Vulnerabilities
Tracked app vulnerabilities
16,398 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,398
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-62455
HIGH 7.8
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2025-62454
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-62221
HIGH 7.8
KEV
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-59517
HIGH 7.8
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-59516
HIGH 7.8
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-55233
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-54100
HIGH 7.8
PowerShell Remote Code Execution Vulnerability |
|
CVE-2025-48615
HIGH 7.8
In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local escalatio… |
|
CVE-2025-48612
HIGH 7.8
In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to improper … |
|
CVE-2025-48600
MEDIUM 5.5
In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information disclosur… |
|
CVE-2025-48566
HIGH 7.8
In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation. This could lead to local e… |
|
CVE-2025-48565
HIGH 7.8
In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could lead to local escalation … |
|
CVE-2025-48564
HIGH 7.0
In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no additional ex… |
|
CVE-2025-40266
HIGH 8.2
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent … |
|
CVE-2025-40214
HIGH 7.8
In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC c… |
|
CVE-2025-12084
MEDIUM 5.3
1 app
When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Avail… |
|
CVE-2025-13837
LOW 5.5
1 app
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues |
|
CVE-2025-13836
MEDIUM 7.5
1 app
When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server… |
|
CVE-2025-8045
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-6573
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-6349
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61619
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61618
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61617
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61610
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61609
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61608
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61607
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-58410
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48639
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48638
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48637
HIGH 7.8
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48633
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48632
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48629
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48628
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48627
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48626
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48624
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48623
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48622
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48621
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48620
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48618
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48614
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48610
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48607
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48604
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48603
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48601
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |