Vulnerabilities
Tracked app vulnerabilities
15,667 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,667
- Actively exploited
- 286
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-20643
MEDIUM 5.4
A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadO… |
|
CVE-2026-4224
HIGH 7.5
1 app
When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow… |
|
CVE-2026-3644
HIGH 7.5
1 app
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths wer… |
|
CVE-2026-26133
HIGH 7.1
13 apps
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
|
CVE-2025-13462
LOW 3.3
1 app
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME … |
|
CVE-2023-43010
HIGH 8.8
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS … |
|
CVE-2026-3784
MEDIUM 6.5
curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. Th… |
|
CVE-2026-26123
MEDIUM 5.5
2 apps
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-26134
HIGH 7.8
1 app
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-26110
CRITICAL 8.4
1 app
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-25180
HIGH 5.5
1 app
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-24294
HIGH 7.8
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24293
HIGH 7.8
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24289
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24285
HIGH 7.0
1 app
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-3783
MEDIUM 5.3
token leak with redirect and netrc |
|
CVE-2026-26132
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-26128
HIGH 7.8
Windows SMB Server Elevation of Privilege Vulnerability |
|
CVE-2026-26111
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-25190
HIGH 7.8
Windows GDI Remote Code Execution Vulnerability |
|
CVE-2026-25189
HIGH 7.8
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2026-25188
HIGH 8.8
Windows Telephony Service Elevation of Privilege Vulnerability |
|
CVE-2026-25187
HIGH 7.8
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2026-25186
HIGH 5.5
Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability |
|
CVE-2026-25185
HIGH 5.3
Windows Shell Link Processing Spoofing Vulnerability |
|
CVE-2026-25181
HIGH 7.5
GDI+ Information Disclosure Vulnerability |
|
CVE-2026-25179
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25178
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25177
HIGH 8.8
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2026-25176
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25175
HIGH 7.8
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2026-25174
HIGH 7.8
Windows Extensible File Allocation Table Elevation of Privilege Vulnerability |
|
CVE-2026-25173
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-25172
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-25171
HIGH 7.0
Windows Authentication Elevation of Privilege Vulnerability |
|
CVE-2026-25170
HIGH 7.0
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2026-25169
HIGH 6.2
Windows Graphics Component Denial of Service Vulnerability |
|
CVE-2026-25168
HIGH 6.2
Windows Graphics Component Denial of Service Vulnerability |
|
CVE-2026-25167
HIGH 7.4
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2026-25165
HIGH 7.8
Performance Counters for Windows Elevation of Privilege Vulnerability |
|
CVE-2026-24297
HIGH 6.5
Windows Kerberos Security Feature Bypass Vulnerability |
|
CVE-2026-24296
HIGH 7.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-24295
HIGH 7.0
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-24292
HIGH 7.8
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2026-24291
HIGH 7.8
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability |
|
CVE-2026-24290
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2026-24288
HIGH 6.8
Windows Mobile Broadband Driver Remote Code Execution Vulnerability |
|
CVE-2026-24287
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-24283
HIGH 8.8
Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability |
|
CVE-2026-24282
HIGH 5.5
Push message Routing Service Elevation of Privilege Vulnerability |