A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The m... This is a high threat mapped to CVE-2026-94128; security leaders should validate exposure, prioritize patching, and verify compensati...
Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows... This is a low threat mapped to CVE-2026-92254; security leaders should validate exposure, prioritize patching, and verify compensatin...
The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via save_ams_license_... This is a medium threat mapped to CVE-2026-13770; security leaders should validate exposure, prioritize patching, and verify compensa...
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. This is a critical threat mapped to CVE-2025-39964; security leaders should validate exposure, priori...
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. This is a critical threat mapped to CVE-2026-53266; security leaders should valid...
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy...
In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, result... This is a low threat mapped to CVE-2026-15419; security leaders should validate exposure, prioritize patching, and verify compensatin...
In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash. This is a low threat mapped to CVE-2026-15417; security leaders should validate exposure, prioritize patching, and verify compensating controls.
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. This is a critical threat mapped to CVE-2026-67277; security leaders should validate exposure, prioritize patching, and verify compensating controls.
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. This is a critical threat mapped to CVE-2025-25249; security leaders should validate exposure, prioritize patching, an...
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This is a critical threat mapped to CVE-2026-53362; security leaders should validate exposure, prioritize patching, and verify compensating controls.
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. This is a critical threat mapped to CVE-2022-0995; security leaders should validate exposure, prioritize patching, and verify compensating controls.
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. This is a critical threat mapped to CVE-2026-65400; security leaders should validate exposure, prioritize patching, and verify compensating controls.
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This is a critical threat mapped to CVE-2025-68686; security leaders should validate exposure, prioritize patching, and verify compensating controls.
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /le... This is a critical threat mapped to CVE-2008-4128; security leaders should validate exposure, prioritize patching, and verify compens...
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. This is a critical threat mapped to CVE-2022-0492; security leaders should validate exposure, prioritize patching, and verify compensating controls.
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. This is a critical threat mapped to CVE-2026-31431; security leaders should validate exposure, prioritize patching, and verify compensating controls.
Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. This is a critical threat mapped to CVE-2025-54068; security leaders should validate exposure, prioritize patching, and verify compensating controls.
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes. This is a critical threat mapped to CVE-2025-43510; security leaders should validate exposure, prioritize patching,...
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory. This is a critical threat mapped to CVE-2025-43520; security leaders should validate exposure, prioritize patc...
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption. This is a critical threat mapped to CVE-2025-31277; security leaders should validate exposure, prioritize patch...
Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption. This is a critical threat mapped to CVE-2023-43000; security leaders should validate exposure, prioritize patching, and verify compensating con...
Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution. This is a critical threat mapped to CVE-2021-30952; security leaders should validate exposure, prioritize patching,...
Apple iOS and iPadOS contain a use-after-free vulnerability. This is a critical threat mapped to CVE-2023-41974; security leaders should validate exposure, prioritize patching, and verify compensating controls.
Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code. This is a critical threat mapped to CVE-2026-20700; security leaders should validate...