Vulnerabilities
Tracked app vulnerabilities
16,453 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,453
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-31200
CRITICAL 9.8
KEV
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, … |
|
CVE-2025-3523
MEDIUM 6.4
1 app
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering ove… |
|
CVE-2025-3522
MEDIUM 6.3
1 app
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird a… |
|
CVE-2025-2830
MEDIUM 6.3
1 app
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when t… |
|
CVE-2025-29805
HIGH 7.5
1 app
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. |
|
CVE-2025-26687
HIGH 7.5
1 app
Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. |
|
CVE-2025-29824
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-29812
HIGH 7.8
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-29811
HIGH 7.8
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
|
CVE-2025-29810
HIGH 7.5
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2025-29809
HIGH 7.1
Windows Kerberos Security Feature Bypass Vulnerability |
|
CVE-2025-29808
HIGH 5.5
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2025-27742
HIGH 5.5
NTFS Information Disclosure Vulnerability |
|
CVE-2025-27741
HIGH 7.8
NTFS Elevation of Privilege Vulnerability |
|
CVE-2025-27740
HIGH 8.8
Active Directory Certificate Services Elevation of Privilege Vulnerability |
|
CVE-2025-27739
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-27738
HIGH 6.5
Windows Resilient File System (ReFS) Information Disclosure Vulnerability |
|
CVE-2025-27737
HIGH 8.6
Windows Security Zone Mapping Security Feature Bypass Vulnerability |
|
CVE-2025-27736
HIGH 5.5
Windows Power Dependency Coordinator Information Disclosure Vulnerability |
|
CVE-2025-27735
HIGH 6.0
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
|
CVE-2025-27733
HIGH 7.8
NTFS Elevation of Privilege Vulnerability |
|
CVE-2025-27732
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-27731
HIGH 7.8
Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability |
|
CVE-2025-27730
HIGH 7.8
Windows Digital Media Elevation of Privilege Vulnerability |
|
CVE-2025-27729
HIGH 7.8
Windows Shell Remote Code Execution Vulnerability |
|
CVE-2025-27728
HIGH 7.8
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2025-27727
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2025-27492
HIGH 7.0
Windows Secure Channel Elevation of Privilege Vulnerability |
|
CVE-2025-27491
CRITICAL 7.1
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2025-27490
HIGH 7.8
Windows Bluetooth Service Elevation of Privilege Vulnerability |
|
CVE-2025-27487
HIGH 8.0
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2025-27486
HIGH 7.5
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2025-27485
HIGH 7.5
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2025-27484
HIGH 7.5
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability |
|
CVE-2025-27483
HIGH 7.8
NTFS Elevation of Privilege Vulnerability |
|
CVE-2025-27482
CRITICAL 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-27481
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-27480
CRITICAL 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-27479
HIGH 7.5
Kerberos Key Distribution Proxy Service Denial of Service Vulnerability |
|
CVE-2025-27478
HIGH 7.0
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability |
|
CVE-2025-27477
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-27476
HIGH 7.8
Windows Digital Media Elevation of Privilege Vulnerability |
|
CVE-2025-27475
HIGH 7.0
Windows Update Stack Elevation of Privilege Vulnerability |
|
CVE-2025-27474
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-27473
HIGH 7.5
HTTP.sys Denial of Service Vulnerability |
|
CVE-2025-27471
HIGH 5.9
Microsoft Streaming Service Denial of Service Vulnerability |
|
CVE-2025-27470
HIGH 7.5
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2025-27469
HIGH 7.5
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2025-26688
HIGH 7.8
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
|
CVE-2025-26686
CRITICAL 7.5
Windows TCP/IP Remote Code Execution Vulnerability |