Overview
Description
A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Statistics
- 1 Post
Last activity: 23 hours ago
Overview
- Microsoft
- Windows Server 2025 (Server Core installation)
09 May 2023
Published
10 Jul 2025
Updated
CVSS v3.1
MEDIUM (6.7)
EPSS
0.58%
KEV
Description
Secure Boot Security Feature Bypass Vulnerability
Statistics
- 1 Post
Last activity: 18 hours ago
Overview
Description
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Statistics
- 1 Post
Last activity: 18 hours ago
Overview
- Microsoft
- Windows 10 Version 1809
11 Jan 2022
Published
02 Jan 2025
Updated
CVSS v3.1
MEDIUM (4.4)
EPSS
42.69%
KEV
Description
Secure Boot Security Feature Bypass Vulnerability
Statistics
- 1 Post
Last activity: 18 hours ago
Overview
Description
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).
An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.
Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec().
This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3.
Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue
Statistics
- 1 Post
Last activity: 18 hours ago