8.7

CVSS4.0

CVE-2025-15499 - Sangfor Operation and Maintenance Management System VersionController.java uploadCN os command inje…

A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.java. The manipulation of the argument filename leads to os command injection. The attack may be initiated remotely. The …

πŸ“… Published: Jan. 9, 2026, 9:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:26 a.m.

5.5

CVSS3.1

CVE-2025-46297 -

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files within an App Sandbox container.

πŸ“… Published: Jan. 9, 2026, 9:18 p.m. πŸ”„ Last Modified: April 2, 2026, 6:25 p.m.

3.5

CVSS3.1

CVE-2025-62487 - Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inheri…

On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked correctly with the proper security levels. The regression was traced back to a change in May 2025, which was meant to allow file uploads to be shared among different artifacts (e.g. …

πŸ“… Published: Jan. 9, 2026, 9:17 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-46298 - Memory Handling Issue in Apple Web Browsers and OSes Leading to Process Crash

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

πŸ“… Published: Jan. 9, 2026, 9:16 p.m. πŸ”„ Last Modified: April 22, 2026, 8:15 p.m.

4.3

CVSS3.1

CVE-2025-46299 - webkitgtk: Processing maliciously crafted web content may disclose internal states of the app

A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may disclose internal states of the app.

πŸ“… Published: Jan. 9, 2026, 9:15 p.m. πŸ”„ Last Modified: April 22, 2026, 8:15 p.m.

4.3

CVSS3.1

CVE-2025-46286 -

A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a backup may prevent passcode from being required immediately after Face ID enrollment.

πŸ“… Published: Jan. 9, 2026, 9:14 p.m. πŸ”„ Last Modified: April 22, 2026, 8:15 p.m.

8.4

CVSS4.0

CVE-2026-0830 - Command Injection in Kiro GitLab Merge Request Helper

Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.

πŸ“… Published: Jan. 9, 2026, 9:10 p.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

6.9

CVSS4.0

CVE-2025-15035 - Arbitrary File Deletion Vulnerability in TP-Link Archer AXE75

Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service interruption or degraded functionality.This issue affects Archer AXE75 v1.6: ≀ …

πŸ“… Published: Jan. 9, 2026, 5:10 p.m. πŸ”„ Last Modified: March 9, 2026, 3:27 p.m.

5.3

CVSS4.0

CVE-2025-15496 - guchengwuyue yshopmall jobs getPage sql injection

A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project w…

πŸ“… Published: Jan. 9, 2026, 5:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.

5.1

CVSS4.0

CVE-2025-15495 - BiggiDroid Simple PHP CMS editsite.php unrestricted upload

A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite.php. The manipulation of the argument image results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. The vendor wa…

πŸ“… Published: Jan. 9, 2026, 5:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:26 a.m.
Total resulsts: 346514
Page 1941 of 34,652
Β« previous page Β» next page
Filters