Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

4,827 CVEs affect a tracked app or OS (High, Android). 39 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
4,827
Actively exploited
39
Publication window
2016-05-09 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

4,827 entries High Android Clear all
CVE
CVE-2026-21373
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-21372
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-21367
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20450
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20449
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20448
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20447
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20435
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20433
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47403
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47401
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47400
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47384
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-42832
HIGH 7.7

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

CVE-2026-41102
HIGH 7.1

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

CVE-2026-41101
HIGH 7.1

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

CVE-2026-43049
HIGH · vendor

HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure

CVE-2025-71256
HIGH 7.5

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

CVE-2025-71255
HIGH 7.5

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

CVE-2025-71254
HIGH 7.5

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

CVE-2025-71253
HIGH 7.5

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

CVE-2025-71252
HIGH 7.5

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

CVE-2025-71251
HIGH 7.5

In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges …

CVE-2026-22167
HIGH 7.8

Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under ce…

CVE-2026-31629
HIGH 8.8

In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_ll…

CVE-2026-6358
HIGH 8.8

Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML p…

CVE-2026-6319
HIGH 7.5

Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures…

CVE-2026-6315
HIGH 8.8

Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestu…

CVE-2026-20432
HIGH 8.0

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a …

CVE-2026-26133
HIGH 7.1

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-26134
HIGH · vendor

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

CVE-2026-25180
HIGH · vendor

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

CVE-2026-24285
HIGH · vendor

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-33636
HIGH · vendor

LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64

CVE-2026-3537
HIGH 8.8

Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a cr…

CVE-2026-0013
HIGH 8.4

In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local esca…

CVE-2026-0011
HIGH 8.4

In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead t…

CVE-2026-0010
HIGH 8.4

In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privileg…

CVE-2026-21385
HIGH · vendor KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20434
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20428
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20427
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20426
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20425
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20422
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20421
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20420
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20406
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20405
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20404
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM