Three flaws in Hugging Face's Diffusers library let crafted model repositories run arbitrary code despite trust_remote_code protections.
CI/CD platforms have become prime targets for attackers seeking supply chain access, and JetBrains’ latest security advisory underscores the risk.
A heap buffer overflow in 7-Zip's XZ decompression lets attackers execute code when victims open crafted archive files.
F5 patched a critical Nginx heap buffer overflow that lets unauthenticated attackers crash workers or achieve remote code execution.
Progress Software told ShareFile customers to power down on-premises Storage Zone Controllers over an undisclosed security threat.
CISA added iCagenda and Balbooa Forms Joomla extension flaws to its KEV catalog, citing active exploitation and remote code execution…
An unauthenticated attacker can exploit a missing authentication control in Splunk Enterprise's PostgreSQL sidecar to write arbitrary files and execute…
A trio of patched vulnerabilities in LangGraph's checkpoint system can be chained through SQL injection and unsafe deserialization to execute…
Sign in to your account