Total CVEs

126,184

Critical Severity

2,292

High Severity

7,950

Last 7 Days

1,214
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 221 - 230 of 230 CVEs

MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts, leveraging the applicat...

Vendor: Inkscape
Product: Inkscape
Published: Jan 22, 2026
Source: NVD
CVE-2026-23950 HIGH - 8.8

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has ...

Vendor: npm
Product: tar
Published: Jan 21, 2026
Source: GitHub
CVE-2025-15032 HIGH - 7.4

Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.

Vendor: The Browser Company of New York
Product: Dia
Published: Jan 16, 2026
Source: NVD
CVE-2025-43508 MEDIUM - 5.5

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jan 16, 2026
Source: NVD

This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.

Vendor: Apple
Product: macOS
Published: Jan 16, 2026
Source: NVD
CVE-2026-22584 CRITICAL - 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.

Vendor: salesforce
Product: uni2ts
Published: Jan 09, 2026
Source: NVD
CVE-2025-46299 MEDIUM - 4.3

A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may disclose internal states of the app.

Vendor: apple
Product: safari
Published: Jan 09, 2026
Source: NVD
CVE-2025-46298 MEDIUM - 6.5

The issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

Vendor: apple
Product: safari
Published: Jan 09, 2026
Source: NVD
CVE-2025-46297 MEDIUM - 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files within an App Sandbox container.

Vendor: apple
Product: macos
Published: Jan 09, 2026
Source: NVD

AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.

Published: Jan 06, 2026
Source: NVD