Vulnerabilities
Tracked app vulnerabilities
11,272 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,272
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-8176
HIGH 7.5
A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML docume… |
|
CVE-2025-26633
HIGH 7.0
KEV
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-26634
HIGH 7.5
Windows Core Messaging Elevation of Privileges Vulnerability |
|
CVE-2025-25008
HIGH 7.1
Windows Server Elevation of Privilege Vulnerability |
|
CVE-2025-24997
HIGH 4.4
DirectX Graphics Kernel File Denial of Service Vulnerability |
|
CVE-2025-24996
HIGH 6.5
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-24995
HIGH 7.8
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24994
HIGH 7.3
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2025-24993
HIGH 7.8
KEV
Windows NTFS Remote Code Execution Vulnerability |
|
CVE-2025-24992
HIGH 5.5
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24991
HIGH 5.5
KEV
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24988
HIGH 6.6
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24987
HIGH 6.6
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24985
HIGH 7.8
KEV
Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
|
CVE-2025-24984
HIGH 4.6
KEV
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24983
HIGH 7.0
KEV
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24855
HIGH 7.8
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is… |
|
CVE-2025-24076
HIGH 7.3
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2025-24072
HIGH 7.8
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability |
|
CVE-2025-24071
HIGH 6.5
Microsoft Windows File Explorer Spoofing Vulnerability |
|
CVE-2025-24067
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24066
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24061
HIGH 7.8
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2025-24059
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24056
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-24055
HIGH 4.3
Windows USB Video Class System Driver Information Disclosure Vulnerability |
|
CVE-2025-24054
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-24051
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-24050
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-24048
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-24046
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24044
HIGH 7.8
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-21247
HIGH 4.3
MapUrlToZone Security Feature Bypass Vulnerability |
|
CVE-2025-21180
HIGH 7.8
Windows exFAT File System Remote Code Execution Vulnerability |
|
CVE-2024-9157
HIGH
Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability |
|
CVE-2024-55549
HIGH 7.8
xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue |
|
CVE-2025-26696
HIGH 7.0
1 app
Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown… |
|
CVE-2024-54546
HIGH 7.5
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected system termination or co… |
|
CVE-2024-44227
HIGH 7.5
The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to cause unexpected sy… |
|
CVE-2025-1943
HIGH 8.2
1 app
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-1937
HIGH 7.5
1 app
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of… |
|
CVE-2025-1936
HIGH 7.3
1 app
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but… |
|
CVE-2025-1933
HIGH 7.6
1 app
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a di… |
|
CVE-2025-1932
HIGH 8.1
1 app
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This … |
|
CVE-2025-1931
HIGH 7.5
1 app
It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerabil… |
|
CVE-2025-1930
HIGH 8.8
1 app
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led t… |
|
CVE-2025-26417
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-22413
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-22407
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-22406
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |