Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

4,828 CVEs affect a tracked app or OS (High, Android). 39 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
4,828
Actively exploited
39
Publication window
2016-05-09 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

4,828 entries High Android Clear all
CVE
CVE-2026-28613
HIGH 7.3

In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This could lead to local esca…

CVE-2026-28612
HIGH 7.8

In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to …

CVE-2026-28611
HIGH 7.8

In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to…

CVE-2026-28609
HIGH 8.8

In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional …

CVE-2026-28607
HIGH 7.8

In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalatio…

CVE-2026-28604
HIGH 7.5

In multiple locations, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privil…

CVE-2026-28603
HIGH 7.8

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could…

CVE-2026-28602
HIGH 7.8

In setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, there is a possible mult-iuser isolation due to a logic error in the code. This coul…

CVE-2026-28600
HIGH 7.8

In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation o…

CVE-2026-28599
HIGH 7.8

In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This could lead to local esc…

CVE-2026-28594
HIGH 7.8

In multiple locations, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional…

CVE-2026-28593
HIGH 7.8

In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation …

CVE-2026-28590
HIGH 7.8

In multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escalation of privileg…

CVE-2026-28583
HIGH 7.8

In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to loca…

CVE-2026-28572
HIGH 7.8

In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no…

CVE-2026-0084
HIGH 7.8

In multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local e…

CVE-2026-0065
HIGH 7.8

In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due …

CVE-2026-80097
HIGH 8.6

Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.

CVE-2026-7477
HIGH 7.8

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows…

CVE-2026-7476
HIGH 7.8

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows…

CVE-2026-5729
HIGH 7.8

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user proces…

CVE-2026-49913
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-49744
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-49743
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-4967
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45529
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45518
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45517
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45203
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45202
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45200
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45198
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45197
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45196
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45195
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-41158
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-41156
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-34195
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-34194
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-34192
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-25288
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-25260
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-25259
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-24092
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-24091
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-24090
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-24088
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-24087
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-24084
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-24080
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM