8.1

CVSS3.1

CVE-2026-23535 - wlc Path traversal: Unsanitized API slugs in download command

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.

πŸ“… Published: Jan. 16, 2026, 7:08 p.m. πŸ”„ Last Modified: April 18, 2026, 4:15 p.m.

7.5

CVSS3.1

CVE-2026-23490 - pyasn1 has a DoS vulnerability in decoder

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

πŸ“… Published: Jan. 16, 2026, 7:03 p.m. πŸ”„ Last Modified: April 18, 2026, 7:15 p.m.

7.8

CVSS3.1

CVE-2025-48647 -

In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Jan. 16, 2026, 6:19 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

7.4

CVSS3.1

CVE-2025-15032 - CVE-2025-15032: Increased Spoofing risk; custom new window missing about:blank

Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.

πŸ“… Published: Jan. 16, 2026, 6:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2026-0629 - Authentication Bypass in Password Recovery Feature via Local Web App on Multiple VIGI Cameras

Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, comprom…

πŸ“… Published: Jan. 16, 2026, 5:24 p.m. πŸ”„ Last Modified: April 18, 2026, 5:45 a.m.

3.3

CVSS3.1

CVE-2025-31186 - Xcode Permissions Issue Allowing Apps to Bypass Privacy Preferences

A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.

πŸ“… Published: Jan. 16, 2026, 5:06 p.m. πŸ”„ Last Modified: April 27, 2026, 9:45 p.m.

3.3

CVSS3.1

CVE-2025-24090 - Enumeration of Installed Apps via Permission Flaw

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's installed apps.

πŸ“… Published: Jan. 16, 2026, 5:06 p.m. πŸ”„ Last Modified: April 27, 2026, 9:45 p.m.

5.5

CVSS3.1

CVE-2025-43508 - Sensitive User Data Exposure via Improper Log Redaction

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

πŸ“… Published: Jan. 16, 2026, 5:06 p.m. πŸ”„ Last Modified: April 22, 2026, 8:15 p.m.

3.3

CVSS3.1

CVE-2024-44210 -

This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.

πŸ“… Published: Jan. 16, 2026, 5:06 p.m. πŸ”„ Last Modified: April 2, 2026, 6:18 p.m.

5.3

CVSS3.1

CVE-2025-24089 - App Enumeration via Permissions Issue on iOS/iPadOS

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's installed apps.

πŸ“… Published: Jan. 16, 2026, 5:06 p.m. πŸ”„ Last Modified: April 27, 2026, 9:45 p.m.
Total resulsts: 349182
Page 2095 of 34,919
Β« previous page Β» next page
Filters