CVE-2025-24813: Apache Tomcat Remote Code Execution Vulnerability
CVE-2025-24813 is a remote code execution flaw in Apache Tomcat disclosed in March 2025 and added to CISA's Known Exploited Vulnerabilities catalog.…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
CVE-2025-24813 is a remote code execution flaw in Apache Tomcat disclosed in March 2025 and added to CISA's Known Exploited Vulnerabilities catalog.…
Cybersecurity researchers at Zafran Security have disclosed four vulnerabilities in Dify, an open-source agentic workflow platform with over 146,000 GitHub stars, collectively…
A use-after-free vulnerability in PDFium, an open-source C++ library for PDF rendering, with a CVSS score of 8.8. It could allow a…
A critical authorization bypass vulnerability (CVSS 9.1) in Dify that allows authenticated editor users to set and enable trace configurations for any…
A critical path traversal vulnerability (CVSS 9.4) in Dify that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal…
An authorization bypass vulnerability (CVSS 7.5/5.9) in Dify's file preview endpoint that allows any authenticated user to read up to 3,000 characters…
An authorization bypass vulnerability (CVSS 6.5) in Dify that allows authenticated users to read the full contents of files uploaded by other…
An unrelated heap overflow vulnerability in Squid's cache_digest functionality, patched in Squid 7.6.
A critical heap over-read vulnerability in the Squid web proxy, dubbed 'Squidbleed' (CVE-2026-47729), can leak cleartext HTTP requests—including credentials and session tokens—to…
CVE-2026-49777 is a critical vulnerability in the Product Slider Pro for WooCommerce plugin from ShapedPlugin, with a CVSS score of 10.0. It…