Vulnerabilities
Tracked app vulnerabilities
15,682 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,682
- Actively exploited
- 286
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-64788
MEDIUM 5.4
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted … |
|
CVE-2026-64787
MEDIUM 6.5
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. P… |
|
CVE-2026-64784
MEDIUM 4.3
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and… |
|
CVE-2026-64782
LOW 3.1
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPa… |
|
CVE-2026-64781
MEDIUM 4.3
The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, mac… |
|
CVE-2026-64780
MEDIUM 4.3
The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 2… |
|
CVE-2026-64779
LOW 3.1
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPa… |
|
CVE-2026-64778
MEDIUM 6.5
The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 2… |
|
CVE-2026-64760
MEDIUM 5.5
An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak sensitive ke… |
|
CVE-2026-64715
MEDIUM 6.5
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPad… |
|
CVE-2026-43795
MEDIUM 4.3
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macO… |
|
CVE-2026-43794
HIGH 8.8
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPa… |
|
CVE-2026-43667
MEDIUM 6.5
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network … |
|
CVE-2026-28984
MEDIUM 4.3
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. Processing maliciously crafted web content may le… |
|
CVE-2026-72971
MEDIUM 5.5
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to p… |
|
CVE-2026-71331
HIGH 8.1
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-70348
MEDIUM 5.5
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. |
|
CVE-2026-70347
HIGH 7.8
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70346
HIGH 7.8
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70345
HIGH 7.8
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70344
HIGH 7.8
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70330
MEDIUM 6.7
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70307
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70304
MEDIUM 6.7
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68820
HIGH 7.0
KEV
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68819
MEDIUM 5.9
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-66804
HIGH 7.8
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-66802
HIGH 8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized a… |
|
CVE-2026-66799
HIGH 7.8
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65814
HIGH 7.8
Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65799
MEDIUM 6.7
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65798
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65797
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65796
HIGH 8.1
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-65795
MEDIUM 6.7
No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65794
MEDIUM 6.5
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-65791
CRITICAL 9.8
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-65790
HIGH 7.8
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65789
HIGH 8.1
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-65788
HIGH 7.0
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65787
HIGH 7.8
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65786
HIGH 7.8
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65785
MEDIUM 6.5
Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. |
|
CVE-2026-65784
MEDIUM 5.5
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-65783
HIGH 7.0
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65782
HIGH 7.0
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65781
HIGH 7.0
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65780
HIGH 7.0
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65779
HIGH 7.0
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65778
HIGH 7.0
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. |