Vulnerabilities
Tracked app vulnerabilities
2,273 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-48101
MEDIUM 6.5
Network 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI cap… |
|
CVE-2026-48092
MEDIUM 4.3
Network 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain a heap memory disclosure via SquashFS fragment offset integer overf… |
|
CVE-2026-28581
MEDIUM 4.0
Local
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lea… |
|
CVE-2026-28578
MEDIUM 5.5
Local
In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to loca… |
|
CVE-2026-0086
MEDIUM 6.8
Local
In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalati… |
|
CVE-2026-0085
MEDIUM 5.5
Local
In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to … |
|
CVE-2026-0080
MEDIUM 6.5
Network
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s… |
|
CVE-2026-0079
MEDIUM 5.5
Local
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local deni… |
|
CVE-2026-0075
MEDIUM 5.9
Local
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no… |
|
CVE-2026-0074
MEDIUM 5.5
Local
In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of s… |
|
CVE-2026-0070
MEDIUM 5.5
Local
In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This coul… |
|
CVE-2026-0069
MEDIUM 5.5
Local
In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with n… |
|
CVE-2026-0067
MEDIUM 5.5
Local
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This coul… |
|
CVE-2026-0061
MEDIUM 5.9
Local
In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could l… |
|
CVE-2026-0060
MEDIUM 5.5
Local
In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lea… |
|
CVE-2026-0055
MEDIUM 6.2
Local
In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a pat… |
|
CVE-2026-0052
MEDIUM 6.5
Network
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s… |
|
CVE-2026-0051
MEDIUM 6.5
Network
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remot… |
|
CVE-2026-0048
MEDIUM 6.8
Local
In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local … |
|
CVE-2026-0046
MEDIUM 6.2
Local
In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead … |
|
CVE-2026-0044
MEDIUM 6.5
Network
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to remote… |
|
CVE-2026-0043
MEDIUM 5.5
Local
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local esca… |
|
CVE-2026-0042
MEDIUM 5.5
Local
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local deni… |
|
CVE-2026-0041
MEDIUM 6.5
Network
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service … |
|
CVE-2026-0040
MEDIUM 6.5
Network
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s… |
|
CVE-2026-0039
MEDIUM 6.5
Network
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote den… |
|
CVE-2026-0018
MEDIUM 5.5
Local
In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead t… |
|
CVE-2025-48648
MEDIUM 5.5
Local
In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with… |
|
CVE-2026-9309
MEDIUM 5.4
Network 1 apps
Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and l… |
|
CVE-2026-9308
MEDIUM 5.4
Network 1 apps
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placehold… |
|
CVE-2026-20454
MEDIUM 6.4
Local
In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has alread… |
|
CVE-2026-20453
MEDIUM 6.7
Local
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has … |
|
CVE-2026-9078
MEDIUM 5.4
Network 1 apps
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RT… |
|
CVE-2026-45585
MEDIUM 6.8
Physical
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerabi… |
|
CVE-2026-8706
MEDIUM 6.5
Adjacent network 1 apps
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receiv… |
|
CVE-2026-8971
MEDIUM 6.5
Network 1 apps
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8961
MEDIUM 6.5
Network 1 apps
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-35429
MEDIUM 4.3
Network 1 apps
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a net… |
|
CVE-2026-32170
MEDIUM 6.7
Local
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-43666
MEDIUM 6.2
Local
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS … |
|
CVE-2026-43659
MEDIUM 4.7
Local
A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7,… |
|
CVE-2026-43653
MEDIUM 6.2
Local
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, mac… |
|
CVE-2026-39869
MEDIUM 4.3
Network
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, mac… |
|
CVE-2026-28996
MEDIUM 5.5
Local
A race condition was addressed with additional validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Ta… |
|
CVE-2026-28994
MEDIUM 5.3
Adjacent network
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequ… |
|
CVE-2026-28993
MEDIUM 5.5
Local
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS … |
|
CVE-2026-28992
MEDIUM 4.7
Local
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Seq… |
|
CVE-2026-28988
MEDIUM 5.5
Local
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5.… |
|
CVE-2026-28985
MEDIUM 6.2
Local
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5. An attac… |
|
CVE-2026-28977
MEDIUM 6.2
Local
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS… |