-
CVE-2025-63649
•
published on January 29, 2026
An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the server.
-
CVE-2025-63650
•
published on January 29, 2026
An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
-
CVE-2025-63651
•
published on January 29, 2026
A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
-
CVE-2025-63652
•
published on January 29, 2026
A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
-
CVE-2025-63653
•
published on January 29, 2026
An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
-
CVE-2025-63655
•
published on January 29, 2026
A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
-
CVE-2025-63656
•
published on January 29, 2026
An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
-
CVE-2025-63657
•
published on January 29, 2026
An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
-
CVE-2025-63658
•
published on January 29, 2026
A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
-
CVE-2025-69516
•
published on January 29, 2026
A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting versions equal to or earlier than v1.3.1, allows low-privileged users with Report Viewer or Report Manager permissions to achieve remote command execution on the server. This occurs due to improper sanitization of the template_md parameter, enabling direct injection of Jinja2 templates. This occurs due to misuse of the generate_html() function, the user-controlled value is inserted into `env.from_string`, a function that processes Jinja2 templates arbitrarily, making an SSTI possible.
-
CVE-2025-69604
•
published on January 29, 2026
An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
-
CVE-2025-69749
•
published on January 29, 2026
Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code.
-
CVE-2025-69929
•
published on January 29, 2026
An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the password hashing on the client side using the MD5 algorithm over a predictable string format
-
CVE-2025-71008
•
published on January 29, 2026
A segmentation violation in the oneflow._oneflow_internal.autograd.Function.FunctionCtx.mark_non_differentiable component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
-
CVE-2025-71009
•
published on January 29, 2026
An input validation vulnerability in the flow.scatter/flow.scatter_add component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted indices.
-
CVE-2025-71011
•
published on January 29, 2026
An input validation vulnerability in the flow.Tensor.new_empty/flow.Tensor.new_ones/flow.Tensor.new_zeros component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
-
CVE-2025-15344
•
published on January 28, 2026
Tanium addressed a SQL injection vulnerability in Asset.
-
CVE-2025-15344
•
published on January 28, 2026
Tanium addressed a SQL injection vulnerability in Asset.
-
CVE-2025-15344
•
published on January 28, 2026
Tanium addressed a SQL injection vulnerability in Asset.
-
CVE-2025-15344
•
published on January 28, 2026
Tanium addressed a SQL injection vulnerability in Asset.