A path traversal bug in Check Point's management plane was already being used against customers weeks before the vendor knew…
A heap overflow in BIG-IP APM hands unauthenticated attackers code execution on any appliance serving as an OAuth authorization server.
A CVSS 10.0 input validation bug in on-premises VeloCloud Orchestrator is under active exploitation, and fixes cover only two of…
CISA added three Linux kernel flaws to its exploited list while a researcher published working root exploits for four more.
Cisco's identity appliance is being hit through an API endpoint that never checked who was asking.
A logic error below Android's reach lets attackers escalate on Pixel handsets without any interaction.
A crafted message can give an unauthenticated attacker root on Cisco's secure email gateway, and the flaw is already being…
CISA added six actively exploited flaws to KEV, including a Citrix NetScaler bug now under attack in the wild.