Vulnerabilities
Tracked app vulnerabilities
6,086 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-20449
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20448
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20447
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20435
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20433
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47403
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47401
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47400
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47392
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47384
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-41615
CRITICAL 9.6
Network 2 apps
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-42832
HIGH 7.7
Local 2 apps
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. |
|
CVE-2026-42831
CRITICAL 7.8
Local 1 apps
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-41102
HIGH 7.1
Local 1 apps
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. |
|
CVE-2026-41101
HIGH 7.1
Local 1 apps
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. |
|
CVE-2026-40363
CRITICAL 8.4
Local 1 apps
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-35429
MEDIUM 4.3
Network 1 apps
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a net… |
|
CVE-2025-71256
HIGH 7.5
Network
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. |
|
CVE-2025-71255
HIGH 7.5
Network
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. |
|
CVE-2025-71254
HIGH 7.5
Network
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. |
|
CVE-2025-71253
HIGH 7.5
Network
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. |
|
CVE-2025-71252
HIGH 7.5
Network
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. |
|
CVE-2025-71251
HIGH 7.5
Network
In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges … |
|
CVE-2026-23866
MEDIUM 4.3
Network 2 apps
Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26… |
|
CVE-2026-22167
HIGH 7.8
Local
Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under ce… |
|
CVE-2026-0073
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-6358
HIGH 8.8
Network 1 apps
Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML p… |
|
CVE-2026-6319
HIGH 7.5
Network 1 apps
Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures… |
|
CVE-2026-6315
HIGH 8.8
Network 1 apps
Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestu… |
|
CVE-2026-33119
MEDIUM 5.4
Network 1 apps
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a net… |
|
CVE-2026-20432
HIGH 8.0
Adjacent network
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a … |
|
CVE-2026-20431
MEDIUM 6.5
Adjacent network
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station con… |
|
CVE-2026-0049
MEDIUM 6.2
Local
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of … |
|
CVE-2025-48651
MEDIUM 5.5
Local
In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead … |
|
CVE-2025-64505
MEDIUM 6.1
[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination |
|
CVE-2026-26133
HIGH 7.1
Network 13 apps
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-26123
MEDIUM 5.5
Local 2 apps
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-26134
HIGH 7.8
Local 1 apps
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-26110
CRITICAL 8.4
Local 1 apps
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-25180
HIGH 5.5
Local 1 apps
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-24285
HIGH 7.0
Local 1 apps
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-3537
HIGH 8.8
Network 1 apps
Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a cr… |
|
CVE-2026-0011
HIGH 8.4
Local
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead t… |
|
CVE-2026-0010
HIGH 8.4
Local
In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privileg… |
|
CVE-2026-21385
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20434
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20428
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20427
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20426
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20425
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |