Total CVEs

126,184

Critical Severity

2,292

High Severity

7,950

Last 7 Days

1,211
Quick preset (or use dates below)
Clear Filters
Showing 221 - 240 of 1,743 CVEs

MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts, leveraging the applicat...

Vendor: Inkscape
Product: Inkscape
Published: Jan 22, 2026
Source: NVD
CVE-2026-23950 HIGH - 8.8

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-insensitive filesystems (such as macOS APFS, In which it has ...

Vendor: npm
Product: tar
Published: Jan 21, 2026
Source: GitHub
CVE-2025-15032 HIGH - 7.4

Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.

Vendor: The Browser Company of New York
Product: Dia
Published: Jan 16, 2026
Source: NVD
CVE-2025-43508 MEDIUM - 5.5

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Jan 16, 2026
Source: NVD

This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data.

Vendor: Apple
Product: macOS
Published: Jan 16, 2026
Source: NVD
CVE-2026-22584 CRITICAL - 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.

Vendor: salesforce
Product: uni2ts
Published: Jan 09, 2026
Source: NVD
CVE-2025-46299 MEDIUM - 4.3

A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may disclose internal states of the app.

Vendor: apple
Product: safari
Published: Jan 09, 2026
Source: NVD
CVE-2025-46298 MEDIUM - 6.5

The issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

Vendor: apple
Product: safari
Published: Jan 09, 2026
Source: NVD
CVE-2025-46297 MEDIUM - 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files within an App Sandbox container.

Vendor: apple
Product: macos
Published: Jan 09, 2026
Source: NVD

AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.

Published: Jan 06, 2026
Source: NVD
CVE-2025-15246 MEDIUM - 6.3

A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS. Affected by this vulnerability is the function FurySerializer.deserialize of the component API. This manipulation of the argument argsStr causes deserialization. Remote exploitation of the attack is possible. The exploit has be...

Published: Dec 30, 2025
Source: NVD

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allo...

Published: Dec 19, 2025
Source: NVD

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user launches the applicati...

Published: Dec 18, 2025
Source: NVD

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic libraries into the app...

Published: Dec 18, 2025
Source: NVD

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may bypass Gatekeeper checks.

Published: Dec 17, 2025
Source: NVD

A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 26.2, iOS 26.2 and iPadOS 26.2, watchOS 26.2, macOS Tahoe 26.2. An app may be able to access sensitive payment tokens.

Published: Dec 17, 2025
Source: NVD

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may be able to access sensitive user data.

Published: Dec 17, 2025
Source: NVD

The issue was addressed with additional permissions checks. This issue is fixed in macOS Tahoe 26.2, Safari 26.2. An app may be able to access sensitive user data.

Published: Dec 17, 2025
Source: NVD

A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.2. An app may be able to break out of its sandbox.

Published: Dec 17, 2025
Source: NVD

A permissions issue was addressed with additional restrictions. This issue is fixed in watchOS 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. An app may be able to identify what other apps a user has installed.

Published: Dec 17, 2025
Source: NVD