Vulnerabilities
Tracked app vulnerabilities
8,536 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,536
- Actively exploited
- 214
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2021-34489
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2021-34488
HIGH 7.8
Windows Console Driver Elevation of Privilege Vulnerability |
|
CVE-2021-34476
HIGH 7.5
Bowser.sys Denial of Service Vulnerability |
|
CVE-2021-33788
HIGH 7.5
Windows LSA Denial of Service Vulnerability |
|
CVE-2021-33786
HIGH 8.1
Windows LSA Security Feature Bypass Vulnerability |
|
CVE-2021-33785
HIGH 7.5
Windows AF_UNIX Socket Provider Denial of Service Vulnerability |
|
CVE-2021-33784
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2021-33783
MEDIUM 6.5
Windows SMB Information Disclosure Vulnerability |
|
CVE-2021-33782
MEDIUM 5.5
Windows Authenticode Spoofing Vulnerability |
|
CVE-2021-33781
HIGH 8.1
Azure AD Security Feature Bypass Vulnerability |
|
CVE-2021-33780
HIGH 8.8
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2021-33779
HIGH 8.1
Windows AD FS Security Feature Bypass Vulnerability |
|
CVE-2021-33774
HIGH 7.0
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2021-33773
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2021-33772
HIGH 7.5
Windows TCP/IP Driver Denial of Service Vulnerability |
|
CVE-2021-33771
HIGH 7.8
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2021-33765
MEDIUM 6.2
Windows Installer Spoofing Vulnerability |
|
CVE-2021-33764
MEDIUM 5.9
Windows Key Distribution Center Information Disclosure Vulnerability |
|
CVE-2021-33763
MEDIUM 5.5
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2021-33761
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2021-33760
MEDIUM 5.5
Media Foundation Information Disclosure Vulnerability |
|
CVE-2021-33759
HIGH 7.8
Windows Desktop Bridge Elevation of Privilege Vulnerability |
|
CVE-2021-33758
HIGH 7.7
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2021-33757
MEDIUM 5.3
Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability |
|
CVE-2021-33756
HIGH 8.8
Windows DNS Snap-in Remote Code Execution Vulnerability |
|
CVE-2021-33755
MEDIUM 6.3
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2021-33754
HIGH 8.0
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2021-33752
HIGH 8.8
Windows DNS Snap-in Remote Code Execution Vulnerability |
|
CVE-2021-33751
HIGH 7.0
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
|
CVE-2021-33750
HIGH 8.8
Windows DNS Snap-in Remote Code Execution Vulnerability |
|
CVE-2021-33749
HIGH 8.8
Windows DNS Snap-in Remote Code Execution Vulnerability |
|
CVE-2021-33746
HIGH 8.0
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2021-33745
MEDIUM 6.5
Windows DNS Server Denial of Service Vulnerability |
|
CVE-2021-33744
MEDIUM 5.3
Windows Secure Kernel Mode Security Feature Bypass Vulnerability |
|
CVE-2021-33743
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2021-33740
HIGH 7.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2021-31979
HIGH 7.8
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2021-31961
MEDIUM 6.1
Windows InstallService Elevation of Privilege Vulnerability |
|
CVE-2021-31183
HIGH 7.5
Windows TCP/IP Driver Denial of Service Vulnerability |
|
CVE-2021-34527
HIGH 8.8
KEV
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull… |
|
CVE-2020-17759
HIGH 8.8
1 app
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the us… |
|
CVE-2021-29967
HIGH 8.8
1 app
Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we pres… |
|
CVE-2021-29964
HIGH 7.1
1 app
A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only … |
|
CVE-2021-29957
MEDIUM 4.3
1 app
If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indi… |
|
CVE-2021-29956
MEDIUM 4.3
1 app
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master pass… |
|
CVE-2021-29951
MEDIUM 6.5
1 app
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop th… |
|
CVE-2021-29950
HIGH 7.5
1 app
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may… |
|
CVE-2021-29949
HIGH 7.8
1 app
When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distri… |
|
CVE-2021-29948
LOW 2.5
1 app
Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replac… |
|
CVE-2021-29946
HIGH 8.8
1 app
Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc hea… |