Vulnerabilities
Tracked app vulnerabilities
15,652 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,652
- Actively exploited
- 286
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2023-35658
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33021
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33019
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33016
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33015
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-28584
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-28581
CRITICAL
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-28573
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-28549
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-28538
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-21653
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-21646
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-40534
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-4452
HIGH 8.8
Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit object corruption via a crafted… |
|
CVE-2023-40217
MEDIUM 5.3
1 app
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HT… |
|
CVE-2023-38831
HIGH 7.8
KEV
1 app
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because … |
|
CVE-2023-41105
HIGH 7.5
1 app
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly… |
|
CVE-2022-48566
MEDIUM 5.9
1 app
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variab… |
|
CVE-2022-48565
CRITICAL 9.8
1 app
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoi… |
|
CVE-2022-48564
MEDIUM 6.5
1 app
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property Li… |
|
CVE-2022-48560
HIGH 7.5
1 app
A use-after-free exists in Python through 3.9 via heappushpop in heapq. |
|
CVE-2023-38898
MEDIUM 5.3
1 app
An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by th… |
|
CVE-2023-39214
HIGH 7.6
3 apps
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access. |
|
CVE-2023-39218
MEDIUM 6.1
3 apps
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access. |
|
CVE-2023-38254
MEDIUM 6.5
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-38186
HIGH 8.8
Windows Mobile Device Management Elevation of Privilege Vulnerability |
|
CVE-2023-38184
HIGH 7.5
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
|
CVE-2023-38172
HIGH 7.5
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-36914
MEDIUM 5.5
Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability |
|
CVE-2023-36913
MEDIUM 6.5
Microsoft Message Queuing Information Disclosure Vulnerability |
|
CVE-2023-36912
HIGH 7.5
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-36911
CRITICAL 9.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2023-36910
CRITICAL 9.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2023-36909
MEDIUM 6.5
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-36908
MEDIUM 6.5
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2023-36907
MEDIUM 5.5
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2023-36906
MEDIUM 5.5
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2023-36905
MEDIUM 5.5
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability |
|
CVE-2023-36904
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36903
HIGH 7.8
Windows System Assessment Tool Elevation of Privilege Vulnerability |
|
CVE-2023-36900
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36898
HIGH 7.8
Tablet Windows User Interface Application Core Remote Code Execution Vulnerability |
|
CVE-2023-36889
MEDIUM 5.5
Windows Group Policy Security Feature Bypass Vulnerability |
|
CVE-2023-36882
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2023-36535
HIGH 7.1
3 apps
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network acc… |
|
CVE-2023-36532
MEDIUM 5.9
3 apps
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. |
|
CVE-2023-35387
HIGH 8.8
Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability |
|
CVE-2023-35386
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-35385
CRITICAL 9.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2023-35384
MEDIUM 5.4
Windows HTML Platforms Security Feature Bypass Vulnerability |