CVE-2025-11371: Gladinet Triofox Critical Vulnerability
A critical flaw (CVSS 9.1) in Gladinet Triofox exploited by Storm-2603 for initial access in ransomware attacks. Used to probe for local…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
A critical flaw (CVSS 9.1) in Gladinet Triofox exploited by Storm-2603 for initial access in ransomware attacks. Used to probe for local…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity remote code execution vulnerability, CVE-2026-45659 (CVSS 8.8), affecting Microsoft SharePoint…
A flaw in Argo CD where an API token with basic read access could retrieve Git repository credentials from a project. Patched…
A vulnerability in Argo CD allowing read-only users to read plaintext Kubernetes secrets. Patched in May 2026.
An unpatched vulnerability in the Argo CD repo-server component allows unauthenticated attackers to execute arbitrary code and potentially take over Kubernetes clusters.…
A vulnerability in Argo CD where the Redis cache lacked authentication, allowing any pod in the cluster to poison deployment data. Fixed…
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by…
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec("php jobs/subtitle_rendering.php ".$login_session."…
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type,…
Adobe has released critical security updates addressing multiple maximum-severity vulnerabilities in Adobe ColdFusion and Adobe Campaign Classic. The patches fix seven CVSS…