Vulnerabilities
Tracked app vulnerabilities
16,398 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,398
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-20754
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-20753
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-20752
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-20751
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-20750
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-20730
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-20727
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-20726
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-20725
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-11133
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-11132
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-11131
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-35970
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-40130
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-43374
MEDIUM 4.3
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS So… |
|
CVE-2025-31266
MEDIUM 4.3
A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is fixed in Safari 18.5, macOS Sequoia 15.5… |
|
CVE-2025-31248
MEDIUM 5.5
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.3,… |
|
CVE-2025-31216
LOW 2.4
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may … |
|
CVE-2025-11001
HIGH 7.8
1 app
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… |
|
CVE-2025-55179
MEDIUM 5.4
1 app
Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.… |
|
CVE-2025-52331
MEDIUM 6.1
1 app
Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the … |
|
CVE-2025-43205
MEDIUM 4.0
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, … |
|
CVE-2025-60724
CRITICAL 9.8
1 app
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-60722
MEDIUM 6.5
1 app
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over… |
|
CVE-2025-65018
HIGH 7.1
LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read` |
|
CVE-2025-64720
HIGH 7.1
LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication |
|
CVE-2025-62452
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-62219
HIGH 7.0
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability |
|
CVE-2025-62218
HIGH 7.0
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability |
|
CVE-2025-62217
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-62215
HIGH 7.0
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-62213
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-62209
HIGH 5.5
Windows License Manager Information Disclosure Vulnerability |
|
CVE-2025-62208
HIGH 5.5
Windows License Manager Information Disclosure Vulnerability |
|
CVE-2025-60723
HIGH 6.3
DirectX Graphics Kernel Denial of Service Vulnerability |
|
CVE-2025-60721
HIGH 7.8
Windows Administrator Protection Elevation of Privilege Vulnerability |
|
CVE-2025-60720
HIGH 7.8
Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability |
|
CVE-2025-60719
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-60718
HIGH 7.8
Windows Administrator Protection Elevation of Privilege Vulnerability |
|
CVE-2025-60717
HIGH 7.0
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
|
CVE-2025-60716
CRITICAL 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-60715
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-60714
HIGH 7.8
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2025-60713
HIGH 7.8
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability |
|
CVE-2025-60710
HIGH 7.8
KEV
Host Process for Windows Tasks Elevation of Privilege Vulnerability |
|
CVE-2025-60709
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-60708
HIGH 6.5
Storvsp.sys Driver Denial of Service Vulnerability |
|
CVE-2025-60707
HIGH 7.8
Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability |
|
CVE-2025-60706
HIGH 5.5
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2025-60705
HIGH 7.8
Windows Client-Side Caching Elevation of Privilege Vulnerability |