CVE-2025-6505

Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine creden ...

Continue Reading
ROS-20250731-01

Vulnerability in the implementation of OAuth request signing logic for Python OAuthLib is due to insufficient user data validation in uri_validate functions. Exploitation of the vulnerability could al ...

Continue Reading
CVE-2025-54529

In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login...Read More ...

Continue Reading
Improper Authentication

goauthentik.io is vulnerable to improper authentication. The vulnerability is due to deactivated users who registered or linked accounts via OAuth/SAML retaining partial access, which allows an attack ...

Continue Reading
PT-2025-31201 · Progress · Hybrid Data Pipeline Server

Name of the Vulnerable Software and Affected Versions: Progress Software Hybrid Data Pipeline Server versions 4.6.2.3226 and below Description: The Hybrid Data Pipeline Server is susceptible to unauth ...

Continue Reading
mod_auth_openidc:2.3 security update

An update is available for module.cjose, module.mod_auth_openidc, mod_auth_openidc, cjose. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a det ...

Continue Reading
mod_auth_openidc:2.3 security update

An update is available for module.cjose, module.mod_auth_openidc, mod_auth_openidc, cjose. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a det ...

Continue Reading
Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44

Cybersecurity researchers have disclosed a now-patched critical security flaw in a popular vibe coding platform called Base44 that could allow unauthorized access to private applications built by its ...

Continue Reading

Back to Main

Subscribe for the latest news: