CISCO fixed 3 critical issues in Elastic Services Controller and Ultra Services FrameworkSecurity Affairs·Jul 6, 08:22 UTC · Jul 6, 2017VulnerabilityCVE-2017-6713CVE-2017-6712CVE-2017-6711+2 CVEs60
Simple bug could lead to RCE flaw on apps built with Electron FrameworkThe Hacker News·May 15, 00:00 UTC · May 15, 2018VulnerabilityCVE-2018-100013660
A Remote Code Execution Vulnerability found in the Spring Framework. Upgrade it now!Security Affairs·Apr 6, 12:50 UTC · Apr 6, 2018VulnerabilityCVE-2018-1270CVE-2018-1271CVE-2018-127260
Remote Execution Flaw Threatens Apps Built Using Spring Framework — Patch NowThe Hacker News·Apr 6, 07:58 UTC · Apr 6, 2018VulnerabilityCVE-2018-1270CVE-2018-1271CVE-2018-127260
The vulnerability landscape in Q1 2026Kaspersky Securelist·May 7, 08:42 UTC · May 7, 2026VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+10 CVEs60
Surge in Magento 2 template attacksSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Vulnerability landscape analysis for Q2 2025Kaspersky Securelist·Aug 27, 10:00 UTC · Aug 27, 2025VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
Critical code execution flaw in Electron framework impacts popular Desktop apps such as Skype and SignalSecurity Affairs·Jan 24, 21:15 UTC · Jan 24, 2018VulnerabilityCVE-2018-100000660
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Unpatched Java Spring Framework 0-Day RCE Bug Threatens Enterprise Web Apps SecurityThe Hacker News·Mar 31, 15:27 UTC · Mar 31, 2022Vulnerability in the wildCVE-2010-1622CVE-2022-22950CVE-2022-2296360
Meta's Llama Framework Flaw Exposes AI Systems to Remote Code Execution RisksThe Hacker News·Jan 28, 05:26 UTC · Jan 28, 2025VulnerabilityCVE-2024-50050CVE-2024-3660160
CISA Issues Warning on Active Exploitation of ZK Java Web Framework VulnerabilityThe Hacker News·Feb 28, 13:28 UTC · Feb 28, 2023Vulnerability in the wildCVE-2022-3653760
Critical Flaw Hits Popular Windows Apps Built With Electron JS FrameworkThe Hacker News·Jan 24, 12:26 UTC · Jan 24, 2018VulnerabilityCVE-2018-100000660
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference FrameworksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025VulnerabilityCVE-2024-50050CVE-2025-30165CVE-2025-23254+1 CVEs60
Critical Flaws in Niagara Framework Threaten Smart Buildings and Industrial Systems WorldwideThe Hacker News·Jul 29, 04:20 UTC · Jul 29, 2025VulnerabilityCVE-2025-3936CVE-2025-3937CVE-2025-3938+6 CVEs60
Critical remote code execution bug found in Cacti frameworkSecurity Affairs·Jan 29, 14:18 UTC · Jan 29, 2025VulnerabilityCVE-2025-22604CVE-2025-2436760
Vendors defeat Magento security patch (+ simple check)Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2022-24086CVE-2022-24087CVE-2026-7565060
Vulnerability landscape in Q4 2025Kaspersky Securelist·Mar 6, 10:00 UTC · Mar 6, 2026Vulnerability in the wildCVE-2018-0802CVE-2017-11882CVE-2017-0199+7 CVEs160
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
Analyzing the vulnerability landscape in Q3 2025Kaspersky Securelist·Dec 3, 10:00 UTC · Dec 3, 2025VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
Lazarus Group exploited ManageEngine vulnerability to target critical infrastructureHelp Net Security·Aug 25, 00:00 UTC · Aug 25, 2023Vulnerability in the wildCVE-2022-4796660
Critical OAuth Vulnerability in Expo Framework Allows Account HijackingThe Hacker News·May 27, 07:45 UTC · May 27, 2023VulnerabilityCVE-2023-28131CVE-2023-2843860
Expo Framework API Flaw Reveals User Data in Online ServicesInfosecurity Magazine·May 25, 17:00 UTC · May 25, 2023VulnerabilityCVE-2023-2813160
Tridium Niagara framework affected by 2 flaws in BlackBerry QNX OSSecurity Affairs·Oct 1, 07:03 UTC · Oct 1, 2019VulnerabilityCVE-2019-8998CVE-2019-1352860
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecastHelp Net Security·Jun 7, 00:00 UTC · Jun 7, 2026Vulnerability in the wildCVE-2026-0257CVE-2026-41089CVE-2025-48595+1 CVEs60
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI FrameworksThe Hacker News·Mar 27, 08:07 UTC · Mar 27, 2026Vulnerability in the wildCVE-2026-34070CVE-2025-68664CVE-2025-67644+2 CVEs160
Max-severity vulnerability in React, Node.js patched, update ASAP (CVE-2025-55182)Help Net Security·Dec 4, 00:00 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
Developers scramble as critical React flaw threatens major appsCyberScoop·Dec 3, 19:23 UTC · Dec 3, 2025Vulnerability in the wildCVE-2025-55182CVE-2025-6647860
Addressing the vulnerability prioritization challengeRecorded Future·Nov 26, 00:00 UTC · Nov 26, 2025Vulnerability in the wild60
Critical Next.js auth bypass vulnerability opens web apps to compromise (CVE-2025-29927)Help Net Security·Apr 2, 08:44 UTC · Apr 2, 2025Vulnerability in the wildCVE-2025-2992760
Researchers Disclose Critical RCE Vulnerability Affecting Quarkus Java FrameworkThe Hacker News·Dec 1, 11:45 UTC · Dec 1, 2022VulnerabilityCVE-2022-411660
Spring4Shell (CVE-2022Kaspersky Securelist·Apr 4, 16:42 UTC · Apr 4, 2022Vulnerability in the wildCVE-2022-22965CVE-2022-22963CVE-2010-162260
Backdoor vulnerability in open source tool exposes thousands of apps to remote code executionCyberScoop·Apr 4, 20:51 UTC · Apr 4, 2019Vulnerability in the wild60
ATT&CKized Splunk - Threat Hunting with MITRE’s ATT&CK using SplunkSecurity Affairs·Feb 19, 06:32 UTC · Feb 19, 2019Vulnerability in the wild60
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0The Hacker News·Jul 21, 04:34 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-63030CVE-2026-60137CVE-2026-15409+26 CVEs160
Week in review: Several companies affected by the Salesloft Drift breach, Sitecore 0-day vulnerabilityHelp Net Security·Sep 7, 00:00 UTC · Sep 7, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-24204CVE-2025-48543+2 CVEs60
Oracle Releases January 2025 Patch to Address 318 Flaws Across Major ProductsThe Hacker News·Jan 22, 13:39 UTC · Jan 22, 2025Vulnerability in the wildCVE-2025-21556CVE-2024-21287CVE-2025-21524+10 CVEs60
A Mirai-based botnet is exploiting the Spring4Shell vulnerabilitySecurity Affairs·Apr 9, 07:45 UTC · Apr 9, 2022Vulnerability in the wildCVE-2022-2296560
Potential Apache Struts 2 RCE flaw fixed, PoCs releasedHelp Net Security·Aug 17, 00:00 UTC · Aug 17, 2020VulnerabilityCVE-2019-0230CVE-2019-0233CVE-2018-11776+1 CVEs60
Expert discovered a Critical Remote Code Execution flaw in Apache StrutsSecurity Affairs·Aug 22, 17:23 UTC · Aug 22, 2018VulnerabilityCVE-2018-1177660