Latest CVE Feed
-
7.1
HIGHCVE-2025-43263
The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.... Read more
Affected Products : xcode- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-43272
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, visionOS 26, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to an unexpected Safari crash.... Read more
- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2025-43279
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-24088
The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to override MDM-enforced settings from profiles.... Read more
Affected Products : macos- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Misconfiguration
-
4.0
MEDIUMCVE-2025-24133
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26 and iPadOS 26. Keyboard suggestions may display sensitive information on the lock screen.... Read more
- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-24197
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access sensitive user data.... Read more
Affected Products : macos- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-30468
This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessed without authentication.... Read more
- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-31254
This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may lead to unexpected URL redirection.... Read more
- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-31255
An authorization issue was addressed with improved state management. This issue is fixed in tvOS 26, macOS Sonoma 14.8, macOS Sequoia 15.7, watchOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to access sensitive user data.... Read more
- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-31268
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protected user data.... Read more
Affected Products : macos- Published: Sep. 15, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-34078
A local privilege escalation vulnerability exists in NSClient++ 0.5.2.35 when both the web interface and ExternalScripts features are enabled. The configuration file (nsclient.ini) stores the administrative password in plaintext and is readable by local u... Read more
Affected Products : nsclient\+\+- Published: Jul. 02, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-52037
A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=sites. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed ... Read more
Affected Products : notescms- Published: Aug. 26, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2024-12511
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.... Read more
Affected Products :- Published: Feb. 03, 2025
- Modified: Sep. 17, 2025
- Vuln Type: Misconfiguration
-
8.2
HIGH- Published: Sep. 13, 2024
- Modified: Sep. 17, 2025
-
7.5
HIGHCVE-2024-8798
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.... Read more
Affected Products : zephyr- Published: Dec. 16, 2024
- Modified: Sep. 17, 2025
-
7.6
HIGHCVE-2024-6259
BT: HCI: adv_ext_report Improper discarding in adv_ext_report... Read more
Affected Products : zephyr- Published: Sep. 13, 2024
- Modified: Sep. 17, 2025
-
6.8
MEDIUMCVE-2024-6258
BT: Missing length checks of net_buf in rfcomm_handle_data... Read more
Affected Products : zephyr- Published: Sep. 13, 2024
- Modified: Sep. 17, 2025
-
7.6
HIGHCVE-2024-6137
BT: Classic: SDP OOB access in get_att_search_list... Read more
Affected Products : zephyr- Published: Sep. 13, 2024
- Modified: Sep. 17, 2025
-
9.6
CRITICALCVE-2024-4008
FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control via access to local KNX Bus-System... Read more
- Published: Jun. 05, 2024
- Modified: Sep. 17, 2025
-
6.5
MEDIUMCVE-2024-5931
BT: Unchecked user input in bap_broadcast_assistant... Read more
Affected Products : zephyr- Published: Sep. 13, 2024
- Modified: Sep. 17, 2025