Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability (CVE-2026-21983)

– This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox.

Read More
NewsSecurity Vulnerabilities

Junos OS specifically crafted ‘show chassis’ command causes chassisd to crash (CVE-2025-60007)

– A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series allows a local attacker with low privileges to cause a Denial-of-Service (DoS).

Read More
NewsSecurity Vulnerabilities

Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability (CVE-2026-0777)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xmind.

Read More
NewsSecurity Vulnerabilities

Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Open Redirect Vulnerability (CVE-2026-20123)

– A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.

Read More
NewsSecurity Vulnerabilities

Adobe ColdFusion CAR File Parsing Directory Traversal Remote Code Execution Vulnerability (CVE-2025-61808)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe ColdFusion.

Read More
NewsSecurity Vulnerabilities

AzeoTech DAQFactory Pro CTL File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability (CVE-2025-66589)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory.

Read More
NewsSecurity Vulnerabilities

Apple macOS AppleIntelKBLGraphics Out-Of-Bounds Read Information Disclosure Vulnerability (CVE-2025-43283)

CVE number = CVE-2025-43283 This vulnerability allows local attackers to disclose sensitive information on affected installations of Apple macOS. An

Read More
NewsSecurity Vulnerabilities

Samsung MagicINFO 9 Server – database account and password are hardcoded (CVE-2026-25202)

– The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.

Read More
NewsSecurity Vulnerabilities

Hancom Office DOC File Parsing Type Confusion Remote Code Execution Vulnerability (CVE-2025-29867)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hancom Office.

Read More
NewsSecurity Vulnerabilities

Vulnerability in WordPress File Uploads Addon for WooCommerce plugin (CVE-2026-24625)

– Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows Exploiting Incorrectly Configured Access Control Security Levels.

Read More