Vulnerabilities
Tracked app vulnerabilities
7,770 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,770
- Actively exploited
- 214
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-21320
HIGH 6.5
Windows Themes Spoofing Vulnerability |
|
CVE-2024-21316
HIGH 6.1
Windows Server Key Distribution Service Security Feature Bypass |
|
CVE-2024-21314
HIGH 6.5
Microsoft Message Queuing Information Disclosure Vulnerability |
|
CVE-2024-21313
HIGH 5.3
Windows TCP/IP Information Disclosure Vulnerability |
|
CVE-2024-21311
HIGH 5.5
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2024-21310
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2024-21309
HIGH 7.8
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2024-21307
HIGH 7.5
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2024-21306
HIGH 5.7
Microsoft Bluetooth Driver Spoofing Vulnerability |
|
CVE-2024-21305
HIGH 4.4
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability |
|
CVE-2024-20700
CRITICAL 7.5
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2024-20699
HIGH 5.5
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2024-20698
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-20697
HIGH 7.3
Windows libarchive Remote Code Execution Vulnerability |
|
CVE-2024-20696
HIGH 7.3
Windows libarchive Remote Code Execution Vulnerability |
|
CVE-2024-20694
HIGH 5.5
Windows CoreMessaging Information Disclosure Vulnerability |
|
CVE-2024-20692
HIGH 5.7
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability |
|
CVE-2024-20691
HIGH 4.7
Windows Themes Information Disclosure Vulnerability |
|
CVE-2024-20690
HIGH 6.5
Windows Nearby Sharing Spoofing Vulnerability |
|
CVE-2024-20687
HIGH 7.5
Microsoft AllJoyn API Denial of Service Vulnerability |
|
CVE-2024-20686
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2024-20683
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2024-20682
HIGH 7.8
Windows Cryptographic Services Remote Code Execution Vulnerability |
|
CVE-2024-20681
HIGH 7.8
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2024-20680
HIGH 6.5
Windows Message Queuing Client (MSMQC) Information Disclosure |
|
CVE-2024-20674
CRITICAL 8.8
Windows Kerberos Security Feature Bypass Vulnerability |
|
CVE-2024-20666
HIGH 6.6
BitLocker Security Feature Bypass Vulnerability |
|
CVE-2024-20664
HIGH 6.5
Microsoft Message Queuing Information Disclosure Vulnerability |
|
CVE-2024-20663
HIGH 6.5
Windows Message Queuing Client (MSMQC) Information Disclosure |
|
CVE-2024-20662
HIGH 4.9
Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability |
|
CVE-2024-20661
HIGH 7.5
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2024-20660
HIGH 6.5
Microsoft Message Queuing Information Disclosure Vulnerability |
|
CVE-2024-20658
HIGH 7.8
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
|
CVE-2024-20657
HIGH 7.0
Windows Group Policy Elevation of Privilege Vulnerability |
|
CVE-2024-20655
HIGH 6.6
Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability |
|
CVE-2024-20654
HIGH 8.0
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-20653
HIGH 7.8
Microsoft Common Log File System Elevation of Privilege Vulnerability |
|
CVE-2024-20652
HIGH 8.1
Windows HTML Platforms Security Feature Bypass Vulnerability |
|
CVE-2023-6864
HIGH 8.8
1 app
Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2023-6863
HIGH 8.8
1 app
The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnera… |
|
CVE-2023-6862
HIGH 8.8
1 app
A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 1… |
|
CVE-2023-6861
HIGH 8.8
1 app
The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6… |
|
CVE-2023-6860
MEDIUM 6.5
1 app
The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affe… |
|
CVE-2023-6859
HIGH 8.8
1 app
A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Fi… |
|
CVE-2023-6858
HIGH 8.8
1 app
Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunder… |
|
CVE-2023-6857
MEDIUM 5.3
1 app
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Uni… |
|
CVE-2023-6856
HIGH 8.8
1 app
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an att… |
|
CVE-2023-50762
MEDIUM 4.3
1 app
When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text w… |
|
CVE-2023-50761
MEDIUM 4.3
1 app
The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare t… |
|
CVE-2023-36696
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |