Vulnerabilities
Tracked app vulnerabilities
16,412 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,412
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-21237
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21236
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21235
HIGH 7.3
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-21234
HIGH 7.0
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2026-21232
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21231
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21222
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-2804
HIGH 6.5
Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo |
|
CVE-2025-46316
MEDIUM 4.3
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a… |
|
CVE-2025-46306
MEDIUM 5.5
The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciously crafte… |
|
CVE-2026-0818
MEDIUM 4.3
1 app
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled… |
|
CVE-2025-11002
HIGH 7.8
1 app
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… |
|
CVE-2025-12781
MEDIUM 5.3
1 app
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepte… |
|
CVE-2025-43508
MEDIUM 5.5
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data. |
|
CVE-2025-31186
LOW 3.3
1 app
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences. |
|
CVE-2025-24090
LOW 3.3
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's insta… |
|
CVE-2025-24089
MEDIUM 5.3
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's insta… |
|
CVE-2024-54556
LOW 2.4
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. A user may be able to view restricted content from… |
|
CVE-2024-44238
HIGH 7.8
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to corrupt coproce… |
|
CVE-2024-44210
LOW 3.3
This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data. |
|
CVE-2026-21265
MEDIUM 6.4
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affect… |
|
CVE-2026-21221
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz… |
|
CVE-2026-20962
MEDIUM 4.4
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. |
|
CVE-2026-20941
HIGH 7.8
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20940
HIGH 7.8
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20939
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20938
HIGH 7.8
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20937
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20936
MEDIUM 4.3
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. |
|
CVE-2026-20935
MEDIUM 6.2
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-20934
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… |
|
CVE-2026-20932
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20931
HIGH 8.0
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. |
|
CVE-2026-20929
HIGH 7.5
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-20927
MEDIUM 5.3
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service… |
|
CVE-2026-20926
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… |
|
CVE-2026-20925
MEDIUM 6.5
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-20924
HIGH 7.8
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20923
HIGH 7.8
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20922
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-20921
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… |
|
CVE-2026-20920
HIGH 7.8
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20919
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… |
|
CVE-2026-20918
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… |
|
CVE-2026-20877
HIGH 7.8
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20876
MEDIUM 6.7
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20875
HIGH 7.5
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-20874
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… |
|
CVE-2026-20873
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… |
|
CVE-2026-20872
MEDIUM 6.5
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |