#remote-code-execution

[ follow ]
#vulnerability
Web frameworks
fromTechRepublic
1 month ago

Stealthy Apache Tomcat Critical Exploit Bypasses Security Filters

Apache Tomcat is vulnerable to remote code execution attacks due to a recently disclosed vulnerability, CVE-2025-24813.
Java
fromCSO Online
3 weeks ago

Big hole in big data: Critical deserialization bug in Apache Parquet allows RCE

A vulnerability in the Parquet-avro module of a Java library could allow remote code execution through crafted files.
Information security
fromTheregister
3 months ago

Attackers are popping clouds using severe Aviatrix bug

The vulnerability in Aviatrix Controller poses critical risks, leading to remote code execution and privilege escalation, with active exploits already observed.
Information security
fromThe Hacker News
8 months ago

GiveWP WordPress Plugin Vulnerability Puts 100,000+ Websites at Risk

A critical vulnerability in the GiveWP plugin could expose over 100,000 websites to remote code execution attacks, necessitating an urgent update.
fromSecuritymagazine
1 day ago
Information security

Commvault Command Center has a critical security flaw

Commvault Command Center has a severe security flaw allowing potential remote code execution.
Web frameworks
fromTechRepublic
1 month ago

Stealthy Apache Tomcat Critical Exploit Bypasses Security Filters

Apache Tomcat is vulnerable to remote code execution attacks due to a recently disclosed vulnerability, CVE-2025-24813.
Java
fromCSO Online
3 weeks ago

Big hole in big data: Critical deserialization bug in Apache Parquet allows RCE

A vulnerability in the Parquet-avro module of a Java library could allow remote code execution through crafted files.
Information security
fromTheregister
3 months ago

Attackers are popping clouds using severe Aviatrix bug

The vulnerability in Aviatrix Controller poses critical risks, leading to remote code execution and privilege escalation, with active exploits already observed.
Information security
fromThe Hacker News
8 months ago

GiveWP WordPress Plugin Vulnerability Puts 100,000+ Websites at Risk

A critical vulnerability in the GiveWP plugin could expose over 100,000 websites to remote code execution attacks, necessitating an urgent update.
fromSecuritymagazine
1 day ago
Information security

Commvault Command Center has a critical security flaw

Commvault Command Center has a severe security flaw allowing potential remote code execution.
more#vulnerability
#security-vulnerability
Information security
fromTheregister
4 months ago

Critical Apache Struts bug under active exploit

Critical security flaw in Apache Struts 2 allows file upload manipulation, posing severe risks of remote code execution; immediate updates are essential.
Information security
fromSecuritymagazine
1 week ago

Devices exposed to remote hacking via Erlang/OTP SSH vulnerability

Erlang/OTP's SSH implementation has a critical vulnerability allowing remote code execution without authentication, requiring urgent attention and action from security teams.
Information security
fromTheregister
7 months ago

Doomsday 9.9 unauthenticated RCE bug affects all Linux

A critical 9.9-rated unauthenticated RCE flaw is affecting GNU/Linux systems, with no fix yet despite disclosure to developers three weeks ago.
fromThe Hacker News
3 months ago
Information security

Meta's Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks

A high-severity vulnerability in Meta's Llama framework could allow remote code execution via deserialization of untrusted data.
fromThe Hacker News
3 weeks ago
Java

Critical Flaw in Apache Parquet Allows Remote Attackers to Execute Arbitrary Code

A critical security vulnerability in Apache Parquet allows remote code execution, affecting versions up to 1.15.0.
fromTechzine Global
5 days ago
Information security

Commvault vulnerability poses serious risk to company data

Commvault's Command Center has a serious vulnerability (CVE-2025-34028) that allows remote code execution.
Organizations must ensure their systems are updated to version 11.38.20 to mitigate the risk.
Information security
fromTheregister
4 months ago

Critical Apache Struts bug under active exploit

Critical security flaw in Apache Struts 2 allows file upload manipulation, posing severe risks of remote code execution; immediate updates are essential.
Information security
fromSecuritymagazine
1 week ago

Devices exposed to remote hacking via Erlang/OTP SSH vulnerability

Erlang/OTP's SSH implementation has a critical vulnerability allowing remote code execution without authentication, requiring urgent attention and action from security teams.
Information security
fromTheregister
7 months ago

Doomsday 9.9 unauthenticated RCE bug affects all Linux

A critical 9.9-rated unauthenticated RCE flaw is affecting GNU/Linux systems, with no fix yet despite disclosure to developers three weeks ago.
fromThe Hacker News
3 months ago
Information security

Meta's Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks

A high-severity vulnerability in Meta's Llama framework could allow remote code execution via deserialization of untrusted data.
fromThe Hacker News
3 weeks ago
Java

Critical Flaw in Apache Parquet Allows Remote Attackers to Execute Arbitrary Code

A critical security vulnerability in Apache Parquet allows remote code execution, affecting versions up to 1.15.0.
fromTechzine Global
5 days ago
Information security

Commvault vulnerability poses serious risk to company data

Commvault's Command Center has a serious vulnerability (CVE-2025-34028) that allows remote code execution.
Organizations must ensure their systems are updated to version 11.38.20 to mitigate the risk.
more#security-vulnerability
#vulnerabilities
Node JS
fromITPro
2 months ago

Flaws in a popular dev library could let hackers run malicious code in your MongoDB database

Two critical vulnerabilities in Mongoose could expose MongoDB databases to remote code execution attacks by hackers.
fromThe Hacker News
1 month ago
Information security

Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication

Critical vulnerabilities in Ingress NGINX Controller expose 6,500 Kubernetes clusters to remote code execution risks.
fromTechCrunch
6 months ago
Information security

CISA issues warning about another Ivanti flaw under active attack | TechCrunch

The U.S. government warns of active exploitation of Ivanti Endpoint Manager vulnerabilities.
fromComputerWeekly.com
6 months ago
Information security

Cups Linux printing bugs open door to DDoS attacks, says Akamai | Computer Weekly

CUPS vulnerabilities can lead to remote code execution and facilitate DDoS attacks.
Exploiting CUPS for DDoS requires minimal resources, making it appealing for attackers.
A crafted packet sent to a CUPS server can initiate a DDoS attack.
Exploiting these vulnerabilities could cost less than one cent on modern platforms.
fromTheregister
8 months ago
Information security

Google patches Quick Share for Windows to shut malware hole

Google's Quick Share for Windows had 10 now-fixed bugs, allowing remote code execution through a full RCE chain.
fromZero Day Initiative
7 months ago
JavaScript

Zero Day Initiative - Exploiting Exchange PowerShell After ProxyNotShell: Part 1 - MultiValuedProperty

The ProxyNotShell vulnerability chain illustrates that patches can be circumvented, allowing for potential attacks even after fixes are released.
Node JS
fromITPro
2 months ago

Flaws in a popular dev library could let hackers run malicious code in your MongoDB database

Two critical vulnerabilities in Mongoose could expose MongoDB databases to remote code execution attacks by hackers.
fromTechCrunch
6 months ago
Information security

CISA issues warning about another Ivanti flaw under active attack | TechCrunch

The U.S. government warns of active exploitation of Ivanti Endpoint Manager vulnerabilities.
fromComputerWeekly.com
6 months ago
Information security

Cups Linux printing bugs open door to DDoS attacks, says Akamai | Computer Weekly

CUPS vulnerabilities can lead to remote code execution and facilitate DDoS attacks.
Exploiting CUPS for DDoS requires minimal resources, making it appealing for attackers.
A crafted packet sent to a CUPS server can initiate a DDoS attack.
Exploiting these vulnerabilities could cost less than one cent on modern platforms.
fromTheregister
8 months ago
Information security

Google patches Quick Share for Windows to shut malware hole

Google's Quick Share for Windows had 10 now-fixed bugs, allowing remote code execution through a full RCE chain.
fromZero Day Initiative
7 months ago
JavaScript

Zero Day Initiative - Exploiting Exchange PowerShell After ProxyNotShell: Part 1 - MultiValuedProperty

The ProxyNotShell vulnerability chain illustrates that patches can be circumvented, allowing for potential attacks even after fixes are released.
more#vulnerabilities
#cybersecurity
Information security
fromThe Hacker News
4 months ago

Over 300K Prometheus Instances Exposed: Credentials and API Keys Leaking Online

Thousands of Prometheus servers lack proper authentication, risking data leakage, DoS, and remote code execution attacks due to their exposure on the internet.
fromThe Hacker News
1 month ago
Information security

Veeam and IBM Release Patches for High-Risk Flaws in Backup and AIX Systems

Veeam's Backup & Replication software has a critical RCE vulnerability fixed in the latest security update.
fromThe Hacker News
4 months ago
New York City

Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation

Sophos has patched critical vulnerabilities in its Firewall products to prevent remote code execution and privileged access.
Information security
fromThe Hacker News
4 months ago

Over 300K Prometheus Instances Exposed: Credentials and API Keys Leaking Online

Thousands of Prometheus servers lack proper authentication, risking data leakage, DoS, and remote code execution attacks due to their exposure on the internet.
fromThe Hacker News
1 month ago
Information security

Veeam and IBM Release Patches for High-Risk Flaws in Backup and AIX Systems

Veeam's Backup & Replication software has a critical RCE vulnerability fixed in the latest security update.
fromThe Hacker News
4 months ago
New York City

Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation

Sophos has patched critical vulnerabilities in its Firewall products to prevent remote code execution and privileged access.
more#cybersecurity
#security-vulnerabilities
fromComputerWeekly.com
7 months ago
Information security

Printing vulnerability affecting Linux distros raises alarm | Computer Weekly

The newly discovered vulnerabilities in Cups pose a significant security risk to numerous devices, potentially exposing them to remote code execution.
fromZDNET
2 months ago
Information security

Your Netgear Wi-Fi router could be wide open to hackers - install the fix now

Netgear has patched critical security vulnerabilities in several Wi-Fi routers and access points, urging timely updates for user safety.
fromTheregister
3 months ago
Information security

MediaTek says 'Happy New Year' with critical RCE, other bugs

MediaTek disclosed a critical vulnerability affecting 51 chipsets, posing severe security risks to multiple device categories.
fromComputerWeekly.com
7 months ago
Information security

Printing vulnerability affecting Linux distros raises alarm | Computer Weekly

The newly discovered vulnerabilities in Cups pose a significant security risk to numerous devices, potentially exposing them to remote code execution.
fromZDNET
2 months ago
Information security

Your Netgear Wi-Fi router could be wide open to hackers - install the fix now

Netgear has patched critical security vulnerabilities in several Wi-Fi routers and access points, urging timely updates for user safety.
fromTheregister
3 months ago
Information security

MediaTek says 'Happy New Year' with critical RCE, other bugs

MediaTek disclosed a critical vulnerability affecting 51 chipsets, posing severe security risks to multiple device categories.
more#security-vulnerabilities
Information security
fromTheregister
8 months ago

PoCcode released for zero-click Windows critical vuln

Windows users must install the latest patches swiftly to protect against CVE-2024-38063, a critical vulnerability that allows remote code execution.
[ Load more ]