Vulnerabilities
Tracked app vulnerabilities
7,770 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,770
- Actively exploited
- 214
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2023-35349
CRITICAL 9.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2023-29348
HIGH 7.5
Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability |
|
CVE-2023-5217
HIGH 8.8
KEV
2 apps
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap… |
|
CVE-2023-5176
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2023-5174
CRITICAL 9.8
1 app
If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free a… |
|
CVE-2023-5171
MEDIUM 6.5
1 app
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potent… |
|
CVE-2023-5169
MEDIUM 6.5
1 app
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable… |
|
CVE-2023-5168
CRITICAL 9.8
1 app
A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable … |
|
CVE-2023-4863
HIGH 8.8
KEV
1 app
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v… |
|
CVE-2023-38162
HIGH 7.5
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2023-38161
HIGH 7.8
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2023-38160
HIGH 5.5
Windows TCP/IP Information Disclosure Vulnerability |
|
CVE-2023-38152
HIGH 5.3
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-38150
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-38149
HIGH 7.5
Windows TCP/IP Denial of Service Vulnerability |
|
CVE-2023-38148
CRITICAL 8.8
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
|
CVE-2023-38147
HIGH 8.8
Windows Miracast Wireless Display Remote Code Execution Vulnerability |
|
CVE-2023-38146
HIGH 8.8
Windows Themes Remote Code Execution Vulnerability |
|
CVE-2023-38144
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-38143
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-38142
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-38141
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-38140
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-38139
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-36805
HIGH 7.0
Windows MSHTML Platform Security Feature Bypass Vulnerability |
|
CVE-2023-36804
HIGH 7.8
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2023-36803
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-36802
HIGH 7.8
KEV
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability |
|
CVE-2023-36801
HIGH 5.3
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-35355
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-4585
HIGH 8.8
1 app
Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2023-4584
HIGH 8.8
1 app
Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence… |
|
CVE-2023-4583
HIGH 7.5
1 app
When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been dis… |
|
CVE-2023-4582
HIGH 8.8
1 app
Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory… |
|
CVE-2023-4581
MEDIUM 4.3
1 app
Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their pot… |
|
CVE-2023-4580
MEDIUM 6.5
1 app
Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability … |
|
CVE-2023-4578
MEDIUM 6.5
1 app
When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function coul… |
|
CVE-2023-4577
MEDIUM 6.5
1 app
When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could pot… |
|
CVE-2023-4576
HIGH 8.6
1 app
On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that… |
|
CVE-2023-4575
MEDIUM 6.5
1 app
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simul… |
|
CVE-2023-4574
MEDIUM 6.5
1 app
When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simu… |
|
CVE-2023-4573
MEDIUM 6.5
1 app
When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exp… |
|
CVE-2023-40217
MEDIUM 5.3
1 app
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HT… |
|
CVE-2023-38831
HIGH 7.8
KEV
1 app
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because … |
|
CVE-2023-41105
HIGH 7.5
1 app
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly… |
|
CVE-2022-48566
MEDIUM 5.9
1 app
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variab… |
|
CVE-2022-48565
CRITICAL 9.8
1 app
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoi… |
|
CVE-2022-48564
MEDIUM 6.5
1 app
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property Li… |
|
CVE-2022-48560
HIGH 7.5
1 app
A use-after-free exists in Python through 3.9 via heappushpop in heapq. |
|
CVE-2023-38898
MEDIUM 5.3
1 app
An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by th… |