Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both enabling unauthenticated remote code execution (RCE). The…
Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both enabling unauthenticated remote code execution (RCE). The…
CERT/CC has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library, mwEmbed (also distributed as html5lib), that allow remote, unauthenticated attackers…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 (CVSS…
Microsoft has disclosed a maximum-severity remote code execution vulnerability in its cloud-based identity and access management service, Microsoft Entra ID (formerly Azure…
A now-patched command injection vulnerability in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is under active exploitation in the wild, according…
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source Node.js sandbox library with over 2,900 stars on GitHub.…
CVE-2024-35058 is a critical remote code execution vulnerability in the API wait function of NASA AIT-Core, affecting versions up to and including…
AIT-Core is the core library of the AMMOS Instrument Toolkit, affected by CVE-2024-35058, a critical remote code execution vulnerability in its API…
Security researchers at Cycode have disclosed a chain of vulnerabilities in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit.…
Cybersecurity researchers have disclosed a critical vulnerability in the Elementor Pro WordPress plugin that could allow unauthenticated attackers to upload PHP files…