Vulnerabilities
Tracked app vulnerabilities
7,814 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 7,814
- Actively exploited
- 214
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2023-25728
MEDIUM 6.5
1 app
The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe t… |
|
CVE-2023-23605
HIGH 8.8
1 app
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of… |
|
CVE-2023-23603
MEDIUM 6.5
1 app
Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Da… |
|
CVE-2023-23602
MEDIUM 6.5
1 app
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to co… |
|
CVE-2023-23601
MEDIUM 6.5
1 app
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability… |
|
CVE-2023-23599
MEDIUM 6.5
1 app
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands … |
|
CVE-2023-23598
MEDIUM 6.5
1 app
Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website cou… |
|
CVE-2023-1945
MEDIUM 6.5
1 app
Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunder… |
|
CVE-2023-0767
HIGH 8.8
1 app
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. … |
|
CVE-2023-0616
MEDIUM 6.5
1 app
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause T… |
|
CVE-2023-0547
MEDIUM 6.5
1 app
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird v… |
|
CVE-2023-0430
MEDIUM 6.5
1 app
Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a vali… |
|
CVE-2023-29336
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-29325
CRITICAL 8.1
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2023-29324
HIGH 6.5
Windows MSHTML Platform Security Feature Bypass Vulnerability |
|
CVE-2023-28283
CRITICAL 8.1
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
|
CVE-2023-28251
HIGH 5.5
Windows Driver Revocation List Security Feature Bypass Vulnerability |
|
CVE-2023-24949
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-24948
HIGH 7.4
Windows Bluetooth Driver Elevation of Privilege Vulnerability |
|
CVE-2023-24947
HIGH 8.8
Windows Bluetooth Driver Remote Code Execution Vulnerability |
|
CVE-2023-24946
HIGH 7.8
Windows Backup Service Elevation of Privilege Vulnerability |
|
CVE-2023-24945
HIGH 5.5
Windows iSCSI Target Service Information Disclosure Vulnerability |
|
CVE-2023-24944
HIGH 6.5
Windows Bluetooth Driver Information Disclosure Vulnerability |
|
CVE-2023-24943
CRITICAL 9.8
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2023-24942
HIGH 7.5
Remote Procedure Call Runtime Denial of Service Vulnerability |
|
CVE-2023-24941
CRITICAL 9.8
Windows Network File System Remote Code Execution Vulnerability |
|
CVE-2023-24940
HIGH 7.5
Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability |
|
CVE-2023-24939
HIGH 7.5
Server for NFS Denial of Service Vulnerability |
|
CVE-2023-24932
HIGH 6.7
Secure Boot Security Feature Bypass Vulnerability |
|
CVE-2023-24905
HIGH 7.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2023-24903
CRITICAL 8.1
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
|
CVE-2023-24902
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-24901
HIGH 7.5
Windows NFS Portmapper Information Disclosure Vulnerability |
|
CVE-2023-24900
HIGH 5.9
Windows NTLM Security Support Provider Information Disclosure Vulnerability |
|
CVE-2023-24899
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2023-24898
HIGH 7.5
Windows SMB Denial of Service Vulnerability |
|
CVE-2023-29007
HIGH 7.0
1 app
Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially cra… |
|
CVE-2023-25652
HIGH 7.5
1 app
Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding spec… |
|
CVE-2023-27043
MEDIUM 5.3
1 app
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is ident… |
|
CVE-2023-28308
HIGH 6.6
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2023-28307
HIGH 6.6
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2023-28306
HIGH 6.6
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2023-28305
HIGH 6.6
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2023-28302
HIGH 7.5
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-28298
HIGH 5.5
Windows Kernel Denial of Service Vulnerability |
|
CVE-2023-28297
HIGH 8.8
Windows Remote Procedure Call Service (RPCSS) Elevation of Privilege Vulnerability |
|
CVE-2023-28293
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-28278
HIGH 6.6
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2023-28277
HIGH 4.9
Windows DNS Server Information Disclosure Vulnerability |
|
CVE-2023-28276
HIGH 4.4
Windows Group Policy Security Feature Bypass Vulnerability |