Vulnerabilities
Tracked app vulnerabilities
7,734 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,734
- Actively exploited
- 213
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-30077
HIGH 8.0
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2024-30076
MEDIUM 6.8
Windows Container Manager Service Elevation of Privilege Vulnerability |
|
CVE-2024-30072
HIGH 7.8
Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability |
|
CVE-2024-30070
HIGH 7.5
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2024-30069
MEDIUM 4.7
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2024-30068
HIGH 8.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-30067
MEDIUM 5.5
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2024-30066
MEDIUM 5.5
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2024-30065
MEDIUM 5.5
Windows Themes Denial of Service Vulnerability |
|
CVE-2024-30063
MEDIUM 6.7
Windows Distributed File System (DFS) Remote Code Execution Vulnerability |
|
CVE-2024-30062
HIGH 7.8
Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability |
|
CVE-2024-5702
HIGH 7.5
1 app
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, an… |
|
CVE-2024-5700
HIGH 7.0
1 app
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume t… |
|
CVE-2024-5696
HIGH 8.6
1 app
By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability… |
|
CVE-2024-5693
MEDIUM 6.1
1 app
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. T… |
|
CVE-2024-5692
MEDIUM 6.5
1 app
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.ur… |
|
CVE-2024-5691
MEDIUM 4.7
1 app
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions… |
|
CVE-2024-5690
MEDIUM 4.3
1 app
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulner… |
|
CVE-2024-5688
HIGH 8.1
1 app
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 12… |
|
CVE-2024-30064
HIGH 8.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-50868
HIGH 7.5
MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU |
|
CVE-2024-36052
HIGH 7.5
1 app
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899. |
|
CVE-2024-4777
HIGH 7.5
1 app
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume t… |
|
CVE-2024-4770
HIGH 8.8
1 app
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.… |
|
CVE-2024-4769
MEDIUM 5.9
1 app
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses… |
|
CVE-2024-4768
MEDIUM 6.1
1 app
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Fi… |
|
CVE-2024-4767
MEDIUM 4.3
1 app
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disa… |
|
CVE-2024-4367
HIGH 8.8
1 app
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Fire… |
|
CVE-2024-27793
HIGH 7.8
1 app
The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termination or ar… |
|
CVE-2024-30051
HIGH 7.8
KEV
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2024-30050
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-30049
HIGH 7.8
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2024-30040
HIGH 8.8
KEV
Windows MSHTML Platform Security Feature Bypass Vulnerability |
|
CVE-2024-30039
HIGH 5.5
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2024-30038
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2024-30037
HIGH 5.5
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-30036
HIGH 6.5
Windows Deployment Services Information Disclosure Vulnerability |
|
CVE-2024-30035
HIGH 7.8
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2024-30034
HIGH 5.5
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability |
|
CVE-2024-30033
HIGH 7.0
Windows Search Service Elevation of Privilege Vulnerability |
|
CVE-2024-30032
HIGH 7.8
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2024-30031
HIGH 7.8
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
|
CVE-2024-30029
HIGH 7.5
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-30028
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2024-30027
HIGH 7.8
NTFS Elevation of Privilege Vulnerability |
|
CVE-2024-30025
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-30024
HIGH 7.5
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-30023
HIGH 7.5
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-30022
HIGH 7.5
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-30021
HIGH 6.8
Windows Mobile Broadband Driver Remote Code Execution Vulnerability |