Remote Code Execution Vulnerability

A Remote Code Execution (RCE) vulnerability is a security flaw that allows an attacker to execute arbitrary code on a remote computer or server over a network, without having physical access to the system. This type of vulnerability is particularly dangerous because it enables attackers to potentially take full control of the affected system, install malware, steal data, or perform other malicious actions.

RCE vulnerabilities are often exploited through weaknesses in software applications, operating systems, or network services, such as buffer overflows, SQL injection, or command injection. They are highly critical because they can be used to compromise systems and networks quickly and remotely.

NewsSecurity Vulnerabilities

Synology BeeStation BST150-4T Unnecessary Privileges Remote Code Execution Vulnerability (CVE-2024-10445)

CVE number = CVE-2024-10445 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology BeeStation BST150-4T

Read More
NewsSecurity Vulnerabilities

Apache ActiveMQ NMS Body Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-29953)

CVE-2025-29953 – This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apache ActiveMQ NMS.

Read More
NewsSecurity Vulnerabilities

Unauthenticated Remote Code Execution in Erlang/OTP SSH (CVE-2025-32433)

A serious vulnerability (CVE-2025-32433) has been identified in the Erlang/OTP SSH server that may allow an attacker to perform unauthenticated remote code execution (RCE).

Read More
NewsSecurity Vulnerabilities

Multiple Cisco Products Unauthenticated Remote Code Execution in Erlang/OTP SSH Server (CVE-2025-32433)

On April 16th 2025, a critical vulnerability in the Erlang/OTP SSH server was disclosed. This vulnerability could allow an unauthenticated, remote attacker to perform remote code execution (RCE) on an affected device.

Read More
NewsSecurity Vulnerabilities

Cisco Webex App Client-Side Remote Code Execution Vulnerability (CVE-2025-20236)

A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the targeted user.

Read More
NewsSecurity Vulnerabilities

Autodesk Navisworks Freedom DWFX File Parsing Memory Corruption Remote Code Execution Vulnerability (CVE-2025-1660)

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk Navisworks Freedom.

Read More
NewsSecurity Vulnerabilities

BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability (CVE-2025-2773)

CVE number – CVE-2025-2773 This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers.

Read More
NewsSecurity Vulnerabilities

Apple macOS MOV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2025-24124)

CVE-2025-24124 – This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS.

Read More
NewsSecurity Vulnerabilities

Remote code execution when loading a crafted GraphQL schema (CVE-2025-27407)

Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution.

Read More
NewsSecurity Vulnerabilities

Trimble SketchUp SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability (CVE-2025-2024)

CVE-2025-2024 – This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp.

Read More