Vulnerabilities
Tracked app vulnerabilities
7,765 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,765
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-2779
CRITICAL 9.8
1 app
Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbir… |
|
CVE-2026-2778
CRITICAL 10.0
1 app
Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox… |
|
CVE-2026-2777
CRITICAL 9.8
1 app
Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, an… |
|
CVE-2026-2776
CRITICAL 10.0
1 app
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 1… |
|
CVE-2026-2775
CRITICAL 9.8
1 app
Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and T… |
|
CVE-2026-2774
CRITICAL 9.8
1 app
Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunder… |
|
CVE-2026-2773
CRITICAL 9.8
1 app
Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, … |
|
CVE-2026-2772
CRITICAL 9.8
1 app
Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and… |
|
CVE-2026-2771
CRITICAL 9.8
1 app
Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and … |
|
CVE-2026-2770
CRITICAL 9.8
1 app
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, an… |
|
CVE-2026-2769
HIGH 8.8
1 app
Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Th… |
|
CVE-2026-2768
CRITICAL 10.0
1 app
Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2767
CRITICAL 9.8
1 app
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2766
CRITICAL 9.8
1 app
Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2765
CRITICAL 9.8
1 app
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. |
|
CVE-2026-2764
CRITICAL 9.8
1 app
JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8,… |
|
CVE-2026-2763
CRITICAL 9.8
1 app
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thu… |
|
CVE-2026-2762
CRITICAL 9.8
1 app
Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbir… |
|
CVE-2026-2761
CRITICAL 10.0
1 app
Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and T… |
|
CVE-2026-2760
CRITICAL 10.0
1 app
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fire… |
|
CVE-2026-2759
CRITICAL 9.8
1 app
Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderb… |
|
CVE-2026-2758
CRITICAL 9.8
1 app
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunde… |
|
CVE-2026-2757
CRITICAL 9.8
1 app
Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunder… |
|
CVE-2026-2447
HIGH 8.8
1 app
Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbir… |
|
CVE-2026-20846
HIGH 7.5
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-21533
HIGH 7.8
KEV
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
|
CVE-2026-21525
MEDIUM 6.2
KEV
Windows Remote Access Connection Manager Denial of Service Vulnerability |
|
CVE-2026-21519
HIGH 7.8
KEV
Desktop Window Manager Elevation of Privilege Vulnerability |
|
CVE-2026-21513
HIGH 8.8
KEV
MSHTML Framework Security Feature Bypass Vulnerability |
|
CVE-2026-21510
HIGH 8.8
KEV
Windows Shell Security Feature Bypass Vulnerability |
|
CVE-2026-21508
HIGH 7.0
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2026-21255
HIGH 8.8
Windows Hyper-V Security Feature Bypass Vulnerability |
|
CVE-2026-21253
HIGH 7.0
Mailslot File System Elevation of Privilege Vulnerability |
|
CVE-2026-21251
HIGH 7.8
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability |
|
CVE-2026-21250
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21249
HIGH 3.3
Windows NTLM Spoofing Vulnerability |
|
CVE-2026-21248
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21247
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21246
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-21245
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21244
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21243
HIGH 7.5
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2026-21242
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21241
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21240
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21239
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21238
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21237
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21236
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21235
HIGH 7.3
Windows Graphics Component Elevation of Privilege Vulnerability |