Export limit exceeded: 395733 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395733 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-64736 | 1 Apple | 7 Ios And Ipados, Ipados, Iphone Os and 4 more | 2026-09-20 | 7.1 High |
| An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory. | ||||
| CVE-2026-64761 | 1 Apple | 3 Ios And Ipados, Ipados, Iphone Os | 2026-09-20 | 7.5 High |
| A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. An app may be able to identify what other apps a user has installed. | ||||
| CVE-2026-84535 | 1 Apple | 1 Macos | 2026-09-20 | 8.2 High |
| An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox. | ||||
| CVE-2026-84523 | 1 Apple | 7 Ios And Ipados, Ipados, Iphone Os and 4 more | 2026-09-20 | 5.5 Medium |
| An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or write kernel memory. | ||||
| CVE-2026-84489 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-20 | 5.5 Medium |
| A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to cause a denial of service. | ||||
| CVE-2026-43687 | 1 Apple | 7 Ios And Ipados, Ipados, Iphone Os and 4 more | 2026-09-20 | 6.5 Medium |
| The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may disclose kernel memory. | ||||
| CVE-2026-65412 | 1 Apple | 6 Ios And Ipados, Ipados, Iphone Os and 3 more | 2026-09-20 | 6.5 Medium |
| A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. Processing web content may lead to a denial-of-service. | ||||
| CVE-2026-64717 | 1 Apple | 7 Ios And Ipados, Ipados, Iphone Os and 4 more | 2026-09-20 | 6.3 Medium |
| A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory. | ||||
| CVE-2026-84555 | 1 Apple | 1 Macos | 2026-09-20 | 5.5 Medium |
| An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to access sensitive user data. | ||||
| CVE-2026-65405 | 1 Apple | 7 Ios And Ipados, Ipados, Iphone Os and 4 more | 2026-09-20 | 5.5 Medium |
| A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to determine kernel memory layout. | ||||
| CVE-2026-65393 | 1 Apple | 2 Macos, Xcode | 2026-09-20 | 5.5 Medium |
| A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data. | ||||
| CVE-2026-64756 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-20 | 5.5 Medium |
| A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data. | ||||
| CVE-2026-84575 | 1 Apple | 7 Ios And Ipados, Ipados, Iphone Os and 4 more | 2026-09-20 | 7.8 High |
| An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted file may lead to unexpected app termination. | ||||
| CVE-2026-84534 | 1 Apple | 5 Ios And Ipados, Ipados, Iphone Os and 2 more | 2026-09-20 | 5.5 Medium |
| A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. Extracting a maliciously crafted archive may allow an attacker to write arbitrary files. | ||||
| CVE-2026-65409 | 1 Apple | 7 Ios And Ipados, Ipados, Iphone Os and 4 more | 2026-09-20 | 5.5 Medium |
| A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause a denial of service. | ||||
| CVE-2026-79425 | 1 Crmeb | 1 Crmeb | 2026-09-20 | 8.1 High |
| An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request. | ||||
| CVE-2026-94045 | 1 Newbee-ltd | 1 Newbee-mall | 2026-09-20 | 3.5 Low |
| A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Performing a manipulation of the argument goodsName results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. ImageIO.read() is a format-agnostic read - it returns non-null for a polyglot PNG|<img onerror> payload, which is exactly why the "image-only" guard is bypassable; the attacker-controlled suffix + /upload/** static mapping is what turns the upload into persisted XSS rather than a one-shot. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-43737 | 1 Apple | 6 Ios And Ipados, Ipados, Iphone Os and 3 more | 2026-09-20 | 5.5 Medium |
| An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access motion data from headphones without user consent. | ||||
| CVE-2026-86904 | 1 Apple | 4 Ios And Ipados, Ipados, Iphone Os and 1 more | 2026-09-20 | 7.5 High |
| A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to track users across apps and websites without permission. | ||||
| CVE-2026-86905 | 1 Apple | 5 Ios And Ipados, Ipados, Iphone Os and 2 more | 2026-09-20 | 5.5 Medium |
| This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to delete credentials stored in Keychain. | ||||