Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
102 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.16% | — | Apple XcodeApple Macos | 14/9/2026 | 22/9/2026 | A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data. | |
| Aplazada | Media (5.5) | 2.1% | — | Polarvista Xcode-mcp-serverAI | 29/4/2026 | 17/6/2026 | A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests of the file src/index.ts of the component MCP Interface. The manipulation of the argument Request results in os command injection. The attack may be launched remotely. The exploit has been made… | |
| Analizada | Media (5.5) | 0.14% | — | Apple Xcode | 25/3/2026 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination. | |
| Analizada | Media (6.2) | 0.15% | — | Apple Xcode | 25/3/2026 | 17/6/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root. | |
| Analizada | Baja (2.1) | 3.4% | — | R-huijts Xcode MCP Server | 8/2/2026 | 17/6/2026 | A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file src/tools/xcode/index.ts of the component run_lldb. The manipulation of the argument args results in command injection. It is possible to launch the attack… | |
| Analizada | Baja (3.3) | 0.16% | — | Apple Xcode | 16/1/2026 | 17/6/2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences. | |
| Analizada | Alta (8.8) | 0.27% | — | Apple Xcode | 4/11/2025 | 17/6/2026 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to heap corruption. | |
| Analizada | Media (4.9) | 0.35% | — | Apple Xcode | 4/11/2025 | 17/6/2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service. | |
| Modificada | Media (5.5) | 0.34% | — | Apple Xcode | 15/9/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process. | |
| Modificada | Alta (8.2) | 0.20% | — | Apple Xcode | 15/9/2025 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox. | |
| Modificada | Alta (7.1) | 0.21% | — | Apple Xcode | 15/9/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox. | |
| Modificada | Media (4) | 0.34% | — | Apple Xcode | 15/9/2025 | 1/10/2026 | A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process. | |
| Analizada | Alta (8) | 4.2% | ⚠ Explotación activa | Git-scm GITDebian LinuxApple Xcode | 8/7/2025 | 24/9/2026 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are… | |
| Modificada | Media (5.5) | 0.23% | — | Apple Xcode | 31/3/2025 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files. | |
| Modificada | Media (5.5) | 0.26% | — | Apple Xcode | 31/3/2025 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information. | |
| Modificada | Alta (7.5) | 0.42% | — | Apple Xcode | 28/10/2024 | 17/6/2026 | This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data. | |
| Modificada | Media (5.5) | 0.25% | — | Apple XcodeApple IpadosApple Iphone OSApple Macos+3 | 17/9/2024 | 17/6/2026 | This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. An app may gain unauthorized access to Bluetooth. | |
| Modificada | Alta (7.8) | 0.21% | — | Apple Xcode | 17/9/2024 | 17/6/2026 | This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain items. | |
| Modificada | Media (5.3) | 0.48% | — | Apple Xcode | 17/9/2024 | 17/6/2026 | A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the owner of the computer. | |
| Modificada | Media (5.5) | 0.52% | — | Apple Xcode | 15/3/2024 | 17/6/2026 | A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks. | |
| Modificada | Media (5.5) | 0.27% | — | Apple Xcode | 27/9/2023 | 17/6/2026 | This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials. | |
| Modificada | Media (5.5) | 0.32% | — | Apple XcodeApple IpadosApple Iphone OSApple Macos+1 | 27/9/2023 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14, Xcode 15. An app may be able to disclose kernel memory. | |
| Modificada | Alta (7.8) | 0.33% | — | Apple XcodeApple IpadosApple Iphone OSApple Macos+2 | 27/9/2023 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to gain elevated privileges. | |
| Modificada | Media (5.5) | 0.21% | — | Apple Xcode | 6/9/2023 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information. | |
| Modificada | Alta (8.6) | 0.23% | — | Apple Xcode | 8/5/2023 | 17/6/2026 | The issue was addressed with improved memory handling. This issue is fixed in Xcode 14.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges. |