Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

554 CVEs affect a tracked app or OS (Medium, Android). 4 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
554
Actively exploited
4
Publication window
2016-05-09 → 2026-09-08

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

554 entries Medium Android Clear all
CVE
CVE-2024-43859
MEDIUM · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-62224
MEDIUM 5.5

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network.

CVE-2025-48600
MEDIUM 5.5

In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information disclosur…

CVE-2025-20755
MEDIUM 5.3

In Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue…

CVE-2025-60722
MEDIUM 6.5

Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over…

CVE-2025-47967
MEDIUM 4.7

Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-56139
MEDIUM 5.3

LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original …

CVE-2025-49755
MEDIUM 4.3

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-49736
MEDIUM 4.3

The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

CVE-2024-50302
MEDIUM · vendor KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-21259
MEDIUM 5.3

Microsoft Outlook Spoofing Vulnerability

CVE-2025-21253
MEDIUM 5.3

Microsoft Edge for IOS and Android Spoofing Vulnerability

CVE-2024-43604
MEDIUM 5.7

Outlook for Android Elevation of Privilege Vulnerability

CVE-2024-39891
MEDIUM 5.3 KEV

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-numb…

CVE-2024-34130
MEDIUM 5.5

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature …

CVE-2024-26196
MEDIUM 4.3

Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability

CVE-2024-26167
MEDIUM 4.3

Microsoft Edge for Android Spoofing Vulnerability

CVE-2024-26188
MEDIUM 4.3

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2024-24699
MEDIUM 6.5

Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

CVE-2024-24698
MEDIUM 4.9

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

CVE-2024-24690
MEDIUM 5.4

Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-49646
MEDIUM 6.4

Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-43583
MEDIUM 4.9

Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user …

CVE-2023-45866
MEDIUM · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-43582
MEDIUM 5.5

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

CVE-2023-39205
MEDIUM 4.3

Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-39204
MEDIUM 4.3

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-39199
MEDIUM 4.9

Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

CVE-2023-36029
MEDIUM 4.3

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2022-20917
MEDIUM 4.3

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attack…

CVE-2023-39218
MEDIUM 6.1

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

CVE-2023-36532
MEDIUM 5.9

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-26083
MEDIUM · vendor KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-25012
MEDIUM · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2022-42703
MEDIUM · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-36539
MEDIUM 5.3

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-28599
MEDIUM 4.3

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi…

CVE-2023-21116
MEDIUM · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-28284
MEDIUM 4.3

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVE-2023-20950
MEDIUM · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-24923
MEDIUM 5.5

Microsoft OneDrive for Android Information Disclosure Vulnerability

CVE-2021-29647
MEDIUM · vendor

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2021-33655
MEDIUM · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-21721
MEDIUM 6.5

Microsoft OneNote Elevation of Privilege Vulnerability

CVE-2022-39842
MEDIUM · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2022-36928
MEDIUM 6.1

Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to …

CVE-2022-42721
MEDIUM · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2018-16135
MEDIUM 6.5

The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.

CVE-2022-24480
MEDIUM 6.3

Outlook for Android Elevation of Privilege Vulnerability

CVE-2022-43363
MEDIUM 6.1

Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relati…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM