Aggregator
CVE-2025-50093 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 DDL improper authorization (Nessus ID 244835 / WID-SEC-2025-1567)
1 month 2 weeks ago
A vulnerability labeled as critical has been found in Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0. This affects an unknown part of the component DDL. The manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2025-50093. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-50087 | Oracle MySQL Cluster/MySQL Server up to 7.6.34/8.0.42/8.4.5/9.3.0 Optimizer improper authorization (EUVD-2025-21493 / Nessus ID 242320)
1 month 2 weeks ago
A vulnerability was found in Oracle MySQL Cluster and MySQL Server up to 7.6.34/8.0.42/8.4.5/9.3.0. It has been classified as critical. This affects an unknown function of the component Optimizer. This manipulation causes improper authorization.
The identification of this vulnerability is CVE-2025-50087. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-50088 | Oracle MySQL Server up to 8.0.41/8.4.4/9.2.0 InnoDB improper authorization (Nessus ID 242315 / WID-SEC-2025-1567)
1 month 2 weeks ago
A vulnerability was found in Oracle MySQL Server up to 8.0.41/8.4.4/9.2.0. It has been declared as critical. This impacts an unknown function of the component InnoDB. Such manipulation leads to improper authorization.
This vulnerability is referenced as CVE-2025-50088. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50089 | Oracle MySQL Server up to 9.1.0 Optimizer improper authorization (Nessus ID 249820 / WID-SEC-2025-1567)
1 month 2 weeks ago
A vulnerability was found in Oracle MySQL Server up to 9.1.0. It has been rated as critical. Affected is an unknown function of the component Optimizer. Performing manipulation results in improper authorization.
This vulnerability is identified as CVE-2025-50089. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-50091 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 Optimizer improper authorization (Nessus ID 244811 / WID-SEC-2025-1567)
1 month 2 weeks ago
A vulnerability categorized as critical has been discovered in Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0. Affected by this vulnerability is an unknown functionality of the component Optimizer. Executing manipulation can lead to improper authorization.
This vulnerability is tracked as CVE-2025-50091. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-50092 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 InnoDB improper authorization (Nessus ID 244813 / WID-SEC-2025-1567)
1 month 2 weeks ago
A vulnerability identified as critical has been detected in Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0. Affected by this issue is some unknown functionality of the component InnoDB. The manipulation leads to improper authorization.
This vulnerability is listed as CVE-2025-50092. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2025-50086 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 Components Service improper authorization (EUVD-2025-21494 / Nessus ID 244799)
1 month 2 weeks ago
A vulnerability was found in Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 and classified as critical. The impacted element is an unknown function of the component Components Service. The manipulation results in improper authorization.
This vulnerability was named CVE-2025-50086. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2023-28200 | Apple macOS up to 13.2.1 Kernel information disclosure (HT213670 / EUVD-2023-31908)
1 month 2 weeks ago
A vulnerability was found in Apple macOS up to 13.2.1 and classified as problematic. This affects an unknown part of the component Kernel. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2023-28200. The attack must be initiated from a local position. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2023-28200 | Apple iOS/iPadOS up to 15.7.3 Kernel Memory information disclosure (HT213670 / EUVD-2023-31908)
1 month 2 weeks ago
A vulnerability marked as problematic has been reported in Apple iOS and iPadOS up to 15.7.3. This vulnerability affects unknown code of the component Kernel Memory Handler. This manipulation causes information disclosure.
This vulnerability appears as CVE-2023-28200. The attack requires local access. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2023-28194 | Apple iOS/iPadOS up to 16.3.1 Safari access control (HT213676 / EUVD-2023-31902)
1 month 2 weeks ago
A vulnerability has been found in Apple iOS and iPadOS up to 16.3.1 and classified as problematic. This affects an unknown function of the component Safari. This manipulation causes improper access controls.
This vulnerability appears as CVE-2023-28194. The attack requires local access. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2023-28192 | Apple macOS up to 13.2.1 System Settings information disclosure (HT213670 / EUVD-2023-31900)
1 month 2 weeks ago
A vulnerability was found in Apple macOS up to 13.2.1 and classified as problematic. Impacted is an unknown function of the component System Settings. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2023-28192. The attack must be carried out locally. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets
1 month 2 weeks ago
The second Shai-Hulud attack last week exposed around 400,000 raw secrets after infecting hundreds of packages in the NPM (Node Package Manager) registry and publishing stolen data in 30,000 GitHub repositories. [...]
Bill Toulas
Small numbers of Notepad++ users reporting security woes
1 month 2 weeks ago
Kevin Beaumont
CVE-2025-50085 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 InnoDB improper authorization (Nessus ID 244833 / WID-SEC-2025-1567)
1 month 2 weeks ago
A vulnerability has been found in Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 and classified as critical. The affected element is an unknown function of the component InnoDB. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2025-50085. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2025-50080 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 Stored Procedure improper authorization (Nessus ID 244807 / WID-SEC-2025-1567)
1 month 2 weeks ago
A vulnerability classified as critical has been found in Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0. This affects an unknown part of the component Stored Procedure. This manipulation causes improper authorization.
This vulnerability appears as CVE-2025-50080. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50082 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 Optimizer improper authorization (EUVD-2025-21498 / Nessus ID 253482)
1 month 2 weeks ago
A vulnerability classified as critical was found in Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0. This vulnerability affects unknown code of the component Optimizer. Such manipulation leads to improper authorization.
This vulnerability is traded as CVE-2025-50082. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-50083 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 Optimizer improper authorization (Nessus ID 244808 / WID-SEC-2025-1567)
1 month 2 weeks ago
A vulnerability, which was classified as critical, has been found in Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0. This issue affects some unknown processing of the component Optimizer. Performing manipulation results in improper authorization.
This vulnerability is known as CVE-2025-50083. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-50084 | Oracle Server up to 8.0.42/8.4.5/9.3.0 Optimizer improper authorization (Nessus ID 244810 / WID-SEC-2025-1567)
1 month 2 weeks ago
A vulnerability, which was classified as critical, was found in Oracle Server up to 8.0.42/8.4.5/9.3.0. Impacted is an unknown function of the component Optimizer. Executing manipulation can lead to improper authorization.
This vulnerability is handled as CVE-2025-50084. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-50081 | Oracle MySQL Cluster/MySQL Client up to 7.6.34/8.0.42/8.4.5/9.3.0 Mysqldump improper authorization (Nessus ID 244800 / WID-SEC-2025-1567)
1 month 2 weeks ago
A vulnerability identified as critical has been detected in Oracle MySQL Cluster and MySQL Client up to 7.6.34/8.0.42/8.4.5/9.3.0. This issue affects some unknown processing of the component Mysqldump. This manipulation causes improper authorization.
This vulnerability is tracked as CVE-2025-50081. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com