CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-47352

    Last Modified: 26 Feb 2026

    Memory corruption while processing audio streaming operations.

    Published: 4 Nov 2025
    8.8
    High

    CVE-2025-27074

    Last Modified: 26 Feb 2026

    Memory corruption while processing a GP command response.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-27070

    Last Modified: 26 Feb 2026

    Memory corruption while performing encryption and decryption commands.

    Published: 4 Nov 2025
    6.1
    Medium

    CVE-2025-27064

    Last Modified: 5 Nov 2025

    Information disclosure while registering commands from clients with diag through diagHal.

    Published: 4 Nov 2025
    6.4
    Medium

    CVE-2025-12324

    Last Modified: 22 Apr 2026

    The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `table` shortcode attributes in all versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Nov 2025
    6.4
    Medium

    CVE-2025-11841

    Last Modified: 21 Apr 2026

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Chart Data attributes in all versions up to, and including, 12.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43373

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 4 Nov 2025
    2.8
    Low

    CVE-2025-43365

    Last Modified: 27 Apr 2026

    A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26 and iPadOS 26. An unprivileged process may be able to terminate a root processes.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43430

    Last Modified: 22 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43426

    Last Modified: 2 Apr 2026

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43390

    Last Modified: 28 Apr 2026

    A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43447

    Last Modified: 27 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. An app may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43502

    Last Modified: 22 Apr 2026

    A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-43386

    Last Modified: 28 Apr 2026

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43345

    Last Modified: 28 Apr 2026

    A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43493

    Last Modified: 22 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Visiting a malicious website may lead to address bar spoofing.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-43387

    Last Modified: 27 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. A malicious app may be able to gain root privileges.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43411

    Last Modified: 27 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43446

    Last Modified: 22 Apr 2026

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to modify protected parts of the file system.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43503

    Last Modified: 2 Apr 2026

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Visiting a malicious website may lead to user interface spoofing.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43450

    Last Modified: 22 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to learn information about the current camera view before being granted camera access.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43391

    Last Modified: 27 Apr 2026

    A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-43407

    Last Modified: 11 Jun 2026

    This issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. An app may be able to break out of its sandbox.

    Published: 4 Nov 2025
    2.4
    Low

    CVE-2025-43309

    Last Modified: 27 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43427

    Last Modified: 2 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025
    8.8
    High

    CVE-2025-43431

    Last Modified: 22 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43348

    Last Modified: 27 Apr 2026

    A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may bypass Gatekeeper checks.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-43364

    Last Modified: 28 Apr 2026

    A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.1. An app may be able to break out of its sandbox.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43396

    Last Modified: 27 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. A sandboxed app may be able to access sensitive user data.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43379

    Last Modified: 28 Apr 2026

    This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to access protected user data.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-43457

    Last Modified: 30 Jun 2026

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43441

    Last Modified: 14 Aug 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025
    4.9
    Medium

    CVE-2025-43504

    Last Modified: 22 Apr 2026

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service.

    Published: 4 Nov 2025
    7.1
    High

    CVE-2025-43338

    Last Modified: 28 Apr 2026

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Sonoma 14.8.4, macOS Tahoe 26. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43380

    Last Modified: 28 Apr 2026

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. Parsing a file may lead to an unexpected app termination.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43288

    Last Modified: 27 Apr 2026

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to bypass Privacy preferences.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43322

    Last Modified: 27 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43334

    Last Modified: 27 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.

    Published: 4 Nov 2025
    7.5
    High

    CVE-2025-43436

    Last Modified: 22 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. An app may be able to enumerate a user's installed apps.

    Published: 4 Nov 2025
    4.7
    Medium

    CVE-2025-43420

    Last Modified: 28 Apr 2026

    A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43498

    Last Modified: 28 Apr 2026

    An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43477

    Last Modified: 27 Apr 2026

    A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43499

    Last Modified: 27 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

    Published: 4 Nov 2025
    7.8
    High

    CVE-2025-43476

    Last Modified: 27 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to break out of its sandbox.

    Published: 4 Nov 2025
    4.3
    Medium

    CVE-2025-43421

    Last Modified: 2 Apr 2026

    Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025
    4.6
    Medium

    CVE-2025-43460

    Last Modified: 22 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive user information.

    Published: 4 Nov 2025
    5.5
    Medium

    CVE-2025-43335

    Last Modified: 27 Apr 2026

    The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access user-sensitive data.

    Published: 4 Nov 2025
    8.1
    High

    CVE-2025-43323

    Last Modified: 27 Apr 2026

    This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to fingerprint the user.

    Published: 4 Nov 2025
    5.4
    Medium

    CVE-2025-43495

    Last Modified: 22 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to monitor keystrokes without user permission.

    Published: 4 Nov 2025
    6.5
    Medium

    CVE-2025-43440

    Last Modified: 22 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 4 Nov 2025