Vulnerabilities
Tracked app vulnerabilities
16,427 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,427
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2022-22738
HIGH 8.8
1 app
Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. … |
|
CVE-2022-22737
HIGH 7.5
1 app
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a p… |
|
CVE-2022-1834
MEDIUM 6.5
1 app
When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displaye… |
|
CVE-2022-1520
MEDIUM 4.3
1 app
When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encr… |
|
CVE-2022-1197
MEDIUM 5.4
1 app
When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet r… |
|
CVE-2022-1196
MEDIUM 6.5
1 app
After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnera… |
|
CVE-2022-1097
MEDIUM 6.5
1 app
<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-fre… |
|
CVE-2022-0566
HIGH 8.8
1 app
It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message.… |
|
CVE-2021-4140
CRITICAL 10.0
1 app
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, … |
|
CVE-2021-4129
CRITICAL 9.8
1 app
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safe… |
|
CVE-2021-4127
CRITICAL 9.8
1 app
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and… |
|
CVE-2021-4126
MEDIUM 6.5
1 app
When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message layer, for example a message footer added by a mailing list … |
|
CVE-2020-15685
HIGH 8.8
1 app
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulner… |
|
CVE-2022-3775
HIGH 7.1
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size.… |
|
CVE-2022-2601
HIGH 8.6
A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, all… |
|
CVE-2022-44708
HIGH 8.3
1 app
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
|
CVE-2022-24480
MEDIUM 6.3
1 app
Outlook for Android Elevation of Privilege Vulnerability |
|
CVE-2022-44710
HIGH 7.8
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2022-44707
HIGH 6.5
Windows Kernel Denial of Service Vulnerability |
|
CVE-2022-44698
MEDIUM 5.4
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-44697
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2022-44689
HIGH 7.8
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability |
|
CVE-2022-44683
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2022-44682
HIGH 6.8
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2022-44681
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-44680
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2022-44679
HIGH 6.5
Windows Graphics Component Information Disclosure Vulnerability |
|
CVE-2022-44678
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-44677
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2022-44676
CRITICAL 8.1
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
|
CVE-2022-44675
HIGH 7.8
Windows Bluetooth Driver Elevation of Privilege Vulnerability |
|
CVE-2022-44674
HIGH 5.5
Windows Bluetooth Driver Information Disclosure Vulnerability |
|
CVE-2022-44673
HIGH 7.0
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
|
CVE-2022-44671
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2022-44670
CRITICAL 8.1
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
|
CVE-2022-44669
HIGH 7.0
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2022-44668
HIGH 7.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2022-44667
HIGH 7.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2022-44666
HIGH 7.8
Windows Contacts Remote Code Execution Vulnerability |
|
CVE-2022-41121
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2022-41094
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2022-41077
HIGH 7.8
Windows Fax Compose Form Elevation of Privilege Vulnerability |
|
CVE-2022-41076
CRITICAL 8.5
PowerShell Remote Code Execution Vulnerability |
|
CVE-2022-41074
HIGH 5.5
Windows Graphics Component Information Disclosure Vulnerability |
|
CVE-2022-43363
MEDIUM 6.1
2 apps
Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relati… |
|
CVE-2022-42772
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42771
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42770
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42756
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42755
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |