Vulnerabilities
Tracked app vulnerabilities
16,412 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,412
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-43300
CRITICAL 10.0
KEV
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, … |
|
CVE-2025-9187
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-9185
HIGH 8.1
1 app
Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunder… |
|
CVE-2025-9184
HIGH 8.1
1 app
Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2025-9182
HIGH 7.5
1 app
Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderbird 142, a… |
|
CVE-2025-9181
MEDIUM 6.5
1 app
Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, T… |
|
CVE-2025-9180
HIGH 8.1
1 app
Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR… |
|
CVE-2025-9179
CRITICAL 9.8
1 app
An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents sl… |
|
CVE-2025-53783
HIGH 7.5
1 app
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-53766
CRITICAL 9.8
1 app
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-53732
HIGH 7.8
1 app
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-49755
MEDIUM 4.3
1 app
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2025-49736
MEDIUM 4.3
1 app
The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2025-38500
HIGH 7.8
In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface collect_md p… |
|
CVE-2025-55231
HIGH 7.5
Windows Storage-based Management Service Remote Code Execution Vulnerability |
|
CVE-2025-55230
HIGH 7.8
Windows MBT Transport Driver Elevation of Privilege Vulnerability |
|
CVE-2025-55229
HIGH 5.3
Windows Certificate Spoofing Vulnerability |
|
CVE-2025-53789
HIGH 7.8
Windows StateRepository API Server file Elevation of Privilege Vulnerability |
|
CVE-2025-53779
MEDIUM 7.2
Windows Kerberos Elevation of Privilege Vulnerability |
|
CVE-2025-53778
CRITICAL 8.8
Windows NTLM Elevation of Privilege Vulnerability |
|
CVE-2025-53726
HIGH 7.8
Windows Push Notifications Apps Elevation of Privilege Vulnerability |
|
CVE-2025-53725
HIGH 7.8
Windows Push Notifications Apps Elevation of Privilege Vulnerability |
|
CVE-2025-53724
HIGH 7.8
Windows Push Notifications Apps Elevation of Privilege Vulnerability |
|
CVE-2025-53723
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-53722
HIGH 7.5
Windows Remote Desktop Services Denial of Service Vulnerability |
|
CVE-2025-53721
HIGH 7.0
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2025-53720
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-53719
HIGH 5.7
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-53718
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-53716
HIGH 6.5
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
|
CVE-2025-53156
HIGH 5.5
Windows Storage Port Driver Information Disclosure Vulnerability |
|
CVE-2025-53155
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-53154
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-53153
HIGH 5.7
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-53152
HIGH 7.8
Desktop Windows Manager Remote Code Execution Vulnerability |
|
CVE-2025-53151
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-53149
HIGH 7.8
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-53148
HIGH 5.7
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-53147
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-53145
HIGH 8.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2025-53144
HIGH 8.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2025-53143
HIGH 8.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2025-53142
HIGH 7.0
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-53141
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-53140
HIGH 7.0
Windows Kernel Transaction Manager Elevation of Privilege Vulnerability |
|
CVE-2025-53138
HIGH 5.7
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-53137
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-53136
HIGH 5.5
NT OS Kernel Information Disclosure Vulnerability |
|
CVE-2025-53135
HIGH 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-53134
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |