Vulnerabilities
Tracked app vulnerabilities
273 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 273
- Actively exploited
- 229
- Publication window
- 2013-06-26 → 2026-05-04
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2019-1244
HIGH 6.5
DirectWrite Information Disclosure Vulnerability |
|
CVE-2019-1215
HIGH 7.8
KEV
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-10529
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2017-5715
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-1184
HIGH 6.7
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1170
HIGH 7.9
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2019-1153
HIGH 5.5
Microsoft Graphics Component Information Disclosure Vulnerability |
|
CVE-2019-1148
HIGH 5.5
Microsoft Graphics Component Information Disclosure Vulnerability |
|
CVE-2019-1125
HIGH 5.6
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2019-11707
HIGH 8.8
KEV
1 app
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware… |
|
CVE-2019-11706
HIGH 7.5
1 app
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulti… |
|
CVE-2019-1128
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1127
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1124
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1123
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1122
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1121
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1120
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1119
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1118
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1117
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1089
HIGH 7.8
Windows RPCSS Elevation of Privilege Vulnerability |
|
CVE-2019-1019
HIGH 8.5
Microsoft Windows Security Feature Bypass Vulnerability |
|
CVE-2019-0959
HIGH 7.0
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2019-0943
HIGH 7.8
Windows ALPC Elevation of Privilege Vulnerability |
|
CVE-2019-10038
HIGH 7.8
1 app
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.a… |
|
CVE-2019-0881
HIGH 8.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2019-0863
HIGH 7.8
KEV
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2019-9813
HIGH 8.8
1 app
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulne… |
|
CVE-2019-9810
HIGH 8.8
1 app
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerabili… |
|
CVE-2019-0841
HIGH 6.8
KEV
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0836
HIGH 7.0
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0805
HIGH 6.7
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0803
HIGH 7.0
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2019-0796
HIGH 6.3
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0735
HIGH 7.0
Windows CSRSS Elevation of Privilege Vulnerability |
|
CVE-2019-0732
HIGH 5.3
Windows Security Feature Bypass Vulnerability |
|
CVE-2019-0731
HIGH 6.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0730
HIGH 6.7
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-2025
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2023
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-20250
HIGH 7.8
KEV
1 app
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When… |
|
CVE-2019-2000
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-1999
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-0574
HIGH 7.8
Windows Data Sharing Service Elevation of Privilege Vulnerability |
|
CVE-2019-0573
HIGH 7.8
Windows Data Sharing Service Elevation of Privilege Vulnerability |
|
CVE-2019-0572
HIGH 7.8
Windows Data Sharing Service Elevation of Privilege Vulnerability |
|
CVE-2019-0571
HIGH 7.8
Windows Data Sharing Service Elevation of Privilege Vulnerability |
|
CVE-2019-0570
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2019-0555
HIGH 7.0
Microsoft XmlDocument Elevation of Privilege Vulnerability |