apple
1,466 known vulnerabilities affecting apple products.
Products
macos 1342
iphone_os 402
ipados 306
visionos 178
watchos 160
tvos 158
safari 66
mac_os_x 4
container 2
swift-crypto 2
swiftnio 1
swiftnio_http\/2 1
swiftnio_ssh 1
swiftnio_ssl 1
servicetalk 1
xcode 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-50528 | Medium | 0.6% | 8.2 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a secu… | |
| CVE-2026-7667 | Medium | 0.6% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create… | |
| CVE-2026-8859 | Medium | 0.6% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write … | |
| CVE-2023-4751 | Medium | 0.6% | 7.8 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331. | |
| CVE-2026-28936 | Medium | 0.6% | 7.5 | The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 … | |
| CVE-2026-64702 | Medium | 0.6% | 9.8 | An access issue was addressed with additional sandbox restrictions. This issue i… | |
| CVE-2026-64775 | Medium | 0.6% | 9.8 | A memory initialization issue was addressed with improved memory handling. This … | |
| CVE-2026-64746 | Medium | 0.6% | 9.8 | An authorization issue was addressed with improved validation. This issue is fix… | |
| CVE-2026-43701 | Medium | 0.6% | 7.1 | The issue was addressed with improved checks. This issue is fixed in Safari 26.5… | |
| CVE-2026-79012 | Medium | 0.5% | 9.6 | Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65… | |
| CVE-2023-4733 | Medium | 0.5% | 7.8 | Use After Free in GitHub repository vim/vim prior to 9.0.1840. | |
| CVE-2026-9119 | Medium | 0.5% | 8.8 | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allow… | |
| CVE-2023-4750 | Medium | 0.5% | 7.8 | Use After Free in GitHub repository vim/vim prior to 9.0.1857. | |
| CVE-2026-43757 | Medium | 0.5% | 9.8 | An out-of-bounds read was addressed with improved bounds checking. This issue is… | |
| CVE-2026-64762 | Medium | 0.5% | 9.8 | An out-of-bounds read was addressed with improved bounds checking. This issue is… | |
| CVE-2026-84553 | Medium | 0.5% | 7.5 | A resource exhaustion issue was addressed with improved input validation. This i… | |
| CVE-2026-28969 | Medium | 0.5% | 7.5 | A use after free issue was addressed with improved memory management. This issue… | |
| CVE-2026-8056 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override com… | |
| CVE-2026-8635 | Medium | 0.5% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate pri… | |
| CVE-2026-47300 | Medium | 0.5% | 8.8 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an a… | |
| CVE-2026-64739 | Medium | 0.5% | 8.8 | An out-of-bounds write issue was addressed with improved bounds checking. This i… | |
| CVE-2026-39873 | Medium | 0.5% | 9.8 | The issue was addressed with improved memory handling. This issue is fixed in ma… | |
| CVE-2026-43710 | Medium | 0.5% | 9.8 | The issue was addressed with improved memory handling. This issue is fixed in ma… | |
| CVE-2026-43692 | Medium | 0.5% | 8.8 | A validation issue was addressed with improved input sanitization. This issue is… | |
| CVE-2026-34690 | Medium | 0.5% | 7.8 | After Effects is affected by a Stack-based Buffer Overflow vulnerability that co… | |
| CVE-2026-43730 | Medium | 0.5% | 9.8 | A permissions issue was addressed with additional restrictions. This issue is fi… | |
| CVE-2026-79039 | Medium | 0.5% | 8.1 | Use after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allow… | |
| CVE-2026-78935 | Medium | 0.5% | 9.6 | Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.… | |
| CVE-2026-76040 | Medium | 0.5% | 8.8 | Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 all… | |
| CVE-2026-43705 | Medium | 0.5% | 8.8 | A type confusion issue was addressed with improved checks. This issue is fixed i… | |
| CVE-2026-5865 | Medium | 0.5% | 8.8 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote at… | |
| CVE-2026-9120 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remo… | |
| CVE-2026-64751 | Medium | 0.5% | 9.8 | A use after free issue was addressed with improved memory management. This issue… | |
| CVE-2026-78964 | Medium | 0.5% | 9.6 | Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed… | |
| CVE-2026-10903 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10943 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10947 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10948 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-65375 | Medium | 0.5% | 7.5 | The issue was addressed with improved authentication. This issue is fixed in mac… | |
| CVE-2026-19298 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-28982 | Medium | 0.5% | 9.8 | A race condition was addressed with improved locking. This issue is fixed in mac… | |
| CVE-2026-17669 | Medium | 0.5% | 9.6 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to … | |
| CVE-2026-17684 | Medium | 0.5% | 9.6 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on… | |
| CVE-2026-64727 | Medium | 0.5% | 9.8 | A type confusion issue was addressed with improved memory handling. This issue i… | |
| CVE-2026-64768 | Medium | 0.5% | 8.1 | An out-of-bounds read issue was addressed with improved input validation. This i… | |
| CVE-2026-5860 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remot… | |
| CVE-2026-17695 | Medium | 0.5% | 9.6 | Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.792… | |
| CVE-2026-17710 | Medium | 0.5% | 9.6 | Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.792… | |
| CVE-2026-35561 | Medium | 0.5% | 7.4 | Insufficient authentication security controls in the browser-based authenticatio… | |
| CVE-2026-28815 | Medium | 0.5% | 7.5 | A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an… |