Vulnerabilities
Tracked app vulnerabilities
16,430 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,430
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-24185
MEDIUM 5.5
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3… |
|
CVE-2024-54565
MEDIUM 6.2
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data. |
|
CVE-2024-54559
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data. |
|
CVE-2024-54525
HIGH 8.8
A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS … |
|
CVE-2024-44276
HIGH 7.3
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2. A user in a privileged netw… |
|
CVE-2024-8176
HIGH 7.5
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML docume… |
|
CVE-2025-24201
CRITICAL 10.0
KEV
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15… |
|
CVE-2025-26633
HIGH 7.0
KEV
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-26645
CRITICAL 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2025-26634
HIGH 7.5
Windows Core Messaging Elevation of Privileges Vulnerability |
|
CVE-2025-25008
HIGH 7.1
Windows Server Elevation of Privilege Vulnerability |
|
CVE-2025-24997
HIGH 4.4
DirectX Graphics Kernel File Denial of Service Vulnerability |
|
CVE-2025-24996
HIGH 6.5
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-24995
HIGH 7.8
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24994
HIGH 7.3
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2025-24993
HIGH 7.8
KEV
Windows NTFS Remote Code Execution Vulnerability |
|
CVE-2025-24992
HIGH 5.5
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24991
HIGH 5.5
KEV
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24988
HIGH 6.6
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24987
HIGH 6.6
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24985
HIGH 7.8
KEV
Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
|
CVE-2025-24984
HIGH 4.6
KEV
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24983
HIGH 7.0
KEV
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24855
HIGH 7.8
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is… |
|
CVE-2025-24084
CRITICAL 8.4
Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability |
|
CVE-2025-24076
HIGH 7.3
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2025-24072
HIGH 7.8
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability |
|
CVE-2025-24071
HIGH 6.5
Microsoft Windows File Explorer Spoofing Vulnerability |
|
CVE-2025-24067
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24066
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24064
CRITICAL 8.1
Windows Domain Name Service Remote Code Execution Vulnerability |
|
CVE-2025-24061
HIGH 7.8
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2025-24059
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24056
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-24055
HIGH 4.3
Windows USB Video Class System Driver Information Disclosure Vulnerability |
|
CVE-2025-24054
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-24051
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-24050
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-24048
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-24046
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24045
CRITICAL 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-24044
HIGH 7.8
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24035
CRITICAL 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-21247
HIGH 4.3
MapUrlToZone Security Feature Bypass Vulnerability |
|
CVE-2025-21180
HIGH 7.8
Windows exFAT File System Remote Code Execution Vulnerability |
|
CVE-2024-9157
HIGH
Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability |
|
CVE-2024-55549
HIGH 7.8
xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue |
|
CVE-2025-26696
HIGH 7.0
1 app
Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown… |
|
CVE-2025-26695
MEDIUM 5.3
1 app
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested emai… |
|
CVE-2024-54560
MEDIUM 5.5
A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app may be ab… |