Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

6,086 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-20449
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20448
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20447
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20435
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20433
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47403
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47401
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47400
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47392
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47384
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-41615
CRITICAL 9.6 Network 2 apps

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

CVE-2026-42832
HIGH 7.7 Local 2 apps

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

CVE-2026-42831
CRITICAL 7.8 Local 1 apps

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-41102
HIGH 7.1 Local 1 apps

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

CVE-2026-41101
HIGH 7.1 Local 1 apps

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

CVE-2026-40363
CRITICAL 8.4 Local 1 apps

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-35429
MEDIUM 4.3 Network 1 apps

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a net…

CVE-2025-71256
HIGH 7.5 Network

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

CVE-2025-71255
HIGH 7.5 Network

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

CVE-2025-71254
HIGH 7.5 Network

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

CVE-2025-71253
HIGH 7.5 Network

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

CVE-2025-71252
HIGH 7.5 Network

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

CVE-2025-71251
HIGH 7.5 Network

In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges …

CVE-2026-23866
MEDIUM 4.3 Network 2 apps

Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26…

CVE-2026-22167
HIGH 7.8 Local

Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under ce…

CVE-2026-0073
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-6358
HIGH 8.8 Network 1 apps

Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML p…

CVE-2026-6319
HIGH 7.5 Network 1 apps

Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures…

CVE-2026-6315
HIGH 8.8 Network 1 apps

Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestu…

CVE-2026-33119
MEDIUM 5.4 Network 1 apps

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a net…

CVE-2026-20432
HIGH 8.0 Adjacent network

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a …

CVE-2026-20431
MEDIUM 6.5 Adjacent network

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station con…

CVE-2026-0049
MEDIUM 6.2 Local

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of …

CVE-2025-48651
MEDIUM 5.5 Local

In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead …

CVE-2025-64505
MEDIUM 6.1

[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination

CVE-2026-26133
HIGH 7.1 Network 13 apps

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-26123
MEDIUM 5.5 Local 2 apps

Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.

CVE-2026-26134
HIGH 7.8 Local 1 apps

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

CVE-2026-26110
CRITICAL 8.4 Local 1 apps

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-25180
HIGH 5.5 Local 1 apps

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

CVE-2026-24285
HIGH 7.0 Local 1 apps

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-3537
HIGH 8.8 Network 1 apps

Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a cr…

CVE-2026-0011
HIGH 8.4 Local

In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead t…

CVE-2026-0010
HIGH 8.4 Local

In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privileg…

CVE-2026-21385
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20434
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20428
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20427
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20426
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20425
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.