Skip to main content
← All Articles

Category

Vulnerabilities

851 articles

Advertisement

VU
CRITICAL
Vulnerabilities

CVE-2024-3300: Critical Everest Forms Pro Bypass Leads to Site Takeover

Hackers are actively exploiting an authentication bypass in the Everest Forms Pro WordPress plugin (CVE-2024-3300). Update immediately to prevent takeover.

Runtime Rebel Intel
4 min read · Jun 6, 2026
SolarWinds Serv-U DoS Vulnerability CVE-2026-28318 Added to CISA KEV
HIGH
Vulnerabilities

SolarWinds Serv-U DoS Vulnerability CVE-2026-28318 Added to CISA KEV

CISA adds CVE-2026-28318 to its KEV catalog following active exploitation of a high-severity DoS vulnerability in SolarWinds Serv-U file server software.

Runtime Rebel Intel
3 min read · Jun 6, 2026
VU
HIGH
Vulnerabilities

CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption Exploit

CISA warns of active exploitation of CVE-2026-28318, an uncontrolled resource consumption flaw in SolarWinds Serv-U. Immediate patching is critical for all organizations.

Runtime Rebel Intel
4 min read · Jun 5, 2026
VU
HIGH
Vulnerabilities

CVE-2024-28995: SolarWinds Serv-U Exploit Leads to Server Crashes

CISA warns of active exploitation of SolarWinds Serv-U CVE-2024-28995. Attackers are leveraging this directory traversal flaw to crash vulnerable servers.

Runtime Rebel Intel
3 min read · Jun 5, 2026
VU
CRITICAL
Vulnerabilities

Cisco Catalyst SD-WAN Manager RCE via CVE-2024-20468 — Patch Now

Cisco warns of a high-severity zero-day vulnerability in Catalyst SD-WAN Manager, tracked as CVE-2024-20468, currently exploited for root privilege escalation.

Runtime Rebel Intel
3 min read · Jun 5, 2026
CVE-2026-3300: Critical RCE in Everest Forms Pro — Patch Now
CRITICAL
Vulnerabilities

CVE-2026-3300: Critical RCE in Everest Forms Pro — Patch Now

Attackers are exploiting CVE-2026-3300 in Everest Forms Pro up to 1.9.12 to achieve RCE. Learn how to protect your WordPress site from full compromise.

Runtime Rebel Intel
3 min read · Jun 5, 2026
VU
CRITICAL
Vulnerabilities

Critical Fortinet, Apache, Cisco IOS XE Vulnerabilities: Patch & Monitor

Alert: New critical vulnerabilities impact FortiClient, FortiNAC, and Apache products. Cisco IOS XE continues to face active exploitation. Urgent patching is required.

Runtime Rebel Intel
5 min read · Jun 5, 2026
VU
MEDIUM
Vulnerabilities

Hitachi Energy MACH HiDraw RCE via CVE-2026-7310 — Patch Guide

Hitachi Energy addresses a heap-based buffer overflow in MACH HiDraw version 9.22. Learn how to mitigate CVE-2026-7310 and protect critical ICS assets.

Runtime Rebel Intel
3 min read · Jun 4, 2026
VU
MEDIUM
Vulnerabilities

CVE-2026-21404: NAVTOR NavBox SOAP Credential Bypass and Mitigation

NAVTOR NavBox version 4.16.1.20 is vulnerable to hard-coded credentials in its SOAP implementation, allowing local attackers to manipulate application files.

Runtime Rebel Intel
3 min read · Jun 4, 2026
Cisco Unified CM RCE via CVE-2026-20230 — Mitigation Guide
HIGH
Vulnerabilities

Cisco Unified CM RCE via CVE-2026-20230 — Mitigation Guide

Cisco patches CVE-2026-20230, a high-severity SSRF in Unified Communications Manager. Learn how public PoC code impacts your security and find remediation steps.

Runtime Rebel Intel
3 min read · Jun 4, 2026
VU
CRITICAL
Vulnerabilities

Mirasvit Full Page Cache Warmer RCE via CVE-2024-34961 - Patch Now

Attackers are exploiting a critical RCE vulnerability in Mirasvit's Full Page Cache Warmer for Magento. Learn how to detect and mitigate CVE-2024-34961.

Runtime Rebel Intel
4 min read · Jun 4, 2026
VU
MEDIUM
Vulnerabilities

Google Gemini Hijack: Command Injection via Messaging Notifications

Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.

Runtime Rebel Intel
4 min read · Jun 4, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-20469: Critical Cisco Unified CM Root Escalation Risk

Cisco patches a critical SQL injection flaw (CVE-2024-20469) in Unified Communications Manager that allows remote attackers to gain full root-level access.

Runtime Rebel Intel
3 min read · Jun 4, 2026
VU
HIGH
Vulnerabilities

VS Code One-Click GitHub Token Theft via URI Handler Exploitation

A flaw in Visual Studio Code allows attackers to steal GitHub authentication tokens with a single click. Learn the technical details and mitigation steps.

Runtime Rebel Intel
4 min read · Jun 4, 2026
VU
HIGH
Vulnerabilities

Cisco Unified CM SSRF CVE-2024-20455 — Public PoC Mitigation Guide

Cisco warns of critical SSRF vulnerabilities in Unified CM with public PoC exploit code. Learn how to detect and patch CVE-2024-20455 to protect your network.

Runtime Rebel Intel
4 min read · Jun 4, 2026
CVE-2026-45247: Magento Mirasvit Cache Warmer RCE Exploit Analysis
CRITICAL
Vulnerabilities

CVE-2026-45247: Magento Mirasvit Cache Warmer RCE Exploit Analysis

CISA adds CVE-2026-45247, a critical Mirasvit Cache Warmer RCE flaw impacting Magento sites, to the KEV catalog following reports of active exploitation.

Runtime Rebel Intel
3 min read · Jun 4, 2026
Google Gemini Hijacked on Android via Poisoned Notifications
HIGH
Vulnerabilities

Google Gemini Hijacked on Android via Poisoned Notifications

Researchers demonstrate how WhatsApp and Slack notifications can trigger indirect prompt injection in Google Gemini, leading to memory poisoning.

Runtime Rebel Intel
4 min read · Jun 3, 2026
VU
HIGH
Vulnerabilities

CVE-2026-45247: Mirasvit Full Page Cache Warmer Exploited — Patch Now

CISA adds CVE-2026-45247, a deserialization vulnerability in Mirasvit Full Page Cache Warmer for Magento, to the KEV catalog after reports of active exploitation.

Runtime Rebel Intel
3 min read · Jun 3, 2026
VU
HIGH
Vulnerabilities

Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626

CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.

Runtime Rebel Intel
4 min read · Jun 3, 2026
Google Gemini Indirect Prompt Injection via Malicious Notifications
MEDIUM
Vulnerabilities

Google Gemini Indirect Prompt Injection via Malicious Notifications

Security researchers demonstrate how malicious notifications can manipulate Google Gemini's voice assistant to perform unauthorized tasks or exfiltrate data.

Runtime Rebel Intel
4 min read · Jun 3, 2026
VU
HIGH
Vulnerabilities

WordPress Sites Targeted via Kirki and Burst Statistics Vulnerabilities

Attackers are exploiting unauthenticated stored XSS in Kirki and Burst Statistics plugins to achieve privilege escalation and website takeover.

Runtime Rebel Intel
3 min read · Jun 3, 2026
VU
HIGH
Vulnerabilities

Acer Wave 7 Router RCE via CVE-2024-41591 and CVE-2024-41592

Acer addresses two critical 10.0 CVSS zero-day vulnerabilities in Wave 7 mesh routers that allow unauthenticated remote code execution and full takeover.

Runtime Rebel Intel
3 min read · Jun 3, 2026
GitHub.dev One-Click Attack: Stealing OAuth Tokens via VS Code
HIGH
Vulnerabilities

GitHub.dev One-Click Attack: Stealing OAuth Tokens via VS Code

New research reveals a one-click exploit in GitHub.dev and VS Code that allows attackers to steal full GitHub OAuth tokens and access private repositories.

Runtime Rebel Intel
4 min read · Jun 3, 2026
VU
HIGH
Vulnerabilities

VS Code Zero-Day Exploit: Stealing GitHub Tokens via URI Handlers

Security researcher mthcht reveals a VS Code zero-day vulnerability allowing GitHub token theft via URI handlers. Learn how to defend against this exploit.

Runtime Rebel Intel
4 min read · Jun 3, 2026