Vulnerabilities
Tracked app vulnerabilities
393 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 393
- Actively exploited
- 286
- Publication window
- 2004-08-06 → 2026-05-04
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2018-5159
CRITICAL 9.8
1 app
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds wr… |
|
CVE-2017-5465
CRITICAL 9.1
1 app
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied i… |
|
CVE-2017-5447
CRITICAL 9.1
1 app
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to … |
|
CVE-2017-5404
CRITICAL 9.8
1 app
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results i… |
|
CVE-2017-5375
CRITICAL 9.8
1 app
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird <… |
|
CVE-2016-9899
CRITICAL 9.8
1 app
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 5… |
|
CVE-2016-9079
HIGH 7.5
KEV
1 app
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a… |
|
CVE-2018-8174
HIGH 7.5
KEV
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution … |
|
CVE-2018-8897
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8134
HIGH 7.0
Windows Elevation of Privilege Vulnerability |
|
CVE-2018-0824
HIGH 7.5
KEV
Microsoft COM for Windows Remote Code Execution Vulnerability |
|
CVE-2018-0975
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0974
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0973
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0972
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0971
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0970
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0969
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0968
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0966
HIGH 5.3
Device Guard Security Feature Bypass Vulnerability |
|
CVE-2018-6849
MEDIUM 4.3
2 apps
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), th… |
|
CVE-2016-5348
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2015-9222
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-0901
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0897
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0895
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0894
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0886
HIGH 7.1
CredSSP Remote Code Execution Vulnerability |
|
CVE-2018-0882
HIGH 7.0
Windows Desktop Bridge Elevation of Privilege Vulnerability |
|
CVE-2018-0880
HIGH 7.0
Windows Desktop Bridge Elevation of Privilege Vulnerability |
|
CVE-2018-0878
HIGH 3.1
Windows Remote Assistance Information Disclosure Vulnerability |
|
CVE-2018-0877
HIGH 7.0
Windows Desktop Bridge VFS Elevation of Privilege Vulnerability |
|
CVE-2017-13262
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2017-13261
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2017-13260
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2017-13258
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2017-13253
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-0832
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0826
HIGH 7.0
Windows Storage Services Elevation of Privilege Vulnerability |
|
CVE-2018-0823
HIGH 7.0
Named Pipe File System Elevation of Privilege Vulnerability |
|
CVE-2018-0822
HIGH 7.0
Windows NTFS Global Reparse Point Elevation of Privilege Vulnerability |
|
CVE-2018-0821
HIGH 5.3
Windows AppContainer Elevation Of Privilege Vulnerability |
|
CVE-2017-13236
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-0752
HIGH 6.6
Windows Elevation of Privilege Vulnerability |
|
CVE-2018-0751
HIGH 6.6
Windows Elevation of Privilege Vulnerability |
|
CVE-2018-0749
HIGH 6.6
SMB Server Elevation of Privilege Vulnerability |
|
CVE-2018-0748
HIGH 6.6
Windows Elevation of Privilege Vulnerability |
|
CVE-2018-0746
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0745
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-0744
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |