Vulnerabilities
Tracked app vulnerabilities
16,430 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,430
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-55334
HIGH 6.2
Windows Kernel Security Feature Bypass Vulnerability |
|
CVE-2025-55333
HIGH 6.1
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55332
HIGH 6.1
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55331
HIGH 7.0
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
|
CVE-2025-55330
HIGH 6.1
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55328
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-55326
HIGH 7.5
Windows Connected Devices Platform Service (Cdpsvc) Remote Code Execution Vulnerability |
|
CVE-2025-55325
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-53768
HIGH 7.8
Xbox IStorageService Elevation of Privilege Vulnerability |
|
CVE-2025-53717
HIGH 7.0
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability |
|
CVE-2025-53150
HIGH 7.8
Windows Digital Media Elevation of Privilege Vulnerability |
|
CVE-2025-53139
HIGH 7.7
Windows Hello Security Feature Bypass Vulnerability |
|
CVE-2025-50175
HIGH 7.8
Windows Digital Media Elevation of Privilege Vulnerability |
|
CVE-2025-50174
HIGH 7.0
Windows Device Association Broker Service Elevation of Privilege Vulnerability |
|
CVE-2025-50152
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-49708
CRITICAL 9.9
Microsoft Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-48813
HIGH 6.3
Virtual Secure Mode Spoofing Vulnerability |
|
CVE-2025-48004
HIGH 7.4
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-47979
HIGH 5.5
Microsoft Failover Cluster Information Disclosure Vulnerability |
|
CVE-2025-47827
HIGH 4.6
KEV
MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11 |
|
CVE-2025-25004
HIGH 7.3
PowerShell Elevation of Privilege Vulnerability |
|
CVE-2025-24990
HIGH 7.8
KEV
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24052
HIGH 7.8
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-43296
MEDIUM 5.5
A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks. |
|
CVE-2025-43400
MEDIUM 6.3
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 18.7.1, iOS 26.0.1 and iPadOS 26.0.1, ma… |
|
CVE-2025-47967
MEDIUM 4.7
1 app
Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2025-10537
HIGH 8.8
1 app
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2025-10536
MEDIUM 6.2
1 app
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140… |
|
CVE-2025-10534
HIGH 8.1
1 app
Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. |
|
CVE-2025-10533
HIGH 8.8
1 app
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140… |
|
CVE-2025-10532
MEDIUM 6.5
1 app
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird… |
|
CVE-2025-10531
MEDIUM 5.4
1 app
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. |
|
CVE-2025-10529
MEDIUM 6.5
1 app
Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3. |
|
CVE-2025-10528
HIGH 7.3
1 app
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, … |
|
CVE-2025-10527
HIGH 7.1
1 app
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and … |
|
CVE-2025-43375
MEDIUM 5.5
1 app
The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process. |
|
CVE-2025-43372
HIGH 7.8
The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, visionOS 26,… |
|
CVE-2025-43371
HIGH 8.2
1 app
This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox. |
|
CVE-2025-43370
MEDIUM 4.0
1 app
A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process. |
|
CVE-2025-43369
MEDIUM 5.5
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26. An app may be able to access protected user data. |
|
CVE-2025-43368
MEDIUM 4.3
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing malici… |
|
CVE-2025-43367
MEDIUM 5.5
A privacy issue was addressed by moving sensitive data. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protected user d… |
|
CVE-2025-43366
MEDIUM 5.5
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to disclose coprocessor memory. |
|
CVE-2025-43362
CRITICAL 9.8
The issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An app may be able to monitor keystrokes w… |
|
CVE-2025-43359
CRITICAL 9.8
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS So… |
|
CVE-2025-43358
HIGH 8.8
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15… |
|
CVE-2025-43357
LOW 3.3
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia… |
|
CVE-2025-43356
MEDIUM 6.5
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvO… |
|
CVE-2025-43355
MEDIUM 5.5
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, … |
|
CVE-2025-43354
MEDIUM 5.5
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An a… |