Search

Search Results (317040 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-62719 1 Linkace 1 Linkace 2025-11-05 N/A
LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function in the FetchController class accepts user-provided URLs and makes HTTP requests to them without validating that the destination is not an internal or private network resource. This Server-Side Request Forgery (SSRF) vulnerability allows authenticated attackers to use the application server to perform port scanning and service discovery on internal networks. Practical impact is very limited because the function only extracts content from HTML meta keywords tags, which prevents meaningful data exfiltration from databases, APIs, or cloud metadata endpoints. This issue is fixed in version 2.4.0.
CVE-2025-56232 2025-11-05 N/A
GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files.
CVE-2025-55342 2025-11-05 N/A
Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_password_olvido_validar.php txt_login parameter.
CVE-2025-55341 2025-11-05 N/A
Cross Site Scripting vulnerability in Quipux 4.0.1 through e1774ac allows anexos/anexos_nuevo.php asocImgRad.
CVE-2025-43507 1 Apple 5 Ios, Ipados, Iphone Os and 2 more 2025-11-05 6.5 Medium
A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An app may be able to fingerprint the user.
CVE-2025-43503 1 Apple 6 Ios, Ipados, Iphone Os and 3 more 2025-11-05 4.3 Medium
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Visiting a malicious website may lead to user interface spoofing.
CVE-2025-43499 1 Apple 3 Macos, Macos Sequoia, Macos Sonoma 2025-11-05 5.5 Medium
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An app may be able to access sensitive user data.
CVE-2025-43496 1 Apple 7 Ios, Ipad Os, Ipados and 4 more 2025-11-05 7.5 High
The issue was addressed by adding additional logic. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Remote content may be loaded even when the 'Load Remote Images' setting is turned off.
CVE-2025-43495 1 Apple 4 Ios, Ipad Os, Ipados and 1 more 2025-11-05 5.4 Medium
The issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An app may be able to monitor keystrokes without user permission.
CVE-2025-43493 1 Apple 5 Ios, Ipados, Iphone Os and 2 more 2025-11-05 4.3 Medium
The issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Visiting a malicious website may lead to address bar spoofing.
CVE-2025-43458 1 Apple 7 Ios, Ipados, Iphone Os and 4 more 2025-11-05 4.3 Medium
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-43454 1 Apple 4 Ios, Ipad Os, Ipados and 1 more 2025-11-05 7.5 High
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. A device may persistently fail to lock.
CVE-2025-43450 1 Apple 3 Ios, Ipados, Iphone Os 2025-11-05 7.5 High
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An app may be able to learn information about the current camera view before being granted camera access.
CVE-2025-43448 1 Apple 9 Ios, Ipados, Iphone Os and 6 more 2025-11-05 6.3 Medium
This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An app may be able to break out of its sandbox.
CVE-2025-43445 1 Apple 9 Ios, Ipados, Iphone Os and 6 more 2025-11-05 4.3 Medium
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
CVE-2025-43444 1 Apple 7 Ios, Ipad Os, Ipados and 4 more 2025-11-05 5.3 Medium
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An app may be able to fingerprint the user.
CVE-2025-43443 1 Apple 7 Ios, Ipados, Iphone Os and 4 more 2025-11-05 4.3 Medium
This issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-43442 1 Apple 4 Ios, Ipad Os, Ipados and 1 more 2025-11-05 3.3 Low
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An app may be able to identify what other apps a user has installed.
CVE-2025-43441 1 Apple 7 Ios, Ipad Os, Ipados and 4 more 2025-11-05 4.3 Medium
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2025-43439 1 Apple 5 Ios, Ipad Os, Ipados and 2 more 2025-11-05 5.5 Medium
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2. An app may be able to fingerprint the user.