Vulnerabilities
Tracked app vulnerabilities
7,765 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,765
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-0886
MEDIUM 5.3
1 app
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, a… |
|
CVE-2026-0885
MEDIUM 6.5
1 app
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0884
CRITICAL 9.8
1 app
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0883
MEDIUM 5.3
1 app
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0882
HIGH 8.8
1 app
Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0881
CRITICAL 10.0
1 app
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. |
|
CVE-2026-0880
HIGH 8.8
1 app
Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbi… |
|
CVE-2026-0879
CRITICAL 9.8
1 app
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140… |
|
CVE-2026-0878
HIGH 8.0
1 app
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thu… |
|
CVE-2026-0877
HIGH 8.1
1 app
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thun… |
|
CVE-2026-20833
HIGH 5.5
Windows Kerberos Information Disclosure Vulnerability |
|
CVE-2026-20830
HIGH 7.0
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
|
CVE-2026-20818
HIGH 6.2
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-20810
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-0386
HIGH 7.5
Windows Deployment Services Remote Code Execution Vulnerability |
|
CVE-2024-55414
HIGH 7.8
Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2023-31096
HIGH 7.8
MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-54957
HIGH 7.0
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-14333
HIGH 8.1
1 app
Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2025-14332
HIGH 7.3
1 app
Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-14331
MEDIUM 6.5
1 app
Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 14… |
|
CVE-2025-14330
CRITICAL 9.8
1 app
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14… |
|
CVE-2025-14329
HIGH 8.8
1 app
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. |
|
CVE-2025-14328
HIGH 8.8
1 app
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. |
|
CVE-2025-14327
HIGH 7.5
1 app
Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7. |
|
CVE-2025-14326
CRITICAL 9.8
1 app
Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146. |
|
CVE-2025-14325
HIGH 7.3
1 app
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14… |
|
CVE-2025-14324
CRITICAL 9.8
1 app
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146… |
|
CVE-2025-14323
HIGH 8.8
1 app
Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, … |
|
CVE-2025-14322
HIGH 8.0
1 app
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Fi… |
|
CVE-2025-14321
CRITICAL 9.8
1 app
Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. |
|
CVE-2025-64680
HIGH 7.8
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-64679
HIGH 7.8
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-64678
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-64673
HIGH 7.8
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-64670
HIGH 6.5
Windows DirectX Information Disclosure Vulnerability |
|
CVE-2025-64661
HIGH 7.8
Windows Shell Elevation of Privilege Vulnerability |
|
CVE-2025-64658
HIGH 7.5
Windows File Explorer Elevation of Privilege Vulnerability |
|
CVE-2025-62573
HIGH 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-62572
HIGH 7.8
Application Information Service Elevation of Privilege Vulnerability |
|
CVE-2025-62571
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2025-62570
HIGH 7.1
Windows Camera Frame Server Monitor Information Disclosure Vulnerability |
|
CVE-2025-62569
HIGH 7.0
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-62567
HIGH 5.3
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2025-62565
HIGH 7.3
Windows File Explorer Elevation of Privilege Vulnerability |
|
CVE-2025-62549
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-62474
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2025-62473
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-62472
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2025-62470
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |