Total CVEs

126,178

Critical Severity

2,292

High Severity

7,949

Last 7 Days

1,218
Quick preset (or use dates below)
Clear Filters
Showing 21 - 40 of 1,743 CVEs
CVE-2025-43210 MEDIUM - 6.3

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing a maliciously crafted media file may lead to une...

Vendor: Apple
Product: iOS and iPadOS, iPadOS, macOS, tvOS, visionOS, watchOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43202 HIGH - 8.8

This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.

Vendor: Apple
Product: iOS and iPadOS, macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44303 HIGH - 7.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify protected parts of the file system.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44286 HIGH - 7.5

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access can input keyboard events to apps running on a locked device.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44250 HIGH - 8.2

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44219 HIGH - 7.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious application with root privileges may be able to access private information.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-40858 HIGH - 7.1

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access Contacts without user consent.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-40849 HIGH - 7.5

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2026-30867 MEDIUM - 5.7

CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exists in the packet parsing logic of CocoaMQTT that allows an attacker (or a compromised/malicious MQTT broker) to remotely crash the host iOS/macOS/tvOS application. If an attacker pu...

Vendor: emqx
Product: CocoaMQTT
Published: Apr 02, 2026
Source: NVD
CVE-2026-34218 MEDIUM - 5.5

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during which only the single compile-time baseline rule was enforced by opfilter. All managed (MDM-delivered) and user-defined fi...

Vendor: craigjbass
Product: clearancekit
Published: Mar 31, 2026
Source: NVD

Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a craft...

Vendor: fleetdm
Product: fleet
Published: Mar 27, 2026
Source: NVD

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.4, two file operation event types โ€” ES_EVENT_TYPE_AUTH_EXCHANGEDATA and ES_EVENT_TYPE_AUTH_CLONE โ€” were not intercepted by ClearanceKit's opfilter system extension, allowing...

Vendor: craigjbass
Product: clearancekit
Published: Mar 26, 2026
Source: NVD
CVE-2026-33631 HIGH - 8.7

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the opfilter Endpoint Security system extension enforced file access policy exclusively by intercepting ES_EVENT_TYPE_AUTH_OPEN events. Seven additional fil...

Vendor: craigjbass
Product: clearancekit
Published: Mar 26, 2026
Source: NVD
CVE-2026-30976 HIGH - 8.6

Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr process. These include application configuration files (containing API keys and database credentials), Windows ...

Vendor: Sonarr
Product: Sonarr
Published: Mar 25, 2026
Source: NVD
CVE-2026-28894 HIGH - 7.5

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A remote attacker may be able to cause a denial-of-service.

Vendor: Apple
Product: iOS and iPadOS, macOS
Published: Mar 25, 2026
Source: NVD

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A document may be written to a temporary file when using print preview.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-28892 MEDIUM - 5.5

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected parts of the file system.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-28891 HIGH - 8.1

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-28888 MEDIUM - 5.1

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to gain root privileges.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-28886 MEDIUM - 5.9

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. A user in a privileged network position may be ...

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Published: Mar 25, 2026
Source: NVD