Post

2025-09-17 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2024-12367Vegagrup Software - Vega MasterExposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Master allows Directory Indexing.This issue affects Vega Master: from v.1.12.35 through 20250916. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available.CVSS3.1: 8.6 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: partialInformation Disclosure in Vegagrup Software’s Vega Mastergithub
CVE-2009-20005InterSystems Corporation - InterSystems CachéA stack-based buffer overflow exists in the UtilConfigHome.csp endpoint of InterSystems Caché 2009.1. The vulnerability is triggered by sending a specially crafted HTTP GET request containing an oversized argument to the .csp handler. Due to insufficient bounds checking, the input overflows a stack buffer, allowing an attacker to overwrite control structures and execute arbitrary code. It is unknown if this vulnerability was patched and an affected version range remains undefined.CVSS4.0: 9.3 - CRITICAL0 1 2 3 4Exploitation: pocAutomatable: yesTechnical Impact: totalInterSystems Caché UtilConfigHome.csp Stack Buffer Overflowgithub
CVE-2025-24088Apple - macOSThe issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to override MDM-enforced settings from profiles.CNA n/a CVSS3.1: 7.5 - HIGH0Exploitation: noneAutomatable: yesTechnical Impact: partialundefinedgithub
CVE-2025-10491MongoDB Inc - MongoDB ServerThe MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB’s process via DLL hijacking. This issue affects MongoDB Server v6.0 version prior to 6.0.25, MongoDB Server v7.0 version prior to 7.0.21 and MongoDB Server v8.0 version prior to 8.0.5CVSS3.1: 7.8 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: totalMongoDB Windows installation MSI may leave ACLs unset on custom installation directoriesgithub
This post is licensed under CC BY 4.0 by the author.