Vulnerabilities
Tracked app vulnerabilities
15,667 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,667
- Actively exploited
- 286
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-21380
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21378
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21376
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21375
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21374
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21373
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21372
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21367
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21353
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21352
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20450
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20449
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20448
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20447
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20435
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20433
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47403
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47401
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47400
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47392
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47384
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-9078
MEDIUM 5.4
1 app
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RT… |
|
CVE-2026-45585
MEDIUM 6.8
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerabi… |
|
CVE-2026-8706
MEDIUM 6.5
1 app
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receiv… |
|
CVE-2026-8975
HIGH 8.8
1 app
Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume th… |
|
CVE-2026-8974
HIGH 8.8
1 app
Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effor… |
|
CVE-2026-8973
HIGH 8.8
1 app
Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h… |
|
CVE-2026-8972
HIGH 8.8
1 app
Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8971
MEDIUM 6.5
1 app
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8970
HIGH 8.8
1 app
Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8969
HIGH 8.1
1 app
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8968
HIGH 7.5
1 app
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird… |
|
CVE-2026-8967
HIGH 7.5
1 app
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8966
HIGH 7.5
1 app
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8965
HIGH 7.5
1 app
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8964
HIGH 7.5
1 app
Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8963
HIGH 7.5
1 app
Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8962
HIGH 8.1
1 app
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8961
MEDIUM 6.5
1 app
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8960
HIGH 7.5
1 app
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8959
HIGH 9.6
1 app
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbir… |
|
CVE-2026-8958
HIGH 8.6
1 app
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderb… |
|
CVE-2026-8957
HIGH 8.8
1 app
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 14… |
|
CVE-2026-8956
HIGH 9.8
1 app
Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8955
HIGH 8.8
1 app
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8954
HIGH 7.5
1 app
Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151,… |
|
CVE-2026-8953
HIGH 9.6
1 app
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.… |
|
CVE-2026-8952
HIGH 8.8
1 app
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8950
HIGH 9.3
1 app
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird … |
|
CVE-2026-8949
HIGH 7.5
1 app
Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |