Skip to content
Signals
NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-18907 · Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filenameNVD · CVE-2026-18897 · 8.8 · A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempENVD · CVE-2026-18896 · 6.3 · A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.phNVD · CVE-2026-18895 · 8.8 · A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · apple

apple

· 557 Critical

Total CVEs

14,345

Critical

557

Products

195

Search All CVEs →

14,345

Products (195)

macos6,107 CVEsmac os x5,568 CVEsiphone os4,549 CVEstvos2,081 CVEsipados2,020 CVEswatchos1,844 CVEssafari1,650 CVEsitunes922 CVEsmac os x server817 CVEsvisionos501 CVEsicloud449 CVEswebkit258 CVEsquicktime250 CVEsxcode96 CVEsipad os89 CVEsipod touch58 CVEscups56 CVEsapple tv36 CVEsdarwin streaming server27 CVEsiphone23 CVEsquicktime streaming server16 CVEsos x server11 CVEsairport base station firmware11 CVEsswiftnio10 CVEsgarageband9 CVEsairport extreme9 CVEsmusic8 CVEsimageio8 CVEsichat8 CVEsmail7 CVEspages7 CVEstv os7 CVEskeynote7 CVEsapple remote desktop6 CVEsipad6 CVEsairport express6 CVEsswiftnio http\/25 CVEscfnetwork5 CVEsiphoto5 CVEstime capsule4 CVEsnumbers4 CVEsswift4 CVEsafp server4 CVEsiwork4 CVEsterminal4 CVEsipad24 CVEslogic pro x3 CVEsbonjour3 CVEswebcore3 CVEswebobjects3 CVEsmdnsresponder3 CVEsairport express base station firmware3 CVEscoregraphics3 CVEsa ux3 CVEsairport extreme base station firmware3 CVEsical3 CVEspowerpc3 CVEswatch os3 CVEsairport base station3 CVEsmac os runtime for java3 CVEsmac os3 CVEsboot camp2 CVEsairplay audio software development kit2 CVEsairplay video software development kit2 CVEsairpods firmware2 CVEsapple support2 CVEsapplescript2 CVEsappleshare2 CVEscarboncore2 CVEscarplay communication plug-in2 CVEscontainer2 CVEsfiles2 CVEsichat server2 CVEsimovie2 CVEsinstaller2 CVEsinstant message framework2 CVEsjava 1.52 CVEsjava 1.62 CVEsmacbook air2 CVEspersonal web sharing2 CVEsquicktime pictureviewer2 CVEsremote desktop2 CVEsshazam2 CVEsshortcuts2 CVEssoftware update2 CVEsxsan2 CVEscore audio technologies1 CVEscontainerization1 CVEscompressor1 CVEsitunes u1 CVEsclaris emailer1 CVEsjava1 CVEsjava 1.41 CVEsa5x1 CVEsa51 CVEs802.11n1 CVEslibsecurity1 CVEsbomarchivehelper1 CVEsm11 CVEsm1 mac mini1 CVEsm1 max1 CVEsm1 pro1 CVEsm1 ultra1 CVEsm21 CVEsm2 max1 CVEsm2 pro1 CVEsm2 ultra1 CVEsm31 CVEsm3 max1 CVEsm3 pro1 CVEsm3 ultra1 CVEsm41 CVEsm4 max1 CVEsm4 pro1 CVEsbeats fit pro firmware1 CVEsbeats fit pro1 CVEsmac os server1 CVEsappleshare mail server1 CVEsmac os x preview.app1 CVEsapple type services1 CVEsa11 bionic1 CVEsmacbook pro1 CVEsapple music1 CVEsmacos server1 CVEsmagic keyboard1 CVEsmagic keyboard firmware1 CVEsapple laserwriter1 CVEsapple airport extreme base station1 CVEsminimal slp service agent1 CVEsmobile safari1 CVEsmotion1 CVEsapp store connect1 CVEsmusic classical1 CVEsnioextras1 CVEsaperture1 CVEsapache mod digest apple1 CVEsairport utility1 CVEspdfkit1 CVEsweblog server1 CVEspodcast producer1 CVEspowerbeats1 CVEspowerbeats firmware1 CVEsairport card1 CVEspreview1 CVEspro video formats1 CVEspykerberos1 CVEsquartz composer1 CVEsquicklook1 CVEsairpods pro firmware1 CVEsquicktime broadcaster1 CVEsquicktime darwin mp3 broadcaster1 CVEsquicktime mpeg-2 playback component1 CVEsa10x fusion1 CVEsairpods pro1 CVEswindows migration assistant1 CVEsairpods max firmware1 CVEssecurerom1 CVEsserver manager1 CVEsa10 fusion1 CVEsxcode tools1 CVEssmart card services1 CVEsxserve lights-out management1 CVEsstudio display1 CVEsstudio display firmware1 CVEsairpods max1 CVEsswift-crypto1 CVEsswift-nio-extras1 CVEsswift foundation1 CVEsswift prometheus1 CVEsairpods1 CVEsa9x1 CVEsswiftnio ssl1 CVEstcp ip configuration utility1 CVEsa91 CVEstextedit1 CVEstexture1 CVEsa8x1 CVEstokend1 CVEstransporter1 CVEsa81 CVEsa71 CVEsa6x1 CVEsa61 CVEswatch ultra1 CVEswatch ultra 21 CVEsimessage1 CVEsichat av1 CVEsipad mini1 CVEsibooks author1 CVEsexposure notifications1 CVEsdata detectors engine1 CVEsiphone 3gs1 CVEsiphone configuration web utility1 CVEscore image fun house1 CVEsiphone se1 CVEs

Recent Vulnerabilities

View all 14,345
CVE-2026-17950HIGH 8.8

Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)

CVE-2026-17849MEDIUM 4.3

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via malicious network traffic. (Chromium security severity: Medium)

CVE-2026-17684CRITICAL 9.6

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-17669CRITICAL 9.6

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-18016MEDIUM 4.3

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-18015CRITICAL 9.6

Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-18013MEDIUM 4.3

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-18011LOW 2.4

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: Low)

CVE-2026-18003MEDIUM 4.3

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17996MEDIUM 6.2

Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)

CVE-2026-17975MEDIUM 6.5

Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17973MEDIUM 5.5

Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17972MEDIUM 4.3

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17967HIGH 8.8

Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17966MEDIUM 6.2

Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17965MEDIUM 4.3

Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17960MEDIUM 4.3

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17944MEDIUM 4.3

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17941MEDIUM 4.3

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17917MEDIUM 6.5

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17912MEDIUM 4.3

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17893MEDIUM 5.8

Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-17874MEDIUM 5.4

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-17873MEDIUM 6.5

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-17865CRITICAL 9.6

Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)