Known vulnerabilities in iPadOS - page 14

Vendor: Apple Inc.
Software: iPadOS
Software CPE: cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
Total vulnerabilities: 1965
Public exploits: 72
Known exploited (KEV): 78
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting iPadOS iPadOS is affected by 1965 known vulnerabilities: 37 critical, 333 high, 326 medium, 1269 low Critical High Medium Low

Vulnerabilities (1965)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124414 - Protection Mechanism Failure
CVE-2025-43534
CWE-693 Low
No
No
18.7.7 22H333, 26.2 23C55 25.03.2026 SB2026032509
SB2025121309
#VU124409 - Information Exposure Through Log Files
CVE-2026-20668
CWE-532 Low
No
No
18.7.7 22H333, 26.3 23D127 25.03.2026 SB2026032506
SB2026032507
SB2026032509
and 3 more
#VU124407 - Use After Free
CVE-2026-20637
CWE-416 Low
No
No
18.7.7 22H333, 26.3 23D127 25.03.2026 SB2026032506
SB2026032507
SB2026032509
and 5 more
#VU124403 - Permissions, Privileges, and Access Controls
CVE-2026-28880
CWE-264 Low
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 3 more
#VU124398 - Exposure of sensitive information to an unauthorized actor
CVE-2026-28864
CWE-200 Low
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 4 more
#VU124390 - Improper Access Control
CVE-2026-28867
CWE-284 Low
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032509
and 4 more
#VU124383 - Improper input validation
CVE-2026-28852
CWE-20 Low
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032509
and 4 more
#VU124360 - Information Exposure Through Log Files
CVE-2026-28868
CWE-532 Low
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 4 more
#VU124355 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-28876
CWE-22 Low
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 3 more
#VU124352 - Improper input validation
CVE-2026-28886
CWE-20 Low
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124349 - Memory corruption
CVE-2026-20690
CWE-119 Low
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124348 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-28866
CWE-59 Low
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 2 more
#VU124346 - Use After Free
CVE-2026-28879
CWE-416 Medium
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124342 - Improper input validation
CVE-2026-28878
CWE-20 Low
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032507
SB2026032509
and 5 more
#VU124335 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2026-28865
CWE-300 Medium
No
No
18.7.7 22H333, 26.4 23E246 25.03.2026 SB2026032504
SB2026032506
SB2026032507
and 5 more
#VU124085 - Protection Mechanism Failure
CVE-2026-20643
CWE-693 Medium
No
No
18.7.7 22H333, 26.3.1 (a) 23D771330a, 26.4 23E246 17.03.2026 SB2026031771
SB2026031772
SB2026031773
and 22 more
#VU123953 - Memory corruption
CVE-2023-43010
CWE-119 High
No
No
15.8.7 19H411, 16.7.15 20H380 12.03.2026 SB2026031235
SB2026031236
SB2026031237
and 3 more
#VU121026 - Insufficiently Protected Credentials
CVE-2025-14524
CWE-522 Low
No
No
18.7.7 22H333, 26.4 23E246 07.01.2026 SB2026010741
SB2026010781
SB2026010782
and 23 more
#VU118780 - Out-of-bounds read
CVE-2025-64505
CWE-125 Medium
No
No
18.7.7 22H333, 26.4 23E246 26.11.2025 SB2025112638
SB2025112639
SB2025112819
and 22 more
#VU118652 - Use After Free
CVE-2023-43000
CWE-416 High
No
Exploited
15.8.7 19H411 20.11.2025 SB2025051619
SB2025120801
SB2025120802
and 4 more


Showing elements 261 - 280 out of 1965