Vulnerabilities
Tracked app vulnerabilities
16,398 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,398
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2023-42853
MEDIUM 5.5
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to … |
|
CVE-2024-1553
HIGH 8.1
1 app
Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-1552
HIGH 7.5
1 app
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices.… |
|
CVE-2024-1551
MEDIUM 6.1
1 app
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well … |
|
CVE-2024-1550
MEDIUM 6.1
1 app
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedl… |
|
CVE-2024-1549
MEDIUM 6.1
1 app
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and un… |
|
CVE-2024-1548
MEDIUM 4.3
1 app
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing… |
|
CVE-2024-1547
MEDIUM 6.5
1 app
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL sh… |
|
CVE-2024-1546
HIGH 7.5
1 app
When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulne… |
|
CVE-2024-24699
MEDIUM 6.5
3 apps
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. |
|
CVE-2024-24698
MEDIUM 4.9
3 apps
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. |
|
CVE-2024-24690
MEDIUM 5.4
3 apps
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2024-21420
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21412
HIGH 8.1
KEV
Internet Shortcut Files Security Feature Bypass Vulnerability |
|
CVE-2024-21406
HIGH 7.5
Windows Printing Service Spoofing Vulnerability |
|
CVE-2024-21405
HIGH 7.0
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2024-21391
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21377
MEDIUM 5.5
Windows DNS Information Disclosure Vulnerability |
|
CVE-2024-21375
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21372
HIGH 8.8
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2024-21371
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-21370
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21369
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21368
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21367
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21366
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21365
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21363
HIGH 7.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2024-21362
MEDIUM 5.5
Windows Kernel Security Feature Bypass Vulnerability |
|
CVE-2024-21361
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21360
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21359
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21358
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21357
HIGH 8.1
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2024-21356
MEDIUM 6.5
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2024-21355
HIGH 7.0
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2024-21354
HIGH 7.8
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2024-21352
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21351
HIGH 7.6
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2024-21350
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21349
HIGH 8.8
Microsoft ActiveX Data Objects Remote Code Execution Vulnerability |
|
CVE-2024-21348
HIGH 7.5
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
|
CVE-2024-21347
HIGH 7.5
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-21346
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2024-21344
MEDIUM 5.9
Windows Network Address Translation (NAT) Denial of Service Vulnerability |
|
CVE-2024-21343
MEDIUM 5.9
Windows Network Address Translation (NAT) Denial of Service Vulnerability |
|
CVE-2024-21341
MEDIUM 6.8
Windows Kernel Remote Code Execution Vulnerability |
|
CVE-2024-21340
MEDIUM 4.6
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2024-21339
MEDIUM 6.4
Windows USB Generic Parent Driver Remote Code Execution Vulnerability |
|
CVE-2024-21338
HIGH 7.8
KEV
Windows Kernel Elevation of Privilege Vulnerability |