Vulnerabilities
Tracked app vulnerabilities
11,275 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,275
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2017-15818
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-10502
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-12385
HIGH 7.0
1 app
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This is… |
|
CVE-2018-12379
HIGH 7.8
1 app
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially ex… |
|
CVE-2018-12368
HIGH 8.1
1 app
Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and h… |
|
CVE-2018-12364
HIGH 8.8
1 app
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the targ… |
|
CVE-2018-12363
HIGH 8.8
1 app
A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node… |
|
CVE-2018-12362
HIGH 8.8
1 app
An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploi… |
|
CVE-2018-12361
HIGH 8.8
1 app
An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when th… |
|
CVE-2018-12360
HIGH 8.8
1 app
A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. This results in a p… |
|
CVE-2018-12359
HIGH 8.8
1 app
A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written ou… |
|
CVE-2018-8453
HIGH 7.8
KEV
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privil… |
|
CVE-2018-8506
HIGH 3.3
Microsoft Windows Codecs Library Information Disclosure Vulnerability |
|
CVE-2018-8497
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8495
HIGH 4.2
Windows Shell Remote Code Execution Vulnerability |
|
CVE-2018-8493
HIGH 5.9
Windows TCP/IP Information Disclosure Vulnerability |
|
CVE-2018-8492
HIGH 5.3
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability |
|
CVE-2018-8486
HIGH 4.7
DirectX Information Disclosure Vulnerability |
|
CVE-2018-8484
HIGH 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8482
HIGH 3.5
Windows Media Player Information Disclosure Vulnerability |
|
CVE-2018-8481
HIGH 3.5
Windows Media Player Information Disclosure Vulnerability |
|
CVE-2018-8472
HIGH 4.7
Windows GDI Information Disclosure Vulnerability |
|
CVE-2018-8432
HIGH 5.0
Microsoft Graphics Components Remote Code Execution Vulnerability |
|
CVE-2018-8423
HIGH 7.8
Microsoft JET Database Engine Remote Code Execution Vulnerability |
|
CVE-2018-8413
HIGH 5.0
Windows Theme API Remote Code Execution Vulnerability |
|
CVE-2018-8411
HIGH 7.0
NTFS Elevation of Privilege Vulnerability |
|
CVE-2018-8333
HIGH 7.0
Microsoft Filter Manager Elevation Of Privilege Vulnerability |
|
CVE-2018-8330
HIGH 4.7
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2018-8329
HIGH 7.0
Linux On Windows Elevation Of Privilege Vulnerability |
|
CVE-2018-8320
HIGH 4.3
Windows DNS Security Feature Bypass Vulnerability |
|
CVE-2018-9515
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9514
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9513
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9511
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9510
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9509
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9508
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9507
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9506
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9505
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9503
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9502
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9501
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9499
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9493
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9492
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-9491
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2018-14647
HIGH 7.5
1 app
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks a… |
|
CVE-2018-10496
HIGH 8.8
1 app
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Internet Browser Fixed in version 6.4.0.15. User in… |
|
CVE-2018-8468
HIGH 4.3
Windows Elevation of Privilege Vulnerability |