CVE-2026-41613: Microsoft Visual Studio Code MCP Install Dialog Flaw (Envade)
A vulnerability in Microsoft Visual Studio Code's MCP install dialog (CVSS 8.8, aka Envade) enables full code execution or MCP tool call…
A vulnerability in Microsoft Visual Studio Code's MCP install dialog (CVSS 8.8, aka Envade) enables full code execution or MCP tool call…
Adobe Bridge received updates to address eight critical vulnerabilities, including untrusted search paths, incorrect authorization, path traversal, and out-of-bounds writes, all leading…
CVE-2025-48828 is a companion vulnerability to CVE-2025-48827, both affecting vBulletin's template engine and enabling pre-authentication code execution. Exploitation attempts were observed shortly…
CVE-2025-48827 is a previous vBulletin template engine vulnerability that allowed pre-authentication code execution. It was part of a chain with CVE-2025-48828 and…
A critical vulnerability in 7-Zip, identified as CVE-2026-14266, allows attackers to execute arbitrary code by tricking users into opening a specially crafted…
CVE-2026-48095 is a heap-write overflow vulnerability in 7-Zip's NTFS handler, fixed in version 26.01. It was detailed by GitHub Security Lab with…
Hugging Face, the world's largest open-source AI model repository, disclosed a security breach perpetrated by an autonomous AI agent system. The attack…
A critical vulnerability in Cursor, an AI-powered code editor, allows arbitrary code execution on Windows when a user opens a cloned repository…
A vulnerability in Git Credential Manager Core where a malicious git.exe in a repository root could be executed during recursive clone, fixed…
Researchers at firmware security firm Binarly have discovered six new vulnerabilities in U-Boot, the widely used bootloader for devices ranging from home…