Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

11,272 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
11,272
Actively exploited
229
Publication window
2010-07-30 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

11,272 entries High Hide N/A Clear all
CVE
CVE-2025-43221
HIGH 7.1

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visi…

CVE-2025-43196
HIGH 7.8

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may …

CVE-2025-43188
HIGH 7.8

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root privileges.

CVE-2025-31280
HIGH 7.8

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted file may lead to …

CVE-2025-31278
HIGH 8.8

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18…

CVE-2025-31277
HIGH 8.8 KEV

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.…

CVE-2025-31273
HIGH 8.8

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.…

CVE-2025-31243
HIGH 7.8

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app ma…

CVE-2025-24224
HIGH 7.5

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.9, macOS Sequoia 15.5, macOS Ventura 13.7.7, tvOS 18…

CVE-2025-24119
HIGH 7.8

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be…

CVE-2025-8040
HIGH 8.8 1 app

Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruptio…

CVE-2025-8039
HIGH 8.1 1 app

In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Firefox ESR 1…

CVE-2025-8036
HIGH 8.1 1 app

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Fire…

CVE-2025-8035
HIGH 8.8 1 app

Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of th…

CVE-2025-8034
HIGH 8.8 1 app

Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunder…

CVE-2025-8032
HIGH 8.1 1 app

XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, …

CVE-2025-8030
HIGH 8.1 1 app

Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in F…

CVE-2025-8029
HIGH 8.1 1 app

Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 14…

CVE-2025-38352
HIGH 7.8 KEV

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If…

CVE-2025-38349
HIGH 7.8

In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still holding the ep mutex Jann Horn points …

CVE-2025-53817
HIGH 7.5 1 app

7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to version 25.0.0, a null pointer dereference …

CVE-2025-53816
HIGH 7.5 1 app

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service …

CVE-2025-6558
HIGH 8.8 KEV

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox…

CVE-2025-6965
HIGH 7.7

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead…

CVE-2025-7425
HIGH 7.8

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as…

CVE-2025-7424
HIGH 7.5

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML t…

CVE-2025-48384
HIGH 8.0 KEV 1 app

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to int…

CVE-2025-38236
HIGH 7.8

In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs. Jann Horn reported a use-after-free i…

CVE-2025-49753
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49744
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-49742
HIGH 7.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-49740
HIGH 8.8

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2025-49733
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2025-49732
HIGH 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-49730
HIGH 7.8

Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability

CVE-2025-49729
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49727
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2025-49726
HIGH 7.8

Windows Notification Elevation of Privilege Vulnerability

CVE-2025-49725
HIGH 7.8

Windows Notification Elevation of Privilege Vulnerability

CVE-2025-49724
HIGH 8.8

Windows Connected Devices Platform Service Remote Code Execution Vulnerability

CVE-2025-49723
HIGH 8.8

Windows StateRepository API Server file Tampering Vulnerability

CVE-2025-49722
HIGH 5.7

Windows Print Spooler Denial of Service Vulnerability

CVE-2025-49721
HIGH 7.8

Windows Fast FAT File System Driver Elevation of Privilege Vulnerability

CVE-2025-49716
HIGH 7.5

Windows Netlogon Denial of Service Vulnerability

CVE-2025-49694
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-49693
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-49691
HIGH 8.0

Windows Miracast Wireless Display Remote Code Execution Vulnerability

CVE-2025-49690
HIGH 7.4

Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

CVE-2025-49689
HIGH 7.8

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-49688
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability