CVE-2025-54988 Apache Tika PDF parser module: XXE vulnerability in PDFParser’s handling of XFA

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA fi ...

Continue Reading
Linux Distros Unpatched Vulnerability : CVE-2023-1428

The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. There exists an vulnerability causing an abort() to be called in ...

Continue Reading
Exploit for Code Injection in Apache Rocketmq

Apache RocketMQ [![Build Status][maven-build-image]][maven-build-url] [![CodeCov][codecov-image]][codecov-url] [![Maven Central][maven-central-image]][maven-central-url] [![Release][release-image]][re ...

Continue Reading
Exploit for Path Traversal in Apache Dolphinscheduler

Dolphin Scheduler Official Website dolphinscheduler.apache.org ============ Design Features DolphinScheduler is a distributed and extensible workflow scheduler platform with powerful DAG visu ...

Continue Reading
Exploit for Code Injection in Apache Rocketmq

Apache RocketMQ Apache RocketMQ is a distributed messaging and streaming platform with low latency, high performance and reliability, trillion-level capacity and flexible scalability. It offe ...

Continue Reading
PT-2025-32984 · Http/2 +1 · Http/2 +1

Name of the Vulnerable Software and Affected Versions: HTTP/2 implementations (affected versions not specified) AMPHP Apache Tomcat Eclipse Foundation F5 Fastly gRPC Mozilla Netty Suse Linux Varnish S ...

Continue Reading
Security update for Multi-Linux Manager Client Tools

This update fixes the following issues: golang-github-prometheus-prometheus was updated to version 2.53.4: Security issues fixed: CVE-2023-45288: Require Go >= 1.23 for building (bsc#1236516) ...

Continue Reading
HTTP/2 implementations are vulnerable to “MadeYouReset” DoS attack through HTTP/2 control frames

Overview A vulnerability has been discovered within many HTTP/2 implementations allowing for denial of service (DoS) attacks through HTTP/2 control frames. This vulnerability is colloquially known as ...

Continue Reading

Back to Main

Subscribe for the latest news: