Microsoft says CVE-2026-69836, a CVSS 10.0 Entra ID RCE flaw, has been exploited in the wild but is fully mitigated with no ...
Elementor Pro CVE-2026-32475 lets unauthenticated attackers bypass file checks and upload PHP for remote code execution.
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. A critical-severity type ...
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity ...
A critical zero-day vulnerability in Microsoft SharePoint is being exploited in the wild right now, and more than 1,300 servers remain exposed to the public internet with no patch applied. The flaw, ...
The type confusion vulnerability allows a guest-to-host sandbox escape which can lead to remote code execution ...
CISA urges federal agencies to immediately patch exploited vulnerabilities in Microsoft, VMware, and Apple products.
Security experts are urging all Zoom users to patch their client, after the video communications giant fixed flaws that a malicious participant could exploit to ...
A critical Telnet vulnerability with a CVSS rating of 9.8 enables attackers to take full control of affected systems before authentication even kicks in, security researchers at Dream Security have ...
A vulnerability in UNISOC modem firmware can allow arbitrary code execution with kernel privileges from the modem context, ...
A flaw in Hugging Face Transformers could allow malicious AI models to execute code, exposing credentials and highlighting AI supply chain risks. Organizations using vulnerable versions of the Hugging ...