cbcvebase.

Apple iPadOS vulnerabilities

2,029 known vulnerabilities affecting apple/ipados.

Total CVEs
2,029
CISA KEV
79
actively exploited
Public exploits
36
Exploited in wild
111
Severity breakdown
CRITICAL132HIGH884MEDIUM888LOW125

Vulnerabilities

Page 100 of 102
CVE-2024-40853P4LOWCVSS 3.3fixed in 18.02024-10-28
CVE-2024-40853 [LOW] CVE-2024-40853: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may be able to use Siri to enable Auto-Answer Calls.
nvd
CVE-2025-24090P4LOWCVSS 3.3fixed in 18.32026-01-16
CVE-2025-24090 [LOW] CWE-200 CVE-2025-24090: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's installed apps.
nvd
CVE-2026-20663P4LOWCVSS 3.3fixed in 18.7.5≥ 26.0, < 26.32026-02-11
CVE-2026-20663 [LOW] CWE-532 CVE-2026-20663: The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, i The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to enumerate a user's installed apps.
nvd
CVE-2023-23541P4LOWCVSS 3.3fixed in 15.7.4≥ 16.0, < 16.42023-05-08
CVE-2023-23541 [LOW] CWE-922 CVE-2023-23541: A privacy issue was addressed with improved private data redaction for log entries. This issue is fi A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. An app may be able to access information about a user’s contacts.
nvd
CVE-2024-54558P4LOWCVSS 2.8fixed in 18.02025-03-10
CVE-2024-54558 [LOW] CWE-451 CVE-2024-54558: A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed i A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to trick a user into granting access to photos from the user's photo library.
nvd
CVE-2023-32365P4LOWCVSS 2.4fixed in 15.7.6≥ 16.0, < 16.52023-06-23
CVE-2023-32365 [LOW] CVE-2023-32365: The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, i The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, iOS 16.5 and iPadOS 16.5. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.
nvd
CVE-2024-44123P4LOWCVSS 2.3fixed in 18.02024-10-28
CVE-2024-44123 [LOW] CVE-2024-44123: A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iP A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. A malicious app with root privileges may be able to access keyboard input and location information without user consent.
nvd
CVE-2020-9780P4LOWCVSS 3.3fixed in 13.42020-04-01
CVE-2020-9780 [LOW] CWE-212 CVE-2020-9780: The issue was resolved by clearing application previews when content is deleted. This issue is fixed The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPadOS 13.4. A local user may be able to view deleted content in the app switcher.
nvd
CVE-2024-40822P4LOWCVSS 2.4fixed in 16.7.9≥ 17.0, < 17.62024-07-29
CVE-2024-40822 [LOW] CWE-284 CVE-2024-40822: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, watchOS 10.6. An attacker with physical access to a device may be able to access contacts from the lock screen.
nvd
CVE-2023-32390P4LOWCVSS 2.4fixed in 16.52023-06-23
CVE-2023-32390 [LOW] CWE-125 CVE-2023-32390: The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watch The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Photos belonging to the Hidden Photos Album could be viewed without authentication through Visual Lookup.
nvd
CVE-2025-24193P4LOWCVSS 2.4fixed in 18.42025-03-31
CVE-2025-24193 [LOW] CWE-284 CVE-2025-24193: This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18 This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos.
nvd
CVE-2022-32879P4LOWCVSS 2.4fixed in 15.72022-11-01
CVE-2022-32879 [LOW] CVE-2022-32879: A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, tvOS 16. A user with physical access to a device may be able to access contacts from the lock screen.
nvd
CVE-2019-8799P4LOWCVSS 2.4fixed in 13.12020-10-27
CVE-2019-8799 [LOW] CVE-2019-8799: This issue was resolved by replacing device names with a random identifier. This issue is fixed in i This issue was resolved by replacing device names with a random identifier. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15, watchOS 6, tvOS 13. An attacker in physical proximity may be able to passively observe device names in AWDL communications.
nvd
CVE-2023-32394P4LOWCVSS 2.4fixed in 16.52023-06-23
CVE-2023-32394 [LOW] CWE-668 CVE-2023-32394: The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watch The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.
nvd
CVE-2021-30915P4LOWCVSS 2.4fixed in 15.12021-08-24
CVE-2021-30915 [LOW] CVE-2021-30915: A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPad A logic issue was addressed with improved state management. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, tvOS 15.1, watchOS 8.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A person with physical access to an iOS device may be able to determine characteristics of a user's password in a secure text entry field.
nvd
CVE-2021-1863P4LOWCVSS 2.4fixed in 14.52021-09-08
CVE-2021-1863 [LOW] CWE-287 CVE-2021-1863: An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed wit An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place phone calls to any phone number.
nvd
CVE-2022-22599P4LOWCVSS 2.4fixed in 15.42022-03-18
CVE-2022-22599 [LOW] CVE-2022-22599: Description: A permissions issue was addressed with improved validation. This issue is fixed in watc Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain some location information from the lock screen.
nvd
CVE-2024-54485P4LOWCVSS 2.4≤ 17.7.3≥ 18.0, < 18.2+1 more2024-12-12
CVE-2024-54485 [LOW] CWE-922 CVE-2024-54485: The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. An attacker with physical access to an iOS device may be able to view notification content from the lock screen.
nvd
CVE-2024-44179P4LOWCVSS 2.4fixed in 17.72025-03-10
CVE-2024-44179 [LOW] CWE-200 CVE-2024-44179: This issue was addressed by restricting options offered on a locked device. This issue is fixed in i This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15. An attacker with physical access to a device may be able to read contact numbers from the lock screen.
nvd
CVE-2022-46717P4LOWCVSS 2.4fixed in 16.22023-04-10
CVE-2022-46717 [LOW] CVE-2022-46717: A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.2 and iPadOS 1 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2. A user with physical access to a locked Apple Watch may be able to view user photos via accessibility features
nvd
Apple iPadOS vulnerabilities | cvebase