Vulnerabilities
Tracked app vulnerabilities
15,668 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,668
- Actively exploited
- 286
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2023-36539
MEDIUM 5.3
4 apps
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. |
|
CVE-2023-34658
MEDIUM 5.3
1 app
Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController. |
|
CVE-2023-36632
HIGH 7.5
1 app
The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling … |
|
CVE-2023-32395
MEDIUM 5.5
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may … |
|
CVE-2023-32353
HIGH 7.8
1 app
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to elevate privileges. |
|
CVE-2023-32351
HIGH 7.8
1 app
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to gain elevated privileges. |
|
CVE-2023-34416
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume t… |
|
CVE-2023-34414
LOW 3.1
1 app
The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks tha… |
|
CVE-2023-29545
MEDIUM 6.5
1 app
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the c… |
|
CVE-2023-29542
CRITICAL 9.8
1 app
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .downlo… |
|
CVE-2023-32214
HIGH 7.5
1 app
Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating… |
|
CVE-2023-29532
MEDIUM 5.5
1 app
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB s… |
|
CVE-2023-29531
CRITICAL 9.8
1 app
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug onl… |
|
CVE-2023-34114
HIGH 7.4
1 app
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable infor… |
|
CVE-2023-28600
MEDIUM 5.2
1 app
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files poten… |
|
CVE-2023-28599
MEDIUM 4.3
3 apps
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi… |
|
CVE-2023-32022
HIGH 7.6
Windows Server Service Security Feature Bypass Vulnerability |
|
CVE-2023-32021
HIGH 7.1
Windows SMB Witness Service Security Feature Bypass Vulnerability |
|
CVE-2023-32020
HIGH 5.6
Windows DNS Spoofing Vulnerability |
|
CVE-2023-32019
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-32018
HIGH 7.8
Windows Hello Remote Code Execution Vulnerability |
|
CVE-2023-32017
HIGH 7.8
Microsoft PostScript Printer Driver Remote Code Execution Vulnerability |
|
CVE-2023-32016
HIGH 5.5
Windows Installer Information Disclosure Vulnerability |
|
CVE-2023-32015
CRITICAL 9.8
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2023-32014
CRITICAL 9.8
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2023-32013
CRITICAL 5.3
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2023-32012
HIGH 7.8
Windows Container Manager Service Elevation of Privilege Vulnerability |
|
CVE-2023-32011
HIGH 7.5
Windows iSCSI Discovery Service Denial of Service Vulnerability |
|
CVE-2023-32010
HIGH 7.0
Windows Bus Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-32009
HIGH 8.8
Windows Collaborative Translation Framework Elevation of Privilege Vulnerability |
|
CVE-2023-32008
HIGH 7.8
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
|
CVE-2023-29373
HIGH 8.8
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2023-29372
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2023-29371
HIGH 7.8
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2023-29370
HIGH 7.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2023-29369
HIGH 6.5
Remote Procedure Call Runtime Denial of Service Vulnerability |
|
CVE-2023-29368
HIGH 7.0
Windows Filtering Platform Elevation of Privilege Vulnerability |
|
CVE-2023-29367
HIGH 7.8
iSCSI Target WMI Provider Remote Code Execution Vulnerability |
|
CVE-2023-29366
HIGH 7.8
Windows Geolocation Service Remote Code Execution Vulnerability |
|
CVE-2023-29365
HIGH 7.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2023-29364
HIGH 7.0
Windows Authentication Elevation of Privilege Vulnerability |
|
CVE-2023-29363
CRITICAL 9.8
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2023-29362
HIGH 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2023-29361
HIGH 7.0
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-29360
HIGH 8.4
KEV
Microsoft Streaming Service Elevation of Privilege Vulnerability |
|
CVE-2023-29359
HIGH 7.8
GDI Elevation of Privilege Vulnerability |
|
CVE-2023-29358
HIGH 7.8
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2023-29355
HIGH 5.3
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-29352
HIGH 6.5
Windows Remote Desktop Security Feature Bypass Vulnerability |
|
CVE-2023-29351
HIGH 8.1
Windows Group Policy Elevation of Privilege Vulnerability |