Vulnerabilities
Tracked app vulnerabilities
350 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 350
- Actively exploited
- 286
- Publication window
- 2010-06-30 → 2026-05-04
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-23918
HIGH 8.8
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommend… |
|
CVE-2026-33829
MEDIUM 4.3
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-32202
MEDIUM 4.3
KEV
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-21250
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21248
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21244
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2025-11001
HIGH 7.8
1 app
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… |
|
CVE-2025-59287
CRITICAL 9.8
KEV
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
|
CVE-2025-59254
HIGH 7.8
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-50154
HIGH 6.5
Microsoft Windows File Explorer Spoofing Vulnerability |
|
CVE-2025-6965
HIGH 7.7
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead… |
|
CVE-2025-49744
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-49730
HIGH 7.8
Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability |
|
CVE-2025-49683
HIGH 7.8
Microsoft Virtual Hard Disk Remote Code Execution Vulnerability |
|
CVE-2025-49677
HIGH 7.0
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-47987
HIGH 7.8
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability |
|
CVE-2025-32462
LOW 2.8
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on … |
|
CVE-2025-33073
HIGH 8.8
KEV
Windows SMB Client Elevation of Privilege Vulnerability |
|
CVE-2025-30397
HIGH 7.5
KEV
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2025-26633
HIGH 7.0
KEV
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-24076
HIGH 7.3
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2025-24071
HIGH 6.5
Microsoft Windows File Explorer Spoofing Vulnerability |
|
CVE-2025-24054
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-24085
CRITICAL 10.0
KEV
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS… |
|
CVE-2025-21333
HIGH 7.8
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2024-49138
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-48795
MEDIUM 5.9
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-38193
HIGH 7.8
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2024-6387
CRITICAL 8.1
RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling |
|
CVE-2024-4367
HIGH 8.8
1 app
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Fire… |
|
CVE-2024-21338
HIGH 7.8
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-21320
HIGH 6.5
Windows Themes Spoofing Vulnerability |
|
CVE-2023-44487
HIGH 7.5
KEV
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w… |
|
CVE-2023-29336
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2022-0847
HIGH 7.8
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-28293
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-21752
HIGH 7.1
Windows Backup Service Elevation of Privilege Vulnerability |
|
CVE-2022-21907
CRITICAL 9.8
HTTP Protocol Stack Remote Code Execution Vulnerability |
|
CVE-2021-44228
CRITICAL 10.0
KEV
1 app
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter… |
|
CVE-2017-14491
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-1472
CRITICAL 10.0
KEV
Netlogon Elevation of Privilege Vulnerability |
|
CVE-2020-0796
CRITICAL 10.0
KEV
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S… |
|
CVE-2019-17026
HIGH 8.8
KEV
1 app
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a… |
|
CVE-2014-4650
CRITICAL 9.8
1 app
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attacke… |
|
CVE-2020-0683
HIGH 7.0
KEV
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2019-11599
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-18426
HIGH 8.2
KEV
1 app
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and l… |
|
CVE-2020-0610
CRITICAL 9.8
Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability |
|
CVE-2020-0609
CRITICAL 9.8
Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability |
|
CVE-2020-0601
HIGH 8.1
KEV
Windows CryptoAPI Spoofing Vulnerability |