All apps
O
Oracle VirtualBox
VirtualizationCross-platform type-2 hypervisor for running virtual machines on desktops
Latest versions
Stable
macOSLinuxWindows
7.2.16Actively exploited
0
CISA KEV · 1 lifetime
Affecting latest
0
v7.2.16
Known CVEs
464
across all versions, as matched by PemSync
Last checked
6 Sep 2026, 0:15
The latest tracked version (7.2.16) is not affected by any matched vulnerability — all 464 recorded CVEs are fixed in versions you're past.
| CVE | Severity | EPSS pct | Status | Score source | |
|---|---|---|---|---|---|
CVE-2019-2725Exploited | CRITICAL 9.8 | 100% | Latest not affected | NVD | 26 Apr 2019 |
| — | 2% | Latest not affected | — | 18 Aug 2026 | |
| — | 5% | Latest not affected | — | 18 Aug 2026 | |
| — | 2% | Latest not affected | — | 18 Aug 2026 | |
| — | 5% | Latest not affected | — | 18 Aug 2026 | |
| — | 5% | Latest not affected | — | 18 Aug 2026 | |
| — | 2% | Latest not affected | — | 18 Aug 2026 | |
| — | 5% | Latest not affected | — | 18 Aug 2026 | |
| — | 5% | Latest not affected | — | 18 Aug 2026 | |
| — | 4% | Latest not affected | — | 18 Aug 2026 | |
| — | 3% | Latest not affected | — | 18 Aug 2026 | |
| — | 7% | Latest not affected | — | 18 Aug 2026 | |
| — | 18% | Latest not affected | — | 18 Aug 2026 | |
| — | 3% | Latest not affected | — | 18 Aug 2026 | |
| — | 5% | Latest not affected | — | 18 Aug 2026 | |
| — | 2% | Latest not affected | — | 18 Aug 2026 | |
| — | 2% | Latest not affected | — | 18 Aug 2026 | |
| — | 2% | Latest not affected | — | 18 Aug 2026 | |
| — | 3% | Latest not affected | — | 18 Aug 2026 | |
| — | 6% | Latest not affected | — | 18 Aug 2026 | |
| — | 6% | Latest not affected | — | 18 Aug 2026 | |
| — | 35% | Latest not affected | — | 18 Aug 2026 | |
| MEDIUM 6.1 | 4% | Latest not affected | CNA | 21 Jul 2026 | |
| MEDIUM 6.1 | 2% | Latest not affected | CNA | 21 Jul 2026 | |
| LOW 3.2 | 6% | Latest not affected | CNA | 21 Jul 2026 |
Showing 1–25 of 464
Page 1 of 19
PemSync reports known, cataloged exploited vulnerabilities (CISA KEV) and published CVEs. It is not a zero-day detection or threat-intelligence system — a vulnerability may be exploited before it appears here. Absence of data does not mean an app is secure.