A critical vulnerability in Capacitor for Android and iOS could let a malicious link opened inside an affected mobile app…
A critical vulnerability in Next.js could allow remote code execution in applications that use the Node.js implementation of ImageResponse from…
A critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute arbitrary code with root-level privileges or trigger…
A Docker flaw, CVE-2026-17106 (dubbed CopyEscape), lets malicious containers write files outside the docker cp destination, potentially enabling code execution…
Autonomous security research platform XBOW has disclosed CVE-2026-72018, a high-severity Linux kernel vulnerability that converts a tightly constrained out-of-bounds memory…
A now-patched vulnerability in Unsloth Studio allowed a malicious Hugging Face model repository to execute Python code when a user…
Octopus Deploy has disclosed a high-severity vulnerability in Octopus Server that could allow authenticated users to execute arbitrary code on…
Apple has released iOS 26.7.1 and iPadOS 26.7.1 to fix a critical zero-day vulnerability that it says may have been…
PHP has fixed a security flaw that could expose login credentials, cookies, and proxy authentication data to an unintended server…
A high-severity security vulnerability in Sudo could allow local attackers to bypass time-based access restrictions and run commands with elevated…