Vulnerabilities
Tracked app vulnerabilities
8,473 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,473
- Actively exploited
- 213
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2018-12374
MEDIUM 4.3
1 app
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects … |
|
CVE-2018-12373
MEDIUM 6.5
1 app
dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderb… |
|
CVE-2018-12372
MEDIUM 6.5
1 app
Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thu… |
|
CVE-2018-12368
HIGH 8.1
1 app
Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and h… |
|
CVE-2018-12367
MEDIUM 4.3
1 app
In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals… |
|
CVE-2018-12366
MEDIUM 6.5
1 app
An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private dat… |
|
CVE-2018-12365
MEDIUM 6.5
1 app
A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. Th… |
|
CVE-2018-12364
HIGH 8.8
1 app
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the targ… |
|
CVE-2018-12363
HIGH 8.8
1 app
A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node… |
|
CVE-2018-12362
HIGH 8.8
1 app
An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploi… |
|
CVE-2018-12361
HIGH 8.8
1 app
An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when th… |
|
CVE-2018-12360
HIGH 8.8
1 app
A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. This results in a p… |
|
CVE-2018-12359
HIGH 8.8
1 app
A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written ou… |
|
CVE-2018-8453
HIGH 7.8
KEV
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privil… |
|
CVE-2018-8506
HIGH 3.3
Microsoft Windows Codecs Library Information Disclosure Vulnerability |
|
CVE-2018-8497
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8495
HIGH 4.2
Windows Shell Remote Code Execution Vulnerability |
|
CVE-2018-8494
CRITICAL 7.5
MS XML Remote Code Execution Vulnerability |
|
CVE-2018-8493
HIGH 5.9
Windows TCP/IP Information Disclosure Vulnerability |
|
CVE-2018-8492
HIGH 5.3
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability |
|
CVE-2018-8490
CRITICAL 7.6
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2018-8489
CRITICAL 7.6
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2018-8486
HIGH 4.7
DirectX Information Disclosure Vulnerability |
|
CVE-2018-8484
HIGH 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8482
HIGH 3.5
Windows Media Player Information Disclosure Vulnerability |
|
CVE-2018-8481
HIGH 3.5
Windows Media Player Information Disclosure Vulnerability |
|
CVE-2018-8472
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2018-8432
HIGH 5.0
Microsoft Graphics Components Remote Code Execution Vulnerability |
|
CVE-2018-8423
HIGH 7.8
Microsoft JET Database Engine Remote Code Execution Vulnerability |
|
CVE-2018-8413
HIGH 5.0
Windows Theme API Remote Code Execution Vulnerability |
|
CVE-2018-8411
HIGH 7.0
NTFS Elevation of Privilege Vulnerability |
|
CVE-2018-8333
HIGH 7.0
Microsoft Filter Manager Elevation Of Privilege Vulnerability |
|
CVE-2018-8330
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-8329
HIGH 7.0
Linux On Windows Elevation Of Privilege Vulnerability |
|
CVE-2018-8320
HIGH 4.3
Windows DNS Security Feature Bypass Vulnerability |
|
CVE-2018-14647
HIGH 7.5
1 app
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks a… |
|
CVE-2018-1000802
CRITICAL 9.8
1 app
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') … |
|
CVE-2018-8475
CRITICAL 8.8
Windows Remote Code Execution Vulnerability |
|
CVE-2018-8468
HIGH 4.3
Windows Elevation of Privilege Vulnerability |
|
CVE-2018-8462
HIGH 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8455
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8449
HIGH 5.3
Device Guard Security Feature Bypass Vulnerability |
|
CVE-2018-8446
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-8445
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-8443
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-8442
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-8441
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2018-8440
HIGH 7.8
KEV
Windows ALPC Elevation of Privilege Vulnerability |
|
CVE-2018-8439
CRITICAL 7.6
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2018-8438
HIGH 5.8
Windows Hyper-V Denial of Service Vulnerability |