Aggregator
Lynx
7 months 2 weeks ago
cohenido
CVE-2022-42799 | Apple macOS WebKit ui layer (HT213488 / Nessus ID 211346)
7 months 2 weeks ago
A vulnerability was found in Apple macOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component WebKit. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is known as CVE-2022-42799. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42823 | Apple tvOS up to 16.0 WebKit type confusion (HT213492 / Nessus ID 211346)
7 months 2 weeks ago
A vulnerability classified as critical was found in Apple tvOS up to 16.0. This vulnerability affects unknown code of the component WebKit. The manipulation leads to type confusion.
This vulnerability was named CVE-2022-42823. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42824 | Apple tvOS up to 16.0 WebKit state issue (HT213492 / Nessus ID 211346)
7 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Apple tvOS up to 16.0. This issue affects some unknown processing of the component WebKit. The manipulation leads to state issue.
The identification of this vulnerability is CVE-2022-42824. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42799 | Apple Safari up to 15.6.1 WebKit Remote Code Execution (HT213495 / Nessus ID 211346)
7 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Apple Safari up to 15.6.1. Affected is an unknown function of the component WebKit. The manipulation leads to Remote Code Execution.
This vulnerability is traded as CVE-2022-42799. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42823 | Apple macOS WebKit type confusion (HT213488 / Nessus ID 211346)
7 months 2 weeks ago
A vulnerability was found in Apple macOS. It has been rated as critical. Affected by this issue is some unknown functionality of the component WebKit. The manipulation leads to type confusion.
This vulnerability is handled as CVE-2022-42823. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42823 | Apple Safari up to 15.6.1 WebKit type confusion (HT213495 / Nessus ID 211346)
7 months 2 weeks ago
A vulnerability has been found in Apple Safari up to 15.6.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component WebKit. The manipulation leads to type confusion.
This vulnerability is known as CVE-2022-42823. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42824 | Apple macOS WebKit state issue (HT213488 / Nessus ID 211346)
7 months 2 weeks ago
A vulnerability classified as problematic has been found in Apple macOS. This affects an unknown part of the component WebKit. The manipulation leads to state issue.
This vulnerability is uniquely identified as CVE-2022-42824. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2893 | Gutenverse Plugin up to 2.2.1 on WordPress Countdown Block cross site scripting
7 months 2 weeks ago
A vulnerability was found in Gutenverse Plugin up to 2.2.1 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Countdown Block Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-2893. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-42404 | OneVision Workspace up to 29.031/30.043/31.039 Java EL code injection
7 months 2 weeks ago
A vulnerability was found in OneVision Workspace up to 29.031/30.043/31.039. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Java EL Handler. The manipulation leads to code injection.
This vulnerability is known as CVE-2023-42404. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Earth Kurma APT is actively targeting government and telecommunications orgs in Southeast Asia
7 months 2 weeks ago
Earth Kurma APT carried out a sophisticated campaign against government and telecommunications sectors in Southeast Asia. Trend Research exposed the Earth Kurma APT campaign targeting Southeast Asia’s government and telecom sectors. Threat actors use custom malware, rootkits, and cloud storage for espionage, credential theft, and data exfiltration, posing a high business risk with advanced evasion […]
Pierluigi Paganini
CVE-2023-35817 | DevExpress up to 23.1.2 AsyncDownloader server-side request forgery
7 months 2 weeks ago
A vulnerability was found in DevExpress up to 23.1.2. It has been classified as critical. Affected is an unknown function of the component AsyncDownloader. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2023-35817. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-35814 | DevExpress up to 23.1.2 ASP.NET Web Form deserialization
7 months 2 weeks ago
A vulnerability was found in DevExpress up to 23.1.2 and classified as problematic. This issue affects some unknown processing of the component ASP.NET Web Form Handler. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2023-35814. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-35816 | DevExpress up to 23.1.2 TypeConverter path traversal
7 months 2 weeks ago
A vulnerability has been found in DevExpress up to 23.1.2 and classified as problematic. This vulnerability affects unknown code of the component TypeConverter Handler. The manipulation leads to relative path traversal.
This vulnerability was named CVE-2023-35816. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46614 | Snowflake ODBC up to 3.6.x log file
7 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Snowflake ODBC up to 3.6.x. This affects an unknown part. The manipulation leads to sensitive information in log files.
This vulnerability is uniquely identified as CVE-2025-46614. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-3224 | Docker Desktop up to 4.40.x on Windows privileges management
7 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Docker Desktop up to 4.40.x on Windows. Affected by this issue is some unknown functionality. The manipulation leads to improper privilege management.
This vulnerability is handled as CVE-2025-3224. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-34491 | GFI MailEssentials up to 21.7 .NET Deserialization deserialization
7 months 2 weeks ago
A vulnerability classified as very critical was found in GFI MailEssentials up to 21.7. Affected by this vulnerability is an unknown functionality of the component .NET Deserialization. The manipulation leads to deserialization.
This vulnerability is known as CVE-2025-34491. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-45947 | PHPGurukul Online Banquet Booking System 1.2 change-password.php password recovery
7 months 2 weeks ago
A vulnerability classified as problematic has been found in PHPGurukul Online Banquet Booking System 1.2. Affected is an unknown function of the file /obbs/change-password.php. The manipulation leads to weak password recovery.
This vulnerability is traded as CVE-2025-45947. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-45953 | PHPGurukul Hostel Management System 2.1 change-password.php password recovery
7 months 2 weeks ago
A vulnerability was found in PHPGurukul Hostel Management System 2.1. It has been rated as problematic. This issue affects some unknown processing of the file /hostel/change-password.php. The manipulation leads to weak password recovery.
The identification of this vulnerability is CVE-2025-45953. The attack may be initiated remotely. There is no exploit available.
vuldb.com