8.7
CVE-2025-15499 - Sangfor Operation and Maintenance Management System VersionController.java uploadCN os command injeβ¦
A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.java. The manipulation of the argument filename leads to os command injection. The attack may be initiated remotely. The β¦
5.5
CVE-2025-46297 -
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files within an App Sandbox container.
3.5
CVE-2025-62487 - Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inheriβ¦
On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked correctly with the proper security levels. The regression was traced back to a change in May 2025, which was meant to allow file uploads to be shared among different artifacts (e.g. β¦
6.5
CVE-2025-46298 - Memory Handling Issue in Apple Web Browsers and OSes Leading to Process Crash
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.
4.3
CVE-2025-46299 - webkitgtk: Processing maliciously crafted web content may disclose internal states of the app
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.
4.3
CVE-2025-46286 -
A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a backup may prevent passcode from being required immediately after Face ID enrollment.
8.4
CVE-2026-0830 - Command Injection in Kiro GitLab Merge Request Helper
Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.
6.9
CVE-2025-15035 - Arbitrary File Deletion Vulnerability in TP-Link Archer AXE75
Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service interruption or degraded functionality.This issue affects Archer AXE75 v1.6: β€ β¦
5.3
CVE-2025-15496 - guchengwuyue yshopmall jobs getPage sql injection
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project wβ¦
5.1
CVE-2025-15495 - BiggiDroid Simple PHP CMS editsite.php unrestricted upload
A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite.php. The manipulation of the argument image results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. The vendor waβ¦