Aggregator
CVE-2025-43508 | Apple macOS up to 26.0 App information disclosure
3 months 2 weeks ago
A vulnerability was found in Apple macOS up to 26.0. It has been declared as problematic. This issue affects some unknown processing of the component App. Executing a manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2025-43508. The attack needs to be launched locally. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
Developing your incident response plan (ITSAP.40.003)
3 months 2 weeks ago
Canadian Centre for Cyber Security
CVE-2025-31186 | Apple Xcode up to 16.2 Privacy Preferences permission
3 months 2 weeks ago
A vulnerability was found in Apple Xcode up to 16.2. It has been classified as critical. This vulnerability affects unknown code of the component Privacy Preferences. Performing a manipulation results in permission issues.
This vulnerability is cataloged as CVE-2025-31186. The attack must be initiated from a local position. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-24090 | Apple iOS/iPadOS up to 18.2 permission
3 months 2 weeks ago
A vulnerability was found in Apple iOS and iPadOS up to 18.2 and classified as critical. This affects an unknown part. Such manipulation leads to permission issues.
This vulnerability is listed as CVE-2025-24090. The attack must be carried out locally. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
Developing your business continuity plan (ITSAP.10.005)
3 months 2 weeks ago
In the event of a cyber incident or natural disaster, your organization will need a business continuity plan (BCP) to resume its most critical business operations quickly. Your BCP will identify the risks from various threats and the impact they would have on your organization.
Canadian Centre for Cyber Security
CVE-2025-24089 | Apple iOS/iPadOS up to 18.2 permission
3 months 2 weeks ago
A vulnerability has been found in Apple iOS and iPadOS up to 18.2 and classified as critical. Affected by this issue is some unknown functionality. This manipulation causes permission issues.
This vulnerability is tracked as CVE-2025-24089. The attack is restricted to local execution. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2024-44238 | Apple iOS/iPadOS up to 18.0 memory corruption
3 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Apple iOS and iPadOS up to 18.0. Affected by this vulnerability is an unknown functionality. The manipulation results in memory corruption.
This vulnerability is identified as CVE-2024-44238. The attack is only possible with local access. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2024-44210 | Apple macOS up to 15.0 App permission
3 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Apple macOS up to 15.0. Affected is an unknown function of the component App. The manipulation leads to permission issues.
This vulnerability is referenced as CVE-2024-44210. The attack can only be performed from a local environment. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
Submit #731233: running-elephant datart latest Code Execution, Command Execution, Server Compromised. [Duplicate]
3 months 2 weeks ago
Submit #731233 / VDB-289628
pyj2cve
CVE-2025-61873 | Best Practical Request Tracker up to 4.4.8/5.0.8/6.0.1 TSV Export csv injection
3 months 2 weeks ago
A vulnerability classified as problematic was found in Best Practical Request Tracker up to 4.4.8/5.0.8/6.0.1. This impacts an unknown function of the component TSV Export. Executing a manipulation can lead to csv injection.
The identification of this vulnerability is CVE-2025-61873. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-43904 | SchedMD Slurm up to 23.11.10/24.05.7/24.11.4 authorization
3 months 2 weeks ago
A vulnerability classified as problematic has been found in SchedMD Slurm up to 23.11.10/24.05.7/24.11.4. This affects an unknown function. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2025-43904. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-54556 | Apple iOS/iPadOS up to 18.0 Lock Screen state issue
3 months 2 weeks ago
A vulnerability described as problematic has been identified in Apple iOS and iPadOS up to 18.0. The impacted element is an unknown function of the component Lock Screen. Such manipulation leads to state issue.
This vulnerability is uniquely identified as CVE-2024-54556. The attack can be executed directly on the physical device. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-0949 | EnterpriseDB Postgres Enterprise Manager up to 9.8.0 cross site scripting
3 months 2 weeks ago
A vulnerability marked as problematic has been reported in EnterpriseDB Postgres Enterprise Manager up to 9.8.0. The affected element is an unknown function. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-0949. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
Black Basta boss makes it onto Interpol's 'Red Notice' list
3 months 2 weeks ago
The identity of the Black Basta ransomware gang leader has been confirmed by law enforcement in Ukraine and Germany, and the individual has been added to the wanted list of Europol and Interpol. [...]
Bill Toulas
CVE-2025-51602 | VideoLAN VLC Media Player up to 3.0.21 mmstu.c out-of-bounds (ID 29146)
3 months 2 weeks ago
A vulnerability labeled as critical has been found in VideoLAN VLC Media Player up to 3.0.21. Impacted is an unknown function of the file mmstu.c. The manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2025-51602. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2025-62291 | strongSwan up to 6.0.2 eap-mschapv2 Plugin integer underflow
3 months 2 weeks ago
A vulnerability identified as critical has been detected in strongSwan up to 6.0.2. This issue affects some unknown processing of the component eap-mschapv2 Plugin. The manipulation leads to integer underflow.
This vulnerability is traded as CVE-2025-62291. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-0629 | TP-Link VIGI Cx20 prior 3.1.0_Build_250820_Rel.57668n Local Web Interface improper authentication
3 months 2 weeks ago
A vulnerability categorized as critical has been discovered in TP-Link VIGI InSight Sx45, VIGI Cx45, VIGI InSight Sx55, VIGI Cx55, VIGI InSight Sx85, VIGI Cx85, VIGI InSight S655I, VIGI InSight Sx45ZI, VIGI InSight Sx85PI, VIGI C340S, VIGI C540S , EasyCam C540S, VIGI C540V, VIGI C250, VIGI Cx50, VIGI Cx20I 1.0, VIGI Cx20I 1.20, VIGI Cx30I 1.0, VIGI Cx30I 1.20, VIGI Cx40I 1.0, VIGI Cx40I 1.20, VIGI Cx30 1.0, VIGI Cx30 1.20, VIGI C230I Mini, VIGI C240 1.0, VIGI C340 2.0, VIGI C440 2.0, VIGI C540 2.0, VIGI C540-4G, VIGI C340-W 2.x, VIGI C440-W 2.0, VIGI C540-W 2.0, VIGI InSight S345-4G, VIGI InSight Sx25 and VIGI Cx20. This vulnerability affects unknown code of the component Local Web Interface. Executing a manipulation can lead to improper authentication.
This vulnerability appears as CVE-2026-0629. The attacker needs to be present on the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-23523 | OpenAgentPlatform Dive up to 0.12.x Deeplink code injection (GHSA-pjj5-f3wm-f9m8)
3 months 2 weeks ago
A vulnerability was found in OpenAgentPlatform Dive up to 0.12.x. It has been rated as critical. This affects an unknown part of the component Deeplink Handler. Performing a manipulation results in code injection.
This vulnerability is reported as CVE-2026-23523. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-23528 | dask distributed prior 2026.1.0 Dask Dashboard cross site scripting (GHSA-c336-7962-wfj2)
3 months 2 weeks ago
A vulnerability was found in dask distributed. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Dask Dashboard. Such manipulation leads to basic cross site scripting.
This vulnerability is documented as CVE-2026-23528. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com