Vulnerabilities
Tracked app vulnerabilities
8,495 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,495
- Actively exploited
- 214
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2019-11764
HIGH 8.8
1 app
Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory c… |
|
CVE-2019-11763
MEDIUM 6.1
1 app
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML commen… |
|
CVE-2019-11762
MEDIUM 6.1
1 app
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on … |
|
CVE-2019-11761
MEDIUM 5.4
1 app
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this o… |
|
CVE-2019-11760
HIGH 8.8
1 app
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vuln… |
|
CVE-2019-11759
HIGH 8.8
1 app
An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute a… |
|
CVE-2019-11758
HIGH 8.8
1 app
Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory c… |
|
CVE-2019-11757
HIGH 8.8
1 app
When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use… |
|
CVE-2019-11745
HIGH 8.8
1 app
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. Th… |
|
CVE-2019-1387
CRITICAL 8.8
1 app
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are cu… |
|
CVE-2019-8801
HIGH 7.8
1 app
A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes… |
|
CVE-2019-8745
HIGH 8.8
1 app
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15, tvOS 13, iTunes for Windows 12.10.1, iCloud for Win… |
|
CVE-2019-8735
HIGH 8.8
1 app
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows … |
|
CVE-2019-8733
HIGH 8.8
1 app
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows … |
|
CVE-2019-8726
HIGH 8.8
1 app
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows … |
|
CVE-2019-8719
MEDIUM 6.1
1 app
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Win… |
|
CVE-2019-8707
HIGH 8.8
1 app
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows … |
|
CVE-2019-8625
MEDIUM 6.1
1 app
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Win… |
|
CVE-2019-19604
HIGH 7.8
1 app
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 becaus… |
|
CVE-2019-1458
HIGH 7.8
KEV
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privil… |
|
CVE-2019-1488
HIGH 3.3
Microsoft Defender Security Feature Bypass Vulnerability |
|
CVE-2019-1484
HIGH 7.8
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2019-1483
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1477
HIGH 7.8
Windows Printer Service Elevation of Privilege Vulnerability |
|
CVE-2019-1476
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1474
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2019-1472
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2019-1471
CRITICAL 8.2
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2019-1470
HIGH 6.0
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2019-1469
HIGH 5.5
Win32k Information Disclosure Vulnerability |
|
CVE-2019-1468
CRITICAL 8.4
Win32k Graphics Remote Code Execution Vulnerability |
|
CVE-2019-1467
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-1466
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-1465
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-1453
HIGH 7.5
Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability |
|
CVE-2016-1000110
MEDIUM 6.1
1 app
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker t… |
|
CVE-2019-11135
MEDIUM 6.5
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via … |
|
CVE-2019-1405
HIGH 7.8
KEV
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP… |
|
CVE-2019-1385
HIGH 7.8
KEV
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to sys… |
|
CVE-2019-1456
HIGH 7.8
OpenType Font Parsing Remote Code Execution Vulnerability |
|
CVE-2019-1454
HIGH
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2019-1440
HIGH 5.0
Win32k Information Disclosure Vulnerability |
|
CVE-2019-1439
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-1438
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2019-1437
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2019-1436
HIGH 5.5
Win32k Information Disclosure Vulnerability |
|
CVE-2019-1435
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2019-1433
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2019-1430
CRITICAL 7.3
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
|
CVE-2019-1424
HIGH 8.1
NetLogon Security Feature Bypass Vulnerability |