Technology · Apple
Apple Multiple Products vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 75 vulnerabilities in Apple Multiple Products: 0 in the last 7 days and 0 in the last 90 days, 75 of them critical and 75 exploited in the wild. The most recent, CVE-2025-43510, was published on 20 March 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 75
- Exploited in the wild
- 75
About Apple Multiple Products
A collection of various hardware and software offerings developed by Apple.
Latest Apple Multiple Products vulnerabilities
- CVE-2025-43510: Apple Multiple Products improper locking in shared memorycriticalexploited in the wildCVSS 7.8EPSS 0.3%
- CVE-2025-43520: Apple Multiple Products classic buffer overflow in kernel memorycriticalexploited in the wildCVSS 5.5EPSS 0.3%
- CVE-2021-22681: Rockwell Automation Logix Designer authentication bypass in Logix Controllerscriticalexploited in the wildCVSS 9.8EPSS 18.2%
- CVE-2021-30952: Apple Multiple Products integer overflow in WebKit content processingcriticalexploited in the wildCVSS 8.8EPSS 0.9%
- CVE-2017-7921: Hikvision IP Cameras improper authenticationcriticalexploited in the wildCVSS 9.8EPSS 94.2%
- CVE-2026-20700: Apple Multiple Operating Systems Buffer Overflowcriticalexploited in the wildCVSS 7.8EPSS 0.4%
- CVE-2026-24858: Fortinet Multiple Products authentication bypass in FortiCloud SSOcriticalexploited in the wildCVSS 9.8EPSS 4.8%
- CVE-2025-20393: Cisco Secure Email Gateway command injection in Spam Quarantinecriticalexploited in the wildCVSS 10EPSS 5.0%
- CVE-2025-43529: Apple WebKit use-after-free in multiple productscriticalexploited in the wildCVSS 8.8EPSS 0.2%
- CVE-2025-59718: Fortinet Multiple Products auth bypass via improper SAML signature verificationcriticalexploited in the wildCVSS 9.8EPSS 9.5%
- CVE-2023-43000: A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6…criticalexploited in the wildCVSS 8.8EPSS 3.9%
- CVE-2022-48503: Apple Multiple Products code execution in JavaScriptCorecriticalexploited in the wildCVSS 8.8EPSS 0.2%
- CVE-2010-3765: Mozilla Multiple Products memory corruption in nsCSSFrameConstructorcriticalexploited in the wildCVSS 9.8EPSS 86.6%
- CVE-2025-53690: Sitecore Multiple Products deserialization of untrusted datacriticalexploited in the wildCVSS 9EPSS 6.8%
- CVE-2025-31277: Apple Multiple Products memory corruption in web content processingcriticalexploited in the wildCVSS 8.8EPSS 1.5%
- CVE-2025-43200: Apple Multiple Products logic issue in iCloud Link media processingcriticalexploited in the wildCVSS 4.2EPSS 0.9%
- CVE-2025-32756: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-31200: Apple Multiple Products Memory Corruption Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-31201: Apple Multiple Products Arbitrary Read and Write Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-24201: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2025-24085: Apple Multiple Products Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2024-55956: Cleo Multiple Products Unauthenticated File Upload Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-50623: Cleo Multiple Products Unrestricted File Upload Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-44309: Apple Multiple Products Cross-Site Scripting (XSS) Vulnerabilitycriticalexploited in the wildCVSS 6.3
- CVE-2024-44308: Apple Multiple Products Code Execution Vulnerabilitycriticalexploited in the wildCVSS 8.8
Most severe Apple Multiple Products vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-20393: Cisco Secure Email Gateway command injection in Spam Quarantinecriticalexploited in the wildCVSS 10EPSS 5.0%
- CVE-2025-24201: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2025-24085: Apple Multiple Products Use-After-Free Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2022-22536: SAP Multiple Products HTTP Request Smuggling Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2017-7921: Hikvision IP Cameras improper authenticationcriticalexploited in the wildCVSS 9.8EPSS 94.2%
- CVE-2010-3765: Mozilla Multiple Products memory corruption in nsCSSFrameConstructorcriticalexploited in the wildCVSS 9.8EPSS 86.6%
- CVE-2021-22681: Rockwell Automation Logix Designer authentication bypass in Logix Controllerscriticalexploited in the wildCVSS 9.8EPSS 18.2%
- CVE-2025-59718: Fortinet Multiple Products auth bypass via improper SAML signature verificationcriticalexploited in the wildCVSS 9.8EPSS 9.5%
- CVE-2026-24858: Fortinet Multiple Products authentication bypass in FortiCloud SSOcriticalexploited in the wildCVSS 9.8EPSS 4.8%
- CVE-2025-32756: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/multiple-products.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Apple Multiple Products vulnerabilities", https://junglewise.ai/threats/technologies/multiple-products, 26 September 2026.