CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2025-31227

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker with physical access to a device may be able to access a deleted call recording.

    Published: 12 May 2025
    9.1
    Critical

    CVE-2025-30436

    Last Modified: 28 Apr 2026

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able to use Siri to enable Auto-Answer Calls.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31196

    Last Modified: 2 Apr 2026

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31250

    Last Modified: 28 Apr 2026

    An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.

    Published: 12 May 2025
    7.7
    High

    CVE-2025-31207

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's installed apps.

    Published: 12 May 2025
    8.8
    High

    CVE-2025-31246

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6. Connecting to a malicious AFP server may corrupt kernel memory.

    Published: 12 May 2025
    6.3
    Medium

    CVE-2025-31195

    Last Modified: 28 Apr 2026

    The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.

    Published: 12 May 2025
    7.1
    High

    CVE-2025-31253

    Last Modified: 28 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. Muting the microphone during a FaceTime call may not result in audio being silenced.

    Published: 12 May 2025
    7.8
    High

    CVE-2025-30442

    Last Modified: 28 Apr 2026

    The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to gain elevated privileges.

    Published: 12 May 2025
    8.8
    High

    CVE-2025-31204

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-24155

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to disclose kernel memory.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31212

    Last Modified: 28 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. An app may be able to access sensitive user data.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31245

    Last Modified: 29 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5. An app may be able to cause unexpected system termination.

    Published: 12 May 2025
    6.8
    Medium

    CVE-2025-31228

    Last Modified: 28 Apr 2026

    The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to access notes from the lock screen.

    Published: 12 May 2025
    7.5
    High

    CVE-2025-31208

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to an unexpected app termination.

    Published: 12 May 2025
    7.1
    High

    CVE-2025-31249

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.

    Published: 12 May 2025
    7.1
    High

    CVE-2025-31232

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A sandboxed app may be able to access sensitive user data.

    Published: 12 May 2025
    7.8
    High

    CVE-2025-31224

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to bypass certain Privacy preferences.

    Published: 12 May 2025
    7.1
    High

    CVE-2025-31225

    Last Modified: 28 Apr 2026

    A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS 18.5. Call history from deleted apps may still appear in spotlight search results.

    Published: 12 May 2025
    6.3
    Medium

    CVE-2025-31233

    Last Modified: 28 Apr 2026

    The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.

    Published: 12 May 2025
    6.3
    Medium

    CVE-2025-31209

    Last Modified: 28 Apr 2026

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to disclosure of user information.

    Published: 12 May 2025
    8.8
    High

    CVE-2025-31244

    Last Modified: 28 Apr 2026

    A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.

    Published: 12 May 2025
    7.6
    High

    CVE-2025-31213

    Last Modified: 2 Apr 2026

    A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to access associated usernames and websites in a user's iCloud Keychain.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-24142

    Last Modified: 28 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to access sensitive user data.

    Published: 12 May 2025
    6.5
    Medium

    CVE-2025-31205

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A malicious website may exfiltrate data cross-origin.

    Published: 12 May 2025
    7.8
    High

    CVE-2025-31259

    Last Modified: 28 Apr 2026

    A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to capture a screenshot of an app entering or exiting full screen mode.

    Published: 12 May 2025
    9.1
    Critical

    CVE-2025-30448

    Last Modified: 2 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, visionOS 2.5. An attacker may be able to turn on sharing of an iCloud folder without authentication.

    Published: 12 May 2025
    6.2
    Medium

    CVE-2025-31218

    Last Modified: 28 Apr 2026

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to observe the hostnames of new network connections.

    Published: 12 May 2025
    8.2
    High

    CVE-2025-31234

    Last Modified: 28 Apr 2026

    The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 12 May 2025
    7.8
    High

    CVE-2025-31222

    Last Modified: 28 Apr 2026

    A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A user may be able to elevate privileges.

    Published: 12 May 2025
    8.1
    High

    CVE-2025-31214

    Last Modified: 28 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5. An attacker in a privileged network position may be able to intercept network traffic.

    Published: 12 May 2025
    7.3
    High

    CVE-2025-31238

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.

    Published: 12 May 2025
    4.3
    Medium

    CVE-2025-31239

    Last Modified: 28 Apr 2026

    A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Parsing a file may lead to an unexpected app termination.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-31242

    Last Modified: 28 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.3, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. An app may be able to access sensitive user data.

    Published: 12 May 2025
    7.8
    High

    CVE-2025-30453

    Last Modified: 28 Apr 2026

    The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A malicious app may be able to gain root privileges.

    Published: 12 May 2025
    6.5
    Medium

    CVE-2025-31215

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-24144

    Last Modified: 28 Apr 2026

    An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia 15.3, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to leak sensitive kernel state.

    Published: 12 May 2025
    8
    High

    CVE-2025-31223

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.

    Published: 12 May 2025
    6.5
    Medium

    CVE-2025-31235

    Last Modified: 28 Apr 2026

    A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to cause unexpected system termination.

    Published: 12 May 2025
    5.5
    Medium

    CVE-2025-24220

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.9. An app may be able to read a persistent device identifier.

    Published: 12 May 2025
    7.1
    High

    CVE-2025-31219

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 12 May 2025
    6.5
    Medium

    CVE-2025-31258

    Last Modified: 28 Apr 2026

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.

    Published: 12 May 2025
    9.4
    Critical

    CVE-2025-3659

    Last Modified: 15 Apr 2026

    Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP IA/Digi One IA - prior to and including 82000774_Z, build date 10/19/2020 * Digi One IAP – prior to and including 82000770 Z, build date 10/19/2020 A specially crafted POST request to the device’s web interface may allow an unauthenticated attacker to modify configuration settings.

    Published: 12 May 2025
    7.8
    High

    CVE-2025-1079

    Last Modified: 29 Jul 2025

    Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature

    Published: 12 May 2025
    7.6
    High

    CVE-2024-4982

    Last Modified: 7 Aug 2025

    A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server.

    Published: 12 May 2025
    7.6
    High

    CVE-2024-4981

    Last Modified: 7 Aug 2025

    A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.

    Published: 12 May 2025
    9.3
    Critical

    CVE-2025-47682

    Last Modified: 29 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.1.

    Published: 12 May 2025
    7.5
    High

    CVE-2025-3632

    Last Modified: 28 Aug 2025

    IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardware Security Module (HSM) due to improper memory allocation of an excessive size.

    Published: 12 May 2025
    6.3
    Medium

    CVE-2025-46743

    Last Modified: 15 Apr 2026

    An authenticated user's token could be used by another source after the user had logged out prior to the token expiring.

    Published: 12 May 2025
    4.4
    Medium

    CVE-2025-46750

    Last Modified: 15 Apr 2026

    SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass password authentication and change password-protected BIOS settings by importing a BIOS settings file with no password set.

    Published: 12 May 2025