Why React Didn't Kill XSS: The New JavaScript Injection PlaybookThe Hacker News·Jul 29, 10:00 UTC · Jul 29, 2025Vulnerability55
ShiftLeft's features identify attackable JavaScript and TypeScript vulnerabilitiesHelp Net Security·Dec 17, 00:00 UTC · Dec 17, 2021Vulnerability55
Avast disables the JavaScript engine component due to a severe issueSecurity Affairs·Mar 11, 23:26 UTC · Mar 11, 2020Vulnerability55
Adobe fixes flaws in Adobe InDesign,Framemaker, Experience ManagerSecurity Affairs·Sep 8, 20:43 UTC · Sep 8, 2020VulnerabilityCVE-2020-9727CVE-2020-9728CVE-2020-9729+15 CVEs60
Why Unmonitored JavaScript Is Your Biggest Holiday Security RiskThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Vulnerability55
Firefox Blocks Inline and Eval JavaScript on Internal Pages to Prevent Injection AttacksThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2019Vulnerability55
Microsoft Patch TuesdayCisco Talos·Jun 13, 20:48 UTC · Jun 13, 2017VulnerabilityCVE-2017-0283CVE-2017-0291CVE-2017-0292+37 CVEs60
OpenJS Foundation Targeted in Potential JavaScript Project Takeover AttemptThe Hacker News·Apr 17, 05:00 UTC · Apr 17, 2024Vulnerability55
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix AttacksThe Hacker News·Jun 26, 07:33 UTC · Jun 26, 2026VulnerabilityCVE-2026-2698060
CERT/CC Warns binary-parser Bug Allows Node.js PrivilegeThe Hacker News·Jan 27, 14:10 UTC · Jan 27, 2026VulnerabilityCVE-2026-124560
5 Threats That Reshaped Web Security This Year [2025]The Hacker News·Dec 4, 11:30 UTC · Dec 4, 2025VulnerabilityCVE-2025-54135CVE-2025-53109CVE-2025-5528460
Over 110,000 Websites Affected by Hijacked Polyfill Supply Chain AttackThe Hacker News·Jun 28, 04:05 UTC · Jun 28, 2024VulnerabilityCVE-2024-34102CVE-2024-296160
Critical Flaws in vm2 JavaScript Library Can Lead to Remote Code ExecutionThe Hacker News·Apr 20, 04:45 UTC · Apr 20, 2023VulnerabilityCVE-2023-29199CVE-2023-30547CVE-2023-29017+1 CVEs60
Researchers Detail Critical RCE Flaw Reported in Popular vm2 JavaScript SandboxThe Hacker News·Oct 11, 11:28 UTC · Oct 11, 2022VulnerabilityCVE-2022-3606760
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersSecurity Affairs·Jul 24, 08:31 UTC · Jul 24, 2026Vulnerability in the wildCVE-2025-6637660
Over 70 Malicious npm and VS Code Packages Found Stealing Data and CryptoThe Hacker News·May 26, 15:12 UTC · May 26, 2025Vulnerability55
Adobe fixes critical flaws in Flash Player and FramemakerSecurity Affairs·Jun 9, 17:59 UTC · Jun 9, 2020VulnerabilityCVE-2020-9633CVE-2020-9643CVE-2020-9647+5 CVEs60
Cisco Talos discloses serious vulnerabilities in Foxit PDF ReaderHelp Net Security·Oct 2, 00:00 UTC · Oct 2, 2018Vulnerability55
vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code ExecutionThe Hacker News·May 11, 03:55 UTC · May 11, 2026VulnerabilityCVE-2026-24118CVE-2026-24120CVE-2023-37466+11 CVEs60
Mass PolyShell attack wave hits 471 stores in one hourSansec (Magento / e-commerce security)·Mar 31, 07:45 UTC · Mar 31, 2026Vulnerability in the wildCVE-2026-7565060
Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet FormulasThe Hacker News·Jan 27, 14:07 UTC · Jan 27, 2026VulnerabilityCVE-2026-24002CVE-2025-6866860
Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution FlawsThe Hacker News·Dec 10, 09:13 UTC · Dec 10, 2025VulnerabilityCVE-2025-59718CVE-2025-59719CVE-2025-10573+6 CVEs60
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference FrameworksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025VulnerabilityCVE-2024-50050CVE-2025-30165CVE-2025-23254+1 CVEs60
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Apple chips can be hacked to leak secrets from Gmail, iCloud, and moreArs Technica · Security·Jan 28, 20:56 UTC · Jan 28, 2025Vulnerability55
Operation Triangulation: The last (hardware) mysteryKaspersky Securelist·Dec 27, 14:00 UTC · Dec 27, 2023Vulnerability in the wildCVE-2023-41990CVE-2023-32434CVE-2023-38606+1 CVEs160
F5 warns its customers of tens of flaws in its productsSecurity Affairs·May 5, 09:47 UTC · May 5, 2022VulnerabilityCVE-2022-1388CVE-2022-25946CVE-2022-27806+1 CVEs60
Moodle vulnerability exposed users to account takeoverSecurity Affairs·Apr 8, 20:22 UTC · Apr 8, 2021Vulnerability55
Mozilla offers rewards for Bypassing Firefox Exploit MitigationsSecurity Affairs·Aug 21, 15:55 UTC · Aug 21, 2020Vulnerability55
Microsoft Patch TuesdayCisco Talos·Aug 8, 18:30 UTC · Aug 8, 2017VulnerabilityCVE-2017-8653CVE-2017-8669CVE-2017-8661+38 CVEs60
Critical DOM XSS flaw on Wix.com put million websites at riskSecurity Affairs·Nov 3, 10:44 UTC · Nov 3, 2016Vulnerability55
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026Security Affairs·Jul 21, 06:08 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-687560
Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025Security Affairs·Mar 19, 14:48 UTC · Mar 19, 2026Vulnerability in the wildCVE-2025-6637660
Critical Flaws Found in Four VS Code Extensions with Over 125 Million InstallsThe Hacker News·Feb 18, 13:16 UTC · Feb 18, 2026VulnerabilityCVE-2025-65717CVE-2025-65716CVE-2025-65715160
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
Critical and High Severity n8n Sandbox Flaws Allow RCEInfosecurity Magazine·Jan 28, 16:00 UTC · Jan 28, 2026VulnerabilityCVE-2026-1470CVE-2026-086360
CVE-2025-10585 is the sixth actively exploited Chrome zeroSecurity Affairs·Nov 18, 08:52 UTC · Nov 18, 2025Vulnerability in the wildCVE-2025-10585CVE-2025-5419CVE-2025-4664+3 CVEs60
ThreatsDay Bulletin: $15B Crypto Bust, Satellite Spying, BillionThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Vulnerability55
iframe Security Exposed: The Blind Spot Fueling Payment Skimmer AttacksThe Hacker News·Sep 24, 11:03 UTC · Sep 24, 2025Vulnerability in the wild60