Vulnerabilities
Tracked app vulnerabilities
8,530 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,530
- Actively exploited
- 214
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2021-36960
HIGH 7.5
Windows SMB Information Disclosure Vulnerability |
|
CVE-2021-36959
MEDIUM 5.5
Windows Authenticode Spoofing Vulnerability |
|
CVE-2021-36955
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2021-36954
HIGH 8.8
Windows Bind Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2021-26435
HIGH 8.1
Windows Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-40529
MEDIUM 5.9
1 app
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between tw… |
|
CVE-2021-40330
HIGH 7.5
1 app
git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol reques… |
|
CVE-2021-29989
HIGH 8.8
1 app
Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption and we pres… |
|
CVE-2021-29988
HIGH 8.8
1 app
Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploita… |
|
CVE-2021-29987
MEDIUM 6.5
1 app
After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still… |
|
CVE-2021-29986
HIGH 8.1
1 app
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operati… |
|
CVE-2021-29985
HIGH 8.8
1 app
A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbir… |
|
CVE-2021-29984
HIGH 8.8
1 app
Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to me… |
|
CVE-2021-29982
MEDIUM 6.5
1 app
Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a single bit of memory. Th… |
|
CVE-2021-29981
HIGH 8.8
1 app
An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code that would lead to a po… |
|
CVE-2021-29980
HIGH 8.8
1 app
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerabil… |
|
CVE-2021-36958
HIGH 7.8
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull… |
|
CVE-2021-36948
HIGH 7.8
KEV
Windows Update Medic Service Elevation of Privilege Vulnerability |
|
CVE-2021-36947
HIGH 8.8
Windows Print Spooler Remote Code Execution Vulnerability |
|
CVE-2021-36942
HIGH 7.5
KEV
Windows LSA Spoofing Vulnerability |
|
CVE-2021-36938
MEDIUM 5.5
Windows Cryptographic Primitives Library Information Disclosure Vulnerability |
|
CVE-2021-36937
HIGH 7.8
Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability |
|
CVE-2021-36936
HIGH 8.8
Windows Print Spooler Remote Code Execution Vulnerability |
|
CVE-2021-36933
HIGH 7.5
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |
|
CVE-2021-36932
HIGH 7.5
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |
|
CVE-2021-36926
HIGH 7.5
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |
|
CVE-2021-34537
HIGH 7.8
Windows Bluetooth Driver Elevation of Privilege Vulnerability |
|
CVE-2021-34536
HIGH 7.8
Windows Storage Spaces Controller Elevation of Privilege Vulnerability |
|
CVE-2021-34535
HIGH 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2021-34534
MEDIUM 6.8
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-34533
HIGH 7.8
Windows Graphics Component Font Parsing Remote Code Execution Vulnerability |
|
CVE-2021-34530
HIGH 7.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2021-34487
HIGH 7.0
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2021-34486
HIGH 7.8
KEV
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2021-34484
HIGH 7.8
KEV
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2021-34483
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2021-34480
MEDIUM 6.8
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-26433
HIGH 7.5
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability |
|
CVE-2021-26432
CRITICAL 9.8
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability |
|
CVE-2021-26431
HIGH 7.8
Windows Recovery Environment Agent Elevation of Privilege Vulnerability |
|
CVE-2021-26426
HIGH 7.0
Windows User Account Profile Picture Elevation of Privilege Vulnerability |
|
CVE-2021-26425
HIGH 7.8
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2021-26424
CRITICAL 9.9
Windows TCP/IP Remote Code Execution Vulnerability |
|
CVE-2021-29976
HIGH 8.8
1 app
Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption … |
|
CVE-2021-29970
HIGH 8.8
1 app
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when acces… |
|
CVE-2021-29969
MEDIUM 5.9
1 app
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS ha… |
|
CVE-2020-18173
HIGH 7.8
1 app
A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code. |
|
CVE-2021-36934
HIGH 7.8
KEV
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accoun… |
|
CVE-2021-34481
HIGH 8.8
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull… |
|
CVE-2021-34466
MEDIUM 5.7
Windows Hello Security Feature Bypass Vulnerability |