Vulnerabilities
Tracked app vulnerabilities
7,765 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,765
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-23670
HIGH 5.7
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
|
CVE-2026-20930
HIGH 7.8
Windows Management Services Elevation of Privilege Vulnerability |
|
CVE-2026-20928
HIGH 4.6
Windows Recovery Environment Security Feature Bypass Vulnerability |
|
CVE-2026-20806
HIGH 5.5
Windows COM Server Information Disclosure Vulnerability |
|
CVE-2026-0390
HIGH 6.7
UEFI Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2023-20585
HIGH 5.3
AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability |
|
CVE-2026-5735
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough … |
|
CVE-2026-5734
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memo… |
|
CVE-2026-5731
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs s… |
|
CVE-2019-25677
MEDIUM 6.2
1 app
WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in … |
|
CVE-2026-4371
HIGH 7.4
1 app
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connectio… |
|
CVE-2026-3889
MEDIUM 6.5
1 app
Spoofing issue in Thunderbird. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9. |
|
CVE-2026-4729
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2026-4728
MEDIUM 6.5
1 app
Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
|
CVE-2026-4727
HIGH 7.5
1 app
Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
|
CVE-2026-4726
HIGH 7.5
1 app
Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
|
CVE-2026-4724
CRITICAL 9.1
1 app
Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
|
CVE-2026-4721
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence… |
|
CVE-2026-4720
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2026-4718
HIGH 8.1
1 app
Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. |
|
CVE-2026-4710
CRITICAL 9.8
1 app
Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 14… |
|
CVE-2026-4694
HIGH 7.5
1 app
Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, … |
|
CVE-2026-4692
CRITICAL 10.0
1 app
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, an… |
|
CVE-2026-4689
CRITICAL 10.0
1 app
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, … |
|
CVE-2026-4519
LOW 3.3
1 app
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior reject… |
|
CVE-2026-4224
HIGH 7.5
1 app
When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow… |
|
CVE-2026-3644
HIGH 7.5
1 app
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths wer… |
|
CVE-2025-13462
LOW 3.3
1 app
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME … |
|
CVE-2026-25180
HIGH 5.5
1 app
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-24294
HIGH 7.8
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24293
HIGH 7.8
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24289
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24285
HIGH 7.0
1 app
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-26132
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-26128
HIGH 7.8
Windows SMB Server Elevation of Privilege Vulnerability |
|
CVE-2026-26111
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-25190
HIGH 7.8
Windows GDI Remote Code Execution Vulnerability |
|
CVE-2026-25189
HIGH 7.8
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2026-25188
HIGH 8.8
Windows Telephony Service Elevation of Privilege Vulnerability |
|
CVE-2026-25187
HIGH 7.8
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2026-25186
HIGH 5.5
Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability |
|
CVE-2026-25185
HIGH 5.3
Windows Shell Link Processing Spoofing Vulnerability |
|
CVE-2026-25181
HIGH 7.5
GDI+ Information Disclosure Vulnerability |
|
CVE-2026-25179
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25178
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25177
HIGH 8.8
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2026-25176
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25175
HIGH 7.8
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2026-25174
HIGH 7.8
Windows Extensible File Allocation Table Elevation of Privilege Vulnerability |
|
CVE-2026-25173
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |