Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

16,398 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
16,398
Actively exploited
286
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

16,398 entries
CVE
CVE-2025-62455
HIGH 7.8

Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

CVE-2025-62454
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-62221
HIGH 7.8 KEV

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-59517
HIGH 7.8

Windows Storage VSP Driver Elevation of Privilege Vulnerability

CVE-2025-59516
HIGH 7.8

Windows Storage VSP Driver Elevation of Privilege Vulnerability

CVE-2025-55233
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2025-54100
HIGH 7.8

PowerShell Remote Code Execution Vulnerability

CVE-2025-48615
HIGH 7.8

In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local escalatio…

CVE-2025-48612
HIGH 7.8

In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to improper …

CVE-2025-48600
MEDIUM 5.5

In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information disclosur…

CVE-2025-48566
HIGH 7.8

In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation. This could lead to local e…

CVE-2025-48565
HIGH 7.8

In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could lead to local escalation …

CVE-2025-48564
HIGH 7.0

In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no additional ex…

CVE-2025-40266
HIGH 8.2

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent …

CVE-2025-40214
HIGH 7.8

In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC c…

CVE-2025-12084
MEDIUM 5.3 1 app

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Avail…

CVE-2025-13837
LOW 5.5 1 app

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

CVE-2025-13836
MEDIUM 7.5 1 app

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server…

CVE-2025-8045
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-6573
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-6349
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-61619
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-61618
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-61617
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-61610
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-61609
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-61608
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-61607
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-58410
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48639
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48638
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48637
HIGH 7.8

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48633
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48632
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48629
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48628
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48627
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48626
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48624
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48623
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48622
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48621
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48620
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48618
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48614
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48610
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48607
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48604
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48603
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48601
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.