Total CVEs

138,073

Critical Severity

3,522

High Severity

12,666

Last 7 Days

1,993
Quick preset (or use dates below)
Clear Filters
Showing 41 - 60 of 1,901 CVEs
CVE-2026-24066 HIGH - 8.4

Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by checking only the subject.OU value of the client&#...

Vendor: Slate Digital LLC
Product: Slate Digital Connect
Published: Jun 10, 2026
Source: NVD
CVE-2026-22926 HIGH - 7.8

Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.

Vendor: Omnissa
Product: Omnissa Workspace ONE® Assist for macOS
Published: Jun 09, 2026
Source: NVD
CVE-2026-24065 HIGH - 8.1

Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused...

Vendor: Waves Audio Ltd.
Product: Waves Central
Published: Jun 09, 2026
Source: NVD
CVE-2026-24064 HIGH - 7.8

Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime entitlements that permit dynamic library injection. A local attacker can set the DYLD_INSERT_LIBRARIES e...

Vendor: Waves Audio Ltd.
Product: Waves Central
Published: Jun 09, 2026
Source: NVD

A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipulation to achieve privileged file corruption.

Published: Jun 09, 2026
Source: NVD

Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-47252 CRITICAL - 9.0

Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin

Vendor: go
Product: github.com/julien040/anyquery/plugins/chrome
Published: Jun 08, 2026
Source: GitHub

Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary w...

Vendor: npm
Product: actual
Published: Jun 08, 2026
Source: GitHub
CVE-2026-6892 MEDIUM - 5.0

Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of directories for which they would not normally have authorization.  *:Ca...

Published: May 29, 2026
Source: NVD
CVE-2026-6891 MEDIUM - 5.0

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authoriza...

Published: May 29, 2026
Source: NVD
CVE-2026-49237 HIGH - 7.8

An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img, qemu-system-aarch64, qemu-s...

Vendor: Canonical
Product: Multipass
Published: May 28, 2026
Source: NVD
CVE-2025-46307 MEDIUM - 5.5

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-46284 HIGH - 7.0

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to gain root privileges.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-46280 MEDIUM - 5.5

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected system termination.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43451 MEDIUM - 5.5

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43306 HIGH - 7.8

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43290 MEDIUM - 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to modify protected parts of the file system.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2025-43289 MEDIUM - 5.5

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: May 26, 2026
Source: NVD
CVE-2026-9560 HIGH - 7.8

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel

Vendor: openvpn
Product: connect
Published: May 26, 2026
Source: NVD
CVE-2026-5843 HIGH - 8.2

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Pyth...

Published: May 22, 2026
Source: NVD