Vulnerabilities
Tracked app vulnerabilities
1,821 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-21450
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-43300
CRITICAL 10.0
KEV
Network
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, … |
|
CVE-2025-9187
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-9179
CRITICAL 9.8
Network 1 apps
An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents sl… |
|
CVE-2025-53766
CRITICAL 9.8
Network 1 apps
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-53778
CRITICAL 8.8
Windows NTLM Elevation of Privilege Vulnerability |
|
CVE-2025-50177
CRITICAL 8.1
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2025-50176
CRITICAL 7.8
DirectX Graphics Kernel Remote Code Execution Vulnerability |
|
CVE-2025-50165
CRITICAL 9.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2025-48807
CRITICAL 6.7
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2025-48530
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-21479
CRITICAL
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-43275
CRITICAL 9.8
Network
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be … |
|
CVE-2025-43273
CRITICAL 9.1
Network
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.8. A sandboxed process may b… |
|
CVE-2025-43261
CRITICAL 9.8
Network
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to b… |
|
CVE-2025-43253
CRITICAL 9.8
Network
This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able to launch … |
|
CVE-2025-43245
CRITICAL 9.8
Network
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7… |
|
CVE-2025-43244
CRITICAL 9.8
Network
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may b… |
|
CVE-2025-43243
CRITICAL 9.8
Network
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app ma… |
|
CVE-2025-43237
CRITICAL 9.8
Network
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause unexpected sys… |
|
CVE-2025-43234
CRITICAL 9.8
Network
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6… |
|
CVE-2025-43233
CRITICAL 9.8
Network
This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A malicious a… |
|
CVE-2025-43232
CRITICAL 9.8
Network
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app ma… |
|
CVE-2025-43222
CRITICAL 9.8
Network
A use-after-free issue was addressed by removing the vulnerable code. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Vent… |
|
CVE-2025-43220
CRITICAL 9.8
Network
This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.… |
|
CVE-2025-43209
CRITICAL 9.8
Network
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, … |
|
CVE-2025-43199
CRITICAL 9.8
Network
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A mali… |
|
CVE-2025-43198
CRITICAL 9.8
Network
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to access protecte… |
|
CVE-2025-43194
CRITICAL 9.8
Network
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modif… |
|
CVE-2025-43193
CRITICAL 9.8
Network
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able… |
|
CVE-2025-43192
CRITICAL 9.8
Network
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. Account-driven User Enrollmen… |
|
CVE-2025-43189
CRITICAL 9.8
Network
This issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able to read ker… |
|
CVE-2025-43186
CRITICAL 9.8
Network
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura … |
|
CVE-2025-43184
CRITICAL 9.8
Network
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.… |
|
CVE-2025-31281
CRITICAL 9.1
Network
An input validation issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS… |
|
CVE-2025-31279
CRITICAL 9.8
Network
A permissions issue was addressed with additional restrictions. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13… |
|
CVE-2025-31229
CRITICAL 9.1
Network
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read aloud by VoiceOver. |
|
CVE-2025-8044
CRITICAL 9.8
Network 1 apps
Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-8043
CRITICAL 9.8
Network 1 apps
Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141. |
|
CVE-2025-8038
CRITICAL 9.8
Network 1 apps
Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141… |
|
CVE-2025-8037
CRITICAL 9.1
Network 1 apps
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie includ… |
|
CVE-2025-8031
CRITICAL 9.8
Network 1 apps
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability … |
|
CVE-2025-8028
CRITICAL 9.8
Network 1 apps
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect compu… |
|
CVE-2025-49702
CRITICAL 7.8
Local 1 apps
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-49697
CRITICAL 8.4
Local 1 apps
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-49696
CRITICAL 8.4
Local 1 apps
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-49695
CRITICAL 8.4
Local 1 apps
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-49735
CRITICAL 8.1
Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability |
|
CVE-2025-48822
CRITICAL 8.6
Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability |
|
CVE-2025-47981
CRITICAL 9.8
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability |