Vulnerabilities
Tracked app vulnerabilities
11,275 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,275
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2019-2136
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2135
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2134
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2133
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2132
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2131
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2129
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2128
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2127
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2126
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2122
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2121
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-2120
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-10538
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-10510
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-10509
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-10499
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-10489
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-9818
HIGH 8.3
1 app
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main pr… |
|
CVE-2019-9815
HIGH 8.1
1 app
If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to… |
|
CVE-2019-9811
HIGH 8.3
1 app
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that … |
|
CVE-2019-11729
HIGH 7.5
1 app
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This … |
|
CVE-2019-11719
HIGH 7.5
1 app
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Servic… |
|
CVE-2019-11712
HIGH 8.8
1 app
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to per… |
|
CVE-2019-11711
HIGH 8.8
1 app
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperative… |
|
CVE-2019-11707
HIGH 8.8
KEV
1 app
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware… |
|
CVE-2019-11706
HIGH 7.5
1 app
A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulti… |
|
CVE-2019-11694
HIGH 7.5
1 app
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an … |
|
CVE-2019-1130
HIGH 7.8
KEV
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privileg… |
|
CVE-2019-13567
HIGH 8.8
1 app
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the h… |
|
CVE-2019-1129
HIGH 7.8
KEV
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1128
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1127
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1126
HIGH 5.3
ADFS Security Feature Bypass Vulnerability |
|
CVE-2019-1124
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1123
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1122
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1121
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1120
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1119
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1118
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1117
HIGH 7.8
DirectWrite Remote Code Execution Vulnerability |
|
CVE-2019-1108
HIGH 6.5
Remote Desktop Protocol Client Information Disclosure Vulnerability |
|
CVE-2019-1097
HIGH 5.5
DirectWrite Information Disclosure Vulnerability |
|
CVE-2019-1096
HIGH 5.5
Win32k Information Disclosure Vulnerability |
|
CVE-2019-1095
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-1094
HIGH 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2019-1093
HIGH 5.5
DirectWrite Information Disclosure Vulnerability |
|
CVE-2019-1091
HIGH 5.5
Microsoft unistore.dll Information Disclosure Vulnerability |
|
CVE-2019-1090
HIGH 7.8
Windows dnsrslvr.dll Elevation of Privilege Vulnerability |