Vulnerabilities
Tracked app vulnerabilities
8,456 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,456
- Actively exploited
- 213
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2019-0901
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0900
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0899
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0898
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0897
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0896
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0895
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0894
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0893
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0892
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2019-0891
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0890
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0889
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0886
HIGH 5.5
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2019-0885
HIGH 7.8
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2019-0882
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-0881
HIGH 8.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2019-0863
HIGH 7.8
KEV
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2019-0758
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-0734
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0733
HIGH 5.3
Windows Defender Application Control Security Feature Bypass Vulnerability |
|
CVE-2019-0727
HIGH 6.7
Diagnostic Hub Standard Collector, Visual Studio Standard Collector Elevation of Privilege Vulnerability |
|
CVE-2019-0725
CRITICAL 8.1
Windows DHCP Server Remote Code Execution Vulnerability |
|
CVE-2019-0707
HIGH 7.0
Windows NDIS Elevation of Privilege Vulnerability |
|
CVE-2018-18524
MEDIUM 6.1
1 app
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. Af… |
|
CVE-2019-9813
HIGH 8.8
1 app
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulne… |
|
CVE-2019-9810
HIGH 8.8
1 app
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerabili… |
|
CVE-2019-9801
MEDIUM 5.3
1 app
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows o… |
|
CVE-2019-9796
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration… |
|
CVE-2019-9795
CRITICAL 9.8
1 app
A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially ex… |
|
CVE-2019-9794
CRITICAL 9.8
1 app
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This cou… |
|
CVE-2019-9793
MEDIUM 5.9
1 app
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnera… |
|
CVE-2019-9792
CRITICAL 9.8
1 app
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then b… |
|
CVE-2019-9791
CRITICAL 9.8
1 app
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just… |
|
CVE-2019-9790
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still… |
|
CVE-2019-9788
CRITICAL 9.8
1 app
Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed e… |
|
CVE-2018-18513
HIGH 7.5
1 app
A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) atta… |
|
CVE-2018-18512
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although th… |
|
CVE-2018-18509
MEDIUM 5.3
1 app
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message… |
|
CVE-2019-0879
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0877
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0859
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2019-0856
HIGH 6.6
Windows Remote Code Execution Vulnerability |
|
CVE-2019-0853
CRITICAL 7.8
GDI+ Remote Code Execution Vulnerability |
|
CVE-2019-0851
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0849
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-0848
HIGH 4.7
Win32k Information Disclosure Vulnerability |
|
CVE-2019-0847
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0846
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0845
CRITICAL 7.5
Windows IOleCvt Interface Remote Code Execution Vulnerability |