Vulnerabilities
Tracked app vulnerabilities
7,750 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,750
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-43646
HIGH 6.7
Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
|
CVE-2024-43645
HIGH 6.7
Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability |
|
CVE-2024-43644
HIGH 7.8
Windows Client-Side Caching Elevation of Privilege Vulnerability |
|
CVE-2024-43643
HIGH 6.8
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-43642
HIGH 7.5
Windows SMB Denial of Service Vulnerability |
|
CVE-2024-43641
HIGH 7.8
Windows Registry Elevation of Privilege Vulnerability |
|
CVE-2024-43640
HIGH 7.8
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2024-43639
CRITICAL 9.8
Windows KDC Proxy Remote Code Execution Vulnerability |
|
CVE-2024-43638
HIGH 6.8
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-43637
HIGH 6.8
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-43636
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2024-43635
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2024-43634
HIGH 6.8
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-43633
HIGH 6.5
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2024-43631
HIGH 6.7
Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
|
CVE-2024-43630
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-43629
HIGH 7.8
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2024-43628
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2024-43627
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2024-43626
HIGH 7.8
Windows Telephony Service Elevation of Privilege Vulnerability |
|
CVE-2024-43625
CRITICAL 8.1
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability |
|
CVE-2024-43624
HIGH 8.8
Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability |
|
CVE-2024-43623
HIGH 7.8
Windows NT OS Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-43622
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2024-43621
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2024-43620
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2024-43530
HIGH 7.8
Windows Update Stack Elevation of Privilege Vulnerability |
|
CVE-2024-43452
HIGH 7.5
Windows Registry Elevation of Privilege Vulnerability |
|
CVE-2024-43451
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2024-43450
HIGH 7.5
Windows DNS Spoofing Vulnerability |
|
CVE-2024-43449
HIGH 6.8
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-43447
HIGH 8.1
Windows SMBv3 Server Remote Code Execution Vulnerability |
|
CVE-2024-38264
HIGH 5.9
Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability |
|
CVE-2024-38203
HIGH 6.2
Windows Package Library Manager Information Disclosure Vulnerability |
|
CVE-2024-10468
MEDIUM 5.3
1 app
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 13… |
|
CVE-2024-10467
HIGH 8.8
1 app
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-10466
HIGH 7.5
1 app
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability… |
|
CVE-2024-10465
MEDIUM 6.5
1 app
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbir… |
|
CVE-2024-10464
MEDIUM 6.5
1 app
Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing r… |
|
CVE-2024-10463
MEDIUM 6.5
1 app
Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Th… |
|
CVE-2024-10462
MEDIUM 6.5
1 app
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird … |
|
CVE-2024-10461
MEDIUM 6.1
1 app
In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could al… |
|
CVE-2024-10460
MEDIUM 5.3
1 app
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Fire… |
|
CVE-2024-10459
HIGH 7.5
1 app
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox <… |
|
CVE-2024-10458
HIGH 7.5
1 app
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Fire… |
|
CVE-2024-9287
MEDIUM 7.8
1 app
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, all… |
|
CVE-2024-44157
MEDIUM 5.5
1 app
A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Par… |
|
CVE-2024-9680
CRITICAL 9.8
KEV
1 app
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner… |
|
CVE-2024-6197
HIGH 8.8
Hackerone: CVE-2024-6197 Freeing stack buffer in utf8asn1str |
|
CVE-2024-43615
HIGH 7.1
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |