2041
|
5.4 |
MEDIUM
Network
|
cryoutcreations
|
liquido
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Liquido allows Stored XSS.This issue affects Liquido: from n/a through 1.0…
|
CWE-79
Cross-site Scripting
|
CVE-2024-43993
|
2024-09-25 22:44 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2042
|
7.5 |
HIGH
Network
apple
|
macos iphone_os ipados
|
An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18, tvOS 18, macOS Sequoia 15. An attacker may be able to force a device to disconnect from a secure …
|
NVD-CWE-noinfo
|
CVE-2024-40856
|
2024-09-25 22:43 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2043
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to modify protected parts of the file system.
|
NVD-CWE-noinfo
|
CVE-2024-40860
|
2024-09-25 22:41 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2044
|
6.1 |
MEDIUM
Network
|
apple
|
macos iphone_os ipados visionos watchos tvos safari
|
This issue was addressed through improved state management. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. Processing maliciously crafted w…
|
CWE-79
Cross-site Scripting
|
CVE-2024-40857
|
2024-09-25 22:41 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2045
|
5.5 |
MEDIUM
Local
|
apple
|
iphone_os ipados
|
This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to leak sensitive user information.
|
NVD-CWE-noinfo
|
CVE-2024-40863
|
2024-09-25 22:40 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2046
|
5.3 |
MEDIUM
Network
huawei
|
harmonyos emui
|
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.
|
NVD-CWE-noinfo
|
CVE-2023-41311
|
2024-09-25 22:35 |
2023-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2047
|
9.8 |
CRITICAL
Network
ivanti
|
endpoint_manager
|
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
|
CWE-20
Improper Input Validation
|
CVE-2023-28324
|
2024-09-25 22:35 |
2023-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2048
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. A malicious application may be able to leak sensitive user information.
|
NVD-CWE-noinfo
|
CVE-2024-44125
|
2024-09-25 22:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2049
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An Automator Quick Action workflow may be abl…
|
NVD-CWE-noinfo
|
CVE-2024-44128
|
2024-09-25 22:29 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2050
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access protected files within an App Sandbox containe…
|
NVD-CWE-noinfo
|
CVE-2024-44135
|
2024-09-25 22:28 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|