code-injection
116 articles with this tag
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
MEDIUM
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
MEDIUM
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
CRITICAL
A hacker group is poisoning open source code at an unprecedented scale
First Shai-Hulud Worm Clones Emerge
Analysis reveals concerning features in official White House app
How to exfiltrate data using only numeric outputs
CVE-2026-39881 Vim Ex command injection in Vims NetBeans integration
CVE-2026-33940 Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
CVE-2026-33941 Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
Hackers exploit a critical Flowise flaw affecting thousands of AI workflows
OpenAI Codex: How a Branch Name Stole GitHub Tokens
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
CISA Adds Five Known Exploited Vulnerabilities to Catalog
Schneider Electric EcoStruxure Automation Expert
Siemens SIMATIC
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains Part 2
Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability
Claude collaboration tools left the door wide open to remote code execution
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
SAP Security Patch Day Fixes Critical Code Injection Flaw in SAP CRM and S/4HANA
SAP Security Patch Day - Critical SAP CRM and SAP S/4HANA Code Injection Vulnerabilities Fixed
NCSC-2026-0052 [1.00] [M/H] Kwetsbaarheden verholpen in SAP producten
From Clawdbot to Moltbot to OpenClaw: Security Experts Detail Critical Vulnerabilities and 6 Immediate Hardening Steps for the Viral AI Agent
USN-8004-1: FreeRDP vulnerabilities
Ivanti’s EPMM is under active attack, thanks to two critical zero-days
GlassWorm Malware Returns to Shatter Developer Ecosystems
Docker Fixes Critical Ask Gordon AI Flaw Allowing Code Execution via Image Metadata
Hundreds of Malicious Crypto Trading Addons Found in Moltbot/OpenClaw
DockerDash Exposes AI Supply Chain Weakness In Docker's Ask Gordon
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package
Hackers exploit critical React Native Metro bug to breach dev systems
Hackers exploit critical React Native Metro bug to breach dev systems
Vulnerability Allows Hackers to Hijack OpenClaw AI Assistant
Critical React Native Vulnerability Exploited in the Wild
USN-7995-1: OpenJDK 25 vulnerabilities
USN-7996-1: CRaC JDK 25 vulnerabilities
USN-7998-1: OpenJDK 17 vulnerabilities
Notepad++ infrastructure hijacked by Chinese APT in sophisticated supply chain attack
USN-8000-1: OpenJDK 8 vulnerabilities
USN-8001-1: OpenJDK 11 vulnerabilities
USN-8002-1: OpenJDK 21 vulnerabilities
USN-8003-1: CRaC JDK 21 vulnerabilities
RedHat Linux Kernel Multiple Vulnerabilities
OpenSSL Multiple Vulnerabilities
Chinese Hackers Hijack Notepad++ Updates for 6 Months
Notepad++ users take note: It's time to check if you're hacked
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link
Notepad++ update feature hijacked by Chinese state hackers for months
OpenClaw patches one-click RCE as security Whac-A-Mole continues
Critical Ivanti Endpoint Manager Mobile (EPMM) zero-day exploited in the wild (CVE-2026-1281 & CVE-2026-1340)
How state-sponsored attackers hijacked Notepad++ updates
Critical RCE bugs expose the n8n automation platform to host‑level compromise
Ivanti patches two actively exploited critical vulnerabilities in EPMM
175,000 Exposed Ollama Hosts Could Enable LLM Abuse
GLSA 202601-01: inetutils: Remote Code Execution
GLSA 202601-02: Vim, gVim: Multiple Vulnerabilities
GLSA 202601-03: GIMP: Arbitrary Code Execution
GLSA 202601-04: Asterisk: Multiple Vulnerabilities
GLSA 202601-05: Commons-BeanUtils: Arbitary Code Execution
VU#244846: Server-Side Template Injection (SSTI) vulnerability exist in Genshi
VU#818729: Safetica contains a kernel driver vulnerability
VU#458022: Open5GS WebUI uses a hard-coded secrets including JSON Web Token signing key
VU#102648: Code injection vulnerability in binary-parser library
AI Coding Assistants Secretly Copying All Code to China
vr2jb: Pwning the PlayStation VR2 using Sony's hidden recovery mode
Zoom Products Remote Code Execution Vulnerability
VMWare Products Multiple Vulnerabilities
Microsoft & Anthropic MCP Servers at Risk of RCE, Cloud Takeovers
Vulnerabilities Threaten to Break Chainlit AI Framework
'Contagious Interview' Attack Now Delivers Backdoor Via VS Code
Exploited Zero-Day Flaw in Cisco UC Could Affect Millions
Another week, another emergency patch as Cisco plugs Unified Comms zero-day
Ancient telnet bug happily hands out root to attackers
Patch or die: VMware vCenter Server bug fixed in 2024 under attack today
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access
CISA Updates KEV Catalog with Four Actively Exploited Software Vulnerabilities
TP-Link Router Multiple Vulnerabilities
Google Chrome Remote Code Execution Vulnerability
Aruba Product Multiple Vulnerabilities
SolarWinds Web Help Desk Multiple Vulnerabilities
Microsoft Edge Remote Code Execution Vulnerability
Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529
Microsoft Rushes Emergency Patch for Office Zero-Day
Months After Patch, WinRAR Bug Poised to Hit SMBs Hardest
Second Round of Critical RCE Bugs in n8n Spikes Corporate Risk
Case study: Securing AI application supply chains
"Open sesame": Critical vulnerabilities in dormakaba physical access control system enable unlocking arbitrary doors
Bypassing Windows Administrator Protection
OpenSSL January 2026 Security Update: CMS and PKCS#12 Buffer Overflows
CVE-2025-40551: SolarWinds WebHelpDesk RCE Deep-Dive and Indicators of Compromise
Gakido - CRLF Injection
Fun RCE in Command & Conquer: Generals
How We Exploited Qodo: From a PR Comment to RCE and an AWS Admin Key - Leaked Twice
1-Click RCE in OpenClaw/Moltbot/ClawdBot
CVE-2020-36952: IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to ...
CVE-2026-1284: An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawin...
CVE-2026-1283: A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS e...
CVE-2026-1429: Single Sign-On Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerabil...
Office zero-day exploited in the wild forces Microsoft OOB patch
Fortinet unearths another critical bug as SSO accounts borked post-patch