Critical Buffer Overflow in TOTOLINK A3700R Router Web Interface Raises Security Concerns
This vulnerability was publicly disclosed on January 19, 2026 and is considered high severity, with a CVSS…
continue reading..
Critical Windows SMB Flaw Actively Exploited: CVE-2025-33073 Allows Attackers to Gain SYSTEM-Level Access
CVE-2025-33073 is a high-severity privilege escalation vulnerability affecting the Windows Server Message Block (SMB) client. At its…
continue reading..
High-Risk Buffer Overflow Vulnerabilities Expose UTT 520W Devices to Remote Attacks
Product name: UTT 进取 (UTT) 520W (firmware v1.7.7-180627 reported as vulnerable)Product type: Small/branch router / firewall (embedded…
continue reading..
Microsoft Patches High-Risk Windows HTTP.sys Privilege Escalation Vulnerability (CVE-2026-20929)
CVE-2026-20929 is a high-impact elevation of privilege vulnerability affecting the HTTP.sys kernel driver in Microsoft Windows.The flaw…
continue reading..
Critical WordPress Plugin Flaw Allows Attackers to Gain Full Admin Access Without Authentication (CVE-2025-15403)
CVE-2025-15403 is a critical privilege escalation vulnerability affecting the RegistrationMagic plugin used on WordPress sites.The flaw allows…
continue reading..
Critical WordPress WooCommerce Plugin Flaw Allows Full Account Takeover Without Login
CVE-2025-10484 is a critical authentication bypass vulnerability affecting a WordPress plugin used for mobile-number-based registration and login…
continue reading..
Critical Windows Security Vulnerabilities: LSASS Remote Code Execution and VBS Enclave Privilege Escalation (CVE-2026-20854 & CVE-2026-20876)
CVE-2026-20854 affects the Windows Local Security Authority Subsystem Service (LSASS), a critical process responsible for handling user…
continue reading..
Critical Windows Kernel Privilege Escalation via Graphics Component Use-After-Free (CVE-2026-20822)
Product Name: Microsoft WindowsAffected Component: Windows Graphics Component (Microsoft Graphics Kernel Subsystem)Vulnerability Type: Elevation of Privilege (Use-After-Free)Attack…
continue reading..
Critical Microsoft Office Remote Code Execution Vulnerabilities in Word and Excel (CVE-2026-20944, CVE-2026-20955, CVE-2026-20957)
CVE-2026-20944, CVE-2026-20955, and CVE-2026-20957 are critical remote code execution vulnerabilities affecting Microsoft Word and Microsoft Excel, posing…
continue reading..
