Vulnerabilities
Tracked app vulnerabilities
3,490 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 3,490
- Actively exploited
- 21
- Publication window
- 2009-07-30 → 2026-09-29
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2021-38632
MEDIUM 5.7
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2021-38629
MEDIUM 6.5
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability |
|
CVE-2021-38624
MEDIUM 6.5
Windows Key Storage Provider Security Feature Bypass Vulnerability |
|
CVE-2021-36972
MEDIUM 5.5
Windows SMB Information Disclosure Vulnerability |
|
CVE-2021-36969
MEDIUM 5.5
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability |
|
CVE-2021-36962
MEDIUM 5.5
Windows Installer Information Disclosure Vulnerability |
|
CVE-2021-36961
MEDIUM 5.5
Windows Installer Denial of Service Vulnerability |
|
CVE-2021-36959
MEDIUM 5.5
Windows Authenticode Spoofing Vulnerability |
|
CVE-2021-40529
MEDIUM 5.9
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between tw… |
|
CVE-2021-30621
MEDIUM 6.5
Chromium: CVE-2021-30621 UI Spoofing in Autofill |
|
CVE-2021-30619
MEDIUM 6.5
Chromium: CVE-2021-30619 UI Spoofing in Autofill |
|
CVE-2021-30617
MEDIUM 6.5
Chromium: CVE-2021-30617 Policy bypass in Blink |
|
CVE-2021-30615
MEDIUM 6.5
Chromium: CVE-2021-30615 Cross-origin data leak in Navigation |
|
CVE-2021-36930
MEDIUM 5.3
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
|
CVE-2021-26436
MEDIUM 6.1
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
|
CVE-2021-30597
Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical ac… |
|
CVE-2021-30596
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar)… |
|
CVE-2021-30594
Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to … |
|
CVE-2021-29987
After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still… |
|
CVE-2021-29982
Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a single bit of memory. Th… |
|
CVE-2021-36938
MEDIUM 5.5
Windows Cryptographic Primitives Library Information Disclosure Vulnerability |
|
CVE-2021-34534
MEDIUM 6.8
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-34480
MEDIUM 6.8
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-29969
MEDIUM 5.9
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS ha… |
|
CVE-2021-30589
Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a… |
|
CVE-2021-30587
Inappropriate implementation in Compositing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially spoof the contents of the Omnibox … |
|
CVE-2021-30584
Incorrect security UI in Downloads in Google Chrome on Android prior to 92.0.4515.107 allowed a remote attacker to perform domain spoofing via a crafted HTML p… |
|
CVE-2021-30583
Insufficient policy enforcement in image handling in iOS in Google Chrome on iOS prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via… |
|
CVE-2021-30582
Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
|
CVE-2021-30580
Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious appl… |
|
CVE-2021-34466
MEDIUM 5.7
Windows Hello Security Feature Bypass Vulnerability |
|
CVE-2021-34457
MEDIUM 5.5
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2021-34454
MEDIUM 5.5
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2021-34448
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-34447
MEDIUM 6.8
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-34444
MEDIUM 6.5
Windows DNS Server Denial of Service Vulnerability |
|
CVE-2021-34440
MEDIUM 5.5
GDI+ Information Disclosure Vulnerability |
|
CVE-2021-34509
MEDIUM 5.5
Storage Spaces Controller Information Disclosure Vulnerability |
|
CVE-2021-34507
MEDIUM 6.5
Windows Remote Assistance Information Disclosure Vulnerability |
|
CVE-2021-34500
MEDIUM 6.3
Windows Kernel Memory Information Disclosure Vulnerability |
|
CVE-2021-34499
MEDIUM 6.5
Windows DNS Server Denial of Service Vulnerability |
|
CVE-2021-34497
MEDIUM 6.8
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-34496
MEDIUM 5.5
Windows GDI Information Disclosure Vulnerability |
|
CVE-2021-34493
MEDIUM 6.7
Windows Partition Management Driver Elevation of Privilege Vulnerability |
|
CVE-2021-34491
MEDIUM 5.5
Win32k Information Disclosure Vulnerability |
|
CVE-2021-33783
MEDIUM 6.5
Windows SMB Information Disclosure Vulnerability |
|
CVE-2021-33782
MEDIUM 5.5
Windows Authenticode Spoofing Vulnerability |
|
CVE-2021-33765
MEDIUM 6.2
Windows Installer Spoofing Vulnerability |
|
CVE-2021-33764
MEDIUM 5.9
Windows Key Distribution Center Information Disclosure Vulnerability |
|
CVE-2021-33763
MEDIUM 5.5
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.