Vulnerabilities
Tracked app vulnerabilities
8,495 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,495
- Actively exploited
- 214
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2019-9816
MEDIUM 5.9
1 app
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security ch… |
|
CVE-2019-9815
HIGH 8.1
1 app
If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to… |
|
CVE-2019-9811
HIGH 8.3
1 app
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that … |
|
CVE-2019-9800
CRITICAL 9.8
1 app
Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed e… |
|
CVE-2019-11730
MEDIUM 6.5
1 app
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directo… |
|
CVE-2019-11729
HIGH 7.5
1 app
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This … |
|
CVE-2019-11719
HIGH 7.5
1 app
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Servic… |
|
CVE-2019-11717
MEDIUM 5.3
1 app
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible … |
|
CVE-2019-11715
MEDIUM 6.1
1 app
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certa… |
|
CVE-2019-11713
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This… |
|
CVE-2019-11712
HIGH 8.8
1 app
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to per… |
|
CVE-2019-11711
HIGH 8.8
1 app
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperative… |
|
CVE-2019-11709
CRITICAL 9.8
1 app
Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory c… |
|
CVE-2019-11708
CRITICAL 10.0
KEV
1 app
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op… |
|
CVE-2019-11707
HIGH 8.8
KEV
1 app
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware… |
|
CVE-2019-11706
HIGH 7.5
1 app
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulti… |
|
CVE-2019-11705
CRITICAL 9.8
1 app
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in … |
|
CVE-2019-11704
CRITICAL 9.8
1 app
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting… |
|
CVE-2019-11703
CRITICAL 9.8
1 app
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a pot… |
|
CVE-2019-11698
MEDIUM 5.3
1 app
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web conten… |
|
CVE-2019-11694
HIGH 7.5
1 app
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an … |
|
CVE-2019-11693
CRITICAL 9.8
1 app
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a … |
|
CVE-2019-11692
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable … |
|
CVE-2019-11691
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been fr… |
|
CVE-2019-1130
HIGH 7.8
KEV
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privileg… |
|
CVE-2018-20852
MEDIUM 5.3
1 app
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into se… |
|
CVE-2019-1129
HIGH 7.8
KEV
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1128
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1127
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1126
HIGH 5.3
ADFS Security Feature Bypass Vulnerability |
|
CVE-2019-1124
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1123
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1122
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1121
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1120
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1119
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1118
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1117
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1108
HIGH 6.5
Remote Desktop Protocol Client Information Disclosure Vulnerability |
|
CVE-2019-1102
CRITICAL 8.4
GDI+ Remote Code Execution Vulnerability |
|
CVE-2019-1097
HIGH 5.5
DirectWrite Information Disclosure Vulnerability |
|
CVE-2019-1096
HIGH 5.5
Win32k Information Disclosure Vulnerability |
|
CVE-2019-1095
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-1094
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-1093
HIGH 5.5
DirectWrite Information Disclosure Vulnerability |
|
CVE-2019-1091
HIGH 5.5
Microsoft unistore.dll Information Disclosure Vulnerability |
|
CVE-2019-1090
HIGH 7.8
Windows dnsrslvr.dll Elevation of Privilege Vulnerability |
|
CVE-2019-1089
HIGH 7.8
Windows RPCSS Elevation of Privilege Vulnerability |
|
CVE-2019-1088
HIGH 7.8
Windows Audio Service Elevation of Privilege Vulnerability |
|
CVE-2019-1087
HIGH 7.8
Windows Audio Service Elevation of Privilege Vulnerability |