Xcode
Vendor:
First CVE: Dec 31, 2004 · Active for 21 years
96
Total CVEs
More Total CVEs than 99% of tracked products
5.6
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
2.1%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Xcode over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Mar 25, 2026
121 days ago
CVE Severity & Scoring
Xcode96 CVEs
38%
55%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local47 (49.0%)
Network24 (25.0%)
Unknown25 (26.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low69 (71.9%)
High2 (2.1%)
Unknown25 (26.0%)
User Interaction
None24 (25.0%)
Unknown25 (26.0%)
Required47 (49.0%)
Privileges Required
Low9 (9.4%)
High1 (1.0%)
None61 (63.5%)
Unknown25 (26.0%)
Top CVEs
Signals from CVEs in this product scope (96 CVEs).
96 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2004-2687HIGH distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, | Dec 31, 2004 | 9.3 | 91 | NO | YES |
CVE-2021-21300HIGH Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/sm | Mar 9, 2021 | 7.5 | 82 | NO | YES |
CVE-2014-9390CRITICAL Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode | Feb 12, 2020 | 9.8 | 76 | NO | YES |
CVE-2016-0742HIGH The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted | Feb 15, 2016 | 7.5 | 70 | NO | NO |
CVE-2025-48384HIGH Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading | Jul 8, 2025 | 8.0 | 66 | YES | NO |
CVE-2017-7529HIGH Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive inf | Jul 13, 2017 | 7.5 | 59 | NO | NO |
CVE-2018-16843HIGH nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with | Nov 7, 2018 | 7.5 | 50 | NO | NO |
CVE-2019-14379CRITICAL SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionM | Jul 29, 2019 | 9.8 | 35 | NO | NO |
CVE-2019-3855HIGH An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compro | Mar 21, 2019 | 8.8 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (96 CVEs).
CISA KEV
2 CVEs
2.1% of CVEs· 96th percentile
Metasploit
4 CVEs
4.2% of CVEs· 96th percentile
Nuclei
2 CVEs
2.1% of CVEs· 96th percentile
ExploitDB
2 CVEs
2.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (96 CVEs).
Media Mentions
Signals from CVEs in this product scope (96 CVEs).
Top CNAs Publishing CVEs For Xcode
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0 | 4 | 5.2 | 10.8% | 0 | 0 |
| 6.2 | 1 | 9.8 | 63.2% | 0 | 1 |
| 6.1.1 | 4 | 4.5 | 8.4% | 0 | 0 |
| 4.3.2 | 1 | 5.0 | 1.1% | 0 | 0 |
| 4.3.1 | 1 | 5.0 | 1.1% | 0 | 0 |
| 4.3 | 1 | 5.0 | 1.1% | 0 | 0 |
| 4.2.1 | 1 | 5.0 | 1.1% | 0 | 0 |
| 4.2 | 1 | 5.0 | 1.1% | 0 | 0 |
| 4.1.1 | 1 | 5.0 | 1.1% | 0 | 0 |
| 4.0.2 | 1 | 5.0 | 1.1% | 0 | 0 |
| 4.0.1 | 1 | 5.0 | 1.1% | 0 | 0 |
| 4.0 | 1 | 5.0 | 1.1% | 0 | 0 |
| 3.2.5 | 1 | 5.0 | 1.1% | 0 | 0 |
| 3.2.4 | 1 | 5.0 | 1.1% | 0 | 0 |
| 3.2.3 | 1 | 5.0 | 1.1% | 0 | 0 |
| 3.2.2 | 1 | 5.0 | 1.1% | 0 | 0 |
| 3.2.1 | 1 | 5.0 | 1.1% | 0 | 0 |
| 3.1.4 | 1 | 5.0 | 1.1% | 0 | 0 |
| 3.1.3 | 1 | 5.0 | 1.1% | 0 | 0 |
| 3.1.2 | 1 | 5.0 | 1.1% | 0 | 0 |