VendorsApplexcodeany version
Vulnerabilities

Apple Xcode any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

86CVEs
CVE-2015-7057
otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted mach-o file, a different vulnerability than CVE-2015-7049.
Published 2015-12-11 · Modified
4.6EPSS 0.003
CVE-2015-3187
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.
Published 2015-08-12 · Modified
4.0EPSS 0.066
CVE-2006-1466
Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.
Published 2006-05-24 · Modified
4.0EPSS 0.021
CVE-2025-43370
A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.
Published 2025-09-15 · Modified
4.0EPSS 0.003
CVE-2015-5910
IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attackers to obtain sensitive information by sniffing the network.
Published 2015-09-18 · Modified
3.3EPSS 0.008
CVE-2025-31186
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.
Published 2026-01-16 · Analyzed
3.3EPSS 0.002
← Prev3 / 3