Vulnerabilities
Tracked app vulnerabilities
16,453 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,453
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-31261
MEDIUM 5.5
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A… |
|
CVE-2025-31231
MEDIUM 5.5
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read sensitive location inform… |
|
CVE-2025-31199
MEDIUM 5.5
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.8.2, visionOS … |
|
CVE-2025-31198
MEDIUM 5.5
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A path han… |
|
CVE-2025-31189
HIGH 8.2
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may… |
|
CVE-2025-30466
CRITICAL 9.8
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A w… |
|
CVE-2025-5272
HIGH 7.3
1 app
Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-5269
HIGH 8.1
1 app
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort t… |
|
CVE-2025-5268
HIGH 8.1
1 app
Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption… |
|
CVE-2025-5262
HIGH 7.5
1 app
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memo… |
|
CVE-2025-31262
MEDIUM 5.5
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, w… |
|
CVE-2025-31185
LOW 3.3
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without auth… |
|
CVE-2025-24189
HIGH 8.8
The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchO… |
|
CVE-2025-24184
MEDIUM 5.5
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, tvOS 18.3, visionOS … |
|
CVE-2025-24183
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local user may be able to… |
|
CVE-2025-4919
HIGH 8.8
1 app
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 1… |
|
CVE-2025-4918
CRITICAL 9.8
1 app
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 1… |
|
CVE-2025-3932
MEDIUM 6.5
1 app
It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accesse… |
|
CVE-2025-3909
HIGH 8.1
1 app
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested ema… |
|
CVE-2025-3875
HIGH 7.5
1 app
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From hea… |
|
CVE-2025-30388
HIGH 7.8
1 app
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. |
|
CVE-2025-30386
CRITICAL 8.4
1 app
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-32709
HIGH 7.8
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-32707
HIGH 7.8
NTFS Elevation of Privilege Vulnerability |
|
CVE-2025-32706
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-32701
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-30400
HIGH 7.8
KEV
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-30397
HIGH 7.5
KEV
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2025-30394
HIGH 5.9
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability |
|
CVE-2025-30385
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-29974
HIGH 5.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2025-29971
HIGH 7.5
Web Threat Defense (WTD.sys) Denial of Service Vulnerability |
|
CVE-2025-29970
HIGH 7.8
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-29969
HIGH 7.5
MS-EVEN RPC Remote Code Execution Vulnerability |
|
CVE-2025-29968
HIGH 6.5
Active Directory Certificate Services (AD CS) Denial of Service Vulnerability |
|
CVE-2025-29967
CRITICAL 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2025-29966
CRITICAL 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2025-29964
HIGH 8.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2025-29963
HIGH 8.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2025-29962
HIGH 8.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2025-29961
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29960
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29959
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29958
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29957
HIGH 6.2
Windows Deployment Services Denial of Service Vulnerability |
|
CVE-2025-29956
HIGH 5.4
Windows SMB Information Disclosure Vulnerability |
|
CVE-2025-29955
HIGH 6.2
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2025-29954
HIGH 5.9
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2025-29842
HIGH 7.5
UrlMon Security Feature Bypass Vulnerability |
|
CVE-2025-29841
HIGH 7.0
Universal Print Management Service Elevation of Privilege Vulnerability |