New Unauthenticated DoS Vulnerability Crashes Next.js Servers with a Single Request
New Unauthenticated DoS Vulnerability Crashes Next.js Servers with a Single Request A newly discovered critical vulnerability in the Next.js framework allows attackers to crash self-hosted servers using a single HTTP request, requiring negligible resources to execute. Discovered by r … Read more Published Date: Nov 27, 2025 (2 hours, 57 minutes ago) Vulnerabilities has been mentioned in […]
CVE-2025-0658 – Automated Logic and Carrier Zone Controllers malformed packets denial of service
The following table lists the changes that have been made to the CVE-2025-0658 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
CVE-2024-5540 – ALC WebCTRL Carrier i-Vu Reflected Cross-Site Scripting
The following table lists the changes that have been made to the CVE-2024-5540 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
CVE-2025-0657 – ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range
The following table lists the changes that have been made to the CVE-2025-0657 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
CVE-2024-5539 – ALC WebCTRL Carrier i-Vu Access Control Bypass
The following table lists the changes that have been made to the CVE-2024-5539 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 27, 2025 Action […]
Critical Ray AI Flaw Exposes Devs via Safari & Firefox (CVE-2025-62593)
Critical Ray AI Flaw Exposes Devs via Safari & Firefox (CVE-2025-62593) A critical remote code execution (RCE) vulnerability has been discovered in the Ray framework, putting AI and Python developers at risk of having their systems compromised. The vulnerability, tracked … Read more Published Date: Nov 27, 2025 (2 hours, 34 minutes ago) Vulnerabilities has been mentioned […]
Water Gamayun Weaponizes “MSC EvilTwin” Zero-Day for Stealthy Backdoor Attacks
Water Gamayun Weaponizes “MSC EvilTwin” Zero-Day for Stealthy Backdoor Attacks A sophisticated new cyber espionage campaign has been uncovered by Zscaler Threat Hunting, revealing how a Russia-aligned Advanced Persistent Threat (APT) group known as Water Gamayun is weaponizing a … Read more Published Date: Nov 27, 2025 (2 hours, 41 minutes ago) Vulnerabilities has been mentioned in […]
Hidden Danger in 3D: Malicious Blender Files Unleash StealC V2 Infostealer
Hidden Danger in 3D: Malicious Blender Files Unleash StealC V2 Infostealer Morphisec has issued a critical alert regarding a sophisticated malware campaign targeting 3D artists, game developers, and hobbyists. For at least six months, threat actors have been weaponizing 3D m … Read more Published Date: Nov 27, 2025 (2 hours, 50 minutes ago) Vulnerabilities has been […]
Zero-Day Warning: Unpatched Twonky Server Flaws Expose Media to Total Takeover
Zero-Day Warning: Unpatched Twonky Server Flaws Expose Media to Total Takeover A critical security warning has been issued for users of Twonky Server, the popular media server software found on countless NAS devices and routers. In a concerning development, researchers at Rapid7 … Read more Published Date: Nov 27, 2025 (2 hours, 55 minutes ago) Vulnerabilities has […]
Angular Alert: Protocol-Relative URLs Leak XSRF Tokens (CVE-2025-66035)
Angular Alert: Protocol-Relative URLs Leak XSRF Tokens (CVE-2025-66035) The Angular team has issued a high-severity security advisory regarding a logic flaw in the framework’s HTTP Client that could render applications vulnerable to Cross-Site Request Forgery (CSRF) attac … Read more Published Date: Nov 27, 2025 (3 hours, 3 minutes ago) Vulnerabilities has been mentioned in this article. […]