VendorsApplemacosall versions
Vulnerabilities

Apple MACOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7076CVEs
CVE-2026-27487
OpenClaw: Prevent shell injection in macOS keychain credential write
Published 2026-02-21 · Analyzed
8.0EPSS 0.019
CVE-2025-26646
.NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability
Published 2025-05-13 · Analyzed
8.0EPSS 0.012
CVE-2025-24137
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3. An attacker on the local network may corrupt process memory.
Published 2025-01-27 · Modified
8.0EPSS 0.010
CVE-2026-34693
Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-06-09 · Analyzed
8.0EPSS 0.006
CVE-2025-24223
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.
Published 2025-05-12 · Modified
8.0EPSS 0.003
CVE-2026-11241
Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.0EPSS 0.001
CVE-2026-48346
Animate | Untrusted Search Path (CWE-426)
Published 2026-07-14 · Analyzed
7.9EPSS 0.003
CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
Published 2018-02-06 · Analyzed
7.8KEV3 PoCEPSS 0.895
CVE-2021-39843
Adobe Acrobat Reader XObject Out-of-Bound Write Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.767
CVE-2021-30860
An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Published 2021-08-24 · Analyzed
7.8KEVEPSS 0.760
CVE-2021-39836
Adobe Acrobat Reader DC AcroForm buttonGetIcon Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.695
CVE-2021-39837
Adobe Acrobat Reader DC AcroForm deleteItemAt Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.652
CVE-2021-39838
Adobe Acrobat Reader DC AcroForm buttonGetCaption Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.652
CVE-2021-39839
Adobe Acrobat Reader DC AcroForm getItemAt Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.652
CVE-2023-21608
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability
Published 2023-01-18 · Analyzed
7.8KEVEPSS 0.615
CVE-2023-22809
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
Published 2023-01-18 · Modified
7.81 PoCEPSS 0.554
CVE-2021-40728
Adobe Acrobat Reader DC Use After Free Arbitrary Code Execution
Published 2021-10-15 · Modified
7.8EPSS 0.546
CVE-2023-41064
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Published 2023-09-07 · Analyzed
7.8KEVEPSS 0.534
CVE-2020-24435
Acrobat Reader DC Heap-based Buffer Overflow Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.527
CVE-2023-32434
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
Published 2023-06-23 · Analyzed
7.8KEVEPSS 0.515
CVE-2021-39840
Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.506
CVE-2020-24437
Acrobat Reader DC Use-After-Free Vulnerability Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.465
CVE-2021-28554
Adobe Acrobat Reader DC Path Parsing Out-Of-Bounds Read could lead to arbitrary code execution
Published 2021-08-24 · Modified
7.8EPSS 0.460
CVE-2020-27930
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.
Published 2020-12-08 · Analyzed
7.8KEVEPSS 0.220
CVE-2021-44701
Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
7.8EPSS 0.209
CVE-2020-24430
Acrobat Pro DC Use-After-Free vulnerability Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.187
CVE-2021-39842
Adobe Acrobat Reader DC messageHandler.OnMessage Use-After-Free Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.174
CVE-2020-24436
Acrobat Pro DC PDF Export Out-Of-Bounds Write Vulnerability Could Lead to Arbitrary Code Execution
Published 2020-11-05 · Modified
7.8EPSS 0.170
CVE-2021-39863
Adobe Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
Published 2021-09-29 · Modified
7.8EPSS 0.132
CVE-2021-45068
Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
7.8EPSS 0.123
CVE-2021-39841
Adobe Acrobat Pro DC DocMedia Type Confusion Remote Code Execution Vulnerability
Published 2021-09-29 · Modified
7.8EPSS 0.117
CVE-2021-45064
Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
7.8EPSS 0.115
CVE-2020-9731
Out-of-bounds memory access could lead to code execution
Published 2020-09-10 · Modified
7.8EPSS 0.113
CVE-2022-34221
Adobe Acrobat Reader Type Confusion vulnerability could lead to Arbitrary code execution
Published 2022-07-15 · Modified
7.8EPSS 0.111
CVE-2020-24432
Acrobat Reader DC Arbitrary JavaScript Execution in PDF Documents
Published 2020-11-05 · Modified
7.8EPSS 0.111
CVE-2023-41992
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
Published 2023-09-21 · Analyzed
7.8KEVEPSS 0.095
CVE-2021-40731
Adobe Acrobat Reader DC JPEG2000 Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2021-10-15 · Modified
7.8EPSS 0.083
CVE-2022-22639
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.
Published 2022-03-18 · Modified
7.8EPSS 0.082
CVE-2024-20752
ZDI-CAN-22653: Adobe Bridge PS File Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2024-03-18 · Analyzed
7.8EPSS 0.078
CVE-2020-3950
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Horizon Client is installed.
Published 2020-03-17 · Analyzed
7.8KEV2 PoCEPSS 0.073
← Prev51 / 177Next →