Vulnerabilities
Tracked app vulnerabilities
15,652 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,652
- Actively exploited
- 286
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2022-44426
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-44425
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42721
MEDIUM 5.5
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42720
HIGH 7.8
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42719
HIGH 8.8
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-41674
HIGH 8.1
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33286
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33285
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33284
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33283
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33276
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33274
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33266
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33255
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33253
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33252
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-32637
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-32636
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-32635
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-2959
HIGH 7.0
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-25746
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-25725
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-23960
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-22088
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20494
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20493
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20492
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20490
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20489
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20461
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20456
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20235
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-35134
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-35113
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-35097
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-16135
MEDIUM 6.5
1 app
The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site. |
|
CVE-2022-46882
CRITICAL 9.8
1 app
A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thun… |
|
CVE-2022-46881
HIGH 8.8
1 app
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was ad… |
|
CVE-2022-46880
MEDIUM 6.5
1 app
A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13t… |
|
CVE-2022-46878
HIGH 8.8
1 app
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of th… |
|
CVE-2022-46875
MEDIUM 6.5
1 app
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue onl… |
|
CVE-2022-46874
HIGH 8.8
1 app
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potenti… |
|
CVE-2022-46872
HIGH 8.6
1 app
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug… |
|
CVE-2022-45421
HIGH 8.8
1 app
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory … |
|
CVE-2022-45420
MEDIUM 6.5
1 app
Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user … |
|
CVE-2022-45418
MEDIUM 6.1
1 app
If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user con… |
|
CVE-2022-45416
MEDIUM 6.5
1 app
Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have… |
|
CVE-2022-45414
HIGH 8.1
1 app
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or … |
|
CVE-2022-45412
HIGH 8.8
1 app
When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing un… |
|
CVE-2022-45411
MEDIUM 6.1
1 app
Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies in… |