CVE-2025-59489High· 7.4▾ MidnightPoC availableUnity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had t…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 40.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
2 GitHub repos (last check)
Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.
editor >= 2017.4, <= 2018.4editor >= 2019.1, < 2019.1.15f1editor >= 2019.2, < 2019.2.23f1editor >= 2019.3, <= 2019.3.17f1editor >= 2019.4, < 2019.4.41f1editor >= 2020.1, < 2020.1.18f1editor >= 2020.2, < 2020.2.8f1editor >= 2020.3, < 2020.3.49f1editor >= 2021.1, < 2021.1.29f1editor >= 2021.2, < 2021.2.20f1editor >= 2021.3, < 2021.3.45f2editor >= 2022.1, < 2022.1.25f1editor >= 2022.2, < 2022.2.23f1editor >= 2022.3, < 2022.3.62f2editor >= 2023.1, < 2023.1.22f1editor >= 2023.2, < 2023.2.22f1editor >= 6000.0, < 6000.0.58f2editor >= 6000.1, < 6000.1.17f1editor >= 6000.2, < 6000.2.6f2editor >= 6000.3, < 6000.3.0b4editor = 2017.1.2p4+editor = 2017.2.0p4+editor = 2017.3.0b9+Upgrade past the affected range:
editor 6000.3.0b4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40938High· 7.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines
CVE-2018-16156High· 7.8In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe
CVE-2022-26488High· 7.0In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured
CVE-2025-9016High· 7.0A vulnerability has been found in Mechrevo Control Center GX V2 5.56.51.48
CVE-2025-9000High· 7.0A vulnerability was detected in Mechrevo Control Center GX V2 5.56.51.48
CVE-2026-105788High· 8.8Microsoft UFO is an open-source framework for intelligent automation across devices and platforms