Vulnerability News

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers to execute malicious code with…

21 minutes ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to…

4 hours ago

Threat Actors Allegedly Selling Microsoft Office 0-Day RCE Vulnerability on Hacking Forums

A threat actor known as Zeroplayer has reportedly listed a zero-day remote code execution (RCE) vulnerability, combined with a sandbox…

22 hours ago

Critical N-able N-central Vulnerabilities Allow attacker to interact with legacy APIs and read sensitive files

N-able's N-central remote management and monitoring (RMM) platform faces critical security risks following the discovery of multiple vulnerabilities. According to…

23 hours ago

Critical Twonky Server Vulnerabilities Let Attackers Bypass Authentication

Twonky Server version 8.5.2 contains two critical authentication bypass vulnerabilities that allow unauthenticated attackers to gain full administrative access to…

23 hours ago

Ollama Vulnerabilities Let Attackers Execute Arbitrary Code by Parsing of Malicious Model Files

A severe vulnerability in Ollama, one of GitHub's most popular open-source projects, with over 155,000 stars. The flaw enables attackers…

1 day ago

CISA Warns of Google Chrome 0-Day Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert about a zero-day vulnerability in Google Chrome,…

1 day ago

Hackers Can Exploit Default ServiceNow AI Assistants Configurations to Launch Prompt Injection Attacks

A dangerous vulnerability in ServiceNow's Now Assist AI platform allows attackers to execute second-order prompt injection attacks via default agent…

1 day ago

Cline AI Coding Agent Vulnerabilities Enables Prompt Injection, Code Execution, and Data Leakage

Cline is an open-source AI coding agent with 3.8 million installs and over 52,000 GitHub stars. Contains four critical security…

1 day ago

Hackers Actively Exploiting 7-Zip RCE Vulnerability in the Wild

Hackers have begun actively exploiting a critical remote code execution (RCE) vulnerability in the popular file archiver 7-Zip, putting millions…

2 days ago