read More
NewsSecurity Vulnerabilities

Apple SceneKit Improper Validation of Array Index Remote Code Execution Vulnerability [CVE-2024-44218]

CVE number = CVE-2024-44218 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS. Interaction

Read More