Vulnerabilities
Tracked app vulnerabilities
11,275 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,275
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-55680
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-55679
HIGH 5.1
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2025-55678
HIGH 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-55677
HIGH 7.8
Windows Device Association Broker Service Elevation of Privilege Vulnerability |
|
CVE-2025-55676
HIGH 5.5
Windows USB Video Class System Driver Information Disclosure Vulnerability |
|
CVE-2025-55340
HIGH 7.0
Windows Remote Desktop Protocol Security Feature Bypass |
|
CVE-2025-55339
HIGH 7.8
Windows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege Vulnerability |
|
CVE-2025-55338
HIGH 6.1
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55337
HIGH 6.1
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55336
HIGH 5.5
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability |
|
CVE-2025-55335
HIGH 7.4
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2025-55334
HIGH 6.2
Windows Kernel Security Feature Bypass Vulnerability |
|
CVE-2025-55333
HIGH 6.1
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55332
HIGH 6.1
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55331
HIGH 7.0
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
|
CVE-2025-55330
HIGH 6.1
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55328
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-55326
HIGH 7.5
Windows Connected Devices Platform Service (Cdpsvc) Remote Code Execution Vulnerability |
|
CVE-2025-55325
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-53768
HIGH 7.8
Xbox IStorageService Elevation of Privilege Vulnerability |
|
CVE-2025-53717
HIGH 7.0
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability |
|
CVE-2025-53150
HIGH 7.8
Windows Digital Media Elevation of Privilege Vulnerability |
|
CVE-2025-53139
HIGH 7.7
Windows Hello Security Feature Bypass Vulnerability |
|
CVE-2025-50175
HIGH 7.8
Windows Digital Media Elevation of Privilege Vulnerability |
|
CVE-2025-50174
HIGH 7.0
Windows Device Association Broker Service Elevation of Privilege Vulnerability |
|
CVE-2025-50152
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-48813
HIGH 6.3
Virtual Secure Mode Spoofing Vulnerability |
|
CVE-2025-48004
HIGH 7.4
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-47979
HIGH 5.5
Microsoft Failover Cluster Information Disclosure Vulnerability |
|
CVE-2025-47827
HIGH 4.6
KEV
MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11 |
|
CVE-2025-25004
HIGH 7.3
PowerShell Elevation of Privilege Vulnerability |
|
CVE-2025-24990
HIGH 7.8
KEV
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24052
HIGH 7.8
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-10537
HIGH 8.8
1 app
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2025-10534
HIGH 8.1
1 app
Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. |
|
CVE-2025-10533
HIGH 8.8
1 app
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140… |
|
CVE-2025-10528
HIGH 7.3
1 app
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, … |
|
CVE-2025-10527
HIGH 7.1
1 app
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and … |
|
CVE-2025-43372
HIGH 7.8
The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, visionOS 26,… |
|
CVE-2025-43371
HIGH 8.2
1 app
This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox. |
|
CVE-2025-43358
HIGH 8.8
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15… |
|
CVE-2025-43341
HIGH 7.8
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to gain root privi… |
|
CVE-2025-43340
HIGH 7.8
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox. |
|
CVE-2025-43333
HIGH 7.8
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to gain root privileges. |
|
CVE-2025-43330
HIGH 8.2
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to break out of its san… |
|
CVE-2025-43329
HIGH 8.8
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be… |
|
CVE-2025-43316
HIGH 7.8
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26, visionOS 26. A malicious app may be able to gain root pr… |
|
CVE-2025-43304
HIGH 7.0
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able t… |
|
CVE-2025-43298
HIGH 7.8
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, m… |
|
CVE-2025-43287
HIGH 7.1
The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26. Processing a maliciously crafted image may corrupt process memory. |