Vulnerabilities
Tracked app vulnerabilities
7,770 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,770
- Actively exploited
- 214
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-26178
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-26177
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2024-26176
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-26174
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2024-26173
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-26170
HIGH 7.8
Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability |
|
CVE-2024-26169
HIGH 7.8
KEV
Windows Error Reporting Service Elevation of Privilege Vulnerability |
|
CVE-2024-26166
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-26162
HIGH 8.8
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-26161
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-26160
HIGH 5.5
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability |
|
CVE-2024-26159
HIGH 8.8
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-21451
HIGH 8.8
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-21450
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21446
HIGH 7.8
NTFS Elevation of Privilege Vulnerability |
|
CVE-2024-21445
HIGH 7.0
Windows USB Print Driver Elevation of Privilege Vulnerability |
|
CVE-2024-21444
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21443
HIGH 7.3
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-21442
HIGH 7.8
Windows USB Print Driver Elevation of Privilege Vulnerability |
|
CVE-2024-21441
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21440
HIGH 8.8
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-21439
HIGH 7.0
Windows Telephony Server Elevation of Privilege Vulnerability |
|
CVE-2024-21438
HIGH 7.5
Microsoft AllJoyn API Denial of Service Vulnerability |
|
CVE-2024-21437
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2024-21436
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2024-21435
HIGH 8.8
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2024-21434
HIGH 7.8
Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability |
|
CVE-2024-21433
HIGH 7.0
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2024-21432
HIGH 7.0
Windows Update Stack Elevation of Privilege Vulnerability |
|
CVE-2024-21431
HIGH 7.8
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability |
|
CVE-2024-21430
HIGH 5.7
Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability |
|
CVE-2024-21429
HIGH 6.8
Windows USB Hub Driver Remote Code Execution Vulnerability |
|
CVE-2024-21427
HIGH 7.5
Windows Kerberos Security Feature Bypass Vulnerability |
|
CVE-2024-21408
CRITICAL 5.5
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2024-21407
CRITICAL 8.1
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2023-28746
HIGH
Intel: CVE-2023-28746 Register File Data Sampling (RFDS) |
|
CVE-2024-1936
HIGH 7.5
1 app
The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Conse… |
|
CVE-2024-1553
HIGH 8.1
1 app
Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-1552
HIGH 7.5
1 app
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices.… |
|
CVE-2024-1551
MEDIUM 6.1
1 app
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well … |
|
CVE-2024-1550
MEDIUM 6.1
1 app
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedl… |
|
CVE-2024-1549
MEDIUM 6.1
1 app
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and un… |
|
CVE-2024-1548
MEDIUM 4.3
1 app
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing… |
|
CVE-2024-1547
MEDIUM 6.5
1 app
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL sh… |
|
CVE-2024-1546
HIGH 7.5
1 app
When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulne… |
|
CVE-2024-21420
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21412
HIGH 8.1
KEV
Internet Shortcut Files Security Feature Bypass Vulnerability |
|
CVE-2024-21406
HIGH 7.5
Windows Printing Service Spoofing Vulnerability |
|
CVE-2024-21405
HIGH 7.0
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2024-21391
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |