8.2

CVSS3.1

CVE-2026-21898 - CryptoLib Has Out-of-bounds Read in Crypto_AOS_ProcessSecurity

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the Crypto_AOS_ProcessSecurity function read…

πŸ“… Published: Jan. 10, 2026, 12:10 a.m. πŸ”„ Last Modified: Jan. 15, 2026, 9:48 p.m.

7.3

CVSS3.1

CVE-2026-21897 - CryptoLib Has Out-of-Bounds Write in Crypto_Config_Add_Gvcid_Managed_Parameters

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the Crypto_Config_Add_Gvcid_Managed_Paramete…

πŸ“… Published: Jan. 10, 2026, 12:07 a.m. πŸ”„ Last Modified: Jan. 15, 2026, 9:48 p.m.

9.3

CVSS4.0

CVE-2025-15501 - Sangfor Operation and Maintenance Management System getCmd WriterHandle.getCmd os command injection

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack i…

πŸ“… Published: Jan. 9, 2026, 10:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:27 a.m.

9.8

CVSS3.1

CVE-2026-22584 -

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.

πŸ“… Published: Jan. 9, 2026, 10:10 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 9:48 p.m.

9.3

CVSS4.0

CVE-2025-15500 - Sangfor Operation and Maintenance Management System HTTP POST Request getHis os command injection

A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Handler. The manipulation of the argument sessionPath results in os command injecti…

πŸ“… Published: Jan. 9, 2026, 9:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:27 a.m.

8.7

CVSS4.0

CVE-2025-15499 - Sangfor Operation and Maintenance Management System VersionController.java uploadCN os command inje…

A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.java. The manipulation of the argument filename leads to os command injection. The attack may be initiated remotely. The …

πŸ“… Published: Jan. 9, 2026, 9:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:26 a.m.

5.5

CVSS3.1

CVE-2025-46297 -

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files within an App Sandbox container.

πŸ“… Published: Jan. 9, 2026, 9:18 p.m. πŸ”„ Last Modified: April 2, 2026, 6:25 p.m.

3.5

CVSS3.1

CVE-2025-62487 - Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inheri…

On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked correctly with the proper security levels. The regression was traced back to a change in May 2025, which was meant to allow file uploads to be shared among different artifacts (e.g. …

πŸ“… Published: Jan. 9, 2026, 9:17 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-46298 -

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

πŸ“… Published: Jan. 9, 2026, 9:16 p.m. πŸ”„ Last Modified: April 2, 2026, 7:21 p.m.

4.3

CVSS3.1

CVE-2025-46299 - webkitgtk: Processing maliciously crafted web content may disclose internal states of the app

A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.

πŸ“… Published: Jan. 9, 2026, 9:15 p.m. πŸ”„ Last Modified: April 2, 2026, 7:21 p.m.
Total resulsts: 344807
Page 1771 of 34,481
Β« previous page Β» next page
Filters