FEED ACTIVE last sync Jul 28 · 11:48Z tracking 20 advisories LIVE
tech · ai · security

The signal, not the noise.

Auto-updated intelligence on technology, AI, and the latest disclosed security advisories. Pulled daily, ranked by what matters.

Critical Advisories

all CVEs →
— · — · CVSS 9.8 · Jul 28

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

NVD detail →
— · — · CVSS 9.8 · Jul 28

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the…

NVD detail →
apache · thrift · CVSS 9.8 · Jul 27

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

NVD detail →
n8n · n8n · CVSS 9.8 · Jul 22

n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any…

NVD detail →
— · — · CVSS 9.8 · Jul 21

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows…

NVD detail →
nlnetlabs · unbound · CVSS 9.3 · Jul 22

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port…

NVD detail →