CVE Severity Distribution (Last 30 Days)
Found 10 CVEs in the last 30 days.
CVE-2026-6471
HIGH
CVSS: 7.2
EPSS: 0.3%
CWE-862
T1078
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Published: 2026-08-13
Mentioned in 2 article(s):
CVE-2026-64713
HIGH
CVSS: 8.1
EPSS: 0.5%
CWE-203
This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.
Published: 2026-07-27
CVE-2026-64719
HIGH
CVSS: 8.1
EPSS: 0.4%
CWE-125
T1005
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-07-27
CVE-2026-64712
HIGH
CVSS: 7.8
EPSS: 0.1%
RECENT DISCOVERY
CWE-284
T1078
This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
Published: 2026-09-14
CVE-2026-64716
HIGH
CVSS: 7.8
EPSS: 0.2%
CWE-119
T1203
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may corrupt process memory.
Published: 2026-07-27
CVE-2026-64710
MEDIUM
CVSS: 5.5
EPSS: 0.2%
CWE-200
T1005
T1083
A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.
Published: 2026-07-27
CVE-2026-64711
MEDIUM
CVSS: 5.5
EPSS: 0.2%
CWE-285
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.
Published: 2026-07-27
CVE-2026-64718
MEDIUM
CVSS: 5.5
EPSS: 0.2%
CWE-416
T1203
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.
Published: 2026-07-27
CVE-2026-64714
UNKNOWN
EPSS: 0.2%
RECENT DISCOVERY
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted image may lead to a denial-of-service.
Published: 2026-09-14
CVE-2026-64717
UNKNOWN
EPSS: 0.2%
RECENT DISCOVERY
A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.
Published: 2026-09-14