Search
CISA has added CVE-2025-61757 to its Known Exploited Vulnerabilities (KEV) catalog.
From securityweek.comCISA warns of a critical authentication bypass flaw (CVE-2025-5095, CVSS 9.8) in ARC Solo devices, allowing attackers to change passwords and take full remote control without authentication.
From securityonline.infoCISA issues an urgent warning about "ToolShell," a sophisticated exploit chain targeting SharePoint servers with multiple vulnerabilities to install webshells and steal crypto keys.
From securityonline.infoCISA warns of critical flaws in Tigo Energy's Cloud Connect Advanced devices, including hard-coded credentials and command injection, that could allow remote attackers to take full control of solar...
From securityonline.infoCISA adds three D-Link vulnerabilities (CVE-2020-25078, -25079, -2022-40799) to its KEV Catalog, confirming active exploitation of EOL IP cameras.
From securityonline.info