Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

16,453 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
16,453
Actively exploited
286
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

16,453 entries
CVE
CVE-2025-31261
MEDIUM 5.5

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A…

CVE-2025-31231
MEDIUM 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read sensitive location inform…

CVE-2025-31199
MEDIUM 5.5

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.8.2, visionOS …

CVE-2025-31198
MEDIUM 5.5

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A path han…

CVE-2025-31189
HIGH 8.2

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may…

CVE-2025-30466
CRITICAL 9.8

This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A w…

CVE-2025-5272
HIGH 7.3 1 app

Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-5269
HIGH 8.1 1 app

Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort t…

CVE-2025-5268
HIGH 8.1 1 app

Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption…

CVE-2025-5262
HIGH 7.5 1 app

A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memo…

CVE-2025-31262
MEDIUM 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, w…

CVE-2025-31185
LOW 3.3

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without auth…

CVE-2025-24189
HIGH 8.8

The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchO…

CVE-2025-24184
MEDIUM 5.5

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, tvOS 18.3, visionOS …

CVE-2025-24183
MEDIUM 5.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local user may be able to…

CVE-2025-4919
HIGH 8.8 1 app

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 1…

CVE-2025-4918
CRITICAL 9.8 1 app

An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 1…

CVE-2025-3932
MEDIUM 6.5 1 app

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accesse…

CVE-2025-3909
HIGH 8.1 1 app

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested ema…

CVE-2025-3875
HIGH 7.5 1 app

Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From hea…

CVE-2025-30388
HIGH 7.8 1 app

Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

CVE-2025-30386
CRITICAL 8.4 1 app

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-32709
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-32707
HIGH 7.8

NTFS Elevation of Privilege Vulnerability

CVE-2025-32706
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-32701
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-30400
HIGH 7.8 KEV

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-30397
HIGH 7.5 KEV

Scripting Engine Memory Corruption Vulnerability

CVE-2025-30394
HIGH 5.9

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

CVE-2025-30385
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-29974
HIGH 5.7

Windows Kernel Information Disclosure Vulnerability

CVE-2025-29971
HIGH 7.5

Web Threat Defense (WTD.sys) Denial of Service Vulnerability

CVE-2025-29970
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-29969
HIGH 7.5

MS-EVEN RPC Remote Code Execution Vulnerability

CVE-2025-29968
HIGH 6.5

Active Directory Certificate Services (AD CS) Denial of Service Vulnerability

CVE-2025-29967
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-29966
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-29964
HIGH 8.8

Windows Media Remote Code Execution Vulnerability

CVE-2025-29963
HIGH 8.8

Windows Media Remote Code Execution Vulnerability

CVE-2025-29962
HIGH 8.8

Windows Media Remote Code Execution Vulnerability

CVE-2025-29961
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29960
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29959
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29958
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29957
HIGH 6.2

Windows Deployment Services Denial of Service Vulnerability

CVE-2025-29956
HIGH 5.4

Windows SMB Information Disclosure Vulnerability

CVE-2025-29955
HIGH 6.2

Windows Hyper-V Denial of Service Vulnerability

CVE-2025-29954
HIGH 5.9

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2025-29842
HIGH 7.5

UrlMon Security Feature Bypass Vulnerability

CVE-2025-29841
HIGH 7.0

Universal Print Management Service Elevation of Privilege Vulnerability