Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,012 CVEs affect a tracked app or OS (all severities, macOS). 103 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,012
Actively exploited
103
Publication window
2004-07-27 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,012 entries macOS Hide N/A Clear all
CVE
CVE-2025-31275
MEDIUM 6.2

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to launch any instal…

CVE-2025-31273
HIGH 8.8

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.…

CVE-2025-31243
HIGH 7.8

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app ma…

CVE-2025-24224
HIGH 7.5

The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.9, macOS Sequoia 15.5, macOS Ventura 13.7.7, tvOS 18…

CVE-2025-24188
MEDIUM 6.5

A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. Processing maliciously crafted web content may lead t…

CVE-2025-24119
HIGH 7.8

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be…

CVE-2025-8011
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2025-8010
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2025-7657
HIGH 8.8

Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…

CVE-2025-7656
HIGH 8.8

Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro…

CVE-2025-6558
HIGH 8.8 KEV

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox…

CVE-2025-6965
HIGH 7.7

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead…

CVE-2025-49462
LOW 3.5

Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.

CVE-2025-7425
HIGH 7.8

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as…

CVE-2025-7424
HIGH 7.5

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML t…

CVE-2025-48384
HIGH 8.0 KEV

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to int…

CVE-2025-49711
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-49705
HIGH 7.8

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2025-49703
HIGH 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-49702
CRITICAL · vendor

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-49700
HIGH 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-49699
HIGH 7.0

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-49698
HIGH 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-49697
CRITICAL · vendor

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-49696
CRITICAL · vendor

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-49695
CRITICAL · vendor

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-48812
MEDIUM 5.5

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2025-6554
HIGH 8.1 KEV

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium secur…

CVE-2025-32462
LOW 2.8

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on …

CVE-2025-6557
MEDIUM 5.4

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specifi…

CVE-2025-6556
MEDIUM 5.4

Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTM…

CVE-2025-6555
MEDIUM 5.4

Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (…

CVE-2025-6192
HIGH 8.8

Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (C…

CVE-2025-6191
HIGH 8.8

Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML…

CVE-2025-43200
MEDIUM 4.2 KEV

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.…

CVE-2025-5959
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…

CVE-2025-5958
HIGH 8.8

Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2025-47953
CRITICAL · vendor

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47175
HIGH 7.8

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2025-47171
MEDIUM 6.7

Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

CVE-2025-47169
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-47168
HIGH 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-47167
CRITICAL · vendor

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47165
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-47164
CRITICAL · vendor

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47162
CRITICAL · vendor

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-5918
LOW 3.9

A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for rea…

CVE-2025-5419
HIGH 8.8 KEV

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

CVE-2025-5068
HIGH 8.8

Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro…

CVE-2025-31264
MEDIUM 4.6

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An …

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM