Vulnerabilities
Tracked app vulnerabilities
749 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-42915
MEDIUM 5.5
Local
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally. |
|
CVE-2026-42914
MEDIUM 5.3
Network
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. |
|
CVE-2026-42907
MEDIUM 6.5
Network
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. |
|
CVE-2026-42906
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. |
|
CVE-2026-42903
MEDIUM 6.5
Network
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. |
|
CVE-2026-48112
MEDIUM 6.5
Network 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD SYMDEF parser. A … |
|
CVE-2026-48111
MEDIUM 4.3
Network 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an off-by-one out-of-bounds read vulnerability in the ParseDepedenc… |
|
CVE-2026-48104
MEDIUM 4.2
Network 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read in the SquashFS archive handler caused b… |
|
CVE-2026-48103
MEDIUM 4.3
Network 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain an off-by-one heap out-of-bounds read in the WIM (Windows Imaging) … |
|
CVE-2026-48101
MEDIUM 6.5
Network 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI cap… |
|
CVE-2026-48092
MEDIUM 4.3
Network 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain a heap memory disclosure via SquashFS fragment offset integer overf… |
|
CVE-2026-45585
MEDIUM 6.8
Physical
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerabi… |
|
CVE-2026-8971
MEDIUM 6.5
Network 1 apps
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8961
MEDIUM 6.5
Network 1 apps
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-32170
MEDIUM 6.7
Local
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-6019
MEDIUM 6.1
Network 1 apps
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sen… |
|
CVE-2026-6783
MEDIUM 5.3
Network 1 apps
Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6779
MEDIUM 5.3
Network 1 apps
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6778
MEDIUM 5.3
Network 1 apps
Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6777
MEDIUM 5.3
Network 1 apps
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6775
MEDIUM 5.3
Network 1 apps
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6774
MEDIUM 5.4
Network 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6770
MEDIUM 6.5
Network 1 apps
Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6767
MEDIUM 5.3
Network 1 apps
Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunde… |
|
CVE-2026-6765
MEDIUM 5.3
Network 1 apps
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6764
MEDIUM 6.5
Network 1 apps
Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Th… |
|
CVE-2026-6763
MEDIUM 6.5
Network 1 apps
Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6762
MEDIUM 6.3
Network 1 apps
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thu… |
|
CVE-2026-6757
MEDIUM 6.3
Network 1 apps
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140… |
|
CVE-2026-6755
MEDIUM 6.5
Network 1 apps
Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-33829
MEDIUM 4.3
Network
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-32223
MEDIUM 6.8
Physical
Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-32220
MEDIUM 4.4
Local
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. |
|
CVE-2019-25677
MEDIUM 6.2
Local 1 apps
WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in … |
|
CVE-2026-3889
MEDIUM 6.5
Network 1 apps
Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9. |
|
CVE-2026-4728
MEDIUM 6.5
Network 1 apps
Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
|
CVE-2026-2804
MEDIUM 5.4
Network 1 apps
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2802
MEDIUM 4.2
Network 1 apps
Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-21525
MEDIUM 6.2
KEV
Windows Remote Access Connection Manager Denial of Service Vulnerability |
|
CVE-2026-0818
MEDIUM 4.3
Network 1 apps
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled… |
|
CVE-2025-12781
MEDIUM 5.3
Network 1 apps
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepte… |
|
CVE-2026-21265
MEDIUM 6.4
Local
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affect… |
|
CVE-2026-20962
MEDIUM 4.4
Local
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. |
|
CVE-2026-20939
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20937
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20936
MEDIUM 4.3
Physical
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. |
|
CVE-2026-20935
MEDIUM 6.2
Local
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-20932
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20927
MEDIUM 5.3
Network
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service… |
|
CVE-2026-20925
MEDIUM 6.5
Network
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |