Vulnerabilities
Tracked app vulnerabilities
15,667 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,667
- Actively exploited
- 286
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2021-0681
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0680
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0644
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0636
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0635
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0598
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0595
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0428
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-29989
HIGH 8.8
1 app
Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption and we pres… |
|
CVE-2021-29988
HIGH 8.8
1 app
Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploita… |
|
CVE-2021-29987
MEDIUM 6.5
1 app
After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still… |
|
CVE-2021-29986
HIGH 8.1
1 app
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operati… |
|
CVE-2021-29985
HIGH 8.8
1 app
A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbir… |
|
CVE-2021-29984
HIGH 8.8
1 app
Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to me… |
|
CVE-2021-29982
MEDIUM 6.5
1 app
Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a single bit of memory. Th… |
|
CVE-2021-29981
HIGH 8.8
1 app
An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code that would lead to a po… |
|
CVE-2021-29980
HIGH 8.8
1 app
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerabil… |
|
CVE-2021-36958
HIGH 7.8
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull… |
|
CVE-2021-36948
HIGH 7.8
KEV
Windows Update Medic Service Elevation of Privilege Vulnerability |
|
CVE-2021-36947
HIGH 8.8
Windows Print Spooler Remote Code Execution Vulnerability |
|
CVE-2021-36942
HIGH 7.5
KEV
Windows LSA Spoofing Vulnerability |
|
CVE-2021-36938
MEDIUM 5.5
Windows Cryptographic Primitives Library Information Disclosure Vulnerability |
|
CVE-2021-36937
HIGH 7.8
Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability |
|
CVE-2021-36936
HIGH 8.8
Windows Print Spooler Remote Code Execution Vulnerability |
|
CVE-2021-36933
HIGH 7.5
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |
|
CVE-2021-36932
HIGH 7.5
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |
|
CVE-2021-36926
HIGH 7.5
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |
|
CVE-2021-34537
HIGH 7.8
Windows Bluetooth Driver Elevation of Privilege Vulnerability |
|
CVE-2021-34536
HIGH 7.8
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
|
CVE-2021-34535
HIGH 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2021-34534
MEDIUM 6.8
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-34533
HIGH 7.8
Windows Graphics Component Font Parsing Remote Code Execution Vulnerability |
|
CVE-2021-34530
HIGH 7.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2021-34487
HIGH 7.0
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2021-34486
HIGH 7.8
KEV
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2021-34484
HIGH 7.8
KEV
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2021-34483
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2021-34480
MEDIUM 6.8
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-26433
HIGH 7.5
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |
|
CVE-2021-26432
CRITICAL 9.8
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability |
|
CVE-2021-26431
HIGH 7.8
Windows Recovery Environment Agent Elevation of Privilege Vulnerability |
|
CVE-2021-26426
HIGH 7.0
Windows User Account Profile Picture Elevation of Privilege Vulnerability |
|
CVE-2021-26425
HIGH 7.8
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2021-26424
CRITICAL 9.9
Windows TCP/IP Remote Code Execution Vulnerability |
|
CVE-2021-38204
MEDIUM 6.8
drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) … |
|
CVE-2021-29976
HIGH 8.8
1 app
Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption … |
|
CVE-2021-29970
HIGH 8.8
1 app
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when acces… |
|
CVE-2021-29969
MEDIUM 5.9
1 app
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS ha… |
|
CVE-2021-30261
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-30260
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |