A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The...
Vous n'êtes pas connecté
Maroc - THECYBERTHRONE.IN - A La Une - 20/12/2024 17:05
Sophos released patches for three critical security vulnerabilities in their widely-used network security tool, Sophos Firewall that posed significant risks, including remote code execution and privilege escalation. CVE-2024-12727: Pre-Authentication SQL Injection This vulnerability with a CVSS score of 9.8 involves the email protection feature of Sophos Firewall. If a specific configuration of Secure PDF eXchange […]
A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The...
The CyberArk Labs team have identified Apache bRPC users are exposed to a critical command injection flaw in the /pprof/heap endpoint...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog. The U.S....
SmarterTools fixed two SmarterMail flaws, including a critical bug (CVE-2026-24423) that could allow arbitrary code execution. SmarterTools fixed two...
BeyondTrust has disclosed a critical pre-authentication remote code execution vulnerability affecting its Remote Support (RS) and Privileged Remote...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly disclosed vulnerability CVE‑2025‑40551 affecting SolarWinds...
Fortinet released fixes for a critical FortiOS SSO auth bypass (CVE-2026-24858) actively exploited, impacting FortiOS, FortiManager, and...
The Django Software Foundation has issued emergency security patches addressing six critical vulnerabilities affecting multiple versions of the...
The four critical flaws could be exploited without authentication for remote code execution or authentication bypass. The post SolarWinds Patches...
Multiple critical security vulnerabilities have recently been disclosed in React Server Components, enabling threat actors to launch Denial-of-Service...