Michael

3 exploits Active since Mar 2020
CVE-2023-38609 NOMISEC HIGH WORKING POC
macOS Ventura <13.5 - Privilege Escalation
An injection issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.5. An app may be able to bypass certain Privacy preferences.
3 stars
CVSS 7.5
CVE-2019-15608 WRITEUP MEDIUM WRITEUP
yarn <1.19.0 - Info Disclosure
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.
CVSS 5.9
CVE-2026-25949 WRITEUP HIGH WRITEUP
Traefik < 3.6.8 - Denial of Service
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling, causing connections to remain open indefinitely, leading to a denial of service. This vulnerability is fixed in 3.6.8.
CVSS 7.5