Vulnerabilities
Tracked app vulnerabilities
318 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 318
- Actively exploited
- 213
- Publication window
- 2004-08-06 → 2026-04-14
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2019-0730
HIGH 6.7
Windows Elevation of Privilege Vulnerability |
|
CVE-2018-20250
HIGH 7.8
KEV
1 app
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When… |
|
CVE-2019-0574
HIGH 7.8
Windows Data Sharing Service Elevation of Privilege Vulnerability |
|
CVE-2019-0573
HIGH 7.8
Windows Data Sharing Service Elevation of Privilege Vulnerability |
|
CVE-2019-0572
HIGH 7.8
Windows Data Sharing Service Elevation of Privilege Vulnerability |
|
CVE-2019-0571
HIGH 7.8
Windows Data Sharing Service Elevation of Privilege Vulnerability |
|
CVE-2019-0570
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2019-0555
HIGH 7.0
Microsoft XmlDocument Elevation of Privilege Vulnerability |
|
CVE-2019-0552
HIGH 7.0
Windows COM Elevation of Privilege Vulnerability |
|
CVE-2019-0543
HIGH 7.8
KEV
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2018-8584
HIGH 7.8
Windows ALPC Elevation of Privilege Vulnerability |
|
CVE-2018-8550
HIGH 7.0
Windows COM Elevation of Privilege Vulnerability |
|
CVE-2018-8544
CRITICAL 7.5
Windows VBScript Engine Remote Code Execution Vulnerability |
|
CVE-2018-8453
HIGH 7.8
KEV
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privil… |
|
CVE-2018-8413
HIGH 5.0
Windows Theme API Remote Code Execution Vulnerability |
|
CVE-2018-8411
HIGH 7.0
NTFS Elevation of Privilege Vulnerability |
|
CVE-2018-8468
HIGH 4.3
Windows Elevation of Privilege Vulnerability |
|
CVE-2018-8449
HIGH 5.3
Device Guard Security Feature Bypass Vulnerability |
|
CVE-2018-8410
HIGH 7.0
Windows Registry Elevation of Privilege Vulnerability |
|
CVE-2018-0952
HIGH 6.7
Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability |
|
CVE-2018-8214
HIGH 7.0
Windows Desktop Bridge Elevation of Privilege Vulnerability |
|
CVE-2018-8208
HIGH 7.0
Windows Desktop Bridge Elevation of Privilege Vulnerability |
|
CVE-2018-0982
HIGH 7.0
Windows Elevation of Privilege Vulnerability |
|
CVE-2018-5159
CRITICAL 9.8
1 app
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds wr… |
|
CVE-2017-5465
CRITICAL 9.1
1 app
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied i… |
|
CVE-2017-5447
CRITICAL 9.1
1 app
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to … |
|
CVE-2017-5404
CRITICAL 9.8
1 app
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results i… |
|
CVE-2017-5375
CRITICAL 9.8
1 app
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird <… |
|
CVE-2016-9899
CRITICAL 9.8
1 app
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 5… |
|
CVE-2016-9079
HIGH 7.5
KEV
1 app
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a… |
|
CVE-2018-8174
HIGH 7.5
KEV
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution … |
|
CVE-2018-8897
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8134
HIGH 7.0
Windows Elevation of Privilege Vulnerability |
|
CVE-2018-0824
HIGH 7.5
KEV
Microsoft COM for Windows Remote Code Execution Vulnerability |
|
CVE-2018-0975
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0974
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0973
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0972
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0971
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0970
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0969
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0968
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0966
HIGH 5.3
Device Guard Security Feature Bypass Vulnerability |
|
CVE-2018-0901
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0897
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0895
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0894
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0886
HIGH 7.1
CredSSP Remote Code Execution Vulnerability |
|
CVE-2018-0882
HIGH 7.0
Windows Desktop Bridge Elevation of Privilege Vulnerability |
|
CVE-2018-0880
HIGH 7.0
Windows Desktop Bridge Elevation of Privilege Vulnerability |