Latest CVE Feed
-
6.5
MEDIUMCVE-2025-31235
A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to cause unexpected system termination.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-31236
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-31237
This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Denial of Service
-
7.3
HIGHCVE-2025-31238
The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-31240
This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
-
5.3
MEDIUMCVE-2025-31241
A double free issue was addressed with improved memory management. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A remote attacker may ... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-26369
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add privileges to user groups via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2023-43652
JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a password or the corresponding SSH private key. An SSH public key should be consid... Read more
Affected Products : jumpserver- Published: Sep. 27, 2023
- Modified: May. 27, 2025
-
7.8
HIGHCVE-2023-29336
Win32k Elevation of Privilege Vulnerability... Read more
- Actively Exploited
- Published: May. 09, 2023
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2025-4632
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.... Read more
Affected Products : magicinfo_9_server- Actively Exploited
- Published: May. 13, 2025
- Modified: May. 27, 2025
- Vuln Type: Path Traversal
-
3.5
LOWCVE-2023-36479
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet... Read more
- Published: Sep. 15, 2023
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2022-29799
A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-d... Read more
Affected Products : windows_defender_for_endpoint- Published: Sep. 21, 2022
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2022-23951
In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.... Read more
Affected Products : keylime- Published: Sep. 21, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2022-23950
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.... Read more
Affected Products : keylime- Published: Sep. 21, 2022
- Modified: May. 27, 2025
-
7.5
HIGHCVE-2022-23949
In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier and registrar.... Read more
Affected Products : keylime- Published: Sep. 21, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2021-43310
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.... Read more
Affected Products : keylime- Published: Sep. 21, 2022
- Modified: May. 27, 2025
-
5.5
MEDIUMCVE-2025-31242
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access sensitive user data.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-31244
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-31245
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. An app may be able to cause unexpected system termination... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-31246
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption