Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

16,430 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
16,430
Actively exploited
286
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

16,430 entries
CVE
CVE-2025-43263
HIGH 7.1 1 app

The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.

CVE-2025-43262
MEDIUM 5.1

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. USB Restricted Mode may not be applied to accessories co…

CVE-2025-43231
MEDIUM 5.5

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8. An app may be able to access user-sensitive data.

CVE-2025-43208
MEDIUM 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to read sensitive location informatio…

CVE-2025-43207
MEDIUM 5.5

This issue was addressed with improved entitlements. This issue is fixed in macOS Tahoe 26. An app may be able to access user-sensitive data.

CVE-2025-43204
HIGH 7.8

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox.

CVE-2025-43203
MEDIUM 4.0

The issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An attacker with physical acce…

CVE-2025-43190
MEDIUM 5.5

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7…

CVE-2025-31271
HIGH 7.5

This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime calls can appear or be accepted on a locke…

CVE-2025-31270
MEDIUM 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access protected user data.

CVE-2025-31269
MEDIUM 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protecte…

CVE-2025-31268
MEDIUM 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be abl…

CVE-2025-31255
CRITICAL 9.8

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS …

CVE-2025-31254
MEDIUM 5.4

This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web content may l…

CVE-2025-30468
MEDIUM 6.5

This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessed without authenti…

CVE-2025-24197
MEDIUM 5.5

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access se…

CVE-2025-24088
HIGH 7.5

The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to override MDM-enforced settings from profiles.

CVE-2025-40909
MEDIUM 5.9

[Apple Perl] Multiple issues in Perl

CVE-2025-9086
HIGH 7.5

1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostnam…

CVE-2025-53799
CRITICAL 5.5 1 app

Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

CVE-2025-59220
HIGH 7.0

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-59216
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-59215
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-55236
CRITICAL 7.3

Graphics Kernel Remote Code Execution Vulnerability

CVE-2025-55234
HIGH 8.8

Windows SMB Elevation of Privilege Vulnerability

CVE-2025-55228
CRITICAL 7.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-55226
CRITICAL 6.7

Graphics Kernel Remote Code Execution Vulnerability

CVE-2025-55225
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-55224
CRITICAL 7.8

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2025-55223
HIGH 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-54919
HIGH 7.5

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-54918
CRITICAL 8.8

Windows NTLM Elevation of Privilege Vulnerability

CVE-2025-54917
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-54916
HIGH 7.8

Windows NTFS Remote Code Execution Vulnerability

CVE-2025-54915
HIGH 6.7

Windows Defender Firewall Service Elevation of Privilege Vulnerability

CVE-2025-54913
HIGH 7.8

Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability

CVE-2025-54912
HIGH 7.8

Windows BitLocker Elevation of Privilege Vulnerability

CVE-2025-54911
HIGH 7.3

Windows BitLocker Elevation of Privilege Vulnerability

CVE-2025-54895
HIGH 7.8

SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability

CVE-2025-54894
HIGH 7.8

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

CVE-2025-54116
HIGH 7.3

Windows MultiPoint Services Elevation of Privilege Vulnerability

CVE-2025-54115
HIGH 7.0

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-54114
HIGH 7.0

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2025-54113
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-54112
HIGH 7.0

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-54111
HIGH 7.8

Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability

CVE-2025-54110
HIGH 8.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-54109
HIGH 6.7

Windows Defender Firewall Service Elevation of Privilege Vulnerability

CVE-2025-54108
HIGH 7.0

Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

CVE-2025-54107
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability