Wordfence and Defiant detail critical flaws in WooCommerce Wholesale Lead Capture and The Events Calendar, both reachable without credentials.
A crafted message can give an unauthenticated attacker root on Cisco's secure email gateway, and the flaw is already being…
A newly named threat actor automated a July Gitea flaw into a framework that stole source code and pushed on…
Check Point has patched two certificate-handling bugs that score 9.8 and could let an unauthenticated attacker run code.
SAP patches OVERPASS, a CVSS 10 kernel bug that lets unauthenticated attackers run commands on SAP hosts.
N-able's fourth N-central hotfix closes a CVSS 10 pre-auth RCE while its own advisories disagree on whether it is already…
TantoSec's public tool turns a Telerik UI padding oracle into unauthenticated code execution for shops that skipped the July patch.
HPE's AOS-CX updates close 34 CVEs including a 9.8-rated unauthenticated RCE cluster.