| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data. |
| A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to modify a file it only had permission to read. |
| A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. |
| A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |
| google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeBinary() API, causing a RangeError: Maximum call stack size exceeded and crashing the process. No authentication or prior knowledge of the schema is required. |
| The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership. |
| Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. |
| Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. |
| Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. |
| Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. |
| Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. |
| Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions. |
| Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. |
| Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions. |
| Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. |
| Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. |
| Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. |