|
111
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-46313
|
2026-06-13 07:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
112
|
5.5 |
MEDIUM
Local
|
-
|
-
|
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
New
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2025-43278
|
2026-06-13 07:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
113
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system ter…
New
|
CWE-284
Improper Access Control
|
CVE-2025-24165
|
2026-06-13 07:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
114
|
- |
|
-
|
-
|
Rejected reason: This candidate was issued in error.
New
|
-
|
CVE-2020-2521
|
2026-06-13 07:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
115
|
- |
|
-
|
-
|
A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form data and set an event’s sharing_group_id to a sharing …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-54397
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
116
|
- |
|
-
|
-
|
An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit request, the user dropdown was populated using the attacke…
New
|
CWE-200
Information Exposure
|
CVE-2026-54396
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
117
|
- |
|
-
|
-
|
MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScript handler using HTML escaping inside a single-quot…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-54395
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
118
|
- |
|
-
|
-
|
MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using organisation-controlled fields such as id, name, and…
New
|
CWE-22
Path Traversal
|
CVE-2026-54394
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
119
|
- |
|
-
|
-
|
A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-controlled path value through setSettingInternal(), bypa…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-54393
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
120
|
- |
|
-
|
-
|
An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view galaxies that should not have been visible to their organisation. The custom ac…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-54362
|
2026-06-13 06:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|