Latest CVE Feed
- 
                                
                                
8.8
HIGHCVE-2025-43431
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. Processing maliciously crafted web content may lead to memory corruption.... Read more
- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-43430
This issue was addressed through improved state management. This issue is fixed in Safari 26.1, visionOS 26.1, watchOS 26.1, iOS 26.1 and iPadOS 26.1, tvOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.... Read more
- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-43427
This issue was addressed through improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, tvOS 26.1, Safari 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.... Read more
- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-43421
Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.... Read more
- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
7.8
HIGHCVE-2025-43387
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2. A malicious app may be able to gain root privileges.... Read more
Affected Products : macos- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
2.8
LOWCVE-2025-43365
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26. An unprivileged process may be able to terminate a root processes.... Read more
- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
8.7
HIGHCVE-2025-41114
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosBy... Read more
Affected Products :- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
8.7
HIGHCVE-2025-41113
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarDenunciaByPin.php'.... Read more
Affected Products :- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
8.7
HIGHCVE-2025-41112
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros2.php'.... Read more
Affected Products :- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
8.7
HIGHCVE-2025-41111
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarComentariosByDenuncia.php'.... Read more
Affected Products :- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
7.8
HIGHCVE-2025-10922
GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in tha... Read more
- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.8
HIGHCVE-2025-10923
GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the tar... Read more
Affected Products : gimp- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.8
HIGHCVE-2025-10924
GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the targe... Read more
Affected Products : gimp- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.8
HIGHCVE-2025-10925
GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in t... Read more
Affected Products : gimp- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.8
HIGHCVE-2025-10934
GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in tha... Read more
- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
7.5
HIGHCVE-2024-55568
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The absence of a NULL check leads to a De... Read more
- Published: Oct. 20, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
7.5
HIGHCVE-2025-26781
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 9110, W920, W930, Modem 5123, and Modem 5300. Incorrect handling of RLC AM PDUs leads to a Denial of S... Read more
Affected Products : exynos_980_firmware exynos_850_firmware exynos_1080_firmware exynos_2200_firmware exynos_1380_firmware exynos_1330_firmware exynos_9110_firmware exynos_w920_firmware exynos_980 exynos_990_firmware +16 more products- Published: Oct. 20, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
6.1
MEDIUMCVE-2025-53701
Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET requests sent to /cgi-bin/action endpoint are not sanitized properly, making it possible to target logged in admin users. The vendor did ... Read more
- Published: Oct. 23, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Cross-Site Scripting
 
 - 
                                
                                
7.1
HIGHCVE-2025-53702
Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action endpoint and render the device completely unresponsive. A manual restart o... Read more
- Published: Oct. 23, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Denial of Service
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-56007
CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding additional users with full permissions by managing the victim to open page with exploit.... Read more
Affected Products : keeneticos- Published: Oct. 23, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Injection