Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

802 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-21353
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-21352
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47392
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-41615
CRITICAL 9.6 Network 2 apps

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

CVE-2026-42831
CRITICAL 7.8 Local 1 apps

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-40363
CRITICAL 8.4 Local 1 apps

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-0073
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-26110
CRITICAL 8.4 Local 1 apps

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-0047
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-0037
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-0030
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-0028
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-0027
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-0006
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48631
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-62557
CRITICAL 8.4 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-62554
CRITICAL 8.4 Local 1 apps

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-48638
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48624
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48623
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47372
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47319
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-60724
CRITICAL 9.8 Network 1 apps

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2025-48593
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-59234
CRITICAL 7.8 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-59227
CRITICAL 7.8 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-53799
CRITICAL 5.5 Local 1 apps

Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

CVE-2025-39682
CRITICAL 9.8 Network

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process …

CVE-2025-27034
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-21483
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-21450
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-53766
CRITICAL 9.8 Network 1 apps

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CVE-2025-48530
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-21479
CRITICAL KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-49702
CRITICAL 7.8 Local 1 apps

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-49697
CRITICAL 8.4 Local 1 apps

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-49696
CRITICAL 8.4 Local 1 apps

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-49695
CRITICAL 8.4 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47953
CRITICAL 8.4 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47167
CRITICAL 8.4 Local 1 apps

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47164
CRITICAL 8.4 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47162
CRITICAL 8.4 Local 1 apps

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-30386
CRITICAL 8.4 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-26416
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-22429
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-22423
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-45551
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-22412
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-22411
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-22410
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.