HAProxy Found Vulnerable to Critical HTTP Request Smuggling AttackThe Hacker News·Sep 8, 12:33 UTC · Sep 8, 2021VulnerabilityCVE-2021-4034660
3 iOS 0-days, a cellular network compromise, and HTTP used to infect an iPhoneArs Technica · Security·Sep 23, 00:23 UTC · Sep 23, 2023VulnerabilityCVE-2023-41993CVE-2023-41991CVE-2023-41992+1 CVEs60
Active exploitation of Cisco IOS XE Software Web Management User Interface vulnerabilitiesCisco Talos·Oct 16, 15:05 UTC · Oct 16, 2023Vulnerability in the wildCVE-2023-20198CVE-2023-20273CVE-2021-1435160
New Cache Poisoning Attack Lets Attackers Target CDN Protected SitesThe Hacker News·Oct 24, 05:34 UTC · Oct 24, 2019VulnerabilityCVE-2019-094160
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Vulnerability Spotlight: Multiple remote vulnerabilities in TP-Link TLCisco Talos·Nov 19, 14:30 UTC · Nov 19, 2018VulnerabilityCVE-2018-3948CVE-2018-3949CVE-2018-3950+1 CVEs60
Know Your Infusion Pump Vulnerabilities and Secure Your Healthcare OrganizationPalo Alto Unit 42·Jun 5, 23:27 UTC · Jun 5, 2024VulnerabilityCVE-2019-12255CVE-2019-12264CVE-2016-9355+7 CVEs160
More than 2 million Apache HTTP servers affected by CVE-2019Security Affairs·Apr 5, 07:51 UTC · Apr 5, 2019VulnerabilityCVE-2019-021160
QNAP Advises Users to Update NAS Firmware to Patch Apache HTTP VulnerabilitiesThe Hacker News·Apr 22, 08:15 UTC · Apr 22, 2022VulnerabilityCVE-2022-22721CVE-2022-23943CVE-2022-22719+3 CVEs60
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCEThe Hacker News·May 21, 07:24 UTC · May 21, 2026VulnerabilityCVE-2026-42945CVE-2026-42946CVE-2026-40701+1 CVEs60
Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin AccountsThe Hacker News·Nov 17, 14:23 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-6444660
CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server TakeoversSecurity Affairs·Jul 20, 09:50 UTC · Jul 20, 2026VulnerabilityCVE-2026-4253360
Fuzzing µC/OS protocol stacks, Part 1: HTTP server fuzzingCisco Talos·Aug 28, 16:00 UTC · Aug 28, 2024Vulnerability55
Apache fixed a source code disclosure flaw in Apache HTTP ServerSecurity Affairs·Jul 7, 17:20 UTC · Jul 7, 2024VulnerabilityCVE-2024-3988460
Apache rolled out a new update in a few days to fix incomplete patch for actively exploited flawSecurity Affairs·Oct 8, 07:38 UTC · Oct 8, 2021Vulnerability in the wildCVE-2021-41773CVE-2021-4201360
CVE-2021-31166 Windows HTTP flaw also impacts WinRM serversSecurity Affairs·May 23, 13:25 UTC · May 23, 2021Vulnerability in the wildCVE-2021-3116660
Critical flaw in Jenkins Server can cause information disclosureSecurity Affairs·Aug 18, 17:55 UTC · Aug 18, 2020VulnerabilityCVE-2019-1763860
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 CrossThe Hacker News·Aug 5, 14:27 UTC · Aug 5, 2026Vulnerability in the wildCVE-2026-58073CVE-2026-58072CVE-2026-58067+10 CVEs160
Critical ASP.NET flaw hits QNAP NetBak PC AgentSecurity Affairs·Oct 28, 12:23 UTC · Oct 28, 2025VulnerabilityCVE-2025-5531560
ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini FilesThe Hacker News·May 12, 14:03 UTC · May 12, 2025Vulnerability in the wildCVE-2025-3462CVE-2025-346360
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
Demystifying Kubernetes CVE-2018Palo Alto Unit 42·Jan 28, 20:53 UTC · Jan 28, 2022VulnerabilityCVE-2018-100210560
Patch Apache HTTP Servers Now to Avoid Zero Day ExploitInfosecurity Magazine·Oct 6, 09:16 UTC · Oct 6, 2021Vulnerability in the wildCVE-2021-41773CVE-2021-4152460
Critical RCE Flaw in Linux APT Allows Remote Attackers to Hack SystemsThe Hacker News·Jan 23, 08:19 UTC · Jan 23, 2019VulnerabilityCVE-2019-346260
Vulnerability Spotlight: Multiple Vulnerabilities in Moxa EDRCisco Talos·Apr 13, 15:57 UTC · Apr 13, 2018VulnerabilityCVE-2017-12120CVE-2017-12121CVE-2017-12123+8 CVEs60
Firefox 51 starts flagging HTTP login pages as insecureHelp Net Security·Jan 25, 00:00 UTC · Jan 25, 2017Vulnerability55
Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and SecretsSecurity Affairs·Jul 7, 21:16 UTC · Jul 7, 2026Vulnerability in the wildCVE-2026-20896160
⚡ Weekly Recap: Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & MoreThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2025Vulnerability in the wildCVE-2025-14174CVE-2025-43529CVE-2025-6218+43 CVEs60
Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code ExecutionThe Hacker News·Dec 4, 15:38 UTC · Dec 4, 2025VulnerabilityCVE-2025-55182CVE-2025-6647860
CISA Confirms Exploitation of SonicWall VulnerabilitiesInfosecurity Magazine·May 2, 15:00 UTC · May 2, 2025Vulnerability in the wildCVE-2023-44221CVE-2024-3847560
Critical RCE Flaw in GFI KerioControl Allows Remote Code Execution via CRLF InjectionThe Hacker News·Jan 9, 10:29 UTC · Jan 9, 2025Vulnerability in the wildCVE-2024-5287560
Personal VPN and Its Evasions: Risk Factors and How to Maintain Network VisibilityPalo Alto Unit 42·Jun 6, 12:16 UTC · Jun 6, 2024VulnerabilityCVE-2020-15590CVE-2019-12579CVE-2019-12578+23 CVEs60
Critical Boot Loader Vulnerability in Shim Impacts Nearly All Linux DistrosThe Hacker News·Feb 8, 03:11 UTC · Feb 8, 2024VulnerabilityCVE-2023-40547CVE-2023-40546CVE-2023-40548+3 CVEs60
Biggest DDoSes of all time generated by protocol 0Ars Technica · Security·Oct 15, 00:00 UTC · Oct 15, 2023Vulnerability55
Expert published NMAP script for Apache CVE-2021Security Affairs·Oct 9, 12:04 UTC · Oct 9, 2021Vulnerability in the wildCVE-2021-41773CVE-2021-42013160
Critical Jenkins Server Vulnerability Could Leak Sensitive InformationThe Hacker News·Aug 21, 13:46 UTC · Aug 21, 2020VulnerabilityCVE-2019-1763860
Juniper Networks addressed many issues in its productsSecurity Affairs·Jul 10, 18:04 UTC · Jul 10, 2020VulnerabilityCVE-2020-1647CVE-2020-165460
F5 Patches Critical NGINX Vulnerabilities Enabling Unauthenticated Code ExecutionSecurity Affairs·Jun 18, 14:07 UTC · Jun 18, 2026VulnerabilityCVE-2026-42530CVE-2026-42055CVE-2026-11311+1 CVEs60
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server TakeoverThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-33032CVE-2026-27944CVE-2026-27825+1 CVEs60
China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bugSecurity Affairs·Jan 16, 10:17 UTC · Jan 16, 2026Vulnerability in the wildCVE-2025-2039360