Unpatched GeoServer Zero-Day Actively Exploited, Could Lead to Remote Code Execution
A newly disclosed zero-day vulnerability in GeoServer is being actively exploited in the wild, according to threat intelligence firm watchTowr. The flaw,…
A newly disclosed zero-day vulnerability in GeoServer is being actively exploited in the wild, according to threat intelligence firm watchTowr. The flaw,…
Adobe has released security updates addressing multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. The most severe include three CVSS 10.0…
A CVSS 9.0 SQL injection vulnerability in Adobe Campaign Classic that could lead to arbitrary code execution. Fixed in ACC v7 7.4.4…
Metabase has disclosed a maximum-severity zero-day vulnerability in its business intelligence and data visualization software that is being actively exploited in the…
Metabase, a provider of business intelligence and data visualization software, disclosed a maximum-severity zero-day vulnerability (CVSS 10.0) that is being exploited in…
Attackers breached an organization's Oracle database via a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit named…
khunt is a post-exploitation toolkit that runs inside Oracle databases by compiling Java source code into stored schema objects. It enables command…
cPanel has released a targeted security update to address a critical vulnerability that could allow authenticated hosting customers to execute SQL commands…
cPanel & WHM is a widely used web hosting control panel. All supported versions are affected by CVE-2026-58048, a critical SQL injection…
WP Squared, a cPanel product for WordPress hosting, is also affected by CVE-2026-58048. The fix is included in build 138.1.6.