Vulnerabilities
Tracked app vulnerabilities
11,279 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,279
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-38151
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2024-38150
HIGH 7.8
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2024-38148
HIGH 7.5
Windows Secure Channel Denial of Service Vulnerability |
|
CVE-2024-38147
HIGH 7.8
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2024-38146
HIGH 7.5
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability |
|
CVE-2024-38145
HIGH 7.5
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability |
|
CVE-2024-38144
HIGH 8.8
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38143
HIGH 4.2
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability |
|
CVE-2024-38142
HIGH 7.8
Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
|
CVE-2024-38141
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2024-38138
HIGH 7.5
Windows Deployment Services Remote Code Execution Vulnerability |
|
CVE-2024-38137
HIGH 7.0
Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability |
|
CVE-2024-38136
HIGH 7.0
Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability |
|
CVE-2024-38135
HIGH 7.8
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
|
CVE-2024-38134
HIGH 7.8
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38133
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-38132
HIGH 7.5
Windows Network Address Translation (NAT) Denial of Service Vulnerability |
|
CVE-2024-38131
HIGH 8.8
Clipboard Virtual Channel Extension Remote Code Execution Vulnerability |
|
CVE-2024-38130
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-38128
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-38127
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2024-38126
HIGH 7.5
Windows Network Address Translation (NAT) Denial of Service Vulnerability |
|
CVE-2024-38125
HIGH 7.8
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38123
HIGH 4.4
Windows Bluetooth Driver Information Disclosure Vulnerability |
|
CVE-2024-38122
HIGH 5.5
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability |
|
CVE-2024-38121
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-38120
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-38118
HIGH 5.5
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability |
|
CVE-2024-38117
HIGH 7.8
NTFS Elevation of Privilege Vulnerability |
|
CVE-2024-38116
HIGH 8.8
Windows IP Routing Management Snapin Remote Code Execution Vulnerability |
|
CVE-2024-38115
HIGH 8.8
Windows IP Routing Management Snapin Remote Code Execution Vulnerability |
|
CVE-2024-38114
HIGH 8.8
Windows IP Routing Management Snapin Remote Code Execution Vulnerability |
|
CVE-2024-38107
HIGH 7.8
KEV
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability |
|
CVE-2024-38106
HIGH 7.0
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-37968
HIGH 7.5
Windows DNS Spoofing Vulnerability |
|
CVE-2024-29995
HIGH 8.1
Windows Kerberos Elevation of Privilege Vulnerability |
|
CVE-2024-21302
HIGH 6.7
Windows Secure Kernel Mode Elevation of Privilege Vulnerability |
|
CVE-2024-42219
HIGH 7.8
1 app
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient. |
|
CVE-2024-7528
HIGH 8.8
1 app
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Th… |
|
CVE-2024-7527
HIGH 8.8
1 app
Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ES… |
|
CVE-2024-7525
HIGH 9.1
1 app
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on… |
|
CVE-2024-7522
HIGH 9.1
1 app
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, F… |
|
CVE-2024-7521
HIGH 9.8
1 app
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.… |
|
CVE-2024-7520
HIGH 8.8
1 app
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox … |
|
CVE-2024-4607
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-36971
HIGH 7.8
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-34743
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-34742
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-34741
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-34740
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |