CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2025-24247

    Last Modified: 28 Apr 2026

    A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker may be able to cause unexpected app termination.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24210

    Last Modified: 28 Apr 2026

    A logic error was addressed with improved error handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Parsing an image may lead to disclosure of user information.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24178

    Last Modified: 18 Jun 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to break out of its sandbox.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-30455

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-31182

    Last Modified: 28 Apr 2026

    This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to delete files for which it does not have permission.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-30443

    Last Modified: 28 Apr 2026

    A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sequoia 15.5, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-31194

    Last Modified: 28 Apr 2026

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A Shortcut may run with admin privileges without authentication.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24237

    Last Modified: 9 May 2026

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24260

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker in a privileged position may be able to perform a denial-of-service.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24276

    Last Modified: 28 Apr 2026

    This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

    Published: 31 Mar 2025
    7.5
    High

    CVE-2025-24221

    Last Modified: 28 Apr 2026

    This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, visionOS 2.4. Sensitive keychain data may be accessible from an iOS backup.

    Published: 31 Mar 2025
    4.3
    Medium

    CVE-2025-30425

    Last Modified: 28 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private browsing mode.

    Published: 31 Mar 2025
    7.8
    High

    CVE-2025-24173

    Last Modified: 28 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.

    Published: 31 Mar 2025
    7.8
    High

    CVE-2025-30464

    Last Modified: 28 Apr 2026

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-30433

    Last Modified: 28 Apr 2026

    This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-30444

    Last Modified: 28 Apr 2026

    A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Mounting a maliciously crafted SMB network share may lead to system termination.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24283

    Last Modified: 2 Apr 2026

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-30452

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An input validation issue was addressed.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24256

    Last Modified: 28 Apr 2026

    The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to disclose kernel memory.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24190

    Last Modified: 18 Jun 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.

    Published: 31 Mar 2025
    6.3
    Medium

    CVE-2025-30429

    Last Modified: 28 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24217

    Last Modified: 28 Apr 2026

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.

    Published: 31 Mar 2025
    4.7
    Medium

    CVE-2025-24240

    Last Modified: 28 Apr 2026

    A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24241

    Last Modified: 28 Apr 2026

    A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to trick a user into copying sensitive data to the pasteboard.

    Published: 31 Mar 2025
    2.4
    Low

    CVE-2025-30469

    Last Modified: 28 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4. A person with physical access to an iOS device may be able to access photos from the lock screen.

    Published: 31 Mar 2025
    7.6
    High

    CVE-2025-24095

    Last Modified: 28 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2.4. An app may be able to bypass Privacy preferences.

    Published: 31 Mar 2025
    4.3
    Medium

    CVE-2025-24216

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24191

    Last Modified: 28 Apr 2026

    The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system.

    Published: 31 Mar 2025
    5.4
    Medium

    CVE-2025-30428

    Last Modified: 28 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.

    Published: 31 Mar 2025
    7.1
    High

    CVE-2025-24257

    Last Modified: 28 Apr 2026

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination or write kernel memory.

    Published: 31 Mar 2025
    7.8
    High

    CVE-2025-31184

    Last Modified: 28 Apr 2026

    This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. An app may gain unauthorized access to Local Network.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24282

    Last Modified: 28 Apr 2026

    A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system.

    Published: 31 Mar 2025
    6.7
    Medium

    CVE-2025-31192

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.

    Published: 31 Mar 2025
    6.4
    Medium

    CVE-2025-30432

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24164

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-30465

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sequoia 15.7.2, macOS Sonoma 14.7.5, macOS Sonoma 14.8.2, macOS Tahoe 26.1, macOS Ventura 13.7.5. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-30424

    Last Modified: 28 Apr 2026

    A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Deleting a conversation in Messages may expose user contact information in system logging.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24172

    Last Modified: 2 Apr 2026

    A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. "Block All Remote Content" may not apply for all mail previews.

    Published: 31 Mar 2025
    7.8
    High

    CVE-2025-31188

    Last Modified: 28 Apr 2026

    A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to bypass Privacy preferences.

    Published: 31 Mar 2025
    7.8
    High

    CVE-2025-24277

    Last Modified: 28 Apr 2026

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

    Published: 31 Mar 2025
    6.6
    Medium

    CVE-2025-3062

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24261

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24148

    Last Modified: 28 Apr 2026

    This issue was addressed with improved handling of executable types. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious JAR file may bypass Gatekeeper checks.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24236

    Last Modified: 2 Apr 2026

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.

    Published: 31 Mar 2025
    7.8
    High

    CVE-2025-30449

    Last Modified: 2 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

    Published: 31 Mar 2025
    6.6
    Medium

    CVE-2025-3061

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.

    Published: 31 Mar 2025
    6.6
    Medium

    CVE-2025-3060

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This issue affects Flattern – Multipurpose Bootstrap Business Profile: *.*.

    Published: 31 Mar 2025
    5.3
    Medium

    CVE-2025-3059

    Last Modified: 2 Sept 2025

    Vulnerability in Drupal Profile Private.This issue affects Profile Private: *.*.

    Published: 31 Mar 2025
    4.8
    Medium

    CVE-2025-3036

    Last Modified: 15 Apr 2025

    A vulnerability, which was classified as problematic, was found in yzk2356911358 StudentServlet-JSP cc0cdce25fbe43b6c58b60a77a2c85f52d2102f5/d4d7a0643f1dae908a4831206f2714b21820f991. This affects an unknown part of the component Student Management Handler. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

    Published: 31 Mar 2025
    5.3
    Medium

    CVE-2025-3018

    Last Modified: 7 Apr 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Mar 2025