CVE Tracker
Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.
1,542
Total CVEs
1,542
CISA KEV
1542
Critical & High
Mar 13, 2026
Last KEV Update
| CVE ID | Severity | Vendor | Description | Published | KEV |
|---|---|---|---|---|---|
| CVE-2020-17530 | High | ApacheStruts | Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution. | Nov 3, 2021 | KEV |
| CVE-2017-5638 | High | ApacheStruts | Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. | Nov 3, 2021 | KEV |
| CVE-2018-11776 | High | ApacheStruts | Apache Struts contains a vulnerability that allows for remote code execution under two circumstances. One, where the alwaysSelectFullNamespace option is true and the value isn't set for a result defined in underlying configurations and in same time, its upper package configuration have no or wildcard namespace. Or, using URL tag which doesn't have value and action set and in same time, its upper package configuration have no or wildcard namespace. | Nov 3, 2021 | KEV |
| CVE-2021-30858 | High | AppleiOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Nov 3, 2021 | KEV |
| CVE-2019-6223 | High | AppleiOS and macOS | Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction. | Nov 3, 2021 | KEV |
| CVE-2021-30860 | High | AppleMultiple Products | Apple iOS, iPadOS, macOS, and watchOS CoreGraphics contain an integer overflow vulnerability which may allow code execution when processing a maliciously crafted PDF. The vulnerability is also known under the moniker of FORCEDENTRY. | Nov 3, 2021 | KEV |
| CVE-2020-27930 | High | AppleMultiple Products | Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front. | Nov 3, 2021 | KEV |
| CVE-2021-30807 | High | AppleMultiple Products | Apple iOS, iPadOS, macOS, and watchOS IOMobileFrameBuffer contain a memory corruption vulnerability which may allow an application to execute code with kernel privileges. | Nov 3, 2021 | KEV |
| CVE-2020-27950 | High | AppleMultiple Products | Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory. | Nov 3, 2021 | KEV |
| CVE-2020-27932 | High | AppleMultiple Products | Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges. | Nov 3, 2021 | KEV |
| CVE-2020-9818 | High | AppleiOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message. | Nov 3, 2021 | KEV |
| CVE-2020-9819 | High | AppleiOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message. | Nov 3, 2021 | KEV |
| CVE-2021-30762 | High | AppleiOS | Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Nov 3, 2021 | KEV |
| CVE-2021-1870 | High | AppleiOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Nov 3, 2021 | KEV |
| CVE-2021-1871 | High | AppleiOS, iPadOS, and macOS | Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Nov 3, 2021 | KEV |
| CVE-2021-1879 | High | AppleiOS, iPadOS, and watchOS | Apple iOS, iPadOS, and watchOS WebKit contain an unspecified vulnerability that allows for universal cross-site scripting (XSS) when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Nov 3, 2021 | KEV |
| CVE-2021-30661 | High | AppleMultiple Products | Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Nov 3, 2021 | KEV |
| CVE-2021-30666 | High | AppleiOS | Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. | Nov 3, 2021 | KEV |
| CVE-2021-30713 | High | ApplemacOS | Apple macOS Transparency, Consent, and Control (TCC) contains an unspecified permissions issue which may allow a malicious application to bypass privacy preferences. | Nov 3, 2021 | KEV |
| CVE-2021-30657 | High | ApplemacOS | Apple macOS contains an unspecified logic issue in System Preferences that may allow a malicious application to bypass Gatekeeper checks. | Nov 3, 2021 | KEV |