CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2024-54471

    Last Modified: 2 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to leak a user's credentials.

    Published: 11 Dec 2024
    9.8
    Critical

    CVE-2024-54534

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-44220

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination.

    Published: 11 Dec 2024
    8.8
    High

    CVE-2024-54505

    Last Modified: 2 Apr 2026

    A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54513

    Last Modified: 2 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An app may be able to access sensitive user data.

    Published: 11 Dec 2024
    5.3
    Medium

    CVE-2024-44246

    Last Modified: 2 Apr 2026

    The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54495

    Last Modified: 2 Apr 2026

    The issue was addressed with improved permissions logic. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to modify protected parts of the file system.

    Published: 11 Dec 2024
    7.8
    High

    CVE-2024-54529

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54476

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to access user-sensitive data.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54524

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to access arbitrary files.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54477

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to access user-sensitive data.

    Published: 11 Dec 2024
    8.8
    High

    CVE-2024-54498

    Last Modified: 2 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to break out of its sandbox.

    Published: 11 Dec 2024
    7.5
    High

    CVE-2024-54508

    Last Modified: 28 May 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 11 Dec 2024
    7.1
    High

    CVE-2024-54528

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.

    Published: 11 Dec 2024
    5.9
    Medium

    CVE-2024-54494

    Last Modified: 2 Apr 2026

    A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An attacker may be able to create a read-only memory mapping that can be written to.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54504

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.

    Published: 11 Dec 2024
    7.8
    High

    CVE-2024-44291

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious app may be able to gain root privileges.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54527

    Last Modified: 2 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to access sensitive user data.

    Published: 11 Dec 2024
    6.5
    Medium

    CVE-2024-44248

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A user with screen sharing access may be able to view another user's screen.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54531

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. An app may be able to bypass kASLR.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54474

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to access user-sensitive data.

    Published: 11 Dec 2024
    7.8
    High

    CVE-2024-44225

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to gain elevated privileges.

    Published: 11 Dec 2024
    7.8
    High

    CVE-2024-44224

    Last Modified: 2 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious app may be able to gain root privileges.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54526

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. A malicious app may be able to access private information.

    Published: 11 Dec 2024
    3.3
    Low

    CVE-2024-44290

    Last Modified: 2 Apr 2026

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, watchOS 11.1. An app may be able to determine a user’s current location.

    Published: 11 Dec 2024
    9.8
    Critical

    CVE-2024-54506

    Last Modified: 2 Apr 2026

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.2. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.

    Published: 11 Dec 2024
    5.1
    Medium

    CVE-2024-54510

    Last Modified: 2 Apr 2026

    A race condition was addressed with improved locking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to leak sensitive kernel state.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-44300

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to access protected user data.

    Published: 11 Dec 2024
    7.1
    High

    CVE-2024-44245

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, visionOS 2.2. An app may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 11 Dec 2024
    7.5
    High

    CVE-2024-54479

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 11 Dec 2024
    5.3
    Medium

    CVE-2024-44212

    Last Modified: 2 Apr 2026

    A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.

    Published: 11 Dec 2024
    3.3
    Low

    CVE-2024-54491

    Last Modified: 2 Apr 2026

    The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. A malicious application may be able to determine a user's current location.

    Published: 11 Dec 2024
    9.8
    Critical

    CVE-2024-44242

    Last Modified: 2 Apr 2026

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54501

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted file may lead to a denial of service.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54500

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted image may result in disclosure of process memory.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-44243

    Last Modified: 2 Apr 2026

    A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.

    Published: 11 Dec 2024
    5.5
    Medium

    CVE-2024-54490

    Last Modified: 2 Apr 2026

    This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may gain access to user's Keychain items.

    Published: 11 Dec 2024
    6.5
    Medium

    CVE-2024-54486

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing a maliciously crafted font may result in the disclosure of process memory.

    Published: 11 Dec 2024
    9.8
    Critical

    CVE-2024-54465

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.

    Published: 11 Dec 2024
    6.9
    Medium

    CVE-2024-55660

    Last Modified: 5 Jun 2025

    SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables. Version 3.1.16 contains a patch for the issue.

    Published: 11 Dec 2024
    8.7
    High

    CVE-2024-55659

    Last Modified: 5 Jun 2025

    SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is vulnerable to both arbitrary file write to the host and stored cross-site scripting (via the file write). Version 3.1.16 contains a patch for the issue.

    Published: 11 Dec 2024
    8.7
    High

    CVE-2024-55658

    Last Modified: 5 Jun 2025

    SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. Version 3.1.16 contains a patch for the issue.

    Published: 11 Dec 2024
    8.7
    High

    CVE-2024-55657

    Last Modified: 5 Jun 2025

    SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/render` endpoint. The absence of proper validation on the path parameter allows attackers to access sensitive files on the host system. Version 3.1.16 contains a patch for the issue.

    Published: 11 Dec 2024
    6.5
    Medium

    CVE-2024-55652

    Last Modified: 15 Apr 2026

    PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an attacker can write a malicious docx template containing expressions that escape the JavaScript sandbox to execute arbitrary code on the system. An attacker who can control the contents of the template document is able to execute arbitrary code on the system. By default, only users with the `admin` role are able to create or update templates. Commit 1d4219c596f4f518798492e48386a20c6e9a2fe6 patches the issue.

    Published: 11 Dec 2024
    6.6
    Medium

    CVE-2024-53845

    Last Modified: 15 Apr 2026

    ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. The IV is set to zero and remains constant throughout the product's lifetime. In AES/CBC mode, if the IV is not properly initialized, the encrypted output becomes deterministic, leading to potential data leakage. To address the aforementioned issues, the application generates a random IV when activating the AES key starting in versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. This IV is then transmitted along with the provision data to the provision device. The provision device has also been equipped with a parser for the AES IV. The upgrade is applicable for all applications and users of ESPTouch v2 component from ESP-IDF. As it is implemented in the ESP Wi-Fi stack, there is no workaround for the user to fix the application layer without upgrading the underlying firmware.

    Published: 11 Dec 2024
    2
    Low

    CVE-2024-53274

    Last Modified: 5 Sept 2025

    Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `home.vue` containsa reflected XSS vulnerability due to an incorrect sanitization function. An attacker can specify a malicious `redirectTo` parameter to trigger the vulnerability. Arbitrary javascript can be executed by the attacker in the context of the victim’s session. Version 5.28.5 contains a patch.

    Published: 11 Dec 2024
    5
    Medium

    CVE-2024-53273

    Last Modified: 5 Sept 2025

    Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `RegisterLoginReset.vue` contains a reflected XSS vulnerability due to an incorrect sanitization function. An attacker can specify a malicious `redirectTo` parameter to trigger the vulnerability, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link. Version 5.28.5 contains a patch.

    Published: 11 Dec 2024
    5
    Medium

    CVE-2024-53272

    Last Modified: 5 Sept 2025

    Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `login` and `social media` function in `RegisterLoginReset.vue` contains two reflected XSS vulnerabilities due to an incorrect sanitization function. An attacker can specify a malicious `redirectTo` parameter to trigger the vulnerability, giving the attacker control of the victim’s account when a victim registers or logins with a specially crafted link. Version 5.28.5 contains a patch.

    Published: 11 Dec 2024
    8.1
    High

    CVE-2024-45404

    Last Modified: 17 May 2025

    OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can break through the two-factor authentication and hijack the account. This is because the otpLogin mutation does not implement One Time Password rate limiting. As of time of publication, it is unknown whether a patch is available.

    Published: 11 Dec 2024
    5.3
    Medium

    CVE-2024-12536

    Last Modified: 13 Dec 2024

    A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/client_data.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 11 Dec 2024