Vulnerabilities
Tracked app vulnerabilities
7,770 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,770
- Actively exploited
- 214
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-26217
HIGH 5.5
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2024-26216
HIGH 7.3
Windows File Server Resource Management Service Elevation of Privilege Vulnerability |
|
CVE-2024-26215
HIGH 7.5
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2024-26214
HIGH 8.8
Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-26213
HIGH 7.0
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2024-26212
HIGH 7.5
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2024-26211
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2024-26210
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-26209
HIGH 5.5
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability |
|
CVE-2024-26208
HIGH 7.2
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2024-26207
HIGH 5.5
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2024-26205
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-26202
HIGH 7.2
DHCP Server Service Remote Code Execution Vulnerability |
|
CVE-2024-26200
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-26195
HIGH 7.2
DHCP Server Service Remote Code Execution Vulnerability |
|
CVE-2024-26194
HIGH 7.4
Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2024-26189
HIGH 8.0
Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2024-26183
HIGH 6.5
Windows Kerberos Denial of Service Vulnerability |
|
CVE-2024-26180
HIGH 8.0
Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2024-26179
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-26175
HIGH 7.8
Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2024-26172
HIGH 5.5
Windows DWM Core Library Information Disclosure Vulnerability |
|
CVE-2024-26171
HIGH 6.7
Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2024-26168
HIGH 6.8
Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2024-26158
HIGH 7.8
Microsoft Install Service Elevation of Privilege Vulnerability |
|
CVE-2024-23594
HIGH 6.4
Lenovo: CVE-2024-23594 Stack buffer overflow in Lenovo system recovery boot manager |
|
CVE-2024-23593
HIGH 6.7
Lenovo: CVE-2024-23593 Modify Boot Manager and Escalate Privileges |
|
CVE-2024-21447
HIGH 7.8
Windows Authentication Elevation of Privilege Vulnerability |
|
CVE-2024-20693
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-20678
HIGH 8.8
Remote Procedure Call Runtime Remote Code Execution Vulnerability |
|
CVE-2024-20669
HIGH 6.7
Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2024-20665
HIGH 6.1
BitLocker Security Feature Bypass Vulnerability |
|
CVE-2022-0001
HIGH 4.7
Intel: CVE-2022-0001 Branch History Injection |
|
CVE-2024-30370
MEDIUM 4.3
1 app
RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected i… |
|
CVE-2024-2616
LOW 2.7
1 app
To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects F… |
|
CVE-2024-2614
HIGH 8.8
1 app
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-2612
HIGH 8.1
1 app
If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code … |
|
CVE-2024-2611
MEDIUM 5.5
1 app
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox… |
|
CVE-2024-2610
MEDIUM 6.1
1 app
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability a… |
|
CVE-2024-2609
MEDIUM 6.1
1 app
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerabi… |
|
CVE-2024-2608
HIGH 8.4
1 app
`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underalloc… |
|
CVE-2024-2607
HIGH 8.1
1 app
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other opera… |
|
CVE-2024-2605
MEDIUM 5.9
1 app
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows … |
|
CVE-2023-5388
MEDIUM 6.5
1 app
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data… |
|
CVE-2023-42938
HIGH 7.8
1 app
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges. |
|
CVE-2024-26197
HIGH 6.5
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2024-26190
HIGH 7.5
Microsoft QUIC Denial of Service Vulnerability |
|
CVE-2024-26185
HIGH 6.5
Windows Compressed Folder Tampering Vulnerability |
|
CVE-2024-26182
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-26181
HIGH 5.5
Windows Kernel Denial of Service Vulnerability |