Vulnerabilities
Tracked app vulnerabilities
7,750 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,750
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-9396
HIGH 8.8
1 app
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. T… |
|
CVE-2024-9394
HIGH 7.5
1 app
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to a… |
|
CVE-2024-9393
HIGH 7.5
1 app
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to acc… |
|
CVE-2024-9392
CRITICAL 9.8
1 app
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3… |
|
CVE-2024-43487
MEDIUM 6.5
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-43467
HIGH 7.5
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-43461
HIGH 8.8
KEV
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-43455
HIGH 8.8
Windows Remote Desktop Licensing Service Spoofing Vulnerability |
|
CVE-2024-43454
HIGH 7.1
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38263
HIGH 7.5
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38260
HIGH 8.8
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38259
HIGH 8.8
Microsoft Management Console Remote Code Execution Vulnerability |
|
CVE-2024-38258
MEDIUM 6.5
Windows Remote Desktop Licensing Service Information Disclosure Vulnerability |
|
CVE-2024-38257
HIGH 7.5
Microsoft AllJoyn API Information Disclosure Vulnerability |
|
CVE-2024-38256
MEDIUM 5.5
Windows Kernel-Mode Driver Information Disclosure Vulnerability |
|
CVE-2024-38254
MEDIUM 5.5
Windows Authentication Information Disclosure Vulnerability |
|
CVE-2024-38253
HIGH 7.8
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2024-38252
HIGH 7.8
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2024-38250
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2024-38249
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2024-38248
HIGH 7.0
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2024-38247
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2024-38246
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2024-38245
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38244
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38243
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38242
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38241
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38240
HIGH 8.1
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2024-38239
HIGH 7.2
Windows Kerberos Elevation of Privilege Vulnerability |
|
CVE-2024-38238
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38237
HIGH 7.8
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38236
HIGH 7.5
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2024-38235
MEDIUM 6.5
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2024-38234
MEDIUM 6.5
Windows Networking Denial of Service Vulnerability |
|
CVE-2024-38231
MEDIUM 6.5
Windows Remote Desktop Licensing Service Denial of Service Vulnerability |
|
CVE-2024-38230
MEDIUM 6.5
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2024-38217
MEDIUM 5.4
KEV
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-38119
HIGH 7.5
Windows Network Address Translation (NAT) Remote Code Execution Vulnerability |
|
CVE-2024-38046
HIGH 7.8
PowerShell Elevation of Privilege Vulnerability |
|
CVE-2024-38045
HIGH 8.1
Windows TCP/IP Remote Code Execution Vulnerability |
|
CVE-2024-38014
HIGH 7.8
KEV
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2024-30073
HIGH 7.8
Windows Security Zone Mapping Security Feature Bypass Vulnerability |
|
CVE-2024-21416
HIGH 8.1
Windows TCP/IP Remote Code Execution Vulnerability |
|
CVE-2024-43495
HIGH 7.3
Windows libarchive Remote Code Execution Vulnerability |
|
CVE-2024-43458
HIGH 7.7
Windows Networking Information Disclosure Vulnerability |
|
CVE-2024-43457
HIGH 7.8
Windows Setup and Deployment Elevation of Privilege Vulnerability |
|
CVE-2024-38233
HIGH 7.5
Windows Networking Denial of Service Vulnerability |
|
CVE-2024-38232
HIGH 7.5
Windows Networking Denial of Service Vulnerability |
|
CVE-2024-7652
HIGH 7.5
1 app
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an ex… |