web-security
77 articles with this tag
HIGH
CRITICAL
HIGH
CRITICAL
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
INFO
CRITICAL
MEDIUM
MEDIUM
MEDIUM
LOW
HIGH
CRITICAL
HIGH
CRITICAL
MEDIUM
MEDIUM
HIGH
MEDIUM
HIGH
MEDIUM
INFO
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
INFO
MEDIUM
INFO
HIGH
HIGH
CRITICAL
MEDIUM
CRITICAL
HIGH
INFO
MEDIUM
MEDIUM
INFO
MEDIUM
HIGH
CRITICAL
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
MEDIUM
MEDIUM
CRITICAL
HIGH
MEDIUM
CRITICAL
MEDIUM
MEDIUM
CRITICAL
MEDIUM
MEDIUM
MEDIUM
MEDIUM
INFO
INFO
MEDIUM
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
[webapps] Marimo 0.20.4 - RCE
GiveWP WordPress donation plugin flaw lets hackers execute server commands
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Claude, Codex, and Hermes installed unowned code inside corporate networks
[NEU] [hoch] CKAN: Mehrere Schwachstellen
NCSC-2026-0331 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic
DSA-6456-1 spip - security update
Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability
CVE-2023-21806 Power BI Report Server Spoofing Vulnerability
CVE-2024-43612 Power BI Report Server Spoofing Vulnerability
CVE-2024-43481 Power BI Report Server Spoofing Vulnerability
The future of AI security research isn’t autonomous, it’s human-amplified
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
I made a full JWT hacking tutorial + testing suite
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
Multiples vulnérabilités dans Traefik (04 août 2026)
Johnson Controls OpenBlue Employee
Multiples vulnérabilités dans Microsoft Edge (27 juillet 2026)
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
[NEU] [mittel] Drupal Module: Mehrere Schwachstellen
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Intruder brings AI-powered, on-demand penetration testing to web applications
[NEU] [mittel] Drupal Core: Mehrere Schwachstellen
CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability
Header injection in Web Filter warning page
SSL-VPN Reflected XSS
[UPDATE] [mittel] Joomla: Mehrere Schwachstellen
Cloudflare teams up with big browsers to help websites tell bots from people
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilities
Cisco Webex App Open Redirect Vulnerability
[NEU] [mittel] Octopus Deploy: Schwachstelle ermöglicht Cross-Site Scripting
Toshiba and Muji warn of fake login screens from polyfill.io
[NEU] [hoch] VMware Cloud Foundation Operations: Mehrere Schwachstellen ermöglichen Cross-Site Scripting
Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS
Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js
WP Engine adds bot management to Global Edge Security
CVE-2026-27142 URLs in meta content attribute actions are not escaped in html/template
Fingerprint launches AI assistant detection tools
NCSC-2026-0171 [1.00] [H/M] Kwetsbaarheid verholpen in Starlette
Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment
Drupal: Critical SQL injection flaw now targeted in attacks
USN-8272-1: Smarty vulnerability
Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare
BWH Hotels confirms cyberattack impacting customer data
Juice Shop v20.0.0 — a fresh squeeze of features, now with AI
[NEU] [mittel] Kyverno: Schwachstelle ermöglicht Cross-Site Scripting
[NEU] [mittel] Pega Platform: Schwachstelle ermöglicht Cross-Site Scripting
CVE-2026-32207 Azure Machine Learning Notebook Spoofing Vulnerability
[webapps] Python-Multipart 0.0.22 - Path Traversal
Why are top university websites serving porn? It comes down to shoddy housekeeping.
Zimbra Collaboration Suite Information Disclosure Vulnerability
Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities
Cisco Unity Connection Arbitrary File Download Vulnerabilities
Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
Cisco Webex Contact Center Cross-Site Scripting Vulnerability
WordPress plugin suite hacked to push malware to thousands of sites
Critical nginx UI tool vulnerability opens web servers to full compromise
Medusa Ransomware Attack
European Commission admits attackers broke into public web systems, but says little else
[NEU] [mittel] Cisco Catalyst SD-WAN Manager: Schwachstelle ermöglicht Cross-Site Scripting
[NEU] [mittel] SolarWinds Platform: Mehrere Schwachstellen ermöglichen Cross-Site Scripting
Magento PolyShell – Unauthenticated File Upload to RCE in Magento (APSB25-94)
WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
Schneider Electric Modicon Controllers M241, M251, M258, and LMC058
Claude Code Security and Magecart: Getting the Threat Model Right
[NEU] [UNGEPATCHT] [mittel] NetBox: Schwachstelle ermöglicht Cross-Site Scripting
Multiple Cisco Contact Center Products Cross-Site Scripting Vulnerabilities
[NEU] [hoch] Siemens SIMATIC S7: Schwachstelle ermöglicht Cross-Site Scripting
[NEU] [mittel] Drupal Extensions: Mehrere Schwachstellen
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Cross-Site Scripting Vulnerability
Cisco Webex Services Cross-Site Scripting Vulnerability
Multiples vulnérabilités dans MISP (02 mars 2026)
Fedora 42 Update: vim-9.1.1706-1.fc42 - package-announce - Fedora mailing-lists
Battling bots face off in cybersecurity arena
Dark Patterns Undermine Security One Click at a Time