Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2026-41253
In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a maliciou…
Iterm2
after 3.6.9
CRITICAL 9.3
CVE-2025-22275
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tm…
Iterm2
3.5.11+
CRITICAL 9.8
CVE-2024-38396
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in…
Iterm2
3.5.2+
CRITICAL 9.8
CVE-2024-38395
In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivial…
Iterm2
3.5.2+
CRITICAL 9.8
CVE-2023-46321
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man…
Iterm2
after 3.4.21
CRITICAL 9.8
CVE-2023-46322
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric…
Iterm2
after 3.4.21
CRITICAL 9.8
CVE-2023-46300
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.
Iterm2
3.4.20+
CRITICAL 9.8
CVE-2023-46301
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.
Iterm2
3.4.20+
CRITICAL 9.8
CVE-2022-45872
iTerm2 before 3.4.18 mishandles a DECRQSS response.
Iterm2
3.4.18+
HIGH 7.5
CVE-2019-19022
iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allo…
Iterm2
after 3.3.6
CRITICAL 9.8
CVE-2019-9535
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by provi…
Iterm2
after 3.3.5
HIGH 7.5
CVE-2015-9231
iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries. A new (default) feature was added to iTerm2 version 3.0…
Iterm2
Patch available