Aggregator
Secure Your Spot at RSAC 2026 Conference
1 month 2 weeks hence
Hackers compromise NGINX servers to redirect user traffic
1 hour 49 minutes ago
A threat actor is compromising NGINX servers in a campaign that hijacks user traffic and reroutes it through the attacker's backend infrastructure. [...]
Bill Toulas
CVE-2025-61732
1 hour 59 minutes ago
Currently trending CVE - Hype Score: 12
CVE-2025-14321
1 hour 59 minutes ago
Currently trending CVE - Hype Score: 8 - Use-after-free in the WebRTC: Signaling component. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.
CVE-2025-0921
1 hour 59 minutes ago
Currently trending CVE - Hype Score: 1 - Execution with Unnecessary Privileges vulnerability in multiple services of Mitsubishi Electric Iconics Digital Solutions GENESIS64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS version 11.00, Mitsubishi Electric GENESIS64 all versions, Mitsubishi Electric ...
CVE-2025-64328
1 hour 59 minutes ago
Currently trending CVE - Hype Score: 7 - FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known ...
CVE-2025-40551
1 hour 59 minutes ago
Currently trending CVE - Hype Score: 15 - SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
CVE-2025-68121
1 hour 59 minutes ago
Currently trending CVE - Hype Score: 20
CVE-2025-46285
1 hour 59 minutes ago
Currently trending CVE - Hype Score: 17 - An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in watchOS 26.2, macOS Sonoma 14.8.3, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, macOS Sequoia 15.7.3, visionOS 26.2, tvOS 26.2. An app may be able to gain root ...
CVE-2025-55182
1 hour 59 minutes ago
Currently trending CVE - Hype Score: 11 - A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code ...
CVE-2025-11953
1 hour 59 minutes ago
Currently trending CVE - Hype Score: 20 - The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server ...
CVE-2025-29824
1 hour 59 minutes ago
Currently trending CVE - Hype Score: 10 - Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2024-37301 | adfinis document-merge-service up to 6.5.1 Template special elements used in a template engine (GHSA-v5gf-r78h-55q6)
2 hours 29 minutes ago
A vulnerability was found in adfinis document-merge-service up to 6.5.1 and classified as critical. This vulnerability affects unknown code of the component Template Handler. The manipulation results in improper neutralization of special elements used in a template engine.
This vulnerability is reported as CVE-2024-37301. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-22890 | Humming Heads Defense Platform Home Edition up to 3.9.51.x unnecessary privileges
2 hours 29 minutes ago
A vulnerability identified as critical has been detected in Humming Heads Defense Platform Home Edition up to 3.9.51.x. This affects an unknown part. This manipulation causes execution with unnecessary privileges.
This vulnerability is registered as CVE-2025-22890. The attack needs to be launched locally. No exploit is available.
vuldb.com
CVE-2025-23236 | Humming Heads Defense Platform Home Edition up to 3.9.51.x buffer overflow
2 hours 29 minutes ago
A vulnerability labeled as critical has been found in Humming Heads Defense Platform Home Edition up to 3.9.51.x. This vulnerability affects unknown code. Such manipulation leads to buffer overflow.
This vulnerability is documented as CVE-2025-23236. The attack needs to be performed locally. There is not any exploit available.
vuldb.com
CVE-2025-20094 | Humming Heads Defense Platform Home Edition up to 3.9.51.x Message shatter
2 hours 29 minutes ago
A vulnerability described as critical has been identified in Humming Heads Defense Platform Home Edition up to 3.9.51.x. Impacted is an unknown function of the component Message Handler. Executing a manipulation can lead to unprotected windows messaging channel.
This vulnerability appears as CVE-2025-20094. The attack requires local access. There is no available exploit.
vuldb.com
CVE-2025-22894 | Humming Heads Defense Platform Home Edition up to 3.9.51.x Message shatter
2 hours 29 minutes ago
A vulnerability classified as problematic has been found in Humming Heads Defense Platform Home Edition up to 3.9.51.x. The affected element is an unknown function of the component Message Handler. The manipulation leads to unprotected windows messaging channel.
This vulnerability is traded as CVE-2025-22894. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2022-50536 | Linux Kernel up to 6f226ffe4458ea3b8c33287cb8c86f87dc198dce sock_put use after free (WID-SEC-2025-2229)
2 hours 29 minutes ago
A vulnerability labeled as critical has been found in Linux Kernel up to 6f226ffe4458ea3b8c33287cb8c86f87dc198dce. Impacted is the function sock_put. Executing a manipulation can lead to use after free.
This vulnerability is tracked as CVE-2022-50536. The attack is only possible within the local network. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2022-50537 | Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1 rpi_firmware_probe memory leak (WID-SEC-2025-2229)
2 hours 29 minutes ago
A vulnerability was found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. It has been rated as critical. Affected by this vulnerability is the function rpi_firmware_probe. This manipulation causes memory leak.
This vulnerability is handled as CVE-2022-50537. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com