vulnerability

Cisco Patches Vulnerabilities in Nexus Switches

Cisco Patches Vulnerabilities in Nexus Switches 2025-02-27 at 14:03 By Eduard Kovacs Cisco has patched command injection and DoS vulnerabilities affecting some of its Nexus switches, including a high-severity flaw. The post Cisco Patches Vulnerabilities in Nexus Switches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Patches Vulnerabilities in Nexus Switches Read More »

Siemens Teamcenter vulnerability could allow account takeover (CVE-2025-23363)

Siemens Teamcenter vulnerability could allow account takeover (CVE-2025-23363) 2025-02-27 at 11:32 By Zeljka Zorz A high-severity vulnerability (CVE-2025-23363) in the Siemens Teamcenter product lifecycle management (PLM) software could allow an attacker to steal users’ valid session data and gain unauthorized access to the vulnerable application. About CVE-2025-23363 Siemens Teamcenter is a suite of applications that

Siemens Teamcenter vulnerability could allow account takeover (CVE-2025-23363) Read More »

Vulnerabilities in MongoDB Library Allow RCE on Node.js Servers

Vulnerabilities in MongoDB Library Allow RCE on Node.js Servers 2025-02-21 at 15:21 By Ionut Arghire OPSWAT details two critical vulnerabilities in the Mongoose ODM library for MongoDB leading to remote code execution on the Node.js server. The post Vulnerabilities in MongoDB Library Allow RCE on Node.js Servers appeared first on SecurityWeek. This article is an

Vulnerabilities in MongoDB Library Allow RCE on Node.js Servers Read More »

Atlassian Patches Critical Vulnerabilities in Confluence, Crowd

Atlassian Patches Critical Vulnerabilities in Confluence, Crowd 2025-02-20 at 15:40 By Ionut Arghire Atlassian has released patches for 12 critical- and high-severity vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd, and Jira. The post Atlassian Patches Critical Vulnerabilities in Confluence, Crowd appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Atlassian Patches Critical Vulnerabilities in Confluence, Crowd Read More »

PoC Exploit Published for Critical Ivanti EPM Vulnerabilities

PoC Exploit Published for Critical Ivanti EPM Vulnerabilities 2025-02-20 at 13:47 By Ionut Arghire Proof-of-concept (PoC) code and technical details on four critical-severity Ivanti EPM vulnerabilities are now available. The post PoC Exploit Published for Critical Ivanti EPM Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PoC Exploit Published for Critical Ivanti EPM Vulnerabilities Read More »

Chrome 133, Firefox 135 Updates Patch High-Severity Vulnerabilities

Chrome 133, Firefox 135 Updates Patch High-Severity Vulnerabilities 2025-02-19 at 15:01 By Ionut Arghire Google and Mozilla resolve high-severity memory safety vulnerabilities with the latest Chrome and Firefox security updates. The post Chrome 133, Firefox 135 Updates Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 133, Firefox 135 Updates Patch High-Severity Vulnerabilities Read More »

Attackers are chaining flaws to breach Palo Alto Networks firewalls

Attackers are chaining flaws to breach Palo Alto Networks firewalls 2025-02-19 at 11:03 By Zeljka Zorz Exploitation attempts targeting CVE-2025-0108, a recently disclosed authentication bypass vulnerability affecting the management web interface of Palo Alto Networks’ firewalls, are ramping up. “GreyNoise now sees 25 malicious IPs actively exploiting CVE-2025-0108, up from 2 on February 13,” the

Attackers are chaining flaws to breach Palo Alto Networks firewalls Read More »

Critical Vulnerability Patched in Juniper Session Smart Router

Critical Vulnerability Patched in Juniper Session Smart Router 2025-02-18 at 15:34 By Eduard Kovacs A critical vulnerability tracked as CVE-2025-21589 has been patched in Juniper Networks’ Session Smart Router. The post Critical Vulnerability Patched in Juniper Session Smart Router appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Vulnerability Patched in Juniper Session Smart Router Read More »

Xerox Versalink Printer Vulnerabilities Enable Lateral Movement

Xerox Versalink Printer Vulnerabilities Enable Lateral Movement 2025-02-17 at 13:03 By Ionut Arghire Xerox released security updates to resolve pass-back attack vulnerabilities in Versalink multifunction printers. The post Xerox Versalink Printer Vulnerabilities Enable Lateral Movement appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Xerox Versalink Printer Vulnerabilities Enable Lateral Movement Read More »

SonicWall Firewall Vulnerability Exploited After PoC Publication

SonicWall Firewall Vulnerability Exploited After PoC Publication 2025-02-14 at 14:36 By Ionut Arghire The exploitation of a recent SonicWall vulnerability has started shortly after proof-of-concept (PoC) code was published. The post SonicWall Firewall Vulnerability Exploited After PoC Publication appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SonicWall Firewall Vulnerability Exploited After PoC Publication Read More »

Palo Alto Networks Patches Potentially Serious Firewall Vulnerability

Palo Alto Networks Patches Potentially Serious Firewall Vulnerability 2025-02-13 at 14:05 By Eduard Kovacs Palo Alto Networks has published 10 new security advisories, including one for a high-severity firewall authentication bypass vulnerability. The post Palo Alto Networks Patches Potentially Serious Firewall Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Palo Alto Networks Patches Potentially Serious Firewall Vulnerability Read More »

CISA Updates Known Exploited Vulnerabilities Catalog with Four Critical Issues

CISA Updates Known Exploited Vulnerabilities Catalog with Four Critical Issues 2025-02-13 at 13:49 By daksh sharma In a recent update to its Known Exploited Vulnerabilities Catalog, the Cybersecurity and Infrastructure Security Agency (CISA) has added four security vulnerabilities that are currently under active exploitation. These vulnerabilities span across multiple platforms and pose substantial security risks

CISA Updates Known Exploited Vulnerabilities Catalog with Four Critical Issues Read More »

Exploitation of Old ThinkPHP, OwnCloud Vulnerabilities Surges

Exploitation of Old ThinkPHP, OwnCloud Vulnerabilities Surges 2025-02-13 at 13:33 By Ionut Arghire Threat actors are increasingly exploiting two old vulnerabilities in ThinkPHP and OwnCloud in their attacks. The post Exploitation of Old ThinkPHP, OwnCloud Vulnerabilities Surges appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation of Old ThinkPHP, OwnCloud Vulnerabilities Surges Read More »

Cyble Warns of Exposed Medical Imaging, Asset Management Systems

Cyble Warns of Exposed Medical Imaging, Asset Management Systems 2025-02-13 at 13:18 By daksh sharma Overview Cyble’s weekly industrial control system (ICS) vulnerability report to clients warned about internet-facing medical imaging and critical infrastructure asset management systems that could be vulnerable to cyberattacks. The report examined six ICS, operational technology (OT), and Supervisory Control and

Cyble Warns of Exposed Medical Imaging, Asset Management Systems Read More »

Google Pays Out $55,000 Bug Bounty for Chrome Vulnerability

Google Pays Out $55,000 Bug Bounty for Chrome Vulnerability 2025-02-13 at 13:00 By Ionut Arghire Google has released a Chrome 133 update to address four high-severity vulnerabilities reported by external researchers. The post Google Pays Out $55,000 Bug Bounty for Chrome Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Google Pays Out $55,000 Bug Bounty for Chrome Vulnerability Read More »

Cyble Warns of Patient Monitor Risk in ICS Vulnerability Report

Cyble Warns of Patient Monitor Risk in ICS Vulnerability Report 2025-02-13 at 06:19 By daksh sharma Cyble’s weekly industrial control system (ICS) vulnerability report to clients included a warning about a severe vulnerability in a patient monitor that could potentially compromise patient safety. In all, the report covered 36 ICS, operational technology (OT) and Supervisory

Cyble Warns of Patient Monitor Risk in ICS Vulnerability Report Read More »

Ivanti, Fortinet Patch Remote Code Execution Vulnerabilities

Ivanti, Fortinet Patch Remote Code Execution Vulnerabilities 2025-02-12 at 15:45 By Ionut Arghire Ivanti and Fortinet on Tuesday released patches for multiple critical- and high-severity vulnerabilities in their products. The post Ivanti, Fortinet Patch Remote Code Execution Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Ivanti, Fortinet Patch Remote Code Execution Vulnerabilities Read More »

High-Severity OpenSSL Vulnerability Found by Apple Allows MitM Attacks

High-Severity OpenSSL Vulnerability Found by Apple Allows MitM Attacks 2025-02-11 at 20:09 By Eduard Kovacs OpenSSL has patched CVE-2024-12797, a high-severity vulnerability found by Apple that can allow man-in-the-middle attacks. The post High-Severity OpenSSL Vulnerability Found by Apple Allows MitM Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

High-Severity OpenSSL Vulnerability Found by Apple Allows MitM Attacks Read More »

Scroll to Top