CVE Catalog

Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.

Jan 27, 2025

Apple macOS Ventura and Sonoma Removable Volume Access Vulnerability

A permissions vulnerability exists in macOS Ventura 13.7.3 and macOS Sonoma 14.7.3, allowing applications to access removable volumes without user consent. This issue was addressed by implementing additional restrictions.

4.3
Jan 27, 2025

Apple TV App Sensitive Location Information Access Vulnerability

A vulnerability exists in the Apple TV app on macOS Sequoia and macOS Sonoma, allowing unauthorized access to sensitive location information. This issue arises from inadequate data protection measures, which could enable an application to read private location details without proper authorization.

4.3
Jan 27, 2025

Apple macOS Sequoia Protected User Data Access Vulnerability

A vulnerability exists in macOS Sequoia that allows applications to access protected user data. This issue has been addressed in the macOS Sequoia 15.3 update.

4.4
Jan 27, 2025

Apple ImageIO Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the ImageIO component of multiple Apple operating systems, including iPadOS, macOS Ventura, macOS Sonoma, watchOS, and tvOS. This vulnerability arises from improper memory handling when processing images, which can lead to unexpected application termination or system resource exhaustion.

4.7
Jan 27, 2025

Apple CoreMedia Privilege Escalation Vulnerability

A use-after-free vulnerability in the CoreMedia component of multiple Apple operating systems, including iOS, iPadOS, macOS Sequoia, watchOS, tvOS, and visionOS, was addressed with improved memory management. This vulnerability allowed a malicious application to elevate privileges and may have been actively exploited in versions of iOS prior to 17.2.

6.6
Jan 27, 2025

Apple macOS SharedFileList Component Logic Vulnerability Allowing Unauthorized File System Access

A logic vulnerability in the SharedFileList component of Apple macOS has been identified, allowing an attacker to gain access to protected areas of the file system. This issue affects multiple macOS versions, including Sonoma 14.7.2, Sequoia 15.2, and Ventura 13.7.2. The vulnerability arises from inadequate restrictions in file handling, which could be exploited to access sensitive data or files without proper authorization.

4.4
Jan 27, 2025

Apple Products Autocomplete Contact Information Logging Vulnerability

A vulnerability exists in various Apple products, including macOS Sequoia 15.2, iOS 18.2, and iPadOS 18.2. This issue allows an application to access autocompleted contact details from Messages and Mail, which may be recorded in the system logs. The vulnerability arises from inadequate redaction of sensitive information before it is logged.

4.4
Jan 27, 2025

Apple macOS Sequoia Sensitive Data Access Vulnerability

A vulnerability exists in macOS Sequoia that allows apps to access user-sensitive data. This issue has been addressed with improved redaction of sensitive information and is fixed in macOS Sequoia 15.2.

4.7
Jan 27, 2025

Apple macOS Protected User Data Access Vulnerability

A vulnerability exists in multiple macOS versions, including Sonoma 14.7.2, Sequoia 15.2, and Ventura 13.7.2, allowing apps to access protected user data. This issue stems from a logic flaw that was addressed with improved file handling and state management.

4.7
Jan 27, 2025

Apple WebKit Memory Corruption Vulnerability

A vulnerability in the WebKit component of multiple Apple operating systems, including visionOS, tvOS, watchOS, iOS, iPadOS, and macOS Sequoia, has been identified. This vulnerability allows processing of maliciously crafted web content, leading to memory corruption. The issue arises from improper handling of memory, which could potentially be exploited to execute arbitrary code or cause other unintended behaviors.

5.0
Jan 27, 2025

Apple Safari Private Browsing Authentication Bypass Vulnerability

A vulnerability exists in Apple Safari's private browsing feature, allowing tabs to be accessed without authentication. This issue affects Safari 18.2 on macOS Sequoia 15.2, watchOS 11.2, iOS 18.2, and iPadOS 18.2. The vulnerability arises from a logic flaw in state management, which could potentially be exploited to access private browsing data without proper authorization.

4.7
Jan 27, 2025

Apple APFS User-Sensitive Data Access Vulnerability

A vulnerability exists in the Apple APFS component of multiple operating systems, including macOS Ventura, macOS Sonoma, visionOS, tvOS, and watchOS. This vulnerability allows apps to access user-sensitive data without proper authorization. The issue has been addressed in the latest versions of these operating systems.

4.8
Jan 27, 2025

Apple macOS WindowServer Lock Screen Keyboard Event Capture Vulnerability

A vulnerability in the WindowServer component of Apple macOS Sonoma, Sequoia, and Ventura allows apps to capture keyboard events from the lock screen. This issue arises from a logic flaw in state management, which could potentially be exploited to intercept keystrokes while the device is locked.

4.7
Jan 27, 2025

Apple QuickTime Player Sandbox Bypass Vulnerability Allowing Unauthorized File Access

A vulnerability exists in QuickTime Player on macOS Sonoma 14.7.2, macOS Sequoia 15.2, and macOS Ventura 13.7.2, allowing applications to read and write files outside of their designated sandbox. This issue arises from insufficient entitlement checks, which could enable unauthorized access to user data.

4.8
Jan 27, 2025

Apple macOS Sequoia NVRAM Variable Modification Vulnerability

A vulnerability exists in Apple macOS Sequoia that allows an application to edit NVRAM variables. This issue arises from insufficient validation of environment variables, potentially leading to unauthorized modifications. The vulnerability affects all versions of macOS Sequoia prior to 15.2.

4.4
Jan 27, 2025

Apple Products Password Autofill Authentication Bypass Vulnerability

A vulnerability exists in multiple Apple products, including macOS Sequoia 15.2, watchOS 11.2, visionOS 2.2, iOS 18.2, and iPadOS 18.2. This vulnerability allows the password autofill feature to incorrectly fill in passwords after a failed authentication attempt. The issue arises from a logic flaw in how password autofill handles authentication states, potentially leading to unauthorized access to sensitive accounts or information.

4.7
Jan 27, 2025

Apple IOMobileFrameBuffer Coprocessor Memory Corruption Vulnerability

A vulnerability exists in the IOMobileFrameBuffer component, available on iPhone XS and later, as well as various iPad and Apple Watch models. This vulnerability allows an app to corrupt coprocessor memory, potentially leading to unintended behavior or system instability. The issue has been addressed with improved bounds checks.

4.4
Jan 27, 2025

Apple IOMobileFrameBuffer Coprocessor Memory Corruption Vulnerability

A vulnerability exists in the IOMobileFrameBuffer component, available on various Apple devices including iPhone, iPad, and Apple Watch. This vulnerability allows an application to corrupt coprocessor memory, potentially leading to unintended behavior or system instability. The issue arises from inadequate bounds checks, which could be exploited by malicious applications to manipulate memory in a way that disrupts normal operations.

4.7
Jan 27, 2025

Apple macOS SharedFileList Overwrite Vulnerability

A path handling vulnerability has been identified in the SharedFileList component of Apple macOS Ventura 13.7.2, macOS Sonoma 14.7.2, and macOS Sequoia 15.2. This vulnerability allows applications to overwrite arbitrary files, potentially leading to unauthorized modifications of user data or system files.

4.4
Jan 27, 2025

Apple macOS Sonoma and Sequoia Logging Vulnerability Allowing Location Data Access

A vulnerability exists in the logging mechanism of macOS Sonoma 14.7.2 and macOS Sequoia 15.2, which may allow applications to access sensitive location information. This issue was addressed by improving how logs are sanitized.

4.7
Jan 27, 2025

Apple IOMobileFrameBuffer Coprocessor Memory Corruption Vulnerability

A vulnerability exists in the IOMobileFrameBuffer component of Apple operating systems, including macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2, and iPadOS 18.2. This vulnerability allows an application to corrupt coprocessor memory, potentially leading to unintended behavior or system instability. The issue arises from inadequate bounds checks, which could be exploited by malicious applications to manipulate memory in a way that disrupts normal operations.

4.7
Jan 27, 2025

Apple IOMobileFrameBuffer Coprocessor Memory Corruption Vulnerability

A vulnerability exists in the IOMobileFrameBuffer component, available on various Apple devices including iPhone, iPad, and Apple Watch. This vulnerability allows an app to corrupt coprocessor memory, potentially leading to unintended behavior or system instability. The issue has been addressed with improved bounds checks.

4.7
Jan 27, 2025

Apple macOS SharedFileList Launch Daemon Approval Vulnerability

A permissions vulnerability exists in the SharedFileList component of Apple macOS Sonoma and Sequoia. This issue allows an application to approve a launch daemon without user consent. The vulnerability has been addressed with additional restrictions in macOS Sonoma 14.7.2 and macOS Sequoia 15.2.

4.4
Jan 27, 2025

Apple Face Gallery Apple Account Fingerprinting Vulnerability

A vulnerability exists in the Face Gallery component of Apple Watch, iOS, and iPadOS, specifically in versions prior to watchOS 11.2, iOS 18.2, and iPadOS 18.2. This vulnerability allows a system binary to fingerprint a user's Apple Account, potentially enabling tracking of the user's activity. The issue was caused by improper handling of certain flags, which has been addressed in the latest software updates.

3.9
Jan 27, 2025

Apple macOS ASP TCP Out-of-Bounds Write Vulnerability Allowing Kernel Memory Corruption

A vulnerability in the ASP TCP component of Apple macOS can lead to unexpected system termination or corruption of kernel memory. This out-of-bounds write issue was addressed with improved input validation. The vulnerability is present in several versions of macOS Sonoma and Sequoia.

4.8
Jan 27, 2025

Apple WebKit Type Confusion Vulnerability Allowing Kernel Memory Read

A type confusion vulnerability has been identified in the WebKit component of Apple macOS Sequoia 15.2, iOS 18.2, and iPadOS 18.2. This vulnerability allows an attacker with user privileges to read kernel memory. The issue arises from improper memory handling, which could potentially be exploited to access sensitive information from the kernel.

4.4
Jan 27, 2025

Apple ImageIO Use-After-Free Vulnerability Leading to Arbitrary Code Execution

A use-after-free vulnerability has been identified in the ImageIO component of multiple Apple operating systems, including iOS 18.2, iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, and watchOS 11.2. This vulnerability arises from improper memory management when processing maliciously crafted images, which may result in arbitrary code execution.

4.8
Jan 27, 2025

Apple WebKit Denial-of-Service Vulnerability

A denial-of-service vulnerability has been identified in the WebKit component of various Apple operating systems, including iPadOS, macOS Ventura, macOS Sonoma, tvOS, watchOS, and visionOS. This vulnerability allows processing maliciously crafted web content to cause an unexpected process crash or memory corruption, potentially leading to a system termination.

4.7
Jan 27, 2025

Apple Photos Logic Vulnerability in Hidden Album Allowing Unauthorized Access

A logic vulnerability has been identified in Apple Photos across multiple platforms, including macOS Ventura, iOS, iPadOS, and macOS Sequoia. This vulnerability allows photos in the Hidden Photos Album to be viewed without authentication. The issue arises from improper file handling, which has been addressed in the latest updates for each operating system.

4.8
Jan 27, 2025

Apple WebKit Out-of-Bounds Access Vulnerability Leading to Process Crash

A vulnerability in the WebKit component of various Apple operating systems, including iPadOS, visionOS, tvOS, watchOS, and macOS, allows for out-of-bounds access. This issue was addressed with improved bounds checking. However, processing maliciously crafted web content could still lead to an unexpected process crash.

4.7
Jan 27, 2025

Apple macOS Privacy Vulnerability Allowing Location Access

A privacy vulnerability in Apple macOS versions Sonoma 14.7.2, Sequoia 15.2, and Ventura 13.7.2 allows apps to access a user's current location. This issue arises from inadequate redaction of private data in log entries, which could potentially be exploited to determine location information.

4.4
Jan 27, 2025

Apple Various Products Kernel Sandbox Escape Vulnerability

A vulnerability exists in the kernel of multiple Apple operating systems, including macOS Ventura, macOS Sonoma, tvOS, watchOS, and iPadOS. This vulnerability allows an application to break out of its sandbox, potentially leading to unauthorized access or actions on behalf of the user.

4.7
Jan 27, 2025

Apple Privacy Vulnerability in Contacts Access on Multiple macOS Versions

A privacy vulnerability has been identified that allows applications to access user contacts without proper authorization. This issue affects macOS Ventura 13.7.3, macOS Sonoma 14.7.3, and macOS Sequoia 15. The vulnerability arises from inadequate data redaction in system logs, which may inadvertently expose contact information.

4.8
Jan 27, 2025

IBM Watson Query and Data Virtualization Improper Data Protection Vulnerability Allowing Sensitive Information Disclosure

A vulnerability exists in IBM Watson Query on Cloud Pak for Data, specifically in the Data Virtualization components of versions 1.8, 2.0, 2.1, 2.2, and 3.0.0. This vulnerability could enable an authenticated user to access sensitive information from objects published through Watson Query. The issue arises from an inadequate data protection mechanism, which fails to govern all columns of published objects, leaving certain sensitive data unprotected.

2.2
Jan 27, 2025

Axiomatic Bento4 Heap-Based Buffer Overflow Vulnerability in mp42aac Component

A critical heap-based buffer overflow vulnerability has been identified in Axiomatic Bento4 versions through 1.6.0. The issue arises in the mp42aac component, specifically within the AP4_StdcFileByteStream::ReadPartial function. This vulnerability can be exploited remotely, allowing attackers to manipulate input data and cause memory corruption by overwriting parts of the heap.

3.7
Jan 27, 2025

Axiomatic Bento4 Heap-Based Buffer Overflow Vulnerability in mp42aac Component

A critical heap-based buffer overflow vulnerability has been identified in Axiomatic Bento4 versions through 1.6.0. The issue arises in the mp42aac component, specifically within the AP4_BitReader::ReadBits function. This vulnerability can be exploited remotely, leading to memory corruption by allowing attackers to manipulate heap memory beyond allocated boundaries.

3.8
Jan 27, 2025

FLXEON Arbitrary Code Execution Vulnerability with Elevated Privileges

A vulnerability exists in FLXEON versions through 9.3.4 that allows network access to execute arbitrary code with elevated privileges.

1.7
Jan 27, 2025

y_project RuoYi Whitelist Component Deserialization Vulnerability

A critical deserialization vulnerability has been identified in the y_project RuoYi application, affecting versions through 4.8.0. The issue arises in the Whitelist component's getBeanName function, allowing remote exploitation.

3.0
Jan 27, 2025

Midea Group Midea Home iOS Sensitive Information Disclosure Vulnerability

A vulnerability in Midea Group's Midea Home application for iOS, specifically version 9.3.12, allows attackers to access sensitive user information by sending a crafted link. This issue arises from inadequate validation of link content, enabling the interception or extraction of personal data from users.

2.0
Jan 27, 2025

Zhiyuan Yuedu Shuqi Novel iOS Sensitive Information Access Vulnerability

A vulnerability in the Zhiyuan Yuedu Shuqi Novel iOS application, version 5.3.8, allows attackers to access sensitive user information by sending a crafted link. This issue could potentially be exploited to retrieve private data from users of the application.

2.0
Jan 27, 2025

Pixocial Technology BeautyPlus iOS Sensitive Information Disclosure Vulnerability

A vulnerability in Pixocial Technology (Singapore) Pte. Ltd BeautyPlus for iOS, version 7.8.010, allows attackers to access sensitive user information by sending a crafted link. This issue could be exploited to retrieve private data from users of the application.

3.3
Jan 27, 2025

Shenzhen Intellirocks Govee Home iOS Sensitive Information Disclosure Vulnerability

A vulnerability in the Govee Home iOS application, version 6.5.01, developed by Shenzhen Intellirocks Tech Co. Ltd, allows attackers to access sensitive user information by sending a crafted payload.

4.5
Jan 27, 2025

Cloud Whale PolyBuzz iOS Sensitive Information Disclosure Vulnerability

A vulnerability in Cloud Whale Interactive Technology LLC. PolyBuzz for iOS, version 2.0.20, allows attackers to access sensitive user information by sending a crafted link.

2.0
Jan 27, 2025

Shanghai Xuan Ting Qidian Reader for iOS Sensitive Information Disclosure Vulnerability

A vulnerability in Qidian Reader for iOS, version 5.9.384, allows attackers to access sensitive user information by sending a crafted link. This issue arises from improper handling of links, which can be exploited to extract personal data from users.

2.0
Jan 27, 2025

Shanghai Shizhi Information Technology Co., Ltd Shihuo iOS Sensitive Information Disclosure Vulnerability

A vulnerability in the Shihuo iOS application, version 8.16.0, developed by Shanghai Shizhi Information Technology Co., Ltd, allows attackers to access sensitive user information by sending a crafted link.

2.0
Jan 27, 2025

Guazi Used Car iOS Sensitive Information Disclosure Vulnerability

A vulnerability in the Guazi Used Car iOS application, version 10.15.1, allows attackers to access sensitive user information by sending a crafted link. This issue could potentially be exploited to gather private data from users of the application.

2.0
Jan 27, 2025

Beijing Sogou Technology Development Co., Ltd Sogou Input Access to Sensitive User Information Vulnerability

A vulnerability in Sogou Input for iOS, version 12.2.0, allows attackers to access sensitive user information by sending a crafted link. This issue arises from inadequate validation of link content, enabling the extraction of personal data from users.

2.0
Jan 27, 2025

Tencent WeSing iOS Sensitive Information Disclosure Vulnerability

A vulnerability in Tencent WeSing for iOS, version 9.3.39, allows attackers to access sensitive user information by sending a crafted link. This issue could be exploited to retrieve private data from users of the application.

2.0
Jan 27, 2025

Tianjin Xiaowu Information Technology Co., Ltd BeiKe Holdings iOS Sensitive Information Disclosure Vulnerability

A vulnerability in the BeiKe Holdings iOS application, version 1.3.50, allows attackers to access sensitive user information by sending a crafted link. This issue arises from inadequate validation of link content, enabling the interception or extraction of personal data from users.

2.0
Jan 27, 2025

Mashang Consumer Finance Anyihua iOS Sensitive Information Disclosure Vulnerability

A vulnerability in Mashang Consumer Finance Co., Ltd Anyihua for iOS, version 3.6.2, allows attackers to access sensitive user information by sending a crafted link. This issue arises from inadequate validation of link inputs, which can be exploited to retrieve private data.

2.0