Recent Advisories

Severity ID Title Vendor Product Date Type
NONE C9229595-56AA-

ember_C9229595-56AA-537C-BB8E-E4AA8A4F81D5

🔥 Ember AI systems burn brightly but hide their secrets. Ember reveals the truth hidden in ashes. A five-layer attack-defense-integration security...

N/A N/A GITHUBEXPLOIT
MEDIUM 5.5 CVE-2025-46313

CVE-2025-46313_CVE-2025-46313

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

Apple macOS CVE
MEDIUM 5.5 CVE-2025-43278

CVE-2025-43278_CVE-2025-43278

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-24165

CVE-2025-24165_CVE-2025-24165

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7....

Apple macOS CVE
HIGH 8.8 CVE-2026-54361

MISP mass assignment vulnerabilities allow unauthorized modification of ownership and delegation records_CVE-2026-54361

MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. ...

misp misp CVE
HIGH 8.4 CVE-2026-54360

MISP sharing group creation mass assignment allows unauthorized takeover of existing sharing groups_CVE-2026-54360

A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove ...

misp misp CVE
HIGH 7.1 CVE-2026-54359

MISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by default_CVE-2026-54359

MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disable...

misp misp CVE
HIGH 7.5 CVE-2026-54358

MISP organization administrators can target site administrator accounts for password reset_CVE-2026-54358

An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same o...

misp misp CVE
MEDIUM 5 CVE-2026-54055

Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol_CVE-2026-54055

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transm...

kovidgoyal kitty < 0.47.2 CVE
HIGH 7.8 CVE-2026-42851

@kitty-edit DCS + –color=geninclude vulnerable to Unauthenticated in-process RCE_CVE-2026-42851

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a...

kovidgoyal kitty < 0.47.0 CVE