Vulnerabilities
Tracked app vulnerabilities
8,456 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,456
- Actively exploited
- 213
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2019-0697
CRITICAL 9.8
Windows DHCP Client Remote Code Execution Vulnerability |
|
CVE-2019-0696
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2019-0695
HIGH 6.8
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2019-0694
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2019-0693
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2019-0692
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2019-0690
HIGH 6.8
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2019-0689
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2019-0683
HIGH 4.9
Active Directory Elevation of Privilege Vulnerability |
|
CVE-2019-0682
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2019-0617
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0614
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-0603
CRITICAL 7.5
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability |
|
CVE-2019-9636
CRITICAL 9.8
1 app
Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. T… |
|
CVE-2018-18499
MEDIUM 6.5
1 app
A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to anothe… |
|
CVE-2018-18498
CRITICAL 9.8
1 app
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked v… |
|
CVE-2018-18494
MEDIUM 6.5
1 app
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another sit… |
|
CVE-2018-18493
CRITICAL 9.8
1 app
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculat… |
|
CVE-2018-18492
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This resul… |
|
CVE-2018-12405
CRITICAL 9.8
1 app
Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory c… |
|
CVE-2018-12393
HIGH 7.5
1 app
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could resu… |
|
CVE-2018-12392
CRITICAL 9.8
1 app
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor ev… |
|
CVE-2018-12390
CRITICAL 9.8
1 app
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory c… |
|
CVE-2018-12389
HIGH 8.8
1 app
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and w… |
|
CVE-2018-20253
HIGH 7.8
1 app
In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful… |
|
CVE-2019-0674
HIGH 7.8
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability |
|
CVE-2019-0673
HIGH 7.8
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability |
|
CVE-2019-0671
HIGH 7.8
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability |
|
CVE-2019-0663
HIGH 4.3
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2019-0662
CRITICAL 8.8
GDI+ Remote Code Execution Vulnerability |
|
CVE-2019-0660
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-0659
HIGH 7.0
Windows Storage Service Elevation of Privilege Vulnerability |
|
CVE-2019-0656
HIGH 4.7
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2019-0637
HIGH 5.3
Windows Defender Firewall Security Feature Bypass Vulnerability |
|
CVE-2019-0636
HIGH 5.5
Windows Information Disclosure Vulnerability |
|
CVE-2019-0635
HIGH 5.4
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2019-0633
HIGH 7.5
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2019-0632
HIGH 5.3
Windows Security Feature Bypass Vulnerability |
|
CVE-2019-0631
HIGH 5.3
Windows Security Feature Bypass Vulnerability |
|
CVE-2019-0630
HIGH 7.5
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2019-0628
HIGH 4.7
Win32k Information Disclosure Vulnerability |
|
CVE-2019-0627
HIGH 5.3
Windows Security Feature Bypass Vulnerability |
|
CVE-2019-0626
CRITICAL 9.8
Windows DHCP Server Remote Code Execution Vulnerability |
|
CVE-2019-0625
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0623
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2019-0621
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2019-0619
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-0618
CRITICAL 8.8
GDI+ Remote Code Execution Vulnerability |
|
CVE-2019-0616
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-0615
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |