OBS-Vigilance

TitleDescriptionDate
Apple iOS macOS: multiple vulnerabilities dated 31/03/2025open in new windowAn attacker can use several vulnerabilities of Apple iOS macOS, dated 31/03/2025...Visit link for details
Python Core: overload via os.path.expandvars()open in new windowAn attacker can trigger an overload of Python Core, via os.path.expandvars()Visit link for details
Netgate pfSense CE: directory traversal via Suricataopen in new windowAn attacker can traverse directories of Netgate pfSense CE, via Suricata, in order to read or write a file outside the service root path...Visit link for details
MediaWiki: multiple vulnerabilities dated 31/10/2025open in new windowAn attacker can use several vulnerabilities of MediaWiki, dated 31/10/2025...Visit link for details
Joomla jDownloads: Cross Site Request Forgery dated 31/10/2025open in new windowAn attacker can trigger a Cross Site Request Forgery of Joomla jDownloads, dated 31/10/2025, in order to force the victim to perform operations...Visit link for details
Doorkeeper: user access via Replay Attacksopen in new windowAn attacker can bypass restrictions of Doorkeeper, via Replay Attacks, in order to gain user privileges...Visit link for details
Keycloak: read-write access via ResourceSetService / PermissionTicketServiceopen in new windowAn attacker can bypass access restrictions of Keycloak, via ResourceSetService / PermissionTicketServVisit link for details
Centreon Web: Cross Site Scripting via Meta-Service Configuration Pageopen in new windowAn attacker can trigger a Cross Site Scripting of Centreon Web, via Meta-Service Configuration Page, in order to run JavaScript code in the context of the web site...Visit link for details
Linux kernel: multiple vulnerabilities dated 30/10/2025open in new windowAn attacker can use several vulnerabilities of the Linux kernel, dated 30/10/2025...Visit link for details
Netty: SMTP command execution via SMTP Codec Carriage Returnopen in new windowAn attacker can use a vulnerability of Netty, via SMTP Codec Carriage Return, in order to run code...Visit link for details