Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.
Some $6 million reached Ethereum before validators froze the chain, stranding the rest on a network that still is not ...
A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object ...
A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others ...
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates ...
Once attackers recovered the AES key, they could complete the G1’s Bluetooth application-level handshake and send Wi-Fi configuration commands. Researchers found that the robot’s Wi-Fi setup script ...
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary ...
CISA added Gitea flaw CVE-2026-60004 to its KEV catalog, confirming active exploitation of the self-hosted Git service.