Total CVEs

149,960

Critical Severity

4,910

High Severity

17,395

Last 7 Days

1,772
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 441 - 460 of 46,365 CVEs
CVE-2026-28973 HIGH - 8.6

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. A malicious app may be able to break out of its sandbox.

Vendor: Apple
Product: iOS and iPadOS, macOS, watchOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-28945 HIGH - 7.1

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to bypass network restrictions.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-28932 MEDIUM - 5.5

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial of service.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-28931 CRITICAL - 9.8

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, watchOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-28928 CRITICAL - 9.8

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, watchOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-28926 HIGH - 7.0

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to elevate privileges.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-28912 HIGH - 7.8

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-28911 CRITICAL - 9.8

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-28900 MEDIUM - 5.5

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-28896 HIGH - 7.7

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An attacker may be able to cause unexpected system termination or read kernel memory.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-28849 MEDIUM - 5.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD
CVE-2026-20672 MEDIUM - 5.5

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jul 27, 2026
Source: NVD

A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5).  Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analys...

Vendor: TP-Link Systems Inc., TP Link Systems Inc.
Product: TL-WR850N v3, Archer C20 v6, TL-WR845N v4, Archer MR200 v5
Published: Jul 27, 2026
Source: NVD
CVE-2026-66018 MEDIUM - 6.5

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving environment properties for a protected build, exposing build environment secrets (confidentiality impact; no inte...

Vendor: jfrog
Product: artifactory
Published: Jul 27, 2026
Source: NVD
CVE-2026-66015 HIGH - 7.2

An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.

Vendor: jfrog
Product: artifactory
Published: Jul 27, 2026
Source: NVD
CVE-2026-66014 HIGH - 8.8

JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.

Vendor: jfrog
Product: artifactory
Published: Jul 27, 2026
Source: NVD
CVE-2026-65925 MEDIUM - 6.5

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

Vendor: jfrog
Product: artifactory
Published: Jul 27, 2026
Source: NVD
CVE-2026-65924 MEDIUM - 6.5

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access is enabled on the repository, an unauthenticated user - could cause Artifactory to issue outbound HTTP requests to arbitrary ...

Vendor: jfrog
Product: artifactory
Published: Jul 27, 2026
Source: NVD
CVE-2026-65923 MEDIUM - 6.8

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The issue primarily affects confidentiality and integrity and has been addressed in fixed Artifactory versions.

Vendor: jfrog
Product: artifactory
Published: Jul 27, 2026
Source: NVD
CVE-2026-65922 HIGH - 7.1

An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is no...

Vendor: jfrog
Product: artifactory
Published: Jul 27, 2026
Source: NVD