Vulnerabilities
Tracked app vulnerabilities
15,691 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,691
- Actively exploited
- 286
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2023-40081
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33105
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33066
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33042
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-28578
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-26188
MEDIUM 4.3
1 app
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
|
CVE-2023-42853
MEDIUM 5.5
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to … |
|
CVE-2024-1553
HIGH 8.1
1 app
Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-1552
HIGH 7.5
1 app
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices.… |
|
CVE-2024-1551
MEDIUM 6.1
1 app
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well … |
|
CVE-2024-1550
MEDIUM 6.1
1 app
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedl… |
|
CVE-2024-1549
MEDIUM 6.1
1 app
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and un… |
|
CVE-2024-1548
MEDIUM 4.3
1 app
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing… |
|
CVE-2024-1547
MEDIUM 6.5
1 app
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL sh… |
|
CVE-2024-1546
HIGH 7.5
1 app
When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulne… |
|
CVE-2024-24699
MEDIUM 6.5
4 apps
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. |
|
CVE-2024-24698
MEDIUM 4.9
4 apps
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. |
|
CVE-2024-24697
HIGH 7.2
1 app
Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access. |
|
CVE-2024-24696
MEDIUM 6.8
1 app
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to … |
|
CVE-2024-24695
MEDIUM 6.8
1 app
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to … |
|
CVE-2024-24691
CRITICAL 9.6
1 app
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user t… |
|
CVE-2024-24690
MEDIUM 5.4
4 apps
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2024-21420
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21412
HIGH 8.1
KEV
Internet Shortcut Files Security Feature Bypass Vulnerability |
|
CVE-2024-21406
HIGH 7.5
Windows Printing Service Spoofing Vulnerability |
|
CVE-2024-21405
HIGH 7.0
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2024-21391
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21377
MEDIUM 5.5
Windows DNS Information Disclosure Vulnerability |
|
CVE-2024-21375
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21372
HIGH 8.8
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2024-21371
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-21370
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21369
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21368
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21367
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21366
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21365
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21363
HIGH 7.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2024-21362
MEDIUM 5.5
Windows Kernel Security Feature Bypass Vulnerability |
|
CVE-2024-21361
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21360
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21359
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21358
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21357
HIGH 8.1
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2024-21356
MEDIUM 6.5
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2024-21355
HIGH 7.0
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2024-21354
HIGH 7.8
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2024-21352
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21351
HIGH 7.6
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2024-21350
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |