Vulnerabilities
Tracked app vulnerabilities
33 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-50419
LOW 3.3
Local
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50416
LOW 3.3
Local
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-58052
LOW 3.3
Local 1 apps
7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supp… |
|
CVE-2026-45642
LOW 3.9
Physical
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a… |
|
CVE-2026-48102
LOW 3.1
Network 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF disc image ha… |
|
CVE-2026-4519
LOW 3.3
Local 1 apps
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior reject… |
|
CVE-2025-13462
LOW 3.3
Local 1 apps
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME … |
|
CVE-2025-13837
LOW 5.5
Local 1 apps
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues |
|
CVE-2025-55188
LOW 3.6
Local 1 apps
7-Zip before 25.01 does not always properly handle symbolic links during extraction. |
|
CVE-2025-49462
LOW 3.5
Network 4 apps
Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access. |
|
CVE-2025-49731
LOW 3.1
Network 2 apps
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network. |
|
CVE-2022-47112
LOW 2.5
Local 1 apps
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected. |
|
CVE-2022-47111
LOW 2.5
Local 1 apps
7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected. |
|
CVE-2024-32021
LOW 3.9
Local 1 apps
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that con… |
|
CVE-2024-32020
LOW 3.9
Local 1 apps
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into … |
|
CVE-2024-3302
LOW 3.7
Network 1 apps
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the b… |
|
CVE-2024-2616
LOW 2.7
Network 1 apps
To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects F… |
|
CVE-2024-23743
LOW 3.3
Local 2 apps
Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must lau… |
|
CVE-2023-43588
LOW 3.5
Network 2 apps
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access. |
|
CVE-2023-39206
LOW 3.7
Network 4 apps
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. |
|
CVE-2023-38039
LOW
Hackerone: CVE-2023-38039 HTTP headers eat all memory |
|
CVE-2023-34414
LOW 3.1
Network 1 apps
The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks tha… |
|
CVE-2023-28602
LOW 2.8
Local 1 apps
Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade… |
|
CVE-2021-29948
LOW 2.5
Local 1 apps
Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replac… |
|
CVE-2020-27895
LOW 3.3
Local 1 apps
An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTune… |
|
CVE-2020-17046
LOW 5.5
Windows Error Reporting Denial of Service Vulnerability |
|
CVE-2019-1348
LOW 3.3
Local 1 apps
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks opti… |
|
CVE-2019-11743
LOW 3.7
Network 1 apps
Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts … |
|
CVE-2018-8136
LOW 6.5
Windows Remote Code Execution Vulnerability |
|
CVE-2018-1000030
LOW 3.6
Local 1 apps
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears t… |
|
CVE-2016-0175
LOW 3.3
Local
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… |
|
CVE-2015-1283
LOW
1 apps
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote … |
|
CVE-2015-4000
LOW 3.7
Network 1 apps
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which… |