Search Results (317020 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-64319 1 Salesforce 1 Mulesoft 2025-11-05 5.3 Medium
Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.11.6.
CVE-2025-64318 1 Salesforce 1 Mulesoft 2025-11-05 5.3 Medium
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.11.6.
CVE-2025-59596 2 Absolute, Microsoft 2 Secure Access, Windows 2025-11-05 N/A
CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy is active, attackers on an adjacent network may be able to send a crafted packet and cause the client system to crash.
CVE-2025-52910 1 Samsung 9 Exynos, Exynos 1280, Exynos 1330 and 6 more 2025-11-05 9.8 Critical
An issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 1480, 2400. A Use-After-Free leads to privilege escalation.
CVE-2025-43481 1 Apple 2 Macos, Macos Sequoia 2025-11-05 5.2 Medium
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2. An app may be able to break out of its sandbox.
CVE-2025-43469 1 Apple 3 Macos, Macos Sequoia, Macos Sonoma 2025-11-05 5.5 Medium
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to access sensitive user data.
CVE-2025-43468 1 Apple 3 Macos, Macos Sequoia, Macos Sonoma 2025-11-05 5.5 Medium
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to access sensitive user data.
CVE-2025-43452 1 Apple 3 Ios, Ipados, Iphone Os 2025-11-05 4.6 Medium
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 26.1 and iPadOS 26.1. Keyboard suggestions may display sensitive information on the lock screen.
CVE-2025-43424 1 Apple 3 Ios, Ipados, Iphone Os 2025-11-05 4.3 Medium
The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. A malicious HID device may cause an unexpected process crash.
CVE-2025-43412 1 Apple 3 Macos, Macos Sequoia, Macos Sonoma 2025-11-05 6.3 Medium
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app may be able to break out of its sandbox.
CVE-2025-43409 1 Apple 1 Macos 2025-11-05 5.5 Medium
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2. An app may be able to access sensitive user data.
CVE-2025-43350 1 Apple 3 Ios, Ipados, Iphone Os 2025-11-05 2.4 Low
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view restricted content from the lock screen.
CVE-2025-12192 2025-11-05 5.3 Medium
The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to the stored opt-in key using a loose comparison, allowing unauthenticated attackers to send a boolean value and obtain the full system report whenever "Yes, automatically share my system information with The Events Calendar support team" setting is enabled.
CVE-2024-23494 1 Deltaww 1 Diaenergie 2025-11-05 8.8 High
SQL injection vulnerability exists in GetDIAE_unListParameters.
CVE-2024-28891 1 Deltaww 1 Diaenergie 2025-11-05 8.8 High
SQL injection vulnerability exists in the script Handler_CFG.ashx.
CVE-2024-23975 1 Deltaww 1 Diaenergie 2025-11-05 8.8 High
SQL injection vulnerability exists in GetDIAE_slogListParameters.
CVE-2024-25567 1 Deltaww 1 Diaenergie 2025-11-05 8.1 High
Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten.
CVE-2024-28040 1 Deltaww 1 Diaenergie 2025-11-05 8.8 High
SQL injection vulnerability exists in GetDIAE_astListParameters.
CVE-2024-28045 1 Deltaww 1 Diaenergie 2025-11-05 4.6 Medium
Improper neutralization of input within the affected product could lead to cross-site scripting.
CVE-2024-28171 1 Deltaww 1 Diaenergie 2025-11-05 8.1 High
It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.