Total CVEs

126,178

Critical Severity

2,292

High Severity

7,949

Last 7 Days

1,215
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 101 - 120 of 230 CVEs
CVE-2026-20665 MEDIUM - 6.5

This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Security Policy from being ...

Vendor: Apple
Product: Safari, iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20664 MEDIUM - 4.3

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

Vendor: Apple
Product: Safari, iOS and iPadOS, macOS, visionOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20657 MEDIUM - 6.5

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5. Parsing a maliciously crafted file may lead to an unexpected app termination.

Vendor: Apple
Product: iOS and iPadOS, macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20651 MEDIUM - 6.2

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20639 HIGH - 7.5

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3. Processing a maliciously crafted string may lead to heap corruption.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20637 MEDIUM - 6.2

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system term...

Vendor: Apple
Product: iOS and iPadOS, macOS, tvOS, visionOS, watchOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20633 MEDIUM - 5.5

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access user-sensitive data.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20632 MEDIUM - 5.3

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20631 HIGH - 8.8

A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. A user may be able to elevate privileges.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20622 HIGH - 7.5

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to capture a user's screen.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20607 MEDIUM - 4.0

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access protected user data.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-32810 MEDIUM - 5.5

Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb, halloy creates its config directory and files using default umask permissions, which typically results in `0644` on files and `0755` on directories. This allows any ...

Vendor: squidowl
Product: halloy
Published: Mar 20, 2026
Source: NVD
CVE-2026-32016 HIGH - 7.0

OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowlist mode that allows local attackers to execute unauthorized binaries by exploiting basename-only allowlist entries. Attackers can execute same-name local binaries ./echo without a...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 19, 2026
Source: NVD
CVE-2026-31993 MEDIUM - 4.8

OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that allows authenticated operators to bypass exec approval checks. Attackers with operator.write privileges and a paired macOS beta node can craft shell-chain payloads that pass incom...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 19, 2026
Source: NVD
CVE-2026-24063 HIGH - 8.2

When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When uninstalling a plugin via the Arturia Software Center the Pr...

Vendor: Arturia
Product: Software Center
Published: Mar 18, 2026
Source: NVD
CVE-2026-24062 HIGH - 7.8

The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects.Β This leads to an attacker being able to connect to the helper and execute privileged actions leading to local privilege escalation.

Vendor: Arturia
Product: Software Center
Published: Mar 18, 2026
Source: NVD
CVE-2026-22179 MEDIUM - 6.6

OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. Attackers can craft shell payloads with command substitution sy...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 18, 2026
Source: NVD
CVE-2026-20643 MEDIUM - 5.4

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Processing maliciously crafted web content may bypass Same Origin Policy.

Vendor: Apple
Product: macOS, iOS, iPadOS
Published: Mar 17, 2026
Source: NVD
CVE-2023-43010 HIGH - 8.8

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

Vendor: Apple
Product: iOS and iPadOS, Safari, macOS
Published: Mar 12, 2026
Source: NVD

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.

Published: Mar 11, 2026
Source: NVD