0.0

CVE-2025-43404 -

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

πŸ“… Published: Dec. 12, 2025, 8:56 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:56 p.m.

0.0

CVE-2025-43393 -

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to break out of its sandbox.

πŸ“… Published: Dec. 12, 2025, 8:56 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:56 p.m.

0.0

CVE-2025-43517 -

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.8.3, macOS Sequoia 15.7.3. An app may be able to access protected user data.

πŸ“… Published: Dec. 12, 2025, 8:56 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:56 p.m.

0.0

CVE-2025-43464 -

A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Tahoe 26.1. Visiting a website may lead to an app denial-of-service.

πŸ“… Published: Dec. 12, 2025, 8:56 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:56 p.m.

0.0

CVE-2025-43521 -

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.3. An app may be able to access sensitive user data.

πŸ“… Published: Dec. 12, 2025, 8:56 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:56 p.m.

6.8

CVSS4.0

CVE-2025-11266 - Grassroots DICOM (GDCM) Out-of-bounds Write

An out-of-bounds write vulnerability exists in the Grassroots DICOM library (GDCM). The issue is triggered during parsing of a malformed DICOM file containing encapsulated PixelData fragments (compressed image data stored as multiple fragments). This vulnerability leads to a segmentation fault caus…

πŸ“… Published: Dec. 12, 2025, 8:48 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:48 p.m.

4.6

CVSS4.0

CVE-2025-67634 - Software Acquisition Guide Supplier Response Web Tool XSS

The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The JavaScript would exe…

πŸ“… Published: Dec. 12, 2025, 8:36 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:36 p.m.

5.1

CVSS4.0

CVE-2025-14580 - Qualitor viewDocumento.php cross site scripting

A security vulnerability has been detected in Qualitor up to 8.24.73. The impacted element is an unknown function of the file /Qualitor/html/bc/bcdocumento9/biblioteca/request/viewDocumento.php. Such manipulation of the argument cdscript leads to cross site scripting. It is possible to launch the a…

πŸ“… Published: Dec. 12, 2025, 8:32 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:32 p.m.

8.7

CVSS4.0

CVE-2024-58316 - Online Shopping System Advanced 1.0 SQL Injection via Payment Success Parameter

Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database inf…

πŸ“… Published: Dec. 12, 2025, 8:14 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:14 p.m.

8.4

CVSS3.1

CVE-2025-67750 - Lightning Flow Scanner is Vulnerable to Code Injection via Unsafe Use of new Function() in APIVersi…

Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows. Versions 6.10.5 and below allow a maliciously crafted flow metadata file to cause arbitrary JavaScript execution during scanning. The APIVersion rule uses new Funct…

πŸ“… Published: Dec. 12, 2025, 8:14 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:14 p.m.
Total resulsts: 322122
Page 6 of 32,213
Β« previous page Β» next page
Filters