Vulnerabilities
Tracked app vulnerabilities
7,770 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,770
- Actively exploited
- 214
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2023-36391
HIGH 7.8
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability |
|
CVE-2023-36012
HIGH 5.3
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-36011
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-36006
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2023-36005
HIGH 7.5
Windows Telephony Server Elevation of Privilege Vulnerability |
|
CVE-2023-36004
HIGH 7.5
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability |
|
CVE-2023-36003
HIGH 6.7
XAML Diagnostics Elevation of Privilege Vulnerability |
|
CVE-2023-35644
HIGH 7.8
Windows Sysmain Service Elevation of Privilege Vulnerability |
|
CVE-2023-35643
HIGH 7.5
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-35642
HIGH 6.5
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
|
CVE-2023-35641
CRITICAL 8.8
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
|
CVE-2023-35639
HIGH 8.8
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2023-35638
HIGH 7.5
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2023-35635
HIGH 5.5
Windows Kernel Denial of Service Vulnerability |
|
CVE-2023-35634
HIGH 8.0
Windows Bluetooth Driver Remote Code Execution Vulnerability |
|
CVE-2023-35632
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2023-35631
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-35630
CRITICAL 8.8
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
|
CVE-2023-35628
CRITICAL 8.1
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2023-35622
HIGH 7.5
Windows DNS Spoofing Vulnerability |
|
CVE-2023-21740
HIGH 7.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2023-20588
HIGH
AMD: CVE-2023-20588 AMD Speculative Leaks Security Notice |
|
CVE-2023-6507
MEDIUM 6.1
1 app
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. … |
|
CVE-2023-6212
HIGH 8.8
1 app
Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2023-6209
MEDIUM 6.5
1 app
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. T… |
|
CVE-2023-6208
HIGH 8.8
1 app
When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboa… |
|
CVE-2023-6207
HIGH 8.8
1 app
Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. |
|
CVE-2023-6206
MEDIUM 5.4
1 app
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact t… |
|
CVE-2023-6205
MEDIUM 6.5
1 app
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability… |
|
CVE-2023-6204
MEDIUM 6.5
1 app
On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on t… |
|
CVE-2023-36719
HIGH 7.8
Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability |
|
CVE-2023-36705
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2023-36428
HIGH 5.5
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability |
|
CVE-2023-36427
HIGH 7.0
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2023-36425
HIGH 8.0
Windows Distributed File System (DFS) Remote Code Execution Vulnerability |
|
CVE-2023-36424
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36423
HIGH 8.8
Microsoft Remote Registry Service Remote Code Execution Vulnerability |
|
CVE-2023-36408
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2023-36407
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2023-36406
HIGH 5.5
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2023-36405
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-36404
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-36403
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-36402
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2023-36401
HIGH 7.2
Microsoft Remote Registry Service Remote Code Execution Vulnerability |
|
CVE-2023-36400
CRITICAL 8.8
Windows HMAC Key Derivation Elevation of Privilege Vulnerability |
|
CVE-2023-36399
HIGH 7.1
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2023-36398
HIGH 6.5
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2023-36397
CRITICAL 9.8
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2023-36396
HIGH 7.8
Windows Compressed Folder Remote Code Execution Vulnerability |