Vulnerabilities
Tracked app vulnerabilities
11,280 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,280
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2016-2488
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2487
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2486
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2485
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2484
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2483
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2482
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2481
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2480
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2479
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2478
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2477
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2476
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2475
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2473
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2472
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2471
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2470
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2066
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-2061
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-0718
HIGH 9.8
1 app
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers… |
|
CVE-2016-0197
HIGH 7.8
dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S… |
|
CVE-2016-0196
HIGH 7.8
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… |
|
CVE-2016-0195
HIGH 8.8
The Imaging Component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows … |
|
CVE-2016-0184
HIGH 8.8
Use-after-free vulnerability in GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an… |
|
CVE-2016-0182
HIGH 7.8
Windows Journal in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arb… |
|
CVE-2016-0180
HIGH 7.8
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and… |
|
CVE-2016-0179
HIGH 7.8
Windows Shell in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code … |
|
CVE-2016-0178
HIGH 8.8
The RPC NDR Engine in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT … |
|
CVE-2016-0176
HIGH 7.8
dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Se… |
|
CVE-2016-0174
HIGH 7.8
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… |
|
CVE-2016-0173
HIGH 7.8
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… |
|
CVE-2016-0171
HIGH 7.8
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… |
|
CVE-2016-0170
HIGH 8.8
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Window… |
|
CVE-2016-2446
HIGH 7.0
The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 2744135… |
|
CVE-2016-0167
HIGH 7.8
KEV
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… |
|
CVE-2016-0165
HIGH 7.8
KEV
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… |
|
CVE-2016-0151
HIGH 7.8
KEV
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages… |
|
CVE-2016-0150
HIGH 7.5
HTTP.sys in Microsoft Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (system hang) via crafted HTTP 2.0 requests, aka "HTTP.sys … |
|
CVE-2016-0145
HIGH 8.8
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.… |
|
CVE-2016-0143
HIGH 7.8
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… |
|
CVE-2016-0135
HIGH 8.4
The Secondary Logon Service in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevati… |
|
CVE-2016-1765
HIGH 7.8
1 app
otool in Apple Xcode before 7.3 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified ve… |
|
CVE-2016-1974
HIGH 8.8
1 app
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, … |
|
CVE-2016-1966
HIGH 8.8
1 app
The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote a… |
|
CVE-2016-1964
HIGH 8.8
1 app
Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execut… |
|
CVE-2016-1961
HIGH 8.8
1 app
Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before … |
|
CVE-2016-1960
HIGH 8.8
1 app
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote atta… |
|
CVE-2016-1954
HIGH 8.8
1 app
The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of… |
|
CVE-2016-1953
HIGH 8.8
1 app
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruptio… |