Activity

Latest CVE events and analysis as they emerge

  1. CVE-2023-43000

    05 Mar 2026, 00:00

    Added to CISA KEV catalog

    Vulnerability name
    Apple Multiple products Use-After-Free Vulnerability
    Product
    Apple Multiple Products

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6. Processing maliciously crafted web content may lead to memory corruption.

  2. CVE-2023-41974

    05 Mar 2026, 00:00

    Added to CISA KEV catalog

    Vulnerability name
    Apple iOS and iPadOS Use-After-Free Vulnerability
    Product
    Apple iOS and iPadOS

    CVE-2023-41974 is a use-after-free vulnerability that impacts Apple's iOS and iPadOS. This flaw, addressed through improved memory management, could allow an application to execute arbitrary code with kernel privileges. Apple resolved this issue in iOS 17 and iPadOS 17. The vulnerability was discovered by Félix Poulin-Bélanger, who also generated proof-of-concept code demonstrating its exploitability, which involves winning a race condition to achieve kernel read and write operations. Due to evidence of active exploitation, CVE-2023-41974 has been added to CISA's Known Exploited Vulnerabilities Catalog.

  3. CVE-2021-30952

    05 Mar 2026, 00:00

    Added to CISA KEV catalog

    Vulnerability name
    Apple Multiple Products Integer Overflow or Wraparound Vulnerability
    Product
    Apple Multiple Products

    An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

  4. CVE-2021-22681

    05 Mar 2026, 00:00

    Added to CISA KEV catalog

    Vulnerability name
    Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
    Product
    Rockwell Multiple Products

    Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

  5. CVE-2017-7921

    05 Mar 2026, 00:00

    Added to CISA KEV catalog

    Vulnerability name
    Hikvision Multiple Products Improper Authentication Vulnerability
    Product
    Hikvision Multiple Products

    An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.