Vulnerabilities
Tracked app vulnerabilities
16,412 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,412
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-20617
HIGH 7.0
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS … |
|
CVE-2026-20616
HIGH 8.8
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe… |
|
CVE-2026-20615
HIGH 7.8
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS… |
|
CVE-2026-20614
HIGH 7.8
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be… |
|
CVE-2026-20612
MEDIUM 5.5
A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to a… |
|
CVE-2026-20611
HIGH 7.8
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS… |
|
CVE-2026-20610
HIGH 7.8
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges. |
|
CVE-2026-20609
MEDIUM 4.4
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, mac… |
|
CVE-2026-20608
MEDIUM 5.5
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS T… |
|
CVE-2026-20606
HIGH 7.1
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, … |
|
CVE-2026-20605
MEDIUM 4.6
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Ta… |
|
CVE-2026-20603
MEDIUM 4.4
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26.3. An app with root privileges may be able to … |
|
CVE-2026-20602
MEDIUM 5.5
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be abl… |
|
CVE-2026-20601
LOW 3.3
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to monitor keystrokes without user … |
|
CVE-2025-46310
MEDIUM 6.0
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26. An attacker with … |
|
CVE-2025-46305
MEDIUM 5.7
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS… |
|
CVE-2025-46304
MEDIUM 5.7
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS… |
|
CVE-2025-46303
MEDIUM 5.7
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS… |
|
CVE-2025-46302
MEDIUM 5.7
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS… |
|
CVE-2025-46301
MEDIUM 5.7
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS… |
|
CVE-2025-46300
MEDIUM 5.7
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS… |
|
CVE-2025-46290
HIGH 7.5
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS So… |
|
CVE-2025-43537
MEDIUM 5.5
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restoring a malici… |
|
CVE-2025-43417
MEDIUM 5.5
A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able… |
|
CVE-2025-43403
MEDIUM 5.5
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26. An app m… |
|
CVE-2026-1837
HIGH 7.5
A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized un… |
|
CVE-2025-59375
MEDIUM 7.5
[Apple libexpat] Processing a maliciously crafted file may lead to a denial-of-service |
|
CVE-2026-20846
HIGH 7.5
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-21533
HIGH 7.8
KEV
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
|
CVE-2026-21525
MEDIUM 6.2
KEV
Windows Remote Access Connection Manager Denial of Service Vulnerability |
|
CVE-2026-21519
HIGH 7.8
KEV
Desktop Window Manager Elevation of Privilege Vulnerability |
|
CVE-2026-21513
HIGH 8.8
KEV
MSHTML Framework Security Feature Bypass Vulnerability |
|
CVE-2026-21510
HIGH 8.8
KEV
Windows Shell Security Feature Bypass Vulnerability |
|
CVE-2026-21508
HIGH 7.0
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2026-21255
HIGH 8.8
Windows Hyper-V Security Feature Bypass Vulnerability |
|
CVE-2026-21253
HIGH 7.0
Mailslot File System Elevation of Privilege Vulnerability |
|
CVE-2026-21251
HIGH 7.8
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability |
|
CVE-2026-21250
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21249
HIGH 3.3
Windows NTLM Spoofing Vulnerability |
|
CVE-2026-21248
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21247
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21246
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-21245
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21244
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21243
HIGH 7.5
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2026-21242
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21241
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21240
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21239
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21238
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |