Vulnerabilities
Tracked app vulnerabilities
15,691 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,691
- Actively exploited
- 286
- Publication window
- 2007-08-28 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-43508
HIGH 5.5
Windows Graphics Component Information Disclosure Vulnerability |
|
CVE-2024-43506
HIGH 7.5
BranchCache Denial of Service Vulnerability |
|
CVE-2024-43502
HIGH 7.1
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-43501
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-43500
HIGH 5.5
Windows Resilient File System (ReFS) Information Disclosure Vulnerability |
|
CVE-2024-43456
HIGH 4.8
Windows Remote Desktop Services Tampering Vulnerability |
|
CVE-2024-43453
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-41957
MEDIUM 5.3
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-38265
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-38262
HIGH 7.5
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38261
HIGH 7.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-38212
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2024-38149
HIGH 7.5
BranchCache Denial of Service Vulnerability |
|
CVE-2024-38129
HIGH 7.5
Windows Kerberos Elevation of Privilege Vulnerability |
|
CVE-2024-38124
HIGH 9.0
Windows Netlogon Elevation of Privilege Vulnerability |
|
CVE-2024-38029
HIGH 7.5
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability |
|
CVE-2024-37983
HIGH 6.7
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability |
|
CVE-2024-37982
HIGH 6.7
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability |
|
CVE-2024-37979
HIGH 6.7
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-37976
HIGH 6.7
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability |
|
CVE-2024-30092
HIGH 8.0
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2024-2466
MEDIUM 6.5
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-20659
HIGH 7.1
Windows Hyper-V Security Feature Bypass Vulnerability |
|
CVE-2024-44207
MEDIUM 4.3
This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to capture a few sec… |
|
CVE-2024-44204
MEDIUM 5.5
A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's saved passwords may be read aloud by VoiceO… |
|
CVE-2024-44193
HIGH 7.8
1 app
A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate their privil… |
|
CVE-2024-9403
HIGH 7.3
1 app
Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h… |
|
CVE-2024-9402
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-9401
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2024-9400
HIGH 8.8
1 app
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. Th… |
|
CVE-2024-9399
HIGH 7.5
1 app
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulner… |
|
CVE-2024-9398
MEDIUM 5.3
1 app
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that … |
|
CVE-2024-9397
MEDIUM 6.1
1 app
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerabilit… |
|
CVE-2024-9396
HIGH 8.8
1 app
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. T… |
|
CVE-2024-9394
HIGH 7.5
1 app
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to a… |
|
CVE-2024-9393
HIGH 7.5
1 app
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to acc… |
|
CVE-2024-9392
CRITICAL 9.8
1 app
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3… |
|
CVE-2024-40677
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-40676
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-40675
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-40674
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-40673
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-40672
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-40670
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-40669
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-40651
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-40649
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-38399
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-34748
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-34733
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |