CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2025-43413

    Last Modified: 28 Apr 2026

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A sandboxed app may be able to observe system-wide network connections.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43385

    Last Modified: 28 Apr 2026

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43468

    Last Modified: 22 Apr 2026

    A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43429

    Last Modified: 22 Apr 2026

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025
    2.4
    Low

    CVE-2025-43350

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view restricted content from the lock screen.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43409

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    6.3
    Medium

    CVE-2025-43448

    Last Modified: 22 Apr 2026

    This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to break out of its sandbox.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43389

    Last Modified: 27 Apr 2026

    A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    8.8
    High

    CVE-2025-43433

    Last Modified: 14 Aug 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43425

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-43472

    Last Modified: 27 Apr 2026

    A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to gain root privileges.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-35021

    Last Modified: 13 Jan 2026

    By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restricted shell on the fourth attempt, and from there, relay connections.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-46556

    Last Modified: 7 Nov 2025

    Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters) due to a lack of server-side validation of note length. Once such a note is added, the activity stream UI fails to render; therefore, new notes cannot be displayed, effectively breaking all future collaboration on the issue. This issue is fixed in version 2.27.2.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-61431

    Last Modified: 4 Feb 2026

    A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchetti v4.1 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the pHtmlSource parameter. A vendor fix was released on 2025-06-18.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-54329

    Last Modified: 7 Nov 2025

    An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to send a multiple-payloads message (including an SMS message) lacks bounds checking, which can lead to a heap overflow.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-54327

    Last Modified: 7 Nov 2025

    An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W1000. Improper input validation in the VTS driver leads to an arbitrary write.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-54325

    Last Modified: 7 Nov 2025

    An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1080, 1280, 2200, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000. A race condition in the VTS driver results in an out-of-bounds read, leading to an information leak.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-27374

    Last Modified: 7 Nov 2025

    An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, 1330, 1380, 1480, 2400. The lack of a length check leads to out-of-bounds writes.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-63294

    Last Modified: 4 Feb 2026

    WorkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create leave or resignation records on behalf of other users.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-60925

    Last Modified: 4 Feb 2026

    codeshare v1.0.0 was discovered to contain an information leakage vulnerability.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-56230

    Last Modified: 10 Feb 2026

    Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-54335

    Last Modified: 7 Nov 2025

    An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU Driver.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-54331

    Last Modified: 7 Nov 2025

    An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-52513

    Last Modified: 7 Nov 2025

    An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in an out-of-bounds write, leading to a denial of service.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-49494

    Last Modified: 7 Nov 2025

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 9110, Modem 5123. Mishandling of an 5G NRMM packet leads to a Denial of Service.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-54332

    Last Modified: 7 Nov 2025

    An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Dereference of profiler.node in the npu_vertex_profileoff function.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-54333

    Last Modified: 7 Nov 2025

    An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Invalid Pointer Dereference of node in the get_vs4l_profiler_node function.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2024-56426

    Last Modified: 7 Nov 2025

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000. The lack of a length check leads to out-of-bounds writes via malformed USB packets to the target.

    Published: 4 Nov 2025
    9.8
    Critical

    CVE-2025-52910

    Last Modified: 7 Nov 2025

    An issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 1480, 2400. A Use-After-Free leads to privilege escalation.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-54334

    Last Modified: 7 Nov 2025

    An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. There is a NULL Pointer Dereference of hdev in the __npu_vertex_bootup function.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-54323

    Last Modified: 7 Nov 2025

    An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, and 1580. Improper debug printing leads to information leakage.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-52512

    Last Modified: 7 Nov 2025

    An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results in out-of-bounds memory access, leading to a denial of service.

    Published: 4 Nov 2025
    5.3
    Medium

    CVE-2025-54330

    Last Modified: 7 Nov 2025

    An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Out-of-bounds Read of q->bufs[] in the __is_done_for_me function.

    Published: 4 Nov 2025
    Unknown

    CVE-2025-12678

    Last Modified: 21 Nov 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 3 Nov 2025
    7
    High

    CVE-2025-34501

    Last Modified: 28 Jul 2026

    Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HTTP, Telnet, SMB, X11) are enabled by default. If an attacker can reach these interfaces - most often through local or near-local access such as connecting to the USB or Ethernet ports beneath the table - the built-in credentials permit administrative login and full control of the system. Once authenticated, an attacker can access firmware utilities, modify controller software, and establish persistent compromise. Remote attack paths via network, cellular, or telemetry links may exist in specific configurations but generally require additional capabilities or operator error. The vendor reports that USB access has been disabled in current firmware builds.

    Published: 3 Nov 2025
    Unknown

    CVE-2016-15054

    Last Modified: 10 Nov 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a downstream effect of an already identified vulnerability, CVE-2012-6708.

    Published: 3 Nov 2025
    5.1
    Medium

    CVE-2021-47698

    Last Modified: 17 Nov 2025

    Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

    Published: 3 Nov 2025
    9.4
    Critical

    CVE-2024-13997

    Last Modified: 17 Nov 2025

    Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the application, resulting in full control of the operating system.

    Published: 3 Nov 2025
    6
    Medium

    CVE-2024-13998

    Last Modified: 17 Nov 2025

    Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking attempts. CVE-2024-13995 addresses a similar vulnerability with a potentially incomplete fix for the underlying problem in earlier versions.

    Published: 3 Nov 2025
    6.8
    Medium

    CVE-2025-11193

    Last Modified: 15 Apr 2026

    A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sensitive device specific information.

    Published: 3 Nov 2025
    6.4
    Medium

    CVE-2025-36172

    Last Modified: 5 Nov 2025

    IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 3 Nov 2025
    5.9
    Medium

    CVE-2025-12657

    Last Modified: 12 Dec 2025

    The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.

    Published: 3 Nov 2025
    7.1
    High

    CVE-2025-12531

    Last Modified: 5 Nov 2025

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

    Published: 3 Nov 2025
    6.9
    Medium

    CVE-2025-12642

    Last Modified: 12 Nov 2025

    lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks. Successful exploitation may allow an attacker to: * Bypass access control rules * Inject unsafe input into backend logic that trusts request headers * Execute HTTP Request Smuggling attacks under some conditions This issue affects lighttpd1.4.80

    Published: 3 Nov 2025
    2.3
    Low

    CVE-2025-8558

    Last Modified: 7 Nov 2025

    Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of registered agents exceeds the licensed limit. Successful exploitation prevents the server from receiving new events from affected agents, resulting in a partial loss of integrity and availability with no impact to confidentiality.

    Published: 3 Nov 2025
    9.8
    Critical

    CVE-2025-12463

    Last Modified: 15 Apr 2026

    An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19.

    Published: 3 Nov 2025
    7.1
    High

    CVE-2025-10280

    Last Modified: 26 Feb 2026

    IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels including 8.3p5, and all prior versions allows some IdentityIQ web services that provide non-HTML content to be accessed via a URL path that will set the Content-Type to HTML allowing a requesting browser to interpret content not properly escaped to prevent Cross-Site Scripting (XSS).

    Published: 3 Nov 2025
    9.8
    Critical

    CVE-2025-11953

    Last Modified: 26 Feb 2026

    The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

    Published: 3 Nov 2025
    4.8
    Medium

    CVE-2025-36093

    Last Modified: 5 Nov 2025

    IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an attacker to access unauthorized content or perform unauthorized actions using man in the middle techniques due to improper access controls.

    Published: 3 Nov 2025
    6.5
    Medium

    CVE-2025-36092

    Last Modified: 5 Nov 2025

    IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper validation of input length.

    Published: 3 Nov 2025