Vulnerabilities
Tracked app vulnerabilities
16,427 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,427
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-27
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2021-0307
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0306
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0304
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0303
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0301
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11262
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11261
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11260
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11250
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11241
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11240
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11239
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11238
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11235
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11233
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11182
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11181
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11159
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11134
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11126
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-10732
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0471
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-9376
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-6328
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-6159
MEDIUM 6.1
1 app
URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain ci… |
|
CVE-2020-0500
MEDIUM 5.5
In startInputUncheckedLocked of InputMethodManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local informa… |
|
CVE-2020-17153
MEDIUM 4.3
1 app
Microsoft Edge for Android Spoofing Vulnerability |
|
CVE-2020-26970
HIGH 8.8
1 app
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on p… |
|
CVE-2020-26968
HIGH 8.8
1 app
Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presu… |
|
CVE-2020-26966
MEDIUM 6.5
1 app
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; res… |
|
CVE-2020-26965
MEDIUM 6.5
1 app
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when… |
|
CVE-2020-26961
MEDIUM 6.5
1 app
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver.… |
|
CVE-2020-26960
HIGH 8.8
1 app
If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free… |
|
CVE-2020-26959
HIGH 8.8
1 app
During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potent… |
|
CVE-2020-26958
MEDIUM 6.1
1 app
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a… |
|
CVE-2020-26956
MEDIUM 6.1
1 app
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox … |
|
CVE-2020-26953
MEDIUM 4.3
1 app
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or other… |
|
CVE-2020-26951
MEDIUM 6.1
1 app
A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of expl… |
|
CVE-2020-26950
HIGH 8.8
1 app
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerab… |
|
CVE-2020-27895
LOW 3.3
1 app
An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTune… |
|
CVE-2020-9999
HIGH 7.8
1 app
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iTunes for Windows 12.10.9. Processing a m… |
|
CVE-2020-29661
HIGH 7.8
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSP… |
|
CVE-2020-29660
MEDIUM 4.4
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may al… |
|
CVE-2020-17140
HIGH 8.1
Windows SMB Information Disclosure Vulnerability |
|
CVE-2020-17139
HIGH 7.8
Windows Overlay Filter Security Feature Bypass Vulnerability |
|
CVE-2020-17138
HIGH 5.5
Windows Error Reporting Information Disclosure Vulnerability |
|
CVE-2020-17137
HIGH 7.8
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-17136
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2020-17134
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2020-17103
HIGH 7.0
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |