Vulnerabilities
Tracked app vulnerabilities
554 CVEs affect a tracked app or OS (Medium, Android). 4 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 554
- Actively exploited
- 4
- Publication window
- 2016-05-09 → 2026-09-08
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-43859
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-62224
MEDIUM 5.5
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. |
|
CVE-2025-48600
MEDIUM 5.5
In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information disclosur… |
|
CVE-2025-20755
MEDIUM 5.3
In Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue… |
|
CVE-2025-60722
MEDIUM 6.5
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over… |
|
CVE-2025-47967
MEDIUM 4.7
Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2025-56139
MEDIUM 5.3
LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original … |
|
CVE-2025-49755
MEDIUM 4.3
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2025-49736
MEDIUM 4.3
The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2024-50302
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-21259
MEDIUM 5.3
Microsoft Outlook Spoofing Vulnerability |
|
CVE-2025-21253
Microsoft Edge for IOS and Android Spoofing Vulnerability |
|
CVE-2024-43604
MEDIUM 5.7
Outlook for Android Elevation of Privilege Vulnerability |
|
CVE-2024-39891
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-numb… |
|
CVE-2024-34130
MEDIUM 5.5
Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature … |
|
CVE-2024-26196
MEDIUM 4.3
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability |
|
CVE-2024-26167
MEDIUM 4.3
Microsoft Edge for Android Spoofing Vulnerability |
|
CVE-2024-26188
MEDIUM 4.3
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
|
CVE-2024-24699
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. |
|
CVE-2024-24698
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. |
|
CVE-2024-24690
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2023-49646
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2023-43583
Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user … |
|
CVE-2023-45866
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-43582
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. |
|
CVE-2023-39205
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2023-39204
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. |
|
CVE-2023-39199
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access. |
|
CVE-2023-36029
MEDIUM 4.3
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
|
CVE-2022-20917
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attack… |
|
CVE-2023-39218
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access. |
|
CVE-2023-36532
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. |
|
CVE-2023-26083
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-25012
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42703
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-36539
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. |
|
CVE-2023-28599
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi… |
|
CVE-2023-21116
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-28284
MEDIUM 4.3
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
|
CVE-2023-20950
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-24923
MEDIUM 5.5
Microsoft OneDrive for Android Information Disclosure Vulnerability |
|
CVE-2021-29647
MEDIUM · vendor
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2021-33655
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-21721
MEDIUM 6.5
Microsoft OneNote Elevation of Privilege Vulnerability |
|
CVE-2022-39842
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-36928
MEDIUM 6.1
Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to … |
|
CVE-2022-42721
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-16135
MEDIUM 6.5
The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site. |
|
CVE-2022-24480
MEDIUM 6.3
Outlook for Android Elevation of Privilege Vulnerability |
|
CVE-2022-43363
Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relati… |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.