Latest CVE Feed
-
7.8
HIGHCVE-2025-31222
A correctness issue was addressed with improved checks. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A user may be able to elevate privileges.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
8.0
HIGHCVE-2025-31223
The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-31224
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to bypass certain Privacy preferences.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-31225
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps may still appear in spotlight search results.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-31226
A logic issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5. Processing a maliciously crafted image may lead to a denial-of-service.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Denial of Service
-
4.6
MEDIUMCVE-2025-31227
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access a deleted call recording.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
6.8
MEDIUMCVE-2025-31228
The issue was addressed with improved authentication. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access notes from the lock screen.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-31232
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A sandboxed app may be able to access sensitive user data.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
6.3
MEDIUMCVE-2025-31233
The issue was addressed with improved input sanitization. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. Processing a maliciously crafte... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
8.2
HIGHCVE-2025-31234
The issue was addressed with improved input sanitization. This issue is fixed in visionOS 2.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-31235
A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to cause unexpected system termination.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-31236
An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-31237
This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Denial of Service
-
7.3
HIGHCVE-2025-31238
The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-31240
This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. Mounting a maliciously crafted AFP network share may lead to system termination.... Read more
Affected Products : macos- Published: May. 12, 2025
- Modified: May. 27, 2025
-
5.3
MEDIUMCVE-2025-31241
A double free issue was addressed with improved memory management. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7.6, tvOS 18.5, iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, macOS Ventura 13.7.6. A remote attacker may ... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-26369
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add privileges to user groups via crafted HTTP requests.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2023-43652
JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a password or the corresponding SSH private key. An SSH public key should be consid... Read more
Affected Products : jumpserver- Published: Sep. 27, 2023
- Modified: May. 27, 2025
-
7.8
HIGHCVE-2023-29336
Win32k Elevation of Privilege Vulnerability... Read more
- Actively Exploited
- Published: May. 09, 2023
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2025-4632
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.... Read more
Affected Products : magicinfo_9_server- Actively Exploited
- Published: May. 13, 2025
- Modified: May. 27, 2025
- Vuln Type: Path Traversal