Vulnerabilities
Tracked app vulnerabilities
8,539 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,539
- Actively exploited
- 214
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2021-29949
HIGH 7.8
1 app
When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distri… |
|
CVE-2021-29948
LOW 2.5
1 app
Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replac… |
|
CVE-2021-29946
HIGH 8.8
1 app
Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc hea… |
|
CVE-2021-29945
MEDIUM 6.5
1 app
The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32… |
|
CVE-2021-24002
HIGH 8.8
1 app
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary c… |
|
CVE-2021-23999
HIGH 8.8
1 app
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should… |
|
CVE-2021-23998
MEDIUM 6.5
1 app
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox E… |
|
CVE-2021-23995
HIGH 8.8
1 app
When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been expl… |
|
CVE-2021-23994
HIGH 8.8
1 app
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10,… |
|
CVE-2021-23993
MEDIUM 6.5
1 app
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a sub… |
|
CVE-2021-23992
MEDIUM 4.3
1 app
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key,… |
|
CVE-2021-23991
MEDIUM 6.8
1 app
If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet b… |
|
CVE-2021-1675
HIGH 7.8
KEV
Windows Print Spooler Remote Code Execution Vulnerability |
|
CVE-2021-33742
CRITICAL 7.5
KEV
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-33739
HIGH 8.4
KEV
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2021-31977
HIGH 8.6
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2021-31976
HIGH 7.5
Server for NFS Information Disclosure Vulnerability |
|
CVE-2021-31975
HIGH 7.5
Server for NFS Information Disclosure Vulnerability |
|
CVE-2021-31974
HIGH 7.5
Server for NFS Denial of Service Vulnerability |
|
CVE-2021-31973
HIGH 7.8
Windows GPSVC Elevation of Privilege Vulnerability |
|
CVE-2021-31972
HIGH 5.5
Event Tracing for Windows Information Disclosure Vulnerability |
|
CVE-2021-31971
HIGH 6.8
Windows HTML Platforms Security Feature Bypass Vulnerability |
|
CVE-2021-31970
HIGH 5.5
Windows TCP/IP Driver Security Feature Bypass Vulnerability |
|
CVE-2021-31969
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2021-31968
HIGH 7.5
Windows Remote Desktop Services Denial of Service Vulnerability |
|
CVE-2021-31962
HIGH 9.4
Kerberos AppContainer Security Feature Bypass Vulnerability |
|
CVE-2021-31960
HIGH 5.5
Windows Bind Filter Driver Information Disclosure Vulnerability |
|
CVE-2021-31959
CRITICAL 6.4
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-31958
HIGH 7.5
Windows NTLM Elevation of Privilege Vulnerability |
|
CVE-2021-31956
HIGH 7.8
KEV
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2021-31955
HIGH 5.5
KEV
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2021-31954
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2021-31953
HIGH 7.8
Windows Filter Manager Elevation of Privilege Vulnerability |
|
CVE-2021-31952
HIGH 7.8
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2021-31951
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2021-31201
HIGH 5.2
KEV
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
|
CVE-2021-31199
HIGH 5.2
KEV
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
|
CVE-2021-26414
HIGH 4.8
Windows DCOM Server Security Feature Bypass |
|
CVE-2021-3426
MEDIUM 5.7
1 app
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server co… |
|
CVE-2021-31208
HIGH 7.8
Windows Container Manager Service Elevation of Privilege Vulnerability |
|
CVE-2021-31205
HIGH 6.5
Windows SMB Client Security Feature Bypass Vulnerability |
|
CVE-2021-31194
CRITICAL 8.8
OLE Automation Remote Code Execution Vulnerability |
|
CVE-2021-31193
HIGH 7.8
Windows SSDP Service Elevation of Privilege Vulnerability |
|
CVE-2021-31192
HIGH 7.8
Windows Media Foundation Core Remote Code Execution Vulnerability |
|
CVE-2021-31191
HIGH 5.5
Windows Projected File System FS Filter Driver Information Disclosure Vulnerability |
|
CVE-2021-31190
HIGH 7.8
Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2021-31188
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2021-31187
HIGH 7.8
Windows WalletService Elevation of Privilege Vulnerability |
|
CVE-2021-31186
HIGH 7.4
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
|
CVE-2021-31185
HIGH 5.5
Windows Desktop Bridge Denial of Service Vulnerability |