Known vulnerabilities in macOS - page 16

Vendor: Apple Inc.
Software: macOS
Software CPE: cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Total vulnerabilities: 3367
Public exploits: 126
Known exploited (KEV): 83
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting macOS macOS is affected by 3367 known vulnerabilities: 39 critical, 535 high, 533 medium, 2260 low Critical High Medium Low

Vulnerabilities (3367)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121151 - Improper Initialization
CVE-2025-46299
CWE-665 Medium
No
No
26.2 25C56 12.01.2026 SB2026011215
SB2025121304
SB2025121306
and 25 more
#VU121150 - Memory corruption
CVE-2025-46298
CWE-119 Low
No
No
26.2 25C56 12.01.2026 SB2026011215
SB2025121304
SB2025121306
and 4 more
#VU121149 - Permissions, Privileges, and Access Controls
CVE-2025-46297
CWE-264 Low
No
No
26.2 25C56 12.01.2026 SB2025121304
#VU119937 - Permissions, Privileges, and Access Controls
CVE-2025-46279
CWE-264 Low
No
No
26.2 25C56 13.12.2025 SB2025121304
SB2025121305
SB2025121306
and 3 more
#VU119930 - Improper input validation
CVE-2025-43514
CWE-20 Low
No
No
26.2 25C56 13.12.2025 SB2025121304
#VU119928 - Information Exposure Through Log Files
CVE-2025-46277
CWE-532 Low
No
No
26.2 25C56 13.12.2025 SB2025121304
SB2025121307
SB2025121309
#VU119924 - Improper input validation
CVE-2025-46291
CWE-20 Low
No
No
26.2 25C56 13.12.2025 SB2025121304
#VU119922 - Improper input validation
CVE-2025-46278
CWE-20 Low
No
No
26.2 25C56 13.12.2025 SB2025121304
#VU119918 - Improper Access Control
CVE-2025-46281
CWE-284 Low
No
No
26.2 25C56 13.12.2025 SB2025121304
#VU119910 - Permissions, Privileges, and Access Controls
CVE-2025-46288
CWE-264 Low
No
No
26.2 25C56 13.12.2025 SB2025121304
SB2025121305
SB2025121307
and 1 more
#VU119909 - Use After Free
CVE-2025-43511
CWE-416 Low
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121305
and 24 more
#VU119908 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-43531
CWE-362 Low
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121305
and 24 more
#VU119907 - Memory corruption
CVE-2025-43501
CWE-119 Low
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121305
and 22 more
#VU119906 - Memory corruption
CVE-2025-43535
CWE-119 Low
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121305
and 22 more
#VU119905 - Use After Free
CVE-2025-43536
CWE-416 Low
No
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121309
and 21 more
#VU119904 - Type confusion
CVE-2025-43541
CWE-843 Low
Available
No
26.2 25C56 13.12.2025 SB2025121303
SB2025121304
SB2025121305
and 22 more
#VU119903 - Permissions, Privileges, and Access Controls
CVE-2025-46282
CWE-264 Low
No
No
26.2 25C56 13.12.2025 SB2025121302
SB2025121303
SB2025121304
#VU119902 - Use After Free
CVE-2025-43529
CWE-416 Critical
Available
Exploited
26.2 25C56, 26.3 25D125 13.12.2025 SB2025121301
SB2025121303
SB2025121304
and 29 more
#VU119833 - Out-of-bounds write
CVE-2025-14174
CWE-787 Critical
Available
Exploited
26.2 25C56, 26.3 25D125 11.12.2025 SB2025121118
SB2025121301
SB2025121303
and 21 more
#VU97450 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2024-8906
CWE-451 Medium
No
No
26.2 25C56 17.09.2024 SB2024091804
SB20240918137
SB20240918138
and 8 more


Showing elements 301 - 320 out of 3367