Vulnerabilities
Tracked app vulnerabilities
7,750 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,750
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2019-11707
HIGH 8.8
KEV
1 app
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware… |
|
CVE-2019-11706
HIGH 7.5
1 app
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulti… |
|
CVE-2019-11705
CRITICAL 9.8
1 app
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in … |
|
CVE-2019-11704
CRITICAL 9.8
1 app
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting… |
|
CVE-2019-11703
CRITICAL 9.8
1 app
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a pot… |
|
CVE-2019-11698
MEDIUM 5.3
1 app
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web conten… |
|
CVE-2019-11694
HIGH 7.5
1 app
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an … |
|
CVE-2019-11693
CRITICAL 9.8
1 app
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a … |
|
CVE-2019-11692
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable … |
|
CVE-2019-11691
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been fr… |
|
CVE-2019-1130
HIGH 7.8
KEV
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privileg… |
|
CVE-2018-20852
MEDIUM 5.3
1 app
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into se… |
|
CVE-2019-1129
HIGH 7.8
KEV
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1128
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1127
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1126
HIGH 5.3
ADFS Security Feature Bypass Vulnerability |
|
CVE-2019-1124
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1123
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1122
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1121
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1120
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1119
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1118
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1117
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1108
HIGH 6.5
Remote Desktop Protocol Client Information Disclosure Vulnerability |
|
CVE-2019-1102
CRITICAL 8.4
GDI+ Remote Code Execution Vulnerability |
|
CVE-2019-1097
HIGH 5.5
DirectWrite Information Disclosure Vulnerability |
|
CVE-2019-1096
HIGH 5.5
Win32k Information Disclosure Vulnerability |
|
CVE-2019-1095
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-1094
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-1093
HIGH 5.5
DirectWrite Information Disclosure Vulnerability |
|
CVE-2019-1091
HIGH 5.5
Microsoft unistore.dll Information Disclosure Vulnerability |
|
CVE-2019-1090
HIGH 7.8
Windows dnsrslvr.dll Elevation of Privilege Vulnerability |
|
CVE-2019-1089
HIGH 7.8
Windows RPCSS Elevation of Privilege Vulnerability |
|
CVE-2019-1088
HIGH 7.8
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2019-1087
HIGH 7.8
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2019-1086
HIGH 7.8
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2019-1085
HIGH 7.8
Windows WLAN Service Elevation of Privilege Vulnerability |
|
CVE-2019-1082
HIGH 7.7
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1074
HIGH 5.3
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1073
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2019-1071
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2019-1067
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2019-1037
HIGH 7.0
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2019-1006
HIGH
WCF/WIF SAML Token Authentication Bypass Vulnerability |
|
CVE-2019-0999
HIGH 7.8
DirectX Elevation of Privilege Vulnerability |
|
CVE-2019-0975
HIGH 4.3
ADFS Security Feature Bypass Vulnerability |
|
CVE-2019-0966
HIGH 6.8
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2019-0887
HIGH 8.0
Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2019-0880
HIGH 7.0
KEV
Microsoft splwow64 Elevation of Privilege Vulnerability |