Vulnerabilities
Tracked app vulnerabilities
4,827 CVEs affect a tracked app or OS (High, Android). 39 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 4,827
- Actively exploited
- 39
- Publication window
- 2016-05-09 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-21373
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21372
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-21367
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20450
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20449
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20448
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20447
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20435
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20433
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47403
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47401
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47400
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-47384
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-42832
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. |
|
CVE-2026-41102
HIGH 7.1
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. |
|
CVE-2026-41101
HIGH 7.1
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. |
|
CVE-2026-43049
HIGH · vendor
HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure |
|
CVE-2025-71256
HIGH 7.5
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. |
|
CVE-2025-71255
HIGH 7.5
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. |
|
CVE-2025-71254
HIGH 7.5
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. |
|
CVE-2025-71253
HIGH 7.5
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. |
|
CVE-2025-71252
HIGH 7.5
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed. |
|
CVE-2025-71251
HIGH 7.5
In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges … |
|
CVE-2026-22167
HIGH 7.8
Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under ce… |
|
CVE-2026-31629
HIGH 8.8
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_ll… |
|
CVE-2026-6358
HIGH 8.8
Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML p… |
|
CVE-2026-6319
HIGH 7.5
Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures… |
|
CVE-2026-6315
HIGH 8.8
Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestu… |
|
CVE-2026-20432
HIGH 8.0
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a … |
|
CVE-2026-26133
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-26134
HIGH · vendor
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-25180
HIGH · vendor
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-24285
HIGH · vendor
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33636
HIGH · vendor
LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64 |
|
CVE-2026-3537
HIGH 8.8
Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a cr… |
|
CVE-2026-0013
HIGH 8.4
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local esca… |
|
CVE-2026-0011
HIGH 8.4
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead t… |
|
CVE-2026-0010
HIGH 8.4
In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privileg… |
|
CVE-2026-21385
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20434
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20428
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20427
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20426
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20425
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20422
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20421
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20420
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20406
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20405
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-20404
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.