Latest CVE Feed
-
7.7
HIGHCVE-2022-20920
A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptiona... Read more
- EPSS Score: %0.24
- Published: Oct. 10, 2022
- Modified: Aug. 01, 2025
-
5.4
MEDIUMCVE-2025-20129
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to impro... Read more
- Published: Jun. 04, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-30164
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that... Read more
Affected Products : icinga_web_2- Published: Mar. 26, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-20209
A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent an affected device from processing any control plane UDP packets. This vulnerability is du... Read more
- Published: Mar. 12, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-25293
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. Prior to versions 1.12.4 and 1.18.0, ruby-saml is susceptible to remote Denial of Service (DoS) with compressed SAML responses. ruby-saml uses zlib to decompress S... Read more
- Published: Mar. 12, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-8292
Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-43229
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.6, Safari 18. 6. Processing maliciously crafted web content may lead to universal cross site scripting.... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Cross-Site Scripting
-
4.0
MEDIUMCVE-2025-43230
The issue was addressed with additional permissions checks. This issue is fixed in iPadOS 17.7.9, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. An app may be able to access user-sensitive data.... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-43232
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Ventura 13.7.7, macOS Sonoma 14.7.7. An app may be able to bypass certain Privacy preferences.... Read more
Affected Products : macos- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-43234
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in watchOS 11.6, iOS 18.6 and iPadOS 18.6, tvOS 18.6, macOS Sequoia 15.6, visionOS 2.6. Processing a maliciously crafted texture may lead to unexpected ap... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-43233
This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A malicious app acting as a HTTPS proxy could get access to sensitive user data.... Read more
Affected Products : macos- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-43235
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-service.... Read more
Affected Products : macos- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-43237
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause unexpected system termination.... Read more
Affected Products : macos- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2025-43239
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. Processing a maliciously crafted file may lead to unexpected app termination.... Read more
Affected Products : macos- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2025-43240
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, Safari 18. 6. A download's origin may be incorrectly associated.... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-43241
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Ventura 13.7.7, macOS Sonoma 14.7.7. An app may be able to read files outside of its sandbox.... Read more
Affected Products : macos- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
4.6
MEDIUMCVE-2025-43259
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker with physical access to a locked device may be able to view sensitive user informa... Read more
Affected Products : macos- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Information Disclosure
-
5.1
MEDIUMCVE-2025-43260
This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to hijack entitlements granted to other privileged apps.... Read more
Affected Products : macos- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-43261
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.... Read more
Affected Products : macos- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2025-43265
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may disclose internal s... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Information Disclosure