CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-2298

    Last Modified: 8 Apr 2026

    The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to to perform unauthorized actions such as creating importing products.

    Published: 8 Mar 2024
    6.4
    Medium

    CVE-2024-1987

    Last Modified: 8 Apr 2026

    The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Mar 2024
    3.5
    Low

    CVE-2024-2285

    Last Modified: 12 Mar 2025

    A vulnerability, which was classified as problematic, has been found in boyiddha Automated-Mess-Management-System 1.0. Affected by this issue is some unknown functionality of the file /member/member_edit.php. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-256052. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Mar 2024
    3.5
    Low

    CVE-2024-2284

    Last Modified: 12 Mar 2025

    A vulnerability classified as problematic was found in boyiddha Automated-Mess-Management-System 1.0. Affected by this vulnerability is an unknown functionality of the file /member/chat.php of the component Chat Book. The manipulation of the argument msg leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256051. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Mar 2024
    6.3
    Medium

    CVE-2024-2283

    Last Modified: 12 Mar 2025

    A vulnerability classified as critical has been found in boyiddha Automated-Mess-Management-System 1.0. Affected is an unknown function of the file /member/view.php. The manipulation of the argument date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-256050 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 8 Mar 2024
    6.5
    Medium

    CVE-2024-23259

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Processing web content may lead to a denial-of-service.

    Published: 8 Mar 2024
    6.7
    Medium

    CVE-2024-23234

    Last Modified: 2 Apr 2026

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to execute arbitrary code with kernel privileges.

    Published: 8 Mar 2024
    4.7
    Medium

    CVE-2024-23275

    Last Modified: 2 Apr 2026

    A race condition was addressed with additional validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access protected user data.

    Published: 8 Mar 2024
    2.4
    Low

    CVE-2024-23255

    Last Modified: 2 Apr 2026

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Photos in the Hidden Photos Album may be viewed without authentication.

    Published: 8 Mar 2024
    3.3
    Low

    CVE-2024-23238

    Last Modified: 2 Apr 2026

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to edit NVRAM variables.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23279

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23297

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may be able to access private information.

    Published: 8 Mar 2024
    8.6
    High

    CVE-2024-23278

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, watchOS 10.4. An app may be able to break out of its sandbox.

    Published: 8 Mar 2024
    8.6
    High

    CVE-2024-0258

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23281

    Last Modified: 2 Apr 2026

    This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4. An app may be able to access sensitive user data.

    Published: 8 Mar 2024
    4.7
    Medium

    CVE-2024-23239

    Last Modified: 2 Apr 2026

    A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to leak sensitive user information.

    Published: 8 Mar 2024
    3.3
    Low

    CVE-2024-23242

    Last Modified: 2 Apr 2026

    A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to view Mail data.

    Published: 8 Mar 2024
    7.8
    High

    CVE-2024-23274

    Last Modified: 2 Apr 2026

    An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.

    Published: 8 Mar 2024
    3.3
    Low

    CVE-2024-23262

    Last Modified: 2 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, visionOS 1.1. An app may be able to spoof system notifications and UI.

    Published: 8 Mar 2024
    4.7
    Medium

    CVE-2024-23235

    Last Modified: 2 Apr 2026

    A race condition was addressed with additional validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to access user-sensitive data.

    Published: 8 Mar 2024
    7.8
    High

    CVE-2024-23258

    Last Modified: 2 Apr 2026

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.4, visionOS 1.1. Processing an image may lead to arbitrary code execution.

    Published: 8 Mar 2024
    3.3
    Low

    CVE-2024-23253

    Last Modified: 2 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a user's Photos Library.

    Published: 8 Mar 2024
    3.3
    Low

    CVE-2024-23245

    Last Modified: 2 Apr 2026

    This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Third-party shortcuts may use a legacy action from Automator to send events to apps without user consent.

    Published: 8 Mar 2024
    7.8
    High

    CVE-2024-23286

    Last Modified: 2 Apr 2026

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing an image may lead to arbitrary code execution.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23269

    Last Modified: 2 Apr 2026

    A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23290

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to access user-sensitive data.

    Published: 8 Mar 2024
    7.1
    High

    CVE-2024-23249

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.

    Published: 8 Mar 2024
    3.3
    Low

    CVE-2024-23232

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.4. An app may be able to capture a user's screen.

    Published: 8 Mar 2024
    7.8
    High

    CVE-2024-23265

    Last Modified: 2 Apr 2026

    A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An app may be able to cause unexpected system termination or write kernel memory.

    Published: 8 Mar 2024
    4.3
    Medium

    CVE-2024-23273

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23272

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An attacker may gain access to protected parts of the file system.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23264

    Last Modified: 2 Apr 2026

    A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1. An application may be able to read restricted memory.

    Published: 8 Mar 2024
    7.8
    High

    CVE-2024-23233

    Last Modified: 2 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.

    Published: 8 Mar 2024
    7.1
    High

    CVE-2024-23248

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.

    Published: 8 Mar 2024
    3.3
    Low

    CVE-2024-23291

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A malicious app may be able to observe user data in log entries related to accessibility notifications.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23287

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An app may be able to access user-sensitive data.

    Published: 8 Mar 2024
    7.8
    High

    CVE-2024-23268

    Last Modified: 2 Apr 2026

    An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.

    Published: 8 Mar 2024
    7.8
    High

    CVE-2024-23244

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4. An app from a standard user account may be able to escalate privilege after admin user login.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23205

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to access sensitive user data.

    Published: 8 Mar 2024
    3.3
    Low

    CVE-2024-23292

    Last Modified: 2 Apr 2026

    This issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to access information about a user's contacts.

    Published: 8 Mar 2024
    7.8
    High

    CVE-2024-23247

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Processing a file may lead to unexpected app termination or arbitrary code execution.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23267

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to bypass certain Privacy preferences.

    Published: 8 Mar 2024
    7.8
    High

    CVE-2024-23288

    Last Modified: 2 Apr 2026

    This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to elevate privileges.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23230

    Last Modified: 2 Apr 2026

    This issue was addressed with improved file handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to access sensitive user data.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23231

    Last Modified: 2 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, watchOS 10.4. An app may be able to access user-sensitive data.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23266

    Last Modified: 2 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system.

    Published: 8 Mar 2024
    3.3
    Low

    CVE-2024-23289

    Last Modified: 2 Apr 2026

    A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A person with physical access to a device may be able to use Siri to access private calendar information.

    Published: 8 Mar 2024
    7.8
    High

    CVE-2024-23270

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4. An app may be able to execute arbitrary code with kernel privileges.

    Published: 8 Mar 2024
    3.3
    Low

    CVE-2024-23227

    Last Modified: 2 Apr 2026

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to read sensitive location information.

    Published: 8 Mar 2024
    5.5
    Medium

    CVE-2024-23250

    Last Modified: 2 Apr 2026

    An access issue was addressed with improved access restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to access Bluetooth-connected microphones without user permission.

    Published: 8 Mar 2024