Vulnerabilities
Tracked app vulnerabilities
7,765 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,765
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-25172
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-25171
HIGH 7.0
Windows Authentication Elevation of Privilege Vulnerability |
|
CVE-2026-25170
HIGH 7.0
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2026-25169
HIGH 6.2
Windows Graphics Component Denial of Service Vulnerability |
|
CVE-2026-25168
HIGH 6.2
Windows Graphics Component Denial of Service Vulnerability |
|
CVE-2026-25167
HIGH 7.4
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2026-25165
HIGH 7.8
Performance Counters for Windows Elevation of Privilege Vulnerability |
|
CVE-2026-24297
HIGH 6.5
Windows Kerberos Security Feature Bypass Vulnerability |
|
CVE-2026-24296
HIGH 7.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-24295
HIGH 7.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-24292
HIGH 7.8
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2026-24291
HIGH 7.8
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability |
|
CVE-2026-24290
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2026-24288
HIGH 6.8
Windows Mobile Broadband Driver Remote Code Execution Vulnerability |
|
CVE-2026-24287
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-24283
HIGH 8.8
Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability |
|
CVE-2026-24282
HIGH 5.5
Push message Routing Service Elevation of Privilege Vulnerability |
|
CVE-2026-23674
HIGH 7.5
MapUrlToZone Security Feature Bypass Vulnerability |
|
CVE-2026-23673
HIGH 7.8
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
|
CVE-2026-23672
HIGH 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-23671
HIGH 7.0
Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability |
|
CVE-2026-23669
HIGH 8.8
RPC Runtime Library Remote Code Execution Vulnerability |
|
CVE-2026-23668
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-23667
HIGH 7.0
Broadcast DVR Elevation of Privilege Vulnerability |
|
CVE-2026-2807
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2026-2806
CRITICAL 9.1
1 app
Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2805
CRITICAL 9.8
1 app
Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2804
MEDIUM 5.4
1 app
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2803
HIGH 7.5
1 app
Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2802
MEDIUM 4.2
1 app
Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2801
HIGH 7.5
1 app
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2799
CRITICAL 9.8
1 app
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2798
HIGH 8.8
1 app
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2797
CRITICAL 9.8
1 app
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2796
CRITICAL 9.8
1 app
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2795
CRITICAL 9.8
1 app
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148. |
|
CVE-2026-2793
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence… |
|
CVE-2026-2792
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2026-2791
CRITICAL 9.8
1 app
Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2790
CRITICAL 9.8
1 app
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14… |
|
CVE-2026-2789
CRITICAL 9.8
1 app
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Th… |
|
CVE-2026-2788
CRITICAL 9.8
1 app
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbir… |
|
CVE-2026-2787
CRITICAL 9.8
1 app
Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, … |
|
CVE-2026-2786
CRITICAL 9.8
1 app
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2785
CRITICAL 9.8
1 app
Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2784
CRITICAL 9.8
1 app
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2783
HIGH 7.5
1 app
Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thund… |
|
CVE-2026-2782
CRITICAL 9.8
1 app
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2781
CRITICAL 9.8
1 app
Integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, Thunderbird 140.8, and Fir… |
|
CVE-2026-2780
CRITICAL 9.8
1 app
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |