vulnerabilities
Every CVE worth your attention, scored and explained.
Tracked, triaged, and written up the moment they matter — with exploit status, affected versions, and what to patch first.
Chrome V8 zero-day exploited in the wild — patch now
A type-confusion bug in V8's JIT compiler allows remote code execution via a crafted web page. Active exploitation confirmed.
Record Patch Tuesday: 206 flaws fixed, including three zero-days
This month's update addresses a record number of vulnerabilities, with three under active exploitation and one critical RCE in a core service.
Critical Splunk-style flaw lets attackers run code without authentication
An unauthenticated deserialization flaw in a popular log management platform allows full remote code execution on the management node.
'usbliter8' breaks Apple A12 and A13 Secure Boot ROM chain
A boot-ROM exploit achieves arbitrary code execution at the hardware root of trust. Because the flaw lives in silicon, no software patch can fully close it.
AutoJack flaw lets a web page hijack an AI browsing agent
A prompt-injection chain embedded in page content can redirect an autonomous browsing agent into executing code on the host machine.
Minor information disclosure fixed in popular CMS plugin
A low-severity flaw allowed limited metadata disclosure under specific misconfigurations. A patch is available and adoption is now over 80%.