CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24101
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3. An app may be able to access …

Jan 27, 2025
CVE-2025-24096
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. A malicious app may be able to access arbitrary …

Jan 27, 2025
CVE-2025-24094
4.7 MEDIUM

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may …

Jan 27, 2025
CVE-2025-24092
5.5 MEDIUM

This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to …

Jan 27, 2025
CVE-2025-24087
5.5 MEDIUM

The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected user …

Jan 27, 2025
CVE-2025-24086
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma …

Jan 27, 2025
CVE-2024-54550
4.0 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An app …

Jan 27, 2025
CVE-2024-54549
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.2. An app may be able to access …

Jan 27, 2025
CVE-2024-54547
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be …

Jan 27, 2025
CVE-2024-54541
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS …

Jan 27, 2025
CVE-2024-54539
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may …

Jan 27, 2025
CVE-2024-54536
5.5 MEDIUM

The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.2. An app may be able to edit …

Jan 27, 2025
CVE-2024-54523
6.3 MEDIUM

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. …

Jan 27, 2025
CVE-2024-54520
5.5 MEDIUM

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app …

Jan 27, 2025
CVE-2024-54519
5.5 MEDIUM

The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to read …

Jan 27, 2025
CVE-2024-54518
5.3 MEDIUM

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. …

Jan 27, 2025
CVE-2024-54507
5.5 MEDIUM

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An attacker …

Jan 27, 2025
CVE-2024-54497
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.3, …

Jan 27, 2025
CVE-2024-54488
5.3 MEDIUM

A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS …

Jan 27, 2025
CVE-2024-54478
6.5 MEDIUM

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, …

Jan 27, 2025
CVE-2024-37526
6.5 MEDIUM

IBM Watson Query on Cloud Pak for Data (IBM Data Virtualization 1.8, 2.0, 2.1, 2.2, and 3.0.0) could allow an authenticated user to obtain sensitive …

Jan 27, 2025
CVE-2025-0753
6.3 MEDIUM

A vulnerability classified as critical was found in Axiomatic Bento4 up to 1.6.0. This vulnerability affects the function AP4_StdcFileByteStream::ReadPartial of the component mp42aac. The manipulation …

Jan 27, 2025
CVE-2025-0751
6.3 MEDIUM

A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the component mp42aac. The manipulation …

Jan 27, 2025
CVE-2025-0734
4.7 MEDIUM

A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function getBeanName of the component Whitelist. …

Jan 27, 2025
CVE-2024-56972
6.5 MEDIUM

An issue in Midea Group Co., Ltd Midea Home iOS 9.3.12 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56971
6.5 MEDIUM

An issue in Zhiyuan Yuedu (Guangzhou) Literature Information Technology Co., Ltd Shuqi Novel iOS 5.3.8 allows attackers to access sensitive user information via supplying a …

Jan 27, 2025
CVE-2024-56969
6.5 MEDIUM

An issue in Pixocial Technology (Singapore) Pte. Ltd BeautyPlus iOS 7.8.010 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56968
6.5 MEDIUM

An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted payload.

Jan 27, 2025
CVE-2024-56967
6.5 MEDIUM

An issue in Cloud Whale Interactive Technology LLC. PolyBuzz iOS 2.0.20 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56966
6.5 MEDIUM

An issue in Shanghai Xuan Ting Entertainment Information & Technology Co., Ltd Qidian Reader iOS 5.9.384 allows attackers to access sensitive user information via supplying …

Jan 27, 2025
CVE-2024-56965
6.5 MEDIUM

An issue in Shanghai Shizhi Information Technology Co., Ltd Shihuo iOS 8.16.0 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56964
6.5 MEDIUM

An issue in Che Hao Duo Used Automobile Agency (Beijing) Co., Ltd Guazi Used Car iOS 10.15.1 allows attackers to access sensitive user information via …

Jan 27, 2025
CVE-2024-56963
6.5 MEDIUM

An issue in Beijing Sogou Technology Development Co., Ltd Sogou Input iOS 12.2.0 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56962
6.5 MEDIUM

An issue in Tencent Technology (Shanghai) Co., Ltd WeSing iOS v9.3.39 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56960
6.5 MEDIUM

An issue in Tianjin Xiaowu Information technology Co., Ltd BeiKe Holdings iOS 1.3.50 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56959
6.5 MEDIUM

An issue in Mashang Consumer Finance Co., Ltd Anyihua iOS 3.6.2 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56957
6.5 MEDIUM

An issue in Kingsoft Office Software Corporation Limited WPS Office iOS 12.20.0 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56955
6.5 MEDIUM

An issue in Tencent Technology (Shenzhen) Company Limited QQMail iOS 6.6.4 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56954
6.5 MEDIUM

An issue in Beijing Baidu Netcom Science & Technology Co Ltd Haokan Video iOS 7.70.0 allows attackers to access sensitive user information via supplying a …

Jan 27, 2025
CVE-2024-56953
6.5 MEDIUM

An issue in Baidu (China) Co Ltd Baidu Input Method (iOS version) v12.6.13 allows attackers to access user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56952
6.5 MEDIUM

An issue in Beijing Baidu Netcom Science & Technology Co Ltd Baidu Lite app (iOS version) 6.40.0 allows attackers to access user information via supplying …

Jan 27, 2025
CVE-2024-56951
6.5 MEDIUM

An issue in Hangzhou Bobo Technology Co Ltd UU Game Booster iOS 10.6.13 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56950
6.5 MEDIUM

An issue in KuGou Technology Co., Ltd KuGou Concept iOS 4.0.61 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56949
6.5 MEDIUM

An issue in Guangzhou Polar Future Culture Technology Co., Ltd University Search iOS 2.27.0 allows attackers to access sensitive user information via supplying a crafted …

Jan 27, 2025
CVE-2024-56948
6.5 MEDIUM

An issue in KuGou Technology CO. LTD KuGou Music iOS v20.0.0 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2024-56947
6.5 MEDIUM

An issue in Xiamen Meitu Technology Co., Ltd. BeautyCam iOS v12.3.60 allows attackers to access sensitive user information via supplying a crafted link.

Jan 27, 2025
CVE-2025-24354
5.3 MEDIUM

imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose …

Jan 27, 2025
CVE-2025-23197
6.5 MEDIUM

matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. When Hookshot 6 version 6.0.1 or below, or Hookshot …

Jan 27, 2025
CVE-2025-0733
4.5 MEDIUM

A vulnerability, which was classified as problematic, was found in Postman up to 11.20 on Windows. This affects an unknown part in the library profapi.dll. …

Jan 27, 2025
CVE-2025-0732
4.5 MEDIUM

A vulnerability, which was classified as problematic, has been found in Discord up to 1.0.9177 on Windows. Affected by this issue is some unknown functionality …

Jan 27, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.