Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-47238

ClipBucket: IDOR in videos subtitle editor_CVE-2026-47238

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video su...

MacWarrior clipbucket-v5 < 5.5.3 - #133 CVE
MEDIUM 5.3 CVE-2025-46308

CVE-2025-46308_CVE-2025-46308

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app ma...

Apple iOS and iPadOS CVE
MEDIUM 5.5 CVE-2025-46293

CVE-2025-46293_CVE-2025-46293

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-43339

CVE-2025-43339_CVE-2025-43339

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access ...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-30459

CVE-2025-30459_CVE-2025-30459

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive us...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-30431

CVE-2025-30431_CVE-2025-30431

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-24268

CVE-2025-24268_CVE-2025-24268

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app m...

Apple macOS CVE
MEDIUM 6.3 CVE-2026-53782

Summarize < 0.17.0 SSRF via podcast:transcript URL fetch_CVE-2026-53782

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the hos...

steipete summarize CVE
MEDIUM 5.3 CVE-2026-53781

Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download_CVE-2026-53781

Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media respons...

steipete summarize CVE
MEDIUM 6 CVE-2026-49949

CodexBar < 0.33.0 Credential Leakage via HTTP Redirect_CVE-2026-49949

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by ...

steipete CodexBar CVE