Macos
Vendor:
First CVE: Aug 1, 1997 · Active for 28 years
6,599
Total CVEs
More Total CVEs than 100% of tracked products
275.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Macos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 1997
28 years ago
Most Recent CVE
Jul 17, 2026
7 days ago
CVE Severity & Scoring
Macos6,599 CVEs
38%
51%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3,612 (54.7%)
Network2,718 (41.2%)
Unknown165 (2.5%)
Physical57 (0.9%)
Adjacent Network47 (0.7%)
Attack Complexity
Low6,006 (91.0%)
High428 (6.5%)
Unknown165 (2.5%)
User Interaction
None1,858 (28.2%)
Unknown165 (2.5%)
Required4,576 (69.3%)
Privileges Required
Low747 (11.3%)
High77 (1.2%)
None5,610 (85.0%)
Unknown165 (2.5%)
Top CVEs
Signals from CVEs in this product scope (6599 CVEs).
6,599 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-5122CRITICAL Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1 | Jul 14, 2015 | 9.8 | 98 | YES | YES |
CVE-2014-0497CRITICAL Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta | Feb 5, 2014 | 9.8 | 98 | YES | YES |
CVE-2010-2883HIGH Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary c | Sep 9, 2010 | 7.3 | 97 | YES | YES |
CVE-2018-4878HIGH A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media pla | Feb 6, 2018 | 7.8 | 96 | YES | YES |
CVE-2011-0609HIGH Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; a | Mar 15, 2011 | 7.8 | 95 | YES | YES |
CVE-2021-21017HIGH Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnera | Feb 11, 2021 | 8.8 | 94 | YES | NO |
CVE-2022-2294HIGH Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Jul 28, 2022 | 8.8 | 91 | YES | NO |
CVE-2021-30657MEDIUM A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekee | Sep 8, 2021 | 5.5 | 91 | YES | YES |
CVE-2021-30860HIGH An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7. | Aug 24, 2021 | 7.8 | 91 | YES | NO |
CVE-2014-0569HIGH Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adob | Oct 15, 2014 | 9.3 | 91 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (6599 CVEs).
CISA KEV
95 CVEs
1.4% of CVEs· 96th percentile
Metasploit
12 CVEs
0.2% of CVEs· 96th percentile
Nuclei
8 CVEs
0.1% of CVEs· 96th percentile
ExploitDB
49 CVEs
0.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (6599 CVEs).
Media Mentions
Signals from CVEs in this product scope (6599 CVEs).
Top CNAs Publishing CVEs For Macos
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0 | 1 | 5.0 | 1.4% | 0 | 0 |
| 9 | 2 | 4.6 | 0.4% | 0 | 0 |
| 8.6 | 2 | 4.6 | 0.7% | 0 | 1 |
| 8.5 | 2 | 4.6 | 0.7% | 0 | 1 |
| 8.1 | 1 | 4.6 | 0.8% | 0 | 1 |
| 8.0 | 1 | 4.6 | 0.8% | 0 | 1 |
| 7.6.1 | 1 | 4.6 | 0.8% | 0 | 1 |
| 7.6 | 1 | 4.6 | 0.8% | 0 | 1 |
| 7.5.3 | 1 | 4.6 | 0.8% | 0 | 1 |
| 26.0 | 5 | 6.5 | 1.6% | 2 | 0 |
| 15.0 | 7 | 5.2 | 0.3% | 0 | 0 |
| 14.1 | 1 | 7.8 | 0.6% | 0 | 0 |
| 14.0 | 30 | 6.0 | 0.4% | 0 | 0 |
| 13.4 | 1 | 5.5 | 0.3% | 0 | 0 |
| 13.3.3 | 1 | 6.3 | 7.9% | 0 | 0 |
| 13.1 | 1 | 5.3 | 1.8% | 0 | 0 |
| 13.0 | 16 | 7.4 | 1.0% | 0 | 0 |
| 12.6.7 | 1 | 6.3 | 7.9% | 0 | 0 |
| 12.0.1 | 2 | 7.2 | 1.3% | 0 | 0 |
| 12.0.0 | 10 | 6.9 | 0.8% | 0 | 0 |