Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 25 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Apple Multiple Buffer Overflow Vulnerability

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to

CWE-119Feb 11, 2026
CVSS7.8v3.1EPSS1.32%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Use-After-Free WebKit Vulnerability

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also

CWE-416Dec 17, 2025
CVSS8.8v3.1EPSS8.77%PoCs7SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Improper Locking Vulnerability

A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may cause unexpected changes in memory shared between processes.

CWE-362CWE-667Dec 12, 2025
CVSS7.8v3.1EPSS0.361%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Classic Buffer Overflow Vulnerability

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may be able to cause unexpected system termination or write kernel memory.

CWE-120CWE-787Dec 12, 2025
CVSS5.5v3.1EPSS0.423%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple products Use-After-Free Vulnerability

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

CWE-416Nov 5, 2025
CVSS8.8v3.1EPSS3.9%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Buffer Overflow Vulnerability

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption.

CWE-119CWE-120Jul 29, 2025
CVSS8.8v3.1EPSS1.48%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Unspecified Vulnerability

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific tar

Jun 16, 2025
CVSS4.2v3.1EPSS1.06%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Memory Corruption Vulnerability

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.

CWE-119CWE-787Apr 16, 2025
CVSS9.8v3.1EPSS19.7%PoCs4SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Arbitrary Read and Write Vulnerability

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.

CWE-1220Apr 16, 2025
CVSS9.8v3.1EPSS14.7%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have

CWE-787Mar 11, 2025
CVSS10.0v3.1EPSS4.12%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Use-After-Free Vulnerability

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.

CWE-276CWE-416Jan 27, 2025
CVSS10.0v3.1EPSS17.3%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

CWE-79Nov 19, 2024
CVSS6.3v3.1EPSS22.7%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Code Execution Vulnerability

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

Nov 19, 2024
CVSS8.8v3.1EPSS9.19%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Memory Corruption Vulnerability

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

CWE-787Mar 5, 2024
CVSS7.8v3.1EPSS1.41%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Memory Corruption Vulnerability

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

CWE-787Mar 5, 2024
CVSS7.8v3.1EPSS1.48%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products WebKit Type Confusion Vulnerability

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma 14.3, macOS Ventura 13.6.4, tvOS 17.3, visionOS 1.0.2. Processing maliciously crafted web content may lead to arbitrary code execution. This fix associated with the Coruna exploit was shipped in iOS 17.3 on January 22, 2024. This update brings that fix to devices that cannot update

CWE-843Jan 23, 2024
CVSS8.8v3.1EPSS10.6%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Memory Corruption Vulnerability

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.

CWE-287CWE-367Jan 9, 2024
CVSS7.0v3.1EPSS0.487%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products WebKit Memory Corruption Vulnerability

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

CWE-787Nov 30, 2023
CVSS8.8v3.1EPSS9.37%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

CWE-125Nov 30, 2023
CVSS6.5v3.1EPSS17.8%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products WebKit Code Execution Vulnerability

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CWE-754Sep 21, 2023
CVSS8.8v3.1EPSS29.2%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Kernel Privilege Escalation Vulnerability

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CWE-754Sep 21, 2023
CVSS7.8v3.1EPSS2.92%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Improper Certificate Validation Vulnerability

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CWE-295Sep 21, 2023
CVSS5.5v3.1EPSS4.55%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Code Execution Vulnerability

The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.

Sep 11, 2023
CVSS7.8v3.1EPSS1.35%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Unspecified Vulnerability

The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.

CWE-129Aug 14, 2023
CVSS8.8v3.1EPSS3.21%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Apple Multiple Products Kernel Unspecified Vulnerability

This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.

Jul 26, 2023
CVSS5.5v3.1EPSS2.9%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX