Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Vulnerability Disclosure

20 articles

GBHackers Vulnerability Disclosure 6d ago

Claude Code Vulnerability Allows Attackers to Run Commands Through Crafted Deeplinks

A recently disclosed flaw in Claude Code allowed attackers to execute arbitrary system commands using a single crafted deeplink URL, turning a convenience fe...

T1190

GBHackers →

Security Affairs Vulnerability Disclosure May 17

Security Affairs newsletter Round 577 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Security Affairs →

Security Affairs Vulnerability Disclosure Oracle WordPress May 17

Attackers exploit Funnel Builder bug to inject e-skimmers into e-stores

Attackers are exploiting a critical flaw in the WordPress Funnel Builder plugin to inject skimming code into WooCommerce checkout pages. A critical vulnerabi...

Security Affairs →

BleepingComputer Vulnerability Disclosure Microsoft May 16

Microsoft rejects critical Azure vulnerability report, no CVE issued

A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and without issuing a CVE. Microsoft d...

BleepingComputer →

The Hacker News Vulnerability Disclosure Oracle WordPress May 16

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaSc...

The Hacker News →

SecurityWeek Vulnerability Disclosure F5 May 16

PoC Code Published for Critical NGINX Vulnerability

Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source. The post PoC Code Published for Critical...

SecurityWeek →

SC Media Vulnerability Disclosure Apple May 15

Researchers bypass Apple's M5 security with AI-powered macOS exploit

Researchers from Calif utilized Anthropic's Mythos Preview AI to chain two previously unknown bugs and several techniques, ultimately creating a functional e...

SC Media →

SC Media Vulnerability Disclosure WordPress May 15

WordPress Funnel Builder vulnerability exploited to steal payment data

The vulnerability in the Funnel Builder plugin, used by over 40,000 websites, allows unauthenticated attackers to modify global settings via an unprotected c...

SC Media →

BleepingComputer Vulnerability Disclosure Oracle WordPress May 15

Funnel Builder WordPress plugin bug exploited to steal credit cards

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce chec...

BleepingComputer →

The Hacker News Vulnerability Disclosure Amazon May 15

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and pers...

T1548 T1041

The Hacker News →

The Record Vulnerability Disclosure Cisco May 15

CISA orders all federal agencies to patch exploited bug in Cisco SD-WAN systems by Sunday

Cisco released a patch for the vulnerability on Thursday, writing in an advisory that it could “allow an unauthenticated, remote attacker to bypass authentic...

The Record →

GBHackers Vulnerability Disclosure Google Linux May 15

Google Project Zero Details Pixel 10 Zero-Click Exploit Chain

A powerful zero-click exploit chain for the Pixel 10 that can take an attacker from a remote Dolby decoding bug to full kernel control through a single vulne...

GBHackers →

GBHackers Vulnerability Disclosure Microsoft May 15

Hackers Exploit OAuth Device Flow to Steal Microsoft 365 Tokens

Hackers are rapidly weaponizing a little-known Microsoft authentication feature to hijack enterprise accounts, as device code phishing surges across the thre...

T1566

GBHackers →

CSO Online Vulnerability Disclosure Cisco May 15

Cisco warns of an actively exploited SD-WAN flaw with max severity

Cisco has disclosed a max-severity authentication bypass vulnerability affecting its Catalyst SD-WAN Controller and Catalyst SD-WAN Manager platforms, warnin...

T1556

CSO Online →

SC Media Vulnerability Disclosure Linux May 15

New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available

Fragnesia is at least the fourth privilege escalation flaw affecting Linux systems disclosed in the last three weeks.

T1548

SC Media →

GBHackers Vulnerability Disclosure Microsoft May 15

Microsoft Warns HPE Operations Agent Abused in Malware-Free Attacks

Microsoft has revealed a stealthy intrusion campaign where attackers bypassed traditional malware and exploits, instead abusing trusted enterprise tools to s...

GBHackers →

Help Net Security Vulnerability Disclosure Linux May 15

Rocky Linux launches opt-in security repository for urgent fixes

Rocky Linux has introduced a Security Repository that allows the distribution to ship urgent security fixes ahead of upstream Enterprise Linux when public ex...

Help Net Security →

GBHackers Vulnerability Disclosure May 15

TeamPCP Hackers Exploit CI/CD Pipelines to Steal Cloud Credentials

A financially motivated threat group known as TeamPCP is aggressively targeting modern software supply chains, abusing trusted CI/CD pipelines to steal sensi...

T1195

GBHackers →

GBHackers Vulnerability Disclosure May 15

Hackers Exploit Scheduled Tasks for Persistence in FrostyNeighbor Attacks

Hackers linked to the long-running FrostyNeighbor cyber‑espionage group have intensified attacks against Ukrainian government organizations, deploying update...

T1053

GBHackers →

Exploit Database Vulnerability Disclosure Microsoft May 15

[local] Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution

Remote Sunrise Helper for Windows 2026.

T1190

Exploit Database →

«Previous page 1 ... 3 4 5 6 7 ... 20 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA