Vulnerabilities
Tracked app vulnerabilities
16,453 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 16,453
- Actively exploited
- 286
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-49080
HIGH 8.8
Windows IP Routing Management Snapin Remote Code Execution Vulnerability |
|
CVE-2024-49079
HIGH 7.8
Input Method Editor (IME) Remote Code Execution Vulnerability |
|
CVE-2024-49078
HIGH 6.8
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
|
CVE-2024-49077
HIGH 6.8
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
|
CVE-2024-49076
HIGH 7.8
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability |
|
CVE-2024-49075
HIGH 7.5
Windows Remote Desktop Services Denial of Service Vulnerability |
|
CVE-2024-49074
HIGH 7.8
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2024-49073
HIGH 6.8
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
|
CVE-2024-49072
HIGH 7.8
Windows Task Scheduler Elevation of Privilege Vulnerability |
|
CVE-2024-2398
HIGH 8.6
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-2004
LOW 3.5
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2023-6277
MEDIUM 6.5
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2022-48554
MEDIUM 5.5
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-43769
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43768
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43767
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43764
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43762
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43701
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43097
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43077
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43052
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43048
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-33063
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-33056
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-33044
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-20125
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-11708
MEDIUM 6.5
1 app
Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 an… |
|
CVE-2024-11706
MEDIUM 6.5
1 app
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed o… |
|
CVE-2024-11705
CRITICAL 9.1
1 app
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading … |
|
CVE-2024-11704
CRITICAL 9.8
1 app
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key c… |
|
CVE-2024-11702
HIGH 7.5
1 app
Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history… |
|
CVE-2024-11701
MEDIUM 4.3
1 app
The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible sp… |
|
CVE-2024-11700
HIGH 8.1
1 app
Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of … |
|
CVE-2024-11699
HIGH 8.8
1 app
Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-11698
CRITICAL 9.8
1 app
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened durin… |
|
CVE-2024-11697
HIGH 8.8
1 app
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have l… |
|
CVE-2024-11696
MEDIUM 5.4
1 app
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an i… |
|
CVE-2024-11695
MEDIUM 5.4
1 app
A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This … |
|
CVE-2024-11694
MEDIUM 6.1
1 app
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the W… |
|
CVE-2024-11693
CRITICAL 9.8
1 app
The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating … |
|
CVE-2024-11692
MEDIUM 4.3
1 app
An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability… |
|
CVE-2024-11691
HIGH 8.8
1 app
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver.… |
|
CVE-2024-11612
MEDIUM 6.5
1 app
7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected i… |
|
CVE-2024-11477
HIGH 7.8
1 app
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af… |
|
CVE-2024-44309
MEDIUM 6.3
KEV
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPad… |
|
CVE-2024-44308
HIGH 8.8
KEV
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 1… |
|
CVE-2024-44307
HIGH 7.8
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code wit… |
|
CVE-2024-44306
HIGH 7.8
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code wit… |
|
CVE-2024-11159
MEDIUM 4.3
1 app
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < … |