291
|
3.3 |
LOW
Local
|
apple
|
macos
|
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to read sensitive location information.
New
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2024-44222
|
2024-10-31 02:25 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
292
|
7.8 |
HIGH
Local
|
apple
|
iphone_os ipados macos
|
This issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, macOS Sonoma 14.7.1, iOS 18.1 and iPadOS 18.1. Processing a maliciously crafted file may lead to he…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44218
|
2024-10-31 02:24 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
293
|
5.5 |
MEDIUM
Local
|
apple
|
macos iphone_os ipados watchos visionos tvos
|
This issue was addressed with improved checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visio…
New
|
NVD-CWE-noinfo
|
CVE-2024-44215
|
2024-10-31 02:22 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
294
|
5.9 |
MEDIUM
Network
|
apple
|
macos
|
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An attacker in a privileged network…
New
|
NVD-CWE-noinfo
|
CVE-2024-44213
|
2024-10-31 02:19 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
295
|
5.5 |
MEDIUM
Local
|
apple
|
ipados iphone_os watchos visionos
|
This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 11.1, visionOS 2.1, iOS 18.1 and iPadOS 18.1. An app may be able to access sensitive user dat…
New
|
NVD-CWE-noinfo
|
CVE-2024-44194
|
2024-10-31 02:16 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
296
|
- |
|
-
|
-
|
A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.
New
|
-
|
CVE-2024-9110
|
2024-10-31 02:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
297
|
- |
|
-
|
-
|
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.
New
|
-
|
CVE-2024-51258
|
2024-10-31 02:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
298
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be able to access sensitive user data.
New
|
CWE-59
Link Following
|
CVE-2024-44175
|
2024-10-31 02:14 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
299
|
4.9 |
MEDIUM
Network
|
mayurik
|
petrol_pump_management
|
A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/invoic…
Update
|
CWE-89
SQL Injection
|
CVE-2024-10355
|
2024-10-31 02:13 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
300
|
3.3 |
LOW
Local
|
apple
|
iphone_os ipados
|
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to use Siri to enable Auto-Answer Calls.
New
|
NVD-CWE-noinfo
|
CVE-2024-40853
|
2024-10-31 02:08 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|