Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 32208 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-29921 1 Powerjob 1 Powerjob 2025-02-05 N/A 5.3 MEDIUM
PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create app interface.
CVE-2023-29586 1 Codesector 1 Teracopy 2025-02-05 N/A 5.5 MEDIUM
Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This leads to Arbitrary File Read by allowing any user to copy any directory in the system to a directory they control. NOTE: the Supplier disputes this because only admin users can copy arbitrary folders, and because the 143984 reference is about a different concern (unrelated to directory copying) that was fixed in 3.5b.
CVE-2023-28122 1 Ui 1 Desktop 2025-02-05 N/A 7.8 HIGH
A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a malicious actor with local access to a Windows device running said application to submit arbitrary commands as SYSTEM.This vulnerability is fixed in Version 0.62.3 and later.
CVE-2022-2507 1 Octopus 1 Octopus Server 2025-02-05 N/A 5.3 MEDIUM
In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage
CVE-2022-29608 1 Opennetworking 1 Onos 2025-02-05 N/A 7.5 HIGH
An issue was discovered in ONOS 2.5.1. An intent with a port that is an intermediate point of its path installs an invalid flow rule, causing a network loop.
CVE-2023-48747 1 Booster 1 Booster For Woocommerce 2025-02-05 N/A 6.5 MEDIUM
Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster for WooCommerce: from n/a through 7.1.2.
CVE-2023-47504 1 Elementor 1 Website Builder 2025-02-05 N/A 7.5 HIGH
Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.
CVE-2025-24120 1 Apple 1 Macos 2025-02-05 N/A 7.5 HIGH
This issue was addressed by improved management of object lifetimes. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An attacker may be able to cause unexpected app termination.
CVE-2025-24100 1 Apple 1 Macos 2025-02-05 N/A 3.3 LOW
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to access information about a user's contacts.
CVE-2025-24086 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2025-02-05 N/A 5.5 MEDIUM
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing an image may lead to a denial-of-service.
CVE-2023-30611 1 Discourse 1 Reactions 2025-02-05 N/A 4.3 MEDIUM
Discourse-reactions is a plugin that allows user to add their reactions to the post in the Discourse messaging platform. In affected versions data about what reactions were performed on a post in a private topic could be leaked. This issue has been addressed in version 0.3. Users are advised to upgrade. Users unable to upgrade should disable the discourse-reactions plugin to fully mitigate the issue.
CVE-2023-29926 1 Powerjob 1 Powerjob 2025-02-05 N/A 9.8 CRITICAL
PowerJob V4.3.2 has unauthorized interface that causes remote code execution.
CVE-2025-24161 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2025-02-04 N/A 5.5 MEDIUM
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.
CVE-2025-24143 1 Apple 4 Ipados, Macos, Safari and 1 more 2025-02-04 N/A 6.5 MEDIUM
The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.
CVE-2025-24141 1 Apple 2 Ipados, Iphone Os 2025-02-04 N/A 3.3 LOW
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.
CVE-2025-24116 1 Apple 1 Macos 2025-02-04 N/A 4.4 MEDIUM
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to bypass Privacy preferences.
CVE-2025-24114 1 Apple 1 Macos 2025-02-04 N/A 5.5 MEDIUM
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.
CVE-2025-24112 1 Apple 1 Macos 2025-02-04 N/A 5.5 MEDIUM
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a file may lead to an unexpected app termination.
CVE-2024-54549 1 Apple 1 Macos 2025-02-04 N/A 5.5 MEDIUM
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.
CVE-2024-54512 1 Apple 3 Ipados, Iphone Os, Watchos 2025-02-04 N/A 9.1 CRITICAL
The issue was addressed by removing the relevant flags. This issue is fixed in watchOS 11.2, iOS 18.2 and iPadOS 18.2. A system binary could be used to fingerprint a user's Apple Account.