Security Bulletin: Vulnerability in GNOME libsoup affects IBM watsonx Assistant for IBM Cloud Pak for Data

Summary A potential vulnerability in GNOME libsoup has been identified that affects IBM watsonx Assistant for IBM Cloud Pak for Data. The vulnerability have been addressed. Refer to details for additi ...

Continue Reading
Remote Code Execution (RCE)

Vitest is vulnerable to Remote Code Execution (RCE). The vulnerability is due to the WebSocket server not validating the Origin header and lacking an authorization mechanism, allowing an attacker to i ...

Continue Reading
CVE-2025-24964 Remote Code Execution when accessing a malicious website while Vitest API server is listening

Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site We ...

Continue Reading
About Authentication Bypass – FortiOS (CVE-2024-55591) vulnerability

About Authentication Bypass - FortiOS (CVE-2024-55591) vulnerability. A critical flaw allows remote attackers to gain super-admin privileges via crafted requests to the Node.js websocket module. Affec ...

Continue Reading
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

Summary Arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks. Details When api option is enabled (V ...

Continue Reading
CVE-2025-24964

Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site We ...

Continue Reading
CVE-2025-24964

Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site We ...

Continue Reading
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

Summary Arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks. Details When api option is enabled (V ...

Continue Reading

Back to Main

Subscribe for the latest news: