Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2025-43339

CVE-2025-43339_CVE-2025-43339

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access ...

Apple macOS CVE
HIGH 7.8 CVE-2025-31272

CVE-2025-31272_CVE-2025-31272

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-30459

CVE-2025-30459_CVE-2025-30459

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive us...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-30431

CVE-2025-30431_CVE-2025-30431

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app...

Apple macOS CVE
HIGH 8.8 CVE-2025-24284

CVE-2025-24284_CVE-2025-24284

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to bre...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-24268

CVE-2025-24268_CVE-2025-24268

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app m...

Apple macOS CVE
MEDIUM 6.3 CVE-2026-53782

Summarize < 0.17.0 SSRF via podcast:transcript URL fetch_CVE-2026-53782

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the hos...

steipete summarize CVE
MEDIUM 5.3 CVE-2026-53781

Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download_CVE-2026-53781

Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media respons...

steipete summarize CVE
CRITICAL 9.2 CVE-2026-49973

Hermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settings_CVE-2026-49973

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initi...

nesquena hermes-webui CVE
MEDIUM 6 CVE-2026-49949

CodexBar < 0.33.0 Credential Leakage via HTTP Redirect_CVE-2026-49949

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by ...

steipete CodexBar CVE