Vulnerabilities
Tracked app vulnerabilities
350 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 350
- Actively exploited
- 286
- Publication window
- 2010-06-30 → 2026-05-04
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2016-6707
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2184
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-7188
HIGH
Windows Diagnostics Hub Elevation of Privilege Vulnerability |
|
CVE-2016-7185
HIGH
Win32k Elevation of Privilege Vulnerability |
|
CVE-2016-7182
HIGH
Graphics Component Font Parsing Elevation of Privilege Vulnerability |
|
CVE-2016-3376
HIGH
Win32k Elevation of Privilege Vulnerability |
|
CVE-2016-3209
HIGH
GDI+ Information Disclosure Vulnerability |
|
CVE-2016-0079
HIGH
Windows Kernel Local Elevation of Privilege Vulnerability |
|
CVE-2016-0075
HIGH
Windows Kernel Local Elevation of Privilege Vulnerability |
|
CVE-2016-0073
HIGH
Windows Kernel Local Elevation of Privilege Vulnerability |
|
CVE-2016-0070
HIGH
Windows Kernel Local Elevation of Privilege Vulnerability |
|
CVE-2016-6689
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-3373
HIGH 6.8
Windows Kernel Local Elevation of Privilege Vulnerability |
|
CVE-2016-3371
HIGH 6.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2016-0772
MEDIUM 6.5
1 app
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might a… |
|
CVE-2016-3861
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-3134
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-1583
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-3309
HIGH
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2016-3301
CRITICAL 8.8
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2016-3237
HIGH 6.4
Kerberos Security Feature Bypass Vulnerability |
|
CVE-2016-4578
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-4486
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-3672
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2107
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-3225
HIGH 7.8
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windo… |
|
CVE-2016-3223
HIGH 8.1
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Go… |
|
CVE-2016-3220
HIGH 7.8
atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server … |
|
CVE-2016-3219
HIGH 7.8
The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privileg… |
|
CVE-2016-3216
MEDIUM 4.3
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an… |
|
CVE-2016-2494
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-0173
HIGH 7.8
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… |
|
CVE-2016-0171
HIGH 7.8
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… |
|
CVE-2016-0170
HIGH 8.8
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Window… |
|
CVE-2016-0169
MEDIUM 6.5
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Window… |
|
CVE-2016-0168
MEDIUM 6.5
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Window… |
|
CVE-2016-0165
HIGH 7.8
KEV
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… |
|
CVE-2016-0151
HIGH 7.8
KEV
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages… |
|
CVE-2016-0145
HIGH 8.8
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.… |
|
CVE-2016-0143
HIGH 7.8
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… |
|
CVE-2016-1960
HIGH 8.8
1 app
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote atta… |
|
CVE-2016-0016
HIGH 7.8
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.… |
|
CVE-2016-0015
HIGH 7.8
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wind… |
|
CVE-2016-0007
HIGH 7.8
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold … |
|
CVE-2016-0006
HIGH 7.3
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold … |
|
CVE-2014-1511
CRITICAL 9.8
1 app
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocke… |
|
CVE-2014-1510
CRITICAL 9.8
1 app
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attac… |
|
CVE-2013-1690
HIGH 8.8
KEV
1 app
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadyst… |
|
CVE-2010-3765
CRITICAL 9.8
KEV
1 app
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when Ja… |
|
CVE-2010-1205
CRITICAL 9.8
1 app
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbi… |