Vulnerabilities
Tracked app vulnerabilities
8,473 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,473
- Actively exploited
- 213
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2019-0547
CRITICAL 9.8
Windows DHCP Client Remote Code Execution Vulnerability |
|
CVE-2019-0543
HIGH 7.8
KEV
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0538
HIGH 7.8
Jet Database Engine Remote Code Execution Vulnerability |
|
CVE-2019-0536
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-20406
HIGH 7.5
1 app
Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size" attempt. … |
|
CVE-2018-8649
HIGH 5.0
Windows Denial of Service Vulnerability |
|
CVE-2018-8641
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2018-8639
HIGH 7.0
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2018-8638
HIGH 4.7
DirectX Information Disclosure Vulnerability |
|
CVE-2018-8637
HIGH 4.7
Win32k Information Disclosure Vulnerability |
|
CVE-2018-8634
CRITICAL 4.2
Microsoft Text-To-Speech Remote Code Execution Vulnerability |
|
CVE-2018-8626
CRITICAL 9.8
Windows DNS Server Heap Overflow Vulnerability |
|
CVE-2018-8612
HIGH 4.7
Connected User Experiences and Telemetry Service Denial of Service Vulnerability |
|
CVE-2018-8611
HIGH 7.0
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8599
HIGH 7.0
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability |
|
CVE-2018-8596
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2018-8595
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2018-8514
HIGH 3.3
Windows Remote Procedure Call Information Disclosure Vulnerability |
|
CVE-2018-8477
HIGH 3.3
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-8592
HIGH 6.4
Windows Elevation Of Privilege Vulnerability |
|
CVE-2018-8584
HIGH 7.8
Windows ALPC Elevation of Privilege Vulnerability |
|
CVE-2018-8566
HIGH 4.6
BitLocker Security Feature Bypass Vulnerability |
|
CVE-2018-8565
HIGH 4.7
Win32k Information Disclosure Vulnerability |
|
CVE-2018-8562
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2018-8561
HIGH 7.0
DirectX Elevation of Privilege Vulnerability |
|
CVE-2018-8554
HIGH 7.0
DirectX Elevation of Privilege Vulnerability |
|
CVE-2018-8553
CRITICAL 7.4
Microsoft Graphics Components Remote Code Execution Vulnerability |
|
CVE-2018-8550
HIGH 7.0
Windows COM Elevation of Privilege Vulnerability |
|
CVE-2018-8549
HIGH 5.5
Windows Security Feature Bypass Vulnerability |
|
CVE-2018-8547
HIGH 6.5
Active Directory Federation Services XSS Vulnerability |
|
CVE-2018-8544
CRITICAL 7.5
Windows VBScript Engine Remote Code Execution Vulnerability |
|
CVE-2018-8485
HIGH 7.0
DirectX Elevation of Privilege Vulnerability |
|
CVE-2018-8476
CRITICAL 8.1
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability |
|
CVE-2018-8471
HIGH 7.0
Microsoft RemoteFX Virtual GPU miniport driver Elevation of Privilege Vulnerability |
|
CVE-2018-8454
HIGH 2.5
Windows Audio Service Information Disclosure Vulnerability |
|
CVE-2018-8450
HIGH 7.5
Windows Search Remote Code Execution Vulnerability |
|
CVE-2018-8417
HIGH 4.5
Microsoft JScript Security Feature Bypass Vulnerability |
|
CVE-2018-8415
HIGH 3.3
Microsoft PowerShell Tampering Vulnerability |
|
CVE-2018-8408
HIGH 3.3
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-8407
HIGH 3.3
Windows Remote Procedure Call Information Disclosure Vulnerability |
|
CVE-2018-8256
HIGH 6.3
Microsoft PowerShell Remote Code Execution Vulnerability |
|
CVE-2018-5188
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that wit… |
|
CVE-2018-5187
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort tha… |
|
CVE-2018-5156
CRITICAL 9.8
1 app
A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being… |
|
CVE-2018-12385
HIGH 7.0
1 app
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This is… |
|
CVE-2018-12383
MEDIUM 5.5
1 app
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because t… |
|
CVE-2018-12379
HIGH 7.8
1 app
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially ex… |
|
CVE-2018-12378
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored… |
|
CVE-2018-12377
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still i… |
|
CVE-2018-12376
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort t… |