Vulnerabilities
Tracked app vulnerabilities
16,453 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,453
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-21459
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-21453
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-20666
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-0427
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-0087
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-0077
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-0072
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-52939
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-49847
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-49846
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-49845
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-49842
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-49841
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-49835
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-49739
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-47900
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-47896
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-47891
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-46975
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-46974
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-45580
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-34739
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-12577
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-35657
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-21342
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-24091
MEDIUM 5.5
An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iP… |
|
CVE-2025-4093
HIGH 8.1
1 app
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort thi… |
|
CVE-2025-4092
MEDIUM 6.5
1 app
Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-4091
HIGH 8.1
1 app
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption a… |
|
CVE-2025-4089
MEDIUM 5.1
1 app
Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading t… |
|
CVE-2025-4088
MEDIUM 6.5
1 app
A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invo… |
|
CVE-2025-4087
MEDIUM 4.8
1 app
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This cou… |
|
CVE-2025-4085
HIGH 7.1
1 app
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. Th… |
|
CVE-2025-4084
MEDIUM 5.7
1 app
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leadi… |
|
CVE-2025-4083
CRITICAL 9.1
1 app
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level docu… |
|
CVE-2025-4082
MEDIUM 5.9
1 app
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate… |
|
CVE-2025-2817
HIGH 8.8
1 app
Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By… |
|
CVE-2025-31203
MEDIUM 6.5
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Son… |
|
CVE-2025-31202
MEDIUM 5.5
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, vision… |
|
CVE-2025-31197
MEDIUM 5.7
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ve… |
|
CVE-2025-30445
MEDIUM 6.5
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.… |
|
CVE-2025-24271
MEDIUM 5.4
An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sono… |
|
CVE-2025-24270
MEDIUM 5.7
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7… |
|
CVE-2025-24252
HIGH 8.8
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS… |
|
CVE-2025-24251
MEDIUM 6.5
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ve… |
|
CVE-2025-24206
HIGH 7.7
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS… |
|
CVE-2025-24179
MEDIUM 5.7
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, ma… |
|
CVE-2022-47112
LOW 2.5
1 app
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected. |
|
CVE-2022-47111
LOW 2.5
1 app
7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected. |
|
CVE-2025-31201
CRITICAL 9.8
KEV
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.… |