Category: Vulnerabilities
16-Year-Old Linux KVM Flaw Allows Guest VMs to Escape to Host
A use-after-free vulnerability in Linux's KVM hypervisor, present in shared shadow MMU code for both Intel and AMD x86 systems, can be…
Opera GX Flaw Allowed Malicious Sites to Silently Install Data-Stealing Mods
A vulnerability in the gaming-focused Opera GX browser let attacker-controlled websites auto-install a browser add-on and extract data from pages the victim…
Google Project Zero Found Nine Bypasses in Windows Administrator Protection
A Google Project Zero researcher identified nine separate vulnerabilities in Windows 11's new Administrator Protection feature before its release, all of which…
ABB Freelance Security Lock Flaw Lets Attackers Bypass ICS User Management
A keyboard shortcut weakness in ABB Freelance Security Lock allows local attackers to sidestep the Freelance Operations kiosk layer and reach underlying…
Delta Electronics DTM Soft Flaw Allows Arbitrary Code Execution
A deserialization vulnerability in all versions of Delta Electronics DTM Soft carries a CVSS v3.1 score of 7.8 and can be exploited…
Siemens Patches OpenSSL Stack Overflow Across Dozens of Industrial Products
A stack-based buffer overflow in OpenSSL tracked as CVE-2025-15467 affects a broad range of Siemens networking, routing, and industrial products, with fixes…
Siemens SIPROTEC 5 Flaw Allows Malicious File Uploads via DIGSI 5
A newly disclosed vulnerability in Siemens SIPROTEC 5 protective relays permits authenticated users to upload arbitrary files through the DIGSI 5 protocol,…
B&R Products Affected by Linux Kernel Privilege Escalation Flaws
CISA has published an advisory detailing Linux kernel vulnerabilities affecting multiple B&R Industrial Automation products, with public proof-of-concept exploits already available for…
CISA Warns of Critical Auth Flaws in EVoke EV Charging Management System
CISA has published an advisory detailing multiple vulnerabilities in EVoke Systems' Charging Station Management System, with the most severe carrying a CVSS…
Schneider Electric PowerLogic P7 Hit by Three ICS Vulnerabilities
CISA has published an advisory detailing three security flaws in Schneider Electric's PowerLogic P7 protection and control platform, including an OS command…
Yokogawa FAST/TOOLS and CI Server Expose Settings via Cleartext Flaw
A high-severity vulnerability in Yokogawa's FAST/TOOLS and Collaborative Information Server allows unauthenticated network attackers to retrieve sensitive configuration data through unencrypted web…
OHIF DICOM Viewer SSRF Flaw Exposes Clinician Auth Tokens
A server-side request forgery vulnerability in OHIF Viewers DICOM versions up to 3.12.0 can leak authenticated OIDC Bearer tokens to attacker-controlled servers…