CISA KEV
Actively exploited vulnerabilities (CISA KEV)
48 actively exploited CVEs (all severities, Android) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.
- Matching CVEs
- 48
- Actively exploited
- 48
- Publication window
- 2016-12-01 → 2026-06-01
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-48595
HIGH 8.4
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no a… |
|
CVE-2026-21385
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48633
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48572
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-39682
CRITICAL 9.8
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process … |
|
CVE-2025-48543
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-27038
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-21479
CRITICAL · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-38352
HIGH 7.8
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If… |
|
CVE-2025-27363
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-53197
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-53150
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-50302
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43093
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-53104
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43047
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-32896
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-36971
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-39891
MEDIUM 5.3
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-numb… |
|
CVE-2024-4610
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33107
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33106
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33063
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-4211
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-5217
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap… |
|
CVE-2023-4863
HIGH 8.8
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v… |
|
CVE-2023-35674
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-26083
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-29256
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-22706
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-0266
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-0847
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-22600
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-2136
CRITICAL 9.6
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a s… |
|
CVE-2022-38181
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-20963
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-1048
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0920
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-28664
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-28663
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-1906
MEDIUM · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-1905
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-11261
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-15999
CRITICAL 9.6
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… |
|
CVE-2020-0069
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0041
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2215
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-5195
CRITICAL · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.