Vulnerabilities
Tracked app vulnerabilities
8,473 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,473
- Actively exploited
- 213
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2018-8239
HIGH 4.4
Windows GDI Information Disclosure Vulnerability |
|
CVE-2018-8233
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2018-8231
CRITICAL 8.1
HTTP Protocol Stack Remote Code Execution Vulnerability |
|
CVE-2018-8226
HIGH 5.3
HTTP.sys Denial of Service Vulnerability |
|
CVE-2018-8225
CRITICAL 8.1
Windows DNSAPI Remote Code Execution Vulnerability |
|
CVE-2018-8221
HIGH 5.3
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability |
|
CVE-2018-8219
HIGH 7.6
Hypervisor Code Integrity Elevation of Privilege Vulnerability |
|
CVE-2018-8218
HIGH 5.7
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2018-8217
HIGH 5.3
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability |
|
CVE-2018-8216
HIGH 5.3
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability |
|
CVE-2018-8215
HIGH 5.3
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability |
|
CVE-2018-8214
HIGH 7.0
Windows Desktop Bridge Elevation of Privilege Vulnerability |
|
CVE-2018-8213
CRITICAL 7.8
Windows Remote Code Execution Vulnerability |
|
CVE-2018-8212
HIGH 5.3
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability |
|
CVE-2018-8211
HIGH 5.3
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability |
|
CVE-2018-8210
HIGH 7.3
Windows Remote Code Execution Vulnerability |
|
CVE-2018-8209
HIGH 5.5
Windows Wireless Network Profile Information Disclosure Vulnerability |
|
CVE-2018-8208
HIGH 7.0
Windows Desktop Bridge Elevation of Privilege Vulnerability |
|
CVE-2018-8207
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-8205
HIGH 5.5
Windows Denial of Service Vulnerability |
|
CVE-2018-8201
HIGH 4.5
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability |
|
CVE-2018-8175
HIGH 5.9
WEBDAV Denial of Service Vulnerability |
|
CVE-2018-8169
HIGH 7.0
HIDParser Elevation of Privilege Vulnerability |
|
CVE-2018-8140
HIGH 6.8
Cortana Elevation of Privilege Vulnerability |
|
CVE-2018-8121
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-1040
HIGH 5.3
Windows Code Integrity Module Denial of Service Vulnerability |
|
CVE-2018-1036
HIGH 7.0
NTFS Elevation of Privilege Vulnerability |
|
CVE-2018-0982
HIGH 7.0
Windows Elevation of Privilege Vulnerability |
|
CVE-2018-5185
MEDIUM 6.5
1 app
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. |
|
CVE-2018-5184
HIGH 7.5
1 app
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. |
|
CVE-2018-5183
CRITICAL 9.8
1 app
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes du… |
|
CVE-2018-5178
HIGH 8.1
1 app
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the us… |
|
CVE-2018-5174
HIGH 7.5
1 app
In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not show any … |
|
CVE-2018-5170
MEDIUM 4.3
1 app
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is … |
|
CVE-2018-5168
MEDIUM 5.3
1 app
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a m… |
|
CVE-2018-5162
HIGH 7.5
1 app
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird … |
|
CVE-2018-5161
MEDIUM 4.3
1 app
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 5… |
|
CVE-2018-5159
CRITICAL 9.8
1 app
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds wr… |
|
CVE-2018-5155
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vu… |
|
CVE-2018-5154
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. T… |
|
CVE-2018-5150
CRITICAL 9.8
1 app
Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume … |
|
CVE-2018-5146
CRITICAL 8.8
1 app
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox… |
|
CVE-2018-5145
CRITICAL 9.8
1 app
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these… |
|
CVE-2018-5144
HIGH 7.3
1 app
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox… |
|
CVE-2018-5129
HIGH 8.6
1 app
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbo… |
|
CVE-2018-5127
HIGH 8.8
1 app
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability… |
|
CVE-2018-5125
HIGH 8.8
1 app
Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough ef… |
|
CVE-2018-5117
MEDIUM 5.3
1 app
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed U… |
|
CVE-2018-5104
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable cra… |
|
CVE-2018-5103
CRITICAL 9.8
1 app
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. … |