Vulnerabilities
Tracked app vulnerabilities
16,412 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,412
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-20812
MEDIUM 6.5
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. |
|
CVE-2026-20811
HIGH 7.8
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20809
HIGH 7.8
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20808
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elev… |
|
CVE-2026-20805
MEDIUM 5.5
KEV
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. |
|
CVE-2026-20804
HIGH 7.7
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. |
|
CVE-2026-0892
CRITICAL 9.8
1 app
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2026-0891
HIGH 8.1
1 app
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2026-0890
MEDIUM 5.4
1 app
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunder… |
|
CVE-2026-0889
HIGH 7.5
1 app
Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. |
|
CVE-2026-0888
MEDIUM 5.3
1 app
Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. |
|
CVE-2026-0887
MEDIUM 4.3
1 app
Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Th… |
|
CVE-2026-0886
MEDIUM 5.3
1 app
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, a… |
|
CVE-2026-0885
MEDIUM 6.5
1 app
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0884
CRITICAL 9.8
1 app
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0883
MEDIUM 5.3
1 app
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0882
HIGH 8.8
1 app
Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0881
CRITICAL 10.0
1 app
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. |
|
CVE-2026-0880
HIGH 8.8
1 app
Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbi… |
|
CVE-2026-0879
CRITICAL 9.8
1 app
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140… |
|
CVE-2026-0878
HIGH 8.0
1 app
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thu… |
|
CVE-2026-0877
HIGH 8.1
1 app
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thun… |
|
CVE-2026-20833
HIGH 5.5
Windows Kerberos Information Disclosure Vulnerability |
|
CVE-2026-20830
HIGH 7.0
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
|
CVE-2026-20818
HIGH 6.2
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-20810
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-0386
HIGH 7.5
Windows Deployment Services Remote Code Execution Vulnerability |
|
CVE-2024-55414
HIGH 7.8
Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2023-31096
HIGH 7.8
MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-46299
MEDIUM 4.3
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS… |
|
CVE-2025-46298
MEDIUM 6.5
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2… |
|
CVE-2025-46297
MEDIUM 5.5
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files within an… |
|
CVE-2025-46286
MEDIUM 4.3
A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a backup may prevent passcode from being … |
|
CVE-2025-62224
MEDIUM 5.5
1 app
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. |
|
CVE-2025-54957
HIGH 7.0
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-46292
MEDIUM 5.5
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able … |
|
CVE-2025-46291
HIGH 7.8
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An app may bypass Gatekeeper checks. |
|
CVE-2025-46288
MEDIUM 5.5
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2.… |
|
CVE-2025-46283
MEDIUM 5.5
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to… |
|
CVE-2025-46282
MEDIUM 5.5
The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app may be able to access sensitive user d… |
|
CVE-2025-46281
HIGH 8.8
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to bre… |
|
CVE-2025-46279
LOW 3.3
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2… |
|
CVE-2025-46278
MEDIUM 5.5
The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected user data. |
|
CVE-2025-46277
LOW 3.3
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, watchOS 26.2. An app may be able… |
|
CVE-2025-43541
MEDIUM 4.3
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, … |
|
CVE-2025-43536
MEDIUM 4.3
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.… |
|
CVE-2025-43535
MEDIUM 4.3
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe … |
|
CVE-2025-43533
MEDIUM 5.7
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS… |
|
CVE-2025-43531
LOW 3.1
A race condition was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS … |
|
CVE-2025-43529
HIGH 8.8
KEV
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.… |