Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
Hitachi Energy MACH HiDraw RCE via CVE-2026-7310 — Patch Guide
Hitachi Energy addresses a heap-based buffer overflow in MACH HiDraw version 9.22. Learn how to mitigate CVE-2026-7310 and protect critical ICS assets.
CVE-2026-21404: NAVTOR NavBox SOAP Credential Bypass and Mitigation
NAVTOR NavBox version 4.16.1.20 is vulnerable to hard-coded credentials in its SOAP implementation, allowing local attackers to manipulate application files.

Cisco Unified CM RCE via CVE-2026-20230 — Mitigation Guide
Cisco patches CVE-2026-20230, a high-severity SSRF in Unified Communications Manager. Learn how public PoC code impacts your security and find remediation steps.
Mirasvit Full Page Cache Warmer RCE via CVE-2024-34961 - Patch Now
Attackers are exploiting a critical RCE vulnerability in Mirasvit's Full Page Cache Warmer for Magento. Learn how to detect and mitigate CVE-2024-34961.
Google Gemini Hijack: Command Injection via Messaging Notifications
Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.
CVE-2024-20469: Critical Cisco Unified CM Root Escalation Risk
Cisco patches a critical SQL injection flaw (CVE-2024-20469) in Unified Communications Manager that allows remote attackers to gain full root-level access.
VS Code One-Click GitHub Token Theft via URI Handler Exploitation
A flaw in Visual Studio Code allows attackers to steal GitHub authentication tokens with a single click. Learn the technical details and mitigation steps.
Cisco Unified CM SSRF CVE-2024-20455 — Public PoC Mitigation Guide
Cisco warns of critical SSRF vulnerabilities in Unified CM with public PoC exploit code. Learn how to detect and patch CVE-2024-20455 to protect your network.

CVE-2026-45247: Magento Mirasvit Cache Warmer RCE Exploit Analysis
CISA adds CVE-2026-45247, a critical Mirasvit Cache Warmer RCE flaw impacting Magento sites, to the KEV catalog following reports of active exploitation.
Atlas RAT Deployment: Chinese Actors Target European Defense
Chinese-speaking threat actors are deploying the new Atlas RAT and exploiting CVE-2023-43208 to target European government and defense organizations.

Google Gemini Hijacked on Android via Poisoned Notifications
Researchers demonstrate how WhatsApp and Slack notifications can trigger indirect prompt injection in Google Gemini, leading to memory poisoning.
CVE-2026-45247: Mirasvit Full Page Cache Warmer Exploited — Patch Now
CISA adds CVE-2026-45247, a deserialization vulnerability in Mirasvit Full Page Cache Warmer for Magento, to the KEV catalog after reports of active exploitation.