Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to RPD crash (CVE-2024-39549)

CVE number = CVE-2024-39549 An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks

Read More
NewsSecurity Vulnerabilities

Apple macOS ImageIO JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability [CVE-2024-44176]

CVE Number = CVE-2024-44176 CVSS Score = 7.8 This vulnerability allows remote attackers to execute arbitrary code on affected installations

Read More
NewsSecurity Vulnerabilities

Apple macOS AppleVADriver Out-Of-Bounds Read Information Disclosure Vulnerability [CVE-2024-27861]

CVE number = CVE-2024-27861 CVSS Score = 4.3 This vulnerability allows remote attackers to disclose sensitive information on affected installations

Read More
NewsSecurity Vulnerabilities

PDF-XChange Editor Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability [CVE-2024-8847]

CVE Number = CVE-2024-8847 CVSS score = 7.8 This vulnerability allows remote attackers to execute arbitrary code on affected installations

Read More
NewsSecurity Vulnerabilities

Broadcom Issues Urgent Security Advisory for VMware vCenter Server and Cloud Foundation

Broadcom has released a critical security advisory concerning two vulnerabilities in VMware vCenter Server, the centralized management tool for virtual

Read More
NewsSecurity Vulnerabilities

Kastle Systems Access Control System [CVE-2024-45861]

CVE number = CVE-2024-45861 CVSS Score = 9.2 Kastle Systems firmware prior to May 1st 2024, contained a hard-coded credential,

Read More
NewsSecurity Vulnerabilities

WinZip Mark-of-the-Web Bypass Vulnerability [CVE-2024-8811]

CVE number = CVE-2024-8811 This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip.

Read More
NewsSecurity Vulnerabilities

mySCADA myPRO Hard-Coded Credentials Remote Code Execution Vulnerability [CVE-2024-4708]

CVE number = CVE-2024-4708 CVSS Score = 9.8 This vulnerability allows remote attackers to execute arbitrary code on affected installations

Read More
NewsSecurity Vulnerabilities

Nextcloud Desktop Client synchronized files vulnerability [CVE-2024-46958]

CVE number = CVE-2024-46958 In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client)

Read More
NewsSecurity Vulnerabilities

Yubico YubiKey 5 Series ECDSA secret-key extraction attack vulnerability [CVE-2024-45678]

CVE number = CVE-2024-45678 Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before

Read More