Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-20706

Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.

PUBLISHED
Vendor
Gitea
Product
Gitea Open Source Git Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-20704

Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page while logged-in to the affected product, unintended operations may be performed.

PUBLISHED
Vendor
ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD., ELECOM CO.,LTD.
Product
WRC-X6000QS-G, WRC-X6000XST-G, WRC-X3000GS2-B, WRC-X1500GS-B, WRC-X1500GSA-B, WRC-XE5400GS-G, WRC-X3000GS2-W, WRC-X1800GS-B, WRC-X3000GST2-B, WRC-X1800GSH-B, WRC-X6000QSA-G, WRC-XE5400GSA-G, WRC-X6000XS-G, WRC-X1800GSA-B, WRC-X3000GS2A-B
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20701

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to connect to a network share without user consent.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-20700

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to

PUBLISHEDCISA KEV
Vendor
Apple, Apple, Apple, Apple, Apple
Product
macOS, iOS and iPadOS, tvOS, watchOS, visionOS
Provider severity
HIGH
Conflicts
2

CVE-2026-2070

A vulnerability has been found in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /goform/formPolicyRouteConf. Such manipulation of the argument GroupName leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
UTT
Product
进取 520W
Provider severity
HIGH
Conflicts
2

CVE-2026-20699

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app may be able to access user-sensitive data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20698

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or corrupt kernel memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
visionOS, watchOS, macOS, tvOS, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20697

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20696

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20695

An information disclosure issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to determine kernel memory layout.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20694

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app may be able to access user-sensitive data.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20693

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An attacker with root privileges may be able to delete protected system files.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20692

A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. "Hide IP Address" and "Block All Remote Content" may not apply to all mail content.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20691

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A maliciously crafted webpage may be able to fingerprint the user.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
Safari, watchOS, iOS and iPadOS, visionOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20690

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing an audio stream in a maliciously crafted media file may terminate the process.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, macOS, tvOS, watchOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2069

A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the file llama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This manipulation causes stack-based buffer overflow. The attack needs to be launched locally. The exploit has been published and may be used. Patch name: 18993. To fix this issue, it is recommended to deploy a patch.

PUBLISHED
Vendor
ggml-org
Product
llama.cpp
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-20688

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to break out of its sandbox.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
macOS, visionOS, iOS and iPadOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-20687

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or write kernel memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
watchOS, iOS and iPadOS, macOS, tvOS
Provider severity
HIGH
Conflicts
2

CVE-2026-20686

This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20685

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.

PUBLISHED
Vendor
Apple
Product
Private Cloud Compute Server Software
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20684

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypass Gatekeeper checks.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
LOW
Conflicts
1

CVE-2026-20682

A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker may be able to discover a user’s deleted notes.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20681

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26.3. An app may be able to access information about a user's contacts.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
LOW
Conflicts
1

CVE-2026-20680

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. A sandboxed app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2068

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/formSyslogConf. The manipulation of the argument ServerIp results in buffer overflow. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
UTT
Product
进取 520W
Provider severity
HIGH
Conflicts
2

CVE-2026-20678

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20677

A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
iOS and iPadOS, macOS, visionOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-20676

This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
macOS, iOS and iPadOS, visionOS, Safari
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20675

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted image may lead to disclosure of user information.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, visionOS, watchOS, tvOS, macOS
Provider severity
HIGH
Conflicts
2

CVE-2026-20674

A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20673

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. Turning off "Load remote content in messages” may not apply to all mail previews.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20672

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20671

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to intercept network traffic.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, tvOS, watchOS, visionOS, macOS
Provider severity
LOW
Conflicts
2

CVE-2026-20670

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-2067

A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTimeGroupConfig. The manipulation of the argument year1 leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
UTT
Product
进取 520W
Provider severity
HIGH
Conflicts
2

CVE-2026-20669

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20668

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
iOS and iPadOS, macOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20667

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, watchOS 26.3. An app may be able to break out of its sandbox.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
macOS, iOS and iPadOS, watchOS
Provider severity
HIGH
Conflicts
2

CVE-2026-20666

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20665

This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
macOS, tvOS, watchOS, iOS and iPadOS, Safari, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20664

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.4, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Red Hat, Red Hat, Red Hat
Product
visionOS, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, macOS, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, iOS and iPadOS, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9.6 Extended Update Support, Safari, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-20663

The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to enumerate a user's installed apps.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
LOW
Conflicts
1

CVE-2026-20662

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20661

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20660

A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A remote user may be able to write arbitrary files.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple
Product
visionOS, macOS, Safari, iOS and iPadOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2066

A weakness has been identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formIpGroupConfig. Executing a manipulation of the argument groupName can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
UTT
Product
进取 520W
Provider severity
HIGH
Conflicts
2

CVE-2026-20658

A package validation issue was addressed by blocking the vulnerable package. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-20657

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. Parsing a maliciously crafted file may lead to an unexpected app termination.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
iOS and iPadOS, macOS, visionOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20656

A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3. An app may be able to access a user's Safari history.

PUBLISHED
Vendor
Apple, Apple, Apple
Product
Safari, iOS and iPadOS, macOS
Provider severity
LOW
Conflicts
2

CVE-2026-20655

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

PUBLISHED
Vendor
Apple
Product
iOS and iPadOS
Provider severity
MEDIUM
Conflicts
1