Opening a File Is Enough: High-Risk Adobe Substance 3D Flaws Enable Silent Code Execution
High Severity | Code Execution Risk Vendor: AdobeAffected Product Line: Adobe Substance 3DVulnerability Type: Out-of-Bounds Write →…
continue reading..
CVE-2025-66169: Apache Camel Neo4j Cypher Injection Enables Unauthorized Graph Manipulation
CVE-2025-66169 — Apache Camel (camel-neo4j) — Cypher Injection CVE Identifier: CVE-2025-66169Vulnerability Type: Cypher InjectionSeverity: MediumCVSS Score: Medium…
continue reading..
CVE-2025-33206: High-Risk Command Injection Flaw in NVIDIA Nsight Graphics (Linux)
Executive Summary CVE-2025-33206 is a high-severity command injection vulnerability affecting NVIDIA Nsight Graphics on Linux platforms. The…
continue reading..
CVE-2026-23492: High-Risk Blind SQL Injection in Pimcore Admin Search Allows Database Data Exposure
Quick Facts Overview — What Happened? Pimcore includes an admin search feature that lets authenticated users query…
continue reading..
CVE-2026-23477: OAuth Client Secrets Exposure Allows Unauthorized App Impersonation in Rocket.Chat
CVE ID: CVE-2026-23477Affected Product: Rocket.Chat (prior to version 6.12.0)Severity: HighCVSS v3.1 Score: 7.7 (High)Impact: Disclosure of OAuth…
continue reading..
CVE-2026-0976: Keycloak Proxy Filter Bypass via URL Parsing Mismatch
CVE ID: CVE-2026-0976Product: KeycloakVulnerability Type: Proxy Filter Bypass / URL Parsing MismatchSeverity: High (Context-dependent)CVSS v3.1 Score: 3.7…
continue reading..
CVE-2026-23512: One Click, One Binary — How a Hidden Search Path Flaw in SumatraPDF Can Hand Over Code Execution
CVE ID: CVE-2026-23512Severity: HighCVSS Score: ~8.6Type: Local Remote Code Execution (RCE) via Untrusted Search PathExploitability: Requires local…
continue reading..
CVE-2026-0600 & CVE-2026-0601: Dual High-Risk Flaws in Sonatype Nexus Expose Internal Networks and Admin Sessions
Product overview Product: Sonatype Nexus Repository Manager 3Vendor: SonatypeWhat it does: Nexus Repository is widely used to…
continue reading..
CVE-2026-23550: Critical Modular DS Flaw Allows Unauthenticated Admin Takeover
CVE-2026-23550 — Modular DS CVE ID: CVE-2026-23550Product: Modular DS (also known as Modular Connector for WordPress)Vulnerability Type:…
continue reading..
