Vulnerabilities
Tracked app vulnerabilities
16,453 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,453
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-47975
HIGH 7.0
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
|
CVE-2025-47973
HIGH 7.8
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
|
CVE-2025-47972
HIGH 8.0
Windows Input Method Editor (IME) Elevation of Privilege Vulnerability |
|
CVE-2025-47971
HIGH 7.8
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
|
CVE-2025-47159
HIGH 7.8
Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability |
|
CVE-2025-33054
HIGH 8.1
Remote Desktop Spoofing Vulnerability |
|
CVE-2025-26636
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2024-36357
CRITICAL 5.6
AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue |
|
CVE-2024-36350
CRITICAL 5.6
AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue |
|
CVE-2025-32462
LOW 2.8
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on … |
|
CVE-2025-6436
HIGH 8.1
1 app
Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-6435
HIGH 8.1
1 app
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file … |
|
CVE-2025-6218
HIGH 7.8
KEV
1 app
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install… |
|
CVE-2025-43200
MEDIUM 4.2
KEV
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.… |
|
CVE-2025-5986
MEDIUM 6.5
1 app
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompti… |
|
CVE-2025-2884
MEDIUM 6.6
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with… |
|
CVE-2025-47953
CRITICAL 8.4
1 app
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-47167
CRITICAL 8.4
1 app
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-47164
CRITICAL 8.4
1 app
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-47162
CRITICAL 8.4
1 app
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-47969
HIGH 4.4
Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability |
|
CVE-2025-47955
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2025-47160
HIGH 5.4
Windows Shortcut Files Security Feature Bypass Vulnerability |
|
CVE-2025-33075
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2025-33073
HIGH 8.8
KEV
Windows SMB Client Elevation of Privilege Vulnerability |
|
CVE-2025-33071
CRITICAL 8.1
Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability |
|
CVE-2025-33070
CRITICAL 8.1
Windows Netlogon Elevation of Privilege Vulnerability |
|
CVE-2025-33069
HIGH 5.1
Windows App Control for Business Security Feature Bypass Vulnerability |
|
CVE-2025-33068
HIGH 7.5
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2025-33067
HIGH 8.4
Windows Task Scheduler Elevation of Privilege Vulnerability |
|
CVE-2025-33066
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-33065
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-33064
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-33063
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-33062
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-33061
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-33060
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-33059
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-33058
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-33057
HIGH 6.5
Windows Local Security Authority (LSA) Denial of Service Vulnerability |
|
CVE-2025-33056
HIGH 7.5
Windows Local Security Authority (LSA) Denial of Service Vulnerability |
|
CVE-2025-33055
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-33053
HIGH 8.8
KEV
Internet Shortcut Files Remote Code Execution Vulnerability |
|
CVE-2025-33052
HIGH 5.5
Windows DWM Core Library Information Disclosure Vulnerability |
|
CVE-2025-33050
HIGH 7.5
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2025-32725
HIGH 7.5
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2025-32724
HIGH 7.5
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
|
CVE-2025-32722
HIGH 5.5
Windows Storage Port Driver Information Disclosure Vulnerability |
|
CVE-2025-32721
HIGH 7.3
Windows Recovery Driver Elevation of Privilege Vulnerability |
|
CVE-2025-32720
HIGH 5.5
Windows Storage Management Provider Information Disclosure Vulnerability |