Vulnerabilities (CVE)

Filtered by vendor Apple Subscribe
Total 14854 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-62871 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-13 N/A 7.8 HIGH
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2018-15982 6 Adobe, Apple, Google and 3 more 11 Flash Player, Flash Player Installer, Mac Os X and 8 more 2026-08-13 10.0 HIGH 7.8 HIGH
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2026-11980 4 Apple, Ibm, Linux and 1 more 4 Macos, Aspera Desktop App, Linux Kernel and 1 more 2026-08-12 N/A 7.3 HIGH
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
CVE-2026-14973 4 Apple, Ibm, Linux and 1 more 4 Macos, Aspera Desktop App, Linux Kernel and 1 more 2026-08-12 N/A 9.3 CRITICAL
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
CVE-2023-44487 33 Akka, Amazon, Apache and 30 more 324 Http Server, Opensearch Data Prepper, Apisix and 321 more 2026-08-11 N/A 7.5 HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2021-44228 12 Apache, Apple, Bentley and 9 more 166 Log4j, Xcode, Synchro and 163 more 2026-08-11 9.3 HIGH 10.0 CRITICAL
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
CVE-2026-48373 3 Adobe, Apple, Microsoft 5 Acrobat, Acrobat Dc, Acrobat Reader Dc and 2 more 2026-08-11 N/A 7.8 HIGH
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2021-38642 2 Apple, Microsoft 2 Iphone Os, Edge 2026-08-10 4.0 MEDIUM 6.1 MEDIUM
Microsoft Edge for iOS Spoofing Vulnerability
CVE-2026-17913 2 Apple, Google 2 Iphone Os, Chrome 2026-08-10 N/A 5.4 MEDIUM
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-17724 2 Apple, Google 2 Iphone Os, Chrome 2026-08-10 N/A 4.2 MEDIUM
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
CVE-2026-17716 2 Apple, Google 2 Macos, Chrome 2026-08-10 N/A 8.4 HIGH
Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via malicious network traffic. (Chromium security severity: High)
CVE-2026-34641 3 Adobe, Apple, Microsoft 4 Premiere, Premiere Pro, Macos and 1 more 2026-08-07 N/A 7.8 HIGH
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-65400 1 Apple 1 Macos 2026-08-07 N/A 7.1 HIGH
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
CVE-2026-17654 2 Apple, Google 2 Macos, Chrome 2026-08-06 N/A 7.8 HIGH
Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)
CVE-2026-39875 1 Apple 1 Macos 2026-08-05 N/A 7.8 HIGH
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
CVE-2026-17789 2 Apple, Google 2 Iphone Os, Chrome 2026-08-04 N/A 6.5 MEDIUM
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Medium)
CVE-2026-18015 2 Apple, Google 2 Macos, Chrome 2026-08-04 N/A 9.6 CRITICAL
Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-17761 2 Apple, Google 2 Iphone Os, Chrome 2026-08-04 N/A 5.4 MEDIUM
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)
CVE-2026-17762 2 Apple, Google 2 Iphone Os, Chrome 2026-08-04 N/A 4.3 MEDIUM
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17770 2 Apple, Google 2 Macos, Chrome 2026-08-04 N/A 5.8 MEDIUM
Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)