1861
|
3.3 |
LOW
Local
|
apple
|
ipados iphone_os
|
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Pho…
|
NVD-CWE-noinfo
|
CVE-2025-24141
|
2025-01-31 03:03 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1862
|
9.8 |
CRITICAL
Network
themerex
|
addons
|
The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and includin…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-13448
|
2025-01-31 03:01 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1863
|
4.4 |
MEDIUM
Local
|
apple
|
macos
|
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. A malicious app may be able to create symlinks to …
|
CWE-59
Link Following
|
CVE-2025-24136
|
2025-01-31 03:00 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1864
|
6.5 |
MEDIUM
Network
|
apple
|
macos ipados iphone_os visionos watchos tvos
|
The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An attacker in a privileged position…
|
NVD-CWE-noinfo
|
CVE-2025-24131
|
2025-01-31 02:58 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1865
|
6.1 |
MEDIUM
Network
|
westguardsolutions
|
ws_form
|
The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the url parameter in all versions up to, and including, 1.10.13…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13509
|
2025-01-31 02:56 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1866
|
5.4 |
MEDIUM
Network
|
ilghera
|
mailup_auto_subscription
|
The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the …
|
CWE-352
Origin Validation Error
|
CVE-2024-13521
|
2025-01-31 02:41 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1867
|
5.4 |
MEDIUM
Network
|
wpmet
|
elementskit
|
The ElementsKit Pro plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitizat…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0321
|
2025-01-31 02:39 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1868
|
5.5 |
MEDIUM
Local
|
apple
|
watchos ipados tvos visionos iphone_os macos
|
This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.2, visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2, macOS Se…
|
NVD-CWE-noinfo
|
CVE-2024-54541
|
2025-01-31 02:31 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1869
|
7.8 |
HIGH
Local
|
apple
|
watchos ipados macos tvos iphone_os
|
The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2 and iPadOS 18.2. An app may be able to corrupt coprocessor memory.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-54522
|
2025-01-31 02:26 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1870
|
9.1 |
CRITICAL
Network
apple
|
watchos ipados iphone_os
|
The issue was addressed by removing the relevant flags. This issue is fixed in watchOS 11.2, iOS 18.2 and iPadOS 18.2. A system binary could be used to fingerprint a user's Apple Account.
|
NVD-CWE-noinfo
|
CVE-2024-54512
|
2025-01-31 02:20 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|