Vulnerability News

Chaotic Eclipse Claims Avast Antivirus 0-Day Vulnerability – PoC Released

Researcher Chaotic Eclipse has claimed to have discovered a zero-day privilege-escalation vulnerability affecting Avast Antivirus and released a public proof-of-concept…

2 weeks ago

3 High-Severity HP Easy Start Flaws Let Attackers Escalate Privileges on macOS

Three high-severity vulnerabilities in HP Easy Start for macOS could allow attackers to interfere with printer-software installation workflows and potentially…

2 weeks ago

Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host

Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let…

2 weeks ago

WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks

A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress…

2 weeks ago

CISA Warns of SonicWall SMA1000 Vulnerabilities Actively Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added two SonicWall SMA1000 appliance vulnerabilities to its Known Exploited Vulnerabilities catalog,…

2 weeks ago

Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability

A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project…

2 weeks ago

GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok

A newly disclosed class of vulnerabilities, dubbed GitSpawn, allows a booby-trapped repository to silently execute code on a developer's machine…

2 weeks ago

FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately

FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges…

2 weeks ago

Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers

Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into…

2 weeks ago

Critical HPE Fabric Composer Flaws Let Unauthenticated Attackers Execute Code and Take Over Systems

HPE has released security updates for HPE Networking Fabric Composer following the discovery of a large set of vulnerabilities that…

2 weeks ago