Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and SecretsSecurity Affairs·Jul 7, 21:16 UTC · Jul 7, 2026Vulnerability in the wildCVE-2026-20896160
⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [27 January]The Hacker News·Jan 27, 12:39 UTC · Jan 27, 2025VulnerabilityCVE-2025-23006CVE-2025-20156CVE-2025-21556+7 CVEs60
New Drupal RCE vulnerability under active exploitation, patch ASAP!Help Net Security·Apr 26, 00:00 UTC · Apr 26, 2018Vulnerability in the wildCVE-2018-7602CVE-2018-760060
Demystifying Kubernetes CVE-2018Palo Alto Unit 42·Jan 28, 20:53 UTC · Jan 28, 2022VulnerabilityCVE-2018-100210560
Microsoft: China Using AIInfosecurity Magazine·Apr 5, 11:03 UTC · Apr 5, 2024VulnerabilityCVE-2023-4279360
New Privilege Escalation Flaw Affects Most Linux DistributionsThe Hacker News·Oct 26, 13:59 UTC · Oct 26, 2018VulnerabilityCVE-2018-1466560
Ivanti Rushes Patches for 4 New Flaws in Connect Secure and Policy SecureThe Hacker News·Apr 4, 06:30 UTC · Apr 4, 2024VulnerabilityCVE-2024-21894CVE-2024-22052CVE-2024-22053+3 CVEs60
Vulnerability Spotlight: Privilege escalation bug in CleanMyMac X's helper serviceCisco Talos·Mar 12, 14:24 UTC · Mar 12, 2019Vulnerability in the wildCVE-2019-501160
Update X.Org libraries to avoid Privilege Escalation and DoS attacksSecurity Affairs·Oct 7, 13:48 UTC · Oct 7, 2016VulnerabilityCVE-2016-7942CVE-2016-7943CVE-2016-7944+10 CVEs60
Actively exploited Firefox, Tor Browser 0-day patched, update now!Help Net Security·Dec 1, 00:00 UTC · Dec 1, 2016Vulnerability in the wildCVE-2016-907960
UPDATE Firefox and Tor to Patch Critical ZeroThe Hacker News·Dec 1, 08:32 UTC · Dec 1, 2016Vulnerability in the wildCVE-2016-907960
CVE-2018-14665 privilege escalation flaw affects popular Linux distrosSecurity Affairs·Oct 26, 18:51 UTC · Oct 26, 2018VulnerabilityCVE-2018-1466560
Vulnerable TP-Link Wi-Fi extenders open to attack, patch now!Help Net Security·Jun 18, 00:00 UTC · Jun 18, 2019VulnerabilityCVE-2019-740660
Apache Struts 2.3.x vulnerable to two year old RCE flawHelp Net Security·Dec 15, 12:31 UTC · Dec 15, 2023VulnerabilityCVE-2016-100003160
QNAP Patches New Flaws in QTS and QuTS hero Impacting NAS AppliancesThe Hacker News·May 22, 06:57 UTC · May 22, 2024VulnerabilityCVE-2024-21902CVE-2024-27127CVE-2024-27128+5 CVEs60
Symfony Flaw Leaves Drupal Sites Vulnerable to Hackers—Patch NowThe Hacker News·Aug 3, 11:13 UTC · Aug 3, 2018Vulnerability in the wildCVE-2018-1477360
Four Critical Vulnerabilities Expose HPE Aruba Devices to RCE AttacksThe Hacker News·May 3, 04:50 UTC · May 3, 2024VulnerabilityCVE-2024-26304CVE-2024-26305CVE-2024-33511+1 CVEs60
CISA Alerts on Critical Security Vulnerabilities in Industrial Control SystemsThe Hacker News·Mar 23, 06:09 UTC · Mar 23, 2023VulnerabilityCVE-2023-1133CVE-2023-1139CVE-2023-1145+3 CVEs60
New Apache Log4j Update Released to Patch Newly Discovered VulnerabilityThe Hacker News·Dec 29, 05:00 UTC · Dec 29, 2021Vulnerability in the wildCVE-2021-44832CVE-2021-44228CVE-2021-45046+2 CVEs60
Vulnerability opens FreeRADIUS servers to unauthenticated attackersHelp Net Security·May 30, 00:00 UTC · May 30, 2017Vulnerability in the wildCVE-2017-914860
NCSC Urges Users to Patch Next.js Flaw ImmediatelyInfosecurity Magazine·Mar 31, 10:15 UTC · Mar 31, 2025VulnerabilityCVE-2025-2992760
Critical Next.js auth bypass vulnerability opens web apps to compromise (CVE-2025-29927)Help Net Security·Apr 2, 08:44 UTC · Apr 2, 2025Vulnerability in the wildCVE-2025-2992760
Critical Next.js Vulnerability Allows Attackers to Bypass Middleware Authorization ChecksThe Hacker News·Mar 25, 03:16 UTC · Mar 25, 2025VulnerabilityCVE-2025-2992760
Patch it up: Old vulnerabilities are everyone’s problemsCisco Talos·Mar 13, 18:04 UTC · Mar 13, 2025Vulnerability in the wildCVE-2025-22224CVE-2024-457760
Ivanti fixes high severity flaw in Pulse Connect Secure VPNSecurity Affairs·May 25, 21:00 UTC · May 25, 2021VulnerabilityCVE-2021-22908160
New High-Severity Vulnerability Reported in Pulse Connect Secure VPNThe Hacker News·May 25, 07:37 UTC · May 25, 2021Vulnerability in the wildCVE-2021-22908CVE-2021-22893CVE-2021-22894+2 CVEs160
Critical Veeam RCE flaw Lets LowSecurity Affairs·Jun 14, 11:48 UTC · Jun 14, 2026Vulnerability in the wildCVE-2026-44963CVE-2025-2312160
Apache Struts users have to update FileUpload library to fix yearsSecurity Affairs·Nov 7, 07:28 UTC · Nov 7, 2018VulnerabilityCVE-2016-1000031CVE-2014-005060
SonicWall released patch for actively exploited SMA 100 zeroSecurity Affairs·Feb 4, 13:57 UTC · Feb 4, 2021Vulnerability in the wildCVE-2021-2001660
Over 80,000 servers hit as roundcube RCE bug gets rapidly exploitedSecurity Affairs·Jun 11, 11:43 UTC · Jun 11, 2025VulnerabilityCVE-2025-4911360
Active exploitation of the MOVEit Transfer vulnerability — CVE-2023Cisco Talos·Jun 16, 18:17 UTC · Jun 16, 2023Vulnerability in the wildCVE-2023-34362CVE-2023-35036CVE-2023-3570860
Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege EscalationThe Hacker News·Nov 21, 15:40 UTC · Nov 21, 2025VulnerabilityCVE-2025-4111560
It's time to patch your SonicWall SMA 100 series appliances again!Help Net Security·Apr 18, 10:13 UTC · Apr 18, 2025VulnerabilityCVE-2021-20038CVE-2021-20045CVE-2021-2004360
Ivanti fixes critical vulnerabilities in Endpoint Management (CVE-2024-29847)Help Net Security·Sep 16, 14:44 UTC · Sep 16, 2024Vulnerability in the wildCVE-2024-29847CVE-2024-819060
Researchers Develop RCE Exploit for the Latest F5 BIGThe Hacker News·May 10, 05:05 UTC · May 10, 2022Vulnerability in the wildCVE-2022-138860
July 2021 Patch Tuesday: Microsoft fixes 4 actively exploited bugsHelp Net Security·Jul 13, 00:00 UTC · Jul 13, 2021Vulnerability in the wildCVE-2021-34527CVE-2021-34448CVE-2021-33771+6 CVEs60
Maximum-severity XXE vulnerability discovered in Apache TikaSecurity Affairs·Dec 6, 00:03 UTC · Dec 6, 2025VulnerabilityCVE-2025-66516CVE-2025-5498860
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git PushThe Hacker News·Apr 28, 18:19 UTC · Apr 28, 2026VulnerabilityCVE-2026-3854160
Vulnerability Spotlight: Multiple vulnerabilities in OpenClinic’s GA web portalCisco Talos·Apr 13, 14:40 UTC · Apr 13, 2021Vulnerability in the wildCVE-2020-27226CVE-2020-27227CVE-2020-27228+7 CVEs60
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office ZeroRecorded Future·Feb 24, 00:00 UTC · Feb 24, 2026Vulnerability in the wildCVE-2026-21509CVE-2026-23760CVE-2026-1281+1 CVEs160