Vulnerabilities
Tracked app vulnerabilities
11,272 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,272
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2020-1358
HIGH 5.5
Windows Resource Policy Information Disclosure Vulnerability |
|
CVE-2020-1357
HIGH 7.8
Windows System Events Broker Elevation of Privilege Vulnerability |
|
CVE-2020-1356
HIGH 7.8
Windows iSCSI Target Service Elevation of Privilege Vulnerability |
|
CVE-2020-1355
HIGH 7.8
Windows Font Driver Host Remote Code Execution Vulnerability |
|
CVE-2020-1354
HIGH 7.8
Windows UPnP Device Host Elevation of Privilege Vulnerability |
|
CVE-2020-1353
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2020-1352
HIGH 7.8
Windows USO Core Worker Elevation of Privilege Vulnerability |
|
CVE-2020-1351
HIGH 5.5
Microsoft Graphics Component Information Disclosure Vulnerability |
|
CVE-2020-1347
HIGH 7.8
Windows Storage Services Elevation of Privilege Vulnerability |
|
CVE-2020-1346
HIGH 7.8
Windows Modules Installer Elevation of Privilege Vulnerability |
|
CVE-2020-1344
HIGH 7.8
Windows WalletService Elevation of Privilege Vulnerability |
|
CVE-2020-1336
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-1333
HIGH 6.7
Group Policy Services Policy Processing Elevation of Privilege Vulnerability |
|
CVE-2020-1330
HIGH 5.5
Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability |
|
CVE-2020-1267
HIGH 4.9
Local Security Authority Subsystem Service Denial of Service Vulnerability |
|
CVE-2020-1249
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2020-1085
HIGH 7.8
Windows Function Discovery Service Elevation of Privilege Vulnerability |
|
CVE-2019-20907
HIGH 7.5
1 app
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pa… |
|
CVE-2020-12420
HIGH 8.8
1 app
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially explo… |
|
CVE-2020-12419
HIGH 8.8
1 app
When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This c… |
|
CVE-2020-12417
HIGH 8.8
1 app
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitab… |
|
CVE-2020-12406
HIGH 8.8
1 app
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it… |
|
CVE-2020-12398
HIGH 7.5
1 app
If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted co… |
|
CVE-2018-12371
HIGH 8.8
1 app
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the … |
|
CVE-2020-15523
HIGH 7.8
1 app
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases wh… |
|
CVE-2020-15502
HIGH 7.5
2 apps
The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers… |
|
CVE-2020-3701
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-3700
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-3688
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0231
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0230
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0228
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0227
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0226
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0122
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0107
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-20636
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-18282
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-14130
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-14124
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-14123
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-10580
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-20669
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-1223
HIGH 8.8
1 app
A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker w… |
|
CVE-2020-1457
HIGH 7.3
Microsoft Windows Codecs Library Remote Code Execution Vulnerability |
|
CVE-2020-1441
HIGH 7.0
Windows Spatial Data Service Elevation of Privilege Vulnerability |
|
CVE-2020-1348
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2020-1334
HIGH 7.8
Windows Runtime Elevation of Privilege Vulnerability |
|
CVE-2020-1324
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2020-1317
HIGH 7.8
Group Policy Elevation of Privilege Vulnerability |