Vulnerabilities
Tracked app vulnerabilities
7,765 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,765
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-48813
HIGH 6.3
Virtual Secure Mode Spoofing Vulnerability |
|
CVE-2025-48004
HIGH 7.4
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-47979
HIGH 5.5
Microsoft Failover Cluster Information Disclosure Vulnerability |
|
CVE-2025-47827
HIGH 4.6
KEV
MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11 |
|
CVE-2025-25004
HIGH 7.3
PowerShell Elevation of Privilege Vulnerability |
|
CVE-2025-24990
HIGH 7.8
KEV
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24052
HIGH 7.8
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-10537
HIGH 8.8
1 app
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2025-10536
MEDIUM 6.2
1 app
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140… |
|
CVE-2025-10534
HIGH 8.1
1 app
Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. |
|
CVE-2025-10533
HIGH 8.8
1 app
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140… |
|
CVE-2025-10532
MEDIUM 6.5
1 app
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird… |
|
CVE-2025-10531
MEDIUM 5.4
1 app
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. |
|
CVE-2025-10529
MEDIUM 6.5
1 app
Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3. |
|
CVE-2025-10528
HIGH 7.3
1 app
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, … |
|
CVE-2025-10527
HIGH 7.1
1 app
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and … |
|
CVE-2025-53799
CRITICAL 5.5
1 app
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. |
|
CVE-2025-59220
HIGH 7.0
Windows Bluetooth Service Elevation of Privilege Vulnerability |
|
CVE-2025-59216
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-59215
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-55236
CRITICAL 7.3
Graphics Kernel Remote Code Execution Vulnerability |
|
CVE-2025-55234
HIGH 8.8
Windows SMB Elevation of Privilege Vulnerability |
|
CVE-2025-55228
CRITICAL 7.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2025-55226
CRITICAL 6.7
Graphics Kernel Remote Code Execution Vulnerability |
|
CVE-2025-55225
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-55224
CRITICAL 7.8
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2025-55223
HIGH 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-54919
HIGH 7.5
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2025-54918
CRITICAL 8.8
Windows NTLM Elevation of Privilege Vulnerability |
|
CVE-2025-54917
HIGH 4.3
MapUrlToZone Security Feature Bypass Vulnerability |
|
CVE-2025-54916
HIGH 7.8
Windows NTFS Remote Code Execution Vulnerability |
|
CVE-2025-54915
HIGH 6.7
Windows Defender Firewall Service Elevation of Privilege Vulnerability |
|
CVE-2025-54913
HIGH 7.8
Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability |
|
CVE-2025-54912
HIGH 7.8
Windows BitLocker Elevation of Privilege Vulnerability |
|
CVE-2025-54911
HIGH 7.3
Windows BitLocker Elevation of Privilege Vulnerability |
|
CVE-2025-54895
HIGH 7.8
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability |
|
CVE-2025-54894
HIGH 7.8
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability |
|
CVE-2025-54116
HIGH 7.3
Windows MultiPoint Services Elevation of Privilege Vulnerability |
|
CVE-2025-54115
HIGH 7.0
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-54114
HIGH 7.0
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2025-54113
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-54112
HIGH 7.0
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
|
CVE-2025-54111
HIGH 7.8
Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability |
|
CVE-2025-54110
HIGH 8.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-54109
HIGH 6.7
Windows Defender Firewall Service Elevation of Privilege Vulnerability |
|
CVE-2025-54108
HIGH 7.0
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
|
CVE-2025-54107
HIGH 4.3
MapUrlToZone Security Feature Bypass Vulnerability |
|
CVE-2025-54106
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-54105
HIGH 7.0
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-54104
HIGH 6.7
Windows Defender Firewall Service Elevation of Privilege Vulnerability |