Skip to content
Appaloosa Scout
Language selector
fr en

Annual recap

App security · 2025

2025 recap indexed by Appaloosa Scout: 2,485 CVEs published during the year on tracked apps, 64 added to the CISA KEV catalog (exploited in the wild), 7 apps affected by at least one KEV.

See multi-year trends in the Threat Observatory

CVE indexed this year
2,485
CISA KEV added
64
Tracked apps affected
7

Severity distribution

CRITICAL 220
HIGH 1,656
MEDIUM 557
LOW 52

Top 10 KEVs of the year

Sorted by CVSS severity. “Apps” counts tracked catalog apps: many KEVs are OS-level and legitimately show 0.

CVE Severity
CVE-2025-43300
0 apps
CRITICAL 10.0
CVE-2025-32433
0 apps
CRITICAL 10.0
CVE-2025-24201
0 apps
CRITICAL 10.0
CVE-2025-24085
0 apps
CRITICAL 10.0
CVE-2010-3765
2 apps
CRITICAL 9.8
CVE-2025-10585
2 apps
CRITICAL 9.8
CVE-2024-21413
2 apps
CRITICAL 9.8
CVE-2025-14611
0 apps
CRITICAL 9.8
CVE-2025-59287
0 apps
CRITICAL 9.8
CVE-2025-53770
0 apps
CRITICAL 9.8

Top vendors by KEV this year

  1. 1 Google LLC 7 KEV · 1 apps
  2. 2 Microsoft 2 KEV · 1 apps
  3. 3 Microsoft Office 2 KEV · 1 apps
  4. 4 win.rar GmbH 2 KEV · 1 apps
  5. 5 Microsoft Corporation 1 KEV · 4 apps
  6. 6 Mozilla 1 KEV · 2 apps
  7. 7 Apple Distribution International 1 KEV · 1 apps
  8. 8 Igor Pavlov 1 KEV · 1 apps
  9. 9 WhatsApp Inc. 1 KEV · 1 apps

Most affected apps

Methodology

KEV: added to the CISA catalog during the year (kev_added_date). CVE: NVD publication date. Apps: those indexed in Scout at query time; the history evolves as new mappings are added.