Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2022-32893 | Apple | iOS and macOS | Apple iOS and macOS Out-of-Bounds Write Vulnerability Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content. | 8.8 CISA | 2022-08-18 | 2022-09-08 | Unknown |
| CVE-2022-32894 | Apple | iOS and macOS | Apple iOS and macOS Out-of-Bounds Write Vulnerability Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges. | 7.8 CISA | 2022-08-18 | 2022-09-08 | Unknown |
| CVE-2018-4344 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution. | 7.8 CISA | 2022-06-27 | 2022-07-18 | Unknown |
| CVE-2019-8605 | Apple | Multiple Products | Apple Multiple Products Use-After-Free Vulnerability A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges. | 7.8 CISA | 2022-06-27 | 2022-07-18 | Unknown |
| CVE-2020-9907 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, and tvOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. | 7.8 CISA | 2022-06-27 | 2022-07-18 | Unknown |
| CVE-2020-3837 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. | 7.8 CISA | 2022-06-27 | 2022-07-18 | Unknown |
| CVE-2021-30983 | Apple | iOS and iPadOS | Apple iOS and iPadOS Buffer Overflow Vulnerability Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges. | 7.8 CISA | 2022-06-27 | 2022-07-18 | Unknown |
| CVE-2016-4657 | Apple | iOS | Apple iOS Webkit Memory Corruption Vulnerability Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 8.8 CISA | 2022-05-24 | 2022-06-14 | Unknown |
| CVE-2016-4656 | Apple | iOS | Apple iOS Memory Corruption Vulnerability A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application. | 7.8 CISA | 2022-05-24 | 2022-06-14 | Unknown |
| CVE-2016-4655 | Apple | iOS | Apple iOS Information Disclosure Vulnerability The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application. | 5.5 CISA | 2022-05-24 | 2022-06-14 | Unknown |
| CVE-2019-7287 | Apple | iOS | Apple iOS Memory Corruption Vulnerability Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution. | 7.8 CISA | 2022-05-23 | 2022-06-13 | Unknown |
| CVE-2019-7286 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation. | 7.8 CISA | 2022-05-23 | 2022-06-13 | Unknown |
| CVE-2021-30883 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution. | 7.8 CISA | 2022-05-23 | 2022-06-13 | Unknown |
| CVE-2019-8506 | Apple | Multiple Products | Apple Multiple Products Type Confusion Vulnerability A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution. | 8.8 CISA | 2022-05-04 | 2022-05-25 | Unknown |
| CVE-2021-1789 | Apple | Multiple Products | Apple Multiple Products Type Confusion Vulnerability A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution. | 8.8 CISA | 2022-05-04 | 2022-05-25 | Unknown |
| CVE-2022-22674 | Apple | macOS | Apple macOS Out-of-Bounds Read Vulnerability macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory. | 5.5 CISA | 2022-04-04 | 2022-04-25 | Unknown |
| CVE-2022-22675 | Apple | macOS | Apple macOS Out-of-Bounds Write Vulnerability macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary code with kernel privileges. | 7.8 CISA | 2022-04-04 | 2022-04-25 | Unknown |
| CVE-2022-22620 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 8.8 CISA | 2022-02-11 | 2022-02-25 | Unknown |
| CVE-2014-4404 | Apple | OS X | Apple OS X Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a privileged context. | 7.8 CISA | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2015-1130 | Apple | OS X | Apple OS X Authentication Bypass Vulnerability The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges. | 7.8 CISA | 2022-02-10 | 2022-08-10 | Unknown |
| CVE-2022-22587 | Apple | iOS and macOS | Apple Memory Corruption Vulnerability Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to execute arbitrary code with kernel privileges. | 9.8 CISA | 2022-01-28 | 2022-02-11 | Unknown |
| CVE-2020-9859 | Apple | Multiple Products | Apple Multiple Products Code Execution Vulnerability Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-30869 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS Type Confusion Vulnerability Apple iOS, iPadOS, and macOS contain a type confusion vulnerability in the XNU which may allow a malicious application to execute code with kernel privileges. | 7.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-30761 | Apple | iOS | Apple iOS WebKit Memory Corruption Vulnerability Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-30663 | Apple | Multiple Products | Apple Multiple Products WebKit Integer Overflow Vulnerability Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 7.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-30665 | Apple | Multiple Products | Apple Multiple Products WebKit Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-30657 | Apple | macOS | Apple macOS Unspecified Vulnerability Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks. | 5.5 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-30713 | Apple | macOS | Apple macOS Unspecified Vulnerability Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences. | 7.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-30666 | Apple | iOS | Apple iOS WebKit Buffer Overflow Vulnerability Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-30661 | Apple | Multiple Products | Apple Multiple Products WebKit Storage Use-After-Free Vulnerability Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-1879 | Apple | iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 6.1 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-1871 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-1870 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-1782 | Apple | Multiple Products | Apple Multiple Products Race Condition Vulnerability Apple iOS, iPadOs, macOS, watchOS, and tvOS contain a race condition vulnerability that may allow a malicious application to elevate privileges. | 7.0 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-30762 | Apple | iOS | Apple iOS WebKit Use-After-Free Vulnerability Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2020-9819 | Apple | iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message. | 4.3 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-9818 | Apple | iOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-27932 | Apple | Multiple Products | Apple Multiple Products Type Confusion Vulnerability Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-27950 | Apple | Multiple Products | Apple Multiple Products Memory Initialization Vulnerability Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory. | 5.5 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-30807 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges. | 7.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2020-27930 | Apple | Multiple Products | Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-30860 | Apple | Multiple Products | Apple Multiple Products Integer Overflow Vulnerability Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. | 7.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2019-6223 | Apple | iOS and macOS | Apple iOS and macOS Group Facetime Vulnerability Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction. | 7.5 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-30858 | Apple | iOS, iPadOS, and macOS | Apple iOS, iPadOS, macOS Use-After-Free Vulnerability Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |