Please turn on your JavaScript for this page to function normally.
ProjectDiscovery
Critical Next.js auth bypass vulnerability opens web apps to compromise (CVE-2025-29927)
A critical vulnerability (CVE-2025-29927) in the open source Next.js framework can be exploited by attackers to bypass authorization checks and gain unauthorized access to web …
Exploit code for critical GitLab auth bypass flaw released (CVE-2024-45409)
If you run a self-managed GitLab installation with configured SAML-based authentication and you haven’t upgraded it since mid-September, do it now, because security …
Critical Zimbra RCE vulnerability under mass exploitation (CVE-2024-45519)
Attackers are actively exploiting CVE-2024-45519, a critical Zimbra vulnerability that allows them to execute arbitrary commands on vulnerable installations. …
Featured news
Resources
Don't miss
- Pricing your bad days and how to build an economic model for security decisions
- Who watches the AI watching your street?
- How AI can fix cybersecurity compliance: From dashboards to continuous execution
- Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)
- SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)