cbcvebase.

Apple macOS vulnerabilities

3,438 known vulnerabilities affecting apple/macos.

Total CVEs
3,438
CISA KEV
75
actively exploited
Public exploits
68
Exploited in wild
116
Severity breakdown
CRITICAL259HIGH1478MEDIUM1549LOW152

Vulnerabilities

Page 82 of 172
CVE-2021-22947P3MEDIUMCVSS 5.9fixed in 12.32021-09-29
CVE-2021-22947 [MEDIUM] CWE-310 CVE-2021-22947: When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *b
nvd
CVE-2026-20665P3MEDIUMCVSS 6.5fixed in 26.42026-03-25
CVE-2026-20665 [MEDIUM] CWE-693 CVE-2026-20665: This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2025-31233P3MEDIUMCVSS 6.3fixed in 13.7.6≥ 14.0, < 14.7.6+3 more2025-05-12
CVE-2025-31233 [MEDIUM] CWE-20 CVE-2025-31233: The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
nvd
CVE-2022-0685P3HIGHCVSS 7.8fixed in 13.02022-02-20
CVE-2022-0685 [HIGH] CWE-823 CVE-2022-0685: Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418. Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
nvd
CVE-2019-8741P3HIGHCVSS 7.5≥ unspecified, < macOS Catalina 10.152020-02-28
CVE-2019-8741 [HIGH] CWE-835 CVE-2019-8741: A denial of service issue was addressed with improved input validation. A denial of service issue was addressed with improved input validation.
nvd
CVE-2022-1851P3HIGHCVSS 7.8fixed in 13.02022-05-25
CVE-2022-1851 [HIGH] CWE-125 CVE-2022-1851: Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2124P3HIGHCVSS 7.8fixed in 11.7≥ 12.0, < 12.62022-06-19
CVE-2022-2124 [HIGH] CWE-126 CVE-2022-2124: Buffer Over-read in GitHub repository vim/vim prior to 8.2. Buffer Over-read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2126P3HIGHCVSS 7.8fixed in 11.7≥ 12.0, < 12.62022-06-19
CVE-2022-2126 [HIGH] CWE-125 CVE-2022-2126: Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-1968P3HIGHCVSS 7.8fixed in 13.02022-06-02
CVE-2022-1968 [HIGH] CWE-416 CVE-2022-1968: Use After Free in GitHub repository vim/vim prior to 8.2. Use After Free in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2042P3HIGHCVSS 7.8fixed in 11.7≥ 12.0, < 12.62022-06-10
CVE-2022-2042 [HIGH] CWE-416 CVE-2022-2042: Use After Free in GitHub repository vim/vim prior to 8.2. Use After Free in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-1898P3HIGHCVSS 7.8fixed in 13.02022-05-27
CVE-2022-1898 [HIGH] CWE-416 CVE-2022-1898: Use After Free in GitHub repository vim/vim prior to 8.2. Use After Free in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-0359P3HIGHCVSS 7.8≥ 12.0, < 12.62022-01-26
CVE-2022-0359 [HIGH] CWE-122 CVE-2022-0359: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2019-8837P3HIGHCVSS 7.8≥ unspecified, < 10.152020-10-27
CVE-2019-8837 [HIGH] CVE-2019-8837: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. A malicious application may be able to access restricted files.
nvd
CVE-2021-30787P3HIGHCVSS 7.8≥ 11.0, < 11.5≥ unspecified, < 11.5+1 more2021-09-08
CVE-2021-30787 [HIGH] CVE-2021-30787: This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security U This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to cause unexpected system termination or write kernel memory.
nvd
CVE-2019-8542P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8542 [HIGH] CWE-120 CVE-2019-8542: A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macO A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges.
nvd
CVE-2019-8511P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.42019-12-18
CVE-2019-8511 [HIGH] CWE-120 CVE-2019-8511: A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.2 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A malicious application may be able to elevate privileges.
nvd
CVE-2019-6221P3HIGHCVSS 7.8≥ unspecified, < macOS Mojave 10.14.32019-03-05
CVE-2019-6221 [HIGH] CWE-125 CVE-2019-6221: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, iTunes 12.9.3 for Windows. A malicious application may be able to elevate privileges.
nvd
CVE-2020-9827P3HIGHCVSS 7.5≥ unspecified, < macOS Catalina 10.15.52020-06-09
CVE-2020-9827 [HIGH] CVE-2020-9827: A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 1 A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service.
nvd
CVE-2020-9924P3HIGHCVSS 7.5≥ unspecified, < macOS Catalina 10.15.62020-10-22
CVE-2020-9924 [HIGH] CVE-2020-9924: A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10 A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.6. A remote attacker may be able to cause a denial of service.
nvd
CVE-2021-30888P3HIGHCVSS 7.4fixed in 12.0.1≥ unspecified, < 12.0+2 more2021-08-24
CVE-2021-30888 [HIGH] CWE-601 CVE-2021-30888: An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS M An information leakage issue was addressed. This issue is fixed in iOS 15.1 and iPadOS 15.1, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1. A malicious website using Content Security Policy reports may be able to leak information via redirect behavior .
nvd
Apple macOS vulnerabilities | cvebase