Total CVEs

126,178

Critical Severity

2,292

High Severity

7,949

Last 7 Days

1,220
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 230 CVEs
CVE-2026-28909 MEDIUM - 6.5

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.

Vendor: Apple
Product: macOS
Published: Apr 30, 2026
Source: NVD

CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can send a malformed packet to the client causing a denial of service.

Vendor: Absolute Software
Product: Secure Access
Published: Apr 30, 2026
Source: NVD

CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small portion of memory to the log files potentially revealing secrets.

Vendor: Absolute Software
Product: Secure Access
Published: Apr 30, 2026
Source: NVD

The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. On other Unix-like systems such as macOS and FreeBSD, the utility fails to utilize th...

Vendor: Uutils
Product: coreutils
Published: Apr 22, 2026
Source: NVD
CVE-2026-40604 MEDIUM - 4.4

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the opfilter Endpoint Security system extension (bundle ID uk.craigbass.clearancekit.opfilter) can be suspended with SIGSTOP or kill -STOP, or killed with SIGKILL/SIGTERM, by any proc...

Vendor: craigjbass
Product: clearancekit
Published: Apr 21, 2026
Source: NVD
CVE-2026-40599 HIGH - 7.1

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID and a non-empty Signing ID as an Apple platform binary. This bug allows a malicious software to impersonate an apple pr...

Vendor: craigjbass
Product: clearancekit
Published: Apr 21, 2026
Source: NVD

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta-1f46165, ClearanceKit's Endpoint Security event handler only checked the source path of dual-path file operations against File Access Authorization (FAA) rules and App Jail ...

Vendor: craigjbass
Product: clearancekit
Published: Apr 10, 2026
Source: NVD
CVE-2026-33092 HIGH - 7.8

Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902.

Vendor: Acronis
Product: Acronis True Image OEM, Acronis True Image
Published: Apr 10, 2026
Source: NVD
CVE-2026-39860 CRITICAL - 9.0

Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-outp...

Vendor: NixOS
Product: nix
Published: Apr 08, 2026
Source: NVD

Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by remote code execution via crafted tophat:// or http://localhost:29070 URLs. The arguments query parameter flows unsanitized from URL parsing through to /bin/bash -c execution, allowing an attacker to execute arbit...

Vendor: Shopify
Product: tophat
Published: Apr 08, 2026
Source: NVD
CVE-2026-28373 CRITICAL - 9.6

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesystem.

Published: Apr 03, 2026
Source: NVD
CVE-2026-28815 HIGH - 7.5

A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1.

Vendor: Apple
Product: macOS
Published: Apr 03, 2026
Source: NVD
CVE-2026-34779 MEDIUM - 6.5

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFolder() used an AppleScript fallback path that did not properly handle certain characters in the appli...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34776 MEDIUM - 5.3

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on macOS and Linux, apps that call app.requestSingleInstanceLock() were vulnerable to an out-of-bounds heap read when parsing a crafted second...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2026-34770 HIGH - 7.0

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected,...

Vendor: npm
Product: electron
Published: Apr 03, 2026
Source: GitHub
CVE-2025-43264 HIGH - 8.8

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43257 HIGH - 8.7

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43238 MEDIUM - 6.2

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An attacker may be able to cause unexpected app termination.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43219 HIGH - 8.8

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD