GiveWP flaw opens server to unauthenticated takeover
A critical GiveWP plugin bug chains three issues, letting attackers run commands on WordPress servers with no account needed.
30 results for “cve”
A critical GiveWP plugin bug chains three issues, letting attackers run commands on WordPress servers with no account needed.
PaperCut Software warns of exploited zero-day in NG/MF, releases emergency patch and IoCs.
A 9.8-rated flaw chain in the Avada WordPress theme lets unauthenticated attackers run PHP code.
Critical MiniOrange SAML SSO flaws exploited in wild; silent patch raises risk for WordPress sites.
Threat actors compromised over 270 Zimbra instances in ongoing RCE attacks, prompting CISA to order urgent patching.
CISA adds CVE-2026-21962 to KEV catalog, citing active exploitation and urging federal agencies to patch by August 27.
CVE-2026-18963 allows full account takeover via reset flow; patches out.
Broadcom patches 91 Spring vulnerabilities, with one critical flaw exposing LDAP servers to attack.
GitLab's CVE-2026-19478 is under active exploitation, days after disclosure, urging immediate patching.
Two flaws in JFrog Artifactory could let low-privileged users tamper with package metadata and compromise software supply chains.
Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.
CISA adds four actively exploited vulnerabilities affecting macOS, SharePoint, vCenter, and Windows IKE to its KEV catalog.
Attackers are exploiting critical MLflow and FUXA vulnerabilities to steal cloud credentials and execute code.
CISA orders federal agencies to fix actively exploited Ray bug in 3 days, citing unique risk.
CISA confirms ransomware gangs are exploiting a Windows Task Host privilege escalation flaw added to KEV in April.
A critical GitLab vulnerability could let unauthenticated attackers modify or delete public projects and user data.
CVE-2026-15826 in User Profile Builder exposes 40,000+ WordPress sites to admin takeover.
GE and Philips confirm probing Clop breach claims as the gang's PTC Windchill attacks ripple through enterprise giants.
A high-severity macOS bug is under attack, with hackers placing Monero miners via port 5900.
Adobe Commerce bug CVE-2026-71362 was exploited within hours of disclosure; Sansec reports active attacks.
Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.
Threat actors are exploiting a critical SharePoint authentication bypass after Rapid7 released a PoC exploit.
A researcher's PoC bypasses Microsoft's Defender patch, granting system-level access to attackers with initial foothold.
Attacks exploiting CVE-2026-59310 target hundreds of victims, deploying reverse_ssh for persistent access.
A high-severity ASA and FTD vulnerability is being exploited to crash devices remotely; hot fixes are available.
August's Patch Tuesday addresses 398 vulnerabilities, including an actively exploited zero-day, as AI-driven discovery swells update volumes.
Microsoft's August Patch Tuesday fixes 421 CVEs, including one exploited zero-day and two publicly disclosed flaws.
Researchers chain AI-found flaws to gain admin on SharePoint servers, bypassing authentication entirely.
CISA adds CVE-2026-45659 to KEV catalog, confirming ransomware abuse of a Microsoft SharePoint RCE flaw.