Vulnerabilities
Tracked app vulnerabilities
6,062 CVEs affect a tracked app or OS (all severities, Android). 47 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 6,062
- Actively exploited
- 47
- Publication window
- 2015-07-23 → 2026-08-04
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2016-2466
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2465
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2464
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2463
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2066
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2062
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2061
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-0718
HIGH 9.8
1 app
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers… |
|
CVE-2016-2457
MEDIUM 5.5
server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to bypass intended res… |
|
CVE-2016-2446
HIGH 7.0
The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 2744135… |
|
CVE-2016-2842
CRITICAL 9.8
The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succee… |
|
CVE-2015-1283
LOW
1 app
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote … |