Aggregator
CVE-2026-21633 | Ubiquiti UniFi Protect Application up to 6.2.71 improper authorization (EUVD-2026-0828 / WID-SEC-2026-0014)
CVE-2025-68668 | n8n-io n8n up to 1.x Environment Variable NODES_EXCLUDE protection mechanism (GHSA-62r4-hw23-cc8v / EUVD-2025-205454)
CVE-2025-32365 | Freedesktop Poppler 0.75.0/0.89.0/20.12.1/22.07.0/22.08.0 File JBIG2Stream.cc JBIG2Bitmap::combine out-of-bounds (Issue 1577 / Nessus ID 234608)
CVE-2025-65018 | libpng up to 1.6.50 png_combine_row heap-based overflow (EUVD-2025-199236 / Nessus ID 276643)
CVE-2025-32364 | Freedesktop Poppler 0.75.0/0.89.0/20.12.1/22.07.0/22.08.0 PSStack::roll integer overflow (Issue 1574 / Nessus ID 234608)
CVE-2025-64720 | libpng up to 1.6.50 png_image_read_composite out-of-bounds (EUVD-2025-199237 / Nessus ID 276641)
Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server
A critical path traversal vulnerability in AdonisJS has been discovered that could allow remote attackers to write arbitrary files to server filesystems, potentially leading to complete system compromise. The vulnerability, tracked as CVE-2026-21440, affects the bodyparser module of the popular TypeScript-first web framework and carries a critical CVSS v4 severity rating. The security flaw resides in […]
The post Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server appeared first on Cyber Security News.
Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover
UK government admits years of cyber policy have failed, announces reset
CVE-2023-33863 | RenderDoc up to 1.26 integer overflow (ID 172804 / EUVD-2023-38013)
CVE-2023-33817 | HotelDruid Hotel Management Software 3.0.5 sql injection (EUVD-2023-37968)
CVE-2023-33829 | Cloudogu SCM Manager up to 1.60 Description cross site scripting (ID 172588 / EUVD-2023-37980)
CVE-2023-33802 | SumatraPDF Reader 3.4.6 Text File buffer overflow (EUVD-2023-37953)
High-Severity Flaw in Open WebUI Affects AI Connections
Critical Dolby Codec Vulnerability Exposes Android Devices to Code Execution Attacks
Google has issued its January 2026 Android Security Bulletin, urging users to update to the 2026-01-05 patch level or later to mitigate a critical vulnerability in Dolby components. The standout issue, CVE-2025-54957, targets the Dolby Digital Plus (DD+) codec and could enable out-of-bounds memory writes on affected Android devices. At the heart of this flaw […]
The post Critical Dolby Codec Vulnerability Exposes Android Devices to Code Execution Attacks appeared first on Cyber Security News.