Vulnerabilities
Tracked app vulnerabilities
749 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-49167
MEDIUM 4.7
Local
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44806
MEDIUM 5.3
Network
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-41087
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-40422
MEDIUM 5.5
Local
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-34349
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. |
|
CVE-2026-34348
MEDIUM 6.5
Network
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. |
|
CVE-2026-34346
MEDIUM 5.5
Local
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. |
|
CVE-2026-34328
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-33842
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-57963
MEDIUM 6.5
Network 1 apps
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. Thi… |
|
CVE-2026-57962
MEDIUM 5.3
Network 1 apps
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplie… |
|
CVE-2026-4360
MEDIUM 5.3
Network 1 apps
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrust… |
|
CVE-2026-12330
MEDIUM 5.4
Network 1 apps
Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 14… |
|
CVE-2026-12329
MEDIUM 5.3
Network 1 apps
Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12. |
|
CVE-2026-12325
MEDIUM 6.5
Network 1 apps
Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, an… |
|
CVE-2026-12323
MEDIUM 5.4
Network 1 apps
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12322
MEDIUM 5.4
Network 1 apps
Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12321
MEDIUM 5.4
Network 1 apps
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12320
MEDIUM 4.3
Network 1 apps
Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12319
MEDIUM 6.5
Network 1 apps
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12313
MEDIUM 4.7
Network 1 apps
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderb… |
|
CVE-2026-12311
MEDIUM 4.7
Network 1 apps
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderb… |
|
CVE-2026-12309
MEDIUM 6.5
Network 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-12308
MEDIUM 5.3
Network 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-12307
MEDIUM 5.3
Network 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-12306
MEDIUM 5.3
Network 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-12303
MEDIUM 4.3
Network 1 apps
Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12302
MEDIUM 6.5
Network 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thu… |
|
CVE-2026-12301
MEDIUM 5.3
Network 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12300
MEDIUM 5.3
Network 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12299
MEDIUM 5.4
Network 1 apps
JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and… |
|
CVE-2026-12298
MEDIUM 5.4
Network 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-50508
MEDIUM 6.5
Network
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-50507
MEDIUM 6.8
Physical
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-48566
MEDIUM 5.5
Local
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-45655
MEDIUM 5.3
Physical
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-45634
MEDIUM 5.5
Local
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. |
|
CVE-2026-45608
MEDIUM 6.8
Local
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-45606
MEDIUM 5.5
Local
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally. |
|
CVE-2026-45604
MEDIUM 5.5
Local
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. |
|
CVE-2026-45595
MEDIUM 5.4
Network
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-45594
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informat… |
|
CVE-2026-44814
MEDIUM 5.5
Local
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-44805
MEDIUM 5.5
Local
Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. |
|
CVE-2026-42973
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42972
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. |
|
CVE-2026-42971
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42970
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42969
MEDIUM 5.5
Local
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42968
MEDIUM 5.5
Local
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. |