Vulnerabilities
Tracked app vulnerabilities
11,272 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,272
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-20141
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-0037
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-40139
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-40138
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-40137
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-40136
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-40135
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-40134
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-40133
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-40122
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-24177
HIGH 7.5
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, ma… |
|
CVE-2025-24176
HIGH 7.1
A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attac… |
|
CVE-2025-24174
HIGH 7.7
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to bypas… |
|
CVE-2025-24169
HIGH 7.5
A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be able to bypass brows… |
|
CVE-2025-24159
HIGH 7.8
A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, … |
|
CVE-2025-24156
HIGH 7.8
An integer overflow was addressed through improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An a… |
|
CVE-2025-24150
HIGH 8.8
A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL … |
|
CVE-2025-24137
HIGH 8.0
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.… |
|
CVE-2025-24135
HIGH 7.8
This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able to gain elevated privileges. |
|
CVE-2025-24129
HIGH 7.5
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Vent… |
|
CVE-2025-24126
HIGH 7.3
An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 1… |
|
CVE-2025-24120
HIGH 7.5
This issue was addressed by improved management of object lifetimes. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An a… |
|
CVE-2025-24118
HIGH 7.1
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to cau… |
|
CVE-2025-24107
HIGH 7.8
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, watchOS 11.3. A… |
|
CVE-2024-54557
HIGH 7.5
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An attacker may g… |
|
CVE-2024-54543
HIGH 8.8
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18… |
|
CVE-2024-54537
HIGH 8.2
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may b… |
|
CVE-2024-54522
HIGH 7.8
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may b… |
|
CVE-2024-54517
HIGH 7.8
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may b… |
|
CVE-2024-54509
HIGH 7.8
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Sonoma 14.7.3.… |
|
CVE-2024-54499
HIGH 8.8
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS … |
|
CVE-2024-54468
HIGH 8.2
The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ve… |
|
CVE-2025-0411
HIGH 7.0
KEV
1 app
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installat… |
|
CVE-2024-40771
HIGH 7.8
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, ma… |
|
CVE-2024-27856
HIGH 7.8
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tv… |
|
CVE-2025-21338
HIGH 7.8
2 apps
GDI+ Remote Code Execution Vulnerability |
|
CVE-2025-21417
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21413
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21411
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21409
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21389
HIGH 7.5
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability |
|
CVE-2025-21382
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-21378
HIGH 7.8
Windows CSC Service Elevation of Privilege Vulnerability |
|
CVE-2025-21374
HIGH 5.5
Windows CSC Service Information Disclosure Vulnerability |
|
CVE-2025-21372
HIGH 7.8
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-21370
HIGH 7.8
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability |
|
CVE-2025-21343
HIGH 7.5
Windows Web Threat Defense User Service Information Disclosure Vulnerability |
|
CVE-2025-21341
HIGH 6.6
Windows Digital Media Elevation of Privilege Vulnerability |
|
CVE-2025-21340
HIGH 5.5
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
|
CVE-2025-21339
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |