Vulnerabilities
Tracked app vulnerabilities
7,750 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,750
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-24059
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24056
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-24055
HIGH 4.3
Windows USB Video Class System Driver Information Disclosure Vulnerability |
|
CVE-2025-24054
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-24051
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-24050
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-24048
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-24046
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24045
CRITICAL 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-24044
HIGH 7.8
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24035
CRITICAL 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-21247
HIGH 4.3
MapUrlToZone Security Feature Bypass Vulnerability |
|
CVE-2025-21180
HIGH 7.8
Windows exFAT File System Remote Code Execution Vulnerability |
|
CVE-2024-9157
HIGH
Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability |
|
CVE-2025-26696
HIGH 7.0
1 app
Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown… |
|
CVE-2025-26695
MEDIUM 5.3
1 app
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested emai… |
|
CVE-2025-1943
HIGH 8.2
1 app
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-1942
CRITICAL 9.8
1 app
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability … |
|
CVE-2025-1938
MEDIUM 6.5
1 app
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption a… |
|
CVE-2025-1937
HIGH 7.5
1 app
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of… |
|
CVE-2025-1936
HIGH 7.3
1 app
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but… |
|
CVE-2025-1935
MEDIUM 4.3
1 app
A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR… |
|
CVE-2025-1934
MEDIUM 6.5
1 app
It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was no… |
|
CVE-2025-1933
HIGH 7.6
1 app
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a di… |
|
CVE-2025-1932
HIGH 8.1
1 app
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This … |
|
CVE-2025-1931
HIGH 7.5
1 app
It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerabil… |
|
CVE-2025-1930
HIGH 8.8
1 app
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led t… |
|
CVE-2025-21420
HIGH 7.8
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability |
|
CVE-2025-21419
HIGH 7.1
Windows Setup Files Cleanup Elevation of Privilege Vulnerability |
|
CVE-2025-21418
HIGH 7.8
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-21414
HIGH 7.0
Windows Core Messaging Elevation of Privileges Vulnerability |
|
CVE-2025-21410
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-21407
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21406
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21391
HIGH 7.1
KEV
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2025-21379
CRITICAL 7.1
DHCP Client Service Remote Code Execution Vulnerability |
|
CVE-2025-21377
HIGH 6.5
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-21376
CRITICAL 8.1
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
|
CVE-2025-21375
HIGH 7.8
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-21373
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2025-21371
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21369
HIGH 8.8
Microsoft Digest Authentication Remote Code Execution Vulnerability |
|
CVE-2025-21368
HIGH 8.8
Microsoft Digest Authentication Remote Code Execution Vulnerability |
|
CVE-2025-21367
HIGH 7.8
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-21359
HIGH 7.8
Windows Kernel Security Feature Bypass Vulnerability |
|
CVE-2025-21358
HIGH 7.8
Windows Core Messaging Elevation of Privileges Vulnerability |
|
CVE-2025-21352
HIGH 6.5
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
|
CVE-2025-21351
HIGH 7.5
Windows Active Directory Domain Services API Denial of Service Vulnerability |
|
CVE-2025-21350
HIGH 5.9
Windows Kerberos Denial of Service Vulnerability |
|
CVE-2025-21349
HIGH 6.8
Windows Remote Desktop Configuration Service Tampering Vulnerability |