Vulnerabilities
Tracked app vulnerabilities
11,275 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,275
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-20658
HIGH 7.8
A package validation issue was addressed by blocking the vulnerable package. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privilege… |
|
CVE-2026-20652
HIGH 7.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe … |
|
CVE-2026-20650
HIGH 7.5
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, … |
|
CVE-2026-20649
HIGH 7.5
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3. A user … |
|
CVE-2026-20641
HIGH 7.1
A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS … |
|
CVE-2026-20628
HIGH 7.1
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15… |
|
CVE-2026-20626
HIGH 7.8
This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3. A malici… |
|
CVE-2026-20620
HIGH 7.7
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. A… |
|
CVE-2026-20617
HIGH 7.0
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS … |
|
CVE-2026-20616
HIGH 8.8
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe… |
|
CVE-2026-20615
HIGH 7.8
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS… |
|
CVE-2026-20614
HIGH 7.8
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be… |
|
CVE-2026-20611
HIGH 7.8
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS… |
|
CVE-2026-20610
HIGH 7.8
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges. |
|
CVE-2026-20606
HIGH 7.1
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, … |
|
CVE-2025-46290
HIGH 7.5
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS So… |
|
CVE-2026-1837
HIGH 7.5
A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized un… |
|
CVE-2026-20846
HIGH 7.5
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-21533
HIGH 7.8
KEV
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
|
CVE-2026-21519
HIGH 7.8
KEV
Desktop Window Manager Elevation of Privilege Vulnerability |
|
CVE-2026-21513
HIGH 8.8
KEV
MSHTML Framework Security Feature Bypass Vulnerability |
|
CVE-2026-21510
HIGH 8.8
KEV
Windows Shell Security Feature Bypass Vulnerability |
|
CVE-2026-21508
HIGH 7.0
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2026-21255
HIGH 8.8
Windows Hyper-V Security Feature Bypass Vulnerability |
|
CVE-2026-21253
HIGH 7.0
Mailslot File System Elevation of Privilege Vulnerability |
|
CVE-2026-21251
HIGH 7.8
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability |
|
CVE-2026-21250
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21249
HIGH 3.3
Windows NTLM Spoofing Vulnerability |
|
CVE-2026-21248
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21247
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21246
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-21245
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21244
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21243
HIGH 7.5
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2026-21242
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21241
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21240
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21239
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21238
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21237
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21236
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21235
HIGH 7.3
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-21234
HIGH 7.0
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2026-21232
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21231
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21222
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-2804
HIGH 6.5
Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo |
|
CVE-2025-11002
HIGH 7.8
1 app
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… |
|
CVE-2024-44238
HIGH 7.8
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to corrupt coproce… |
|
CVE-2026-21221
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz… |