Vulnerabilities
Tracked app vulnerabilities
8,495 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 8,495
- Actively exploited
- 214
- Publication window
- 2002-10-04 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-62727
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-75874
CRITICAL 10.0
1 app
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. |
|
CVE-2026-74990
CRITICAL 9.8
1 app
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or … |
|
CVE-2026-74989
CRITICAL 9.8
1 app
Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume th… |
|
CVE-2026-74988
CRITICAL 9.8
1 app
Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevan… |
|
CVE-2026-74987
CRITICAL 9.8
1 app
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or … |
|
CVE-2026-74983
HIGH 8.1
1 app
Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, T… |
|
CVE-2026-74979
CRITICAL 9.8
1 app
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
CVE-2026-74976
MEDIUM 6.5
1 app
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154… |
|
CVE-2026-74974
MEDIUM 5.4
1 app
Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR… |
|
CVE-2026-74973
MEDIUM 4.2
1 app
Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.… |
|
CVE-2026-74972
MEDIUM 4.3
1 app
Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbir… |
|
CVE-2026-74971
MEDIUM 4.3
1 app
Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Th… |
|
CVE-2026-74969
HIGH 8.8
1 app
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1,… |
|
CVE-2026-74968
MEDIUM 5.4
1 app
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153… |
|
CVE-2026-74967
MEDIUM 5.4
1 app
Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbi… |
|
CVE-2026-74965
HIGH 8.8
1 app
Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, T… |
|
CVE-2026-74964
CRITICAL 9.8
1 app
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 14… |
|
CVE-2026-74963
MEDIUM 5.4
1 app
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird… |
|
CVE-2026-74962
HIGH 8.1
1 app
Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154,… |
|
CVE-2026-74961
CRITICAL 9.1
1 app
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
CVE-2026-74958
HIGH 7.5
1 app
Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
CVE-2026-74956
CRITICAL 9.1
1 app
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbi… |
|
CVE-2026-74955
HIGH 8.8
1 app
Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
CVE-2026-74954
HIGH 7.5
1 app
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154… |
|
CVE-2026-74953
HIGH 8.8
1 app
Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154,… |
|
CVE-2026-74952
HIGH 8.8
1 app
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. |
|
CVE-2026-74950
HIGH 8.8
1 app
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
CVE-2026-74949
HIGH 8.8
1 app
Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 15… |
|
CVE-2026-74947
HIGH 8.8
1 app
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thu… |
|
CVE-2026-74946
HIGH 8.8
1 app
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.… |
|
CVE-2026-74944
CRITICAL 9.8
1 app
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderb… |
|
CVE-2026-74943
CRITICAL 9.8
1 app
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thu… |
|
CVE-2026-74942
HIGH 8.8
1 app
Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR … |
|
CVE-2026-74941
HIGH 8.8
1 app
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 15… |
|
CVE-2026-74940
CRITICAL 9.8
1 app
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunder… |
|
CVE-2026-74939
HIGH 8.8
1 app
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, … |
|
CVE-2026-74938
CRITICAL 9.1
1 app
Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
CVE-2026-74937
HIGH 8.8
1 app
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
|
CVE-2026-74936
CRITICAL 9.8
1 app
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, T… |
|
CVE-2026-74935
HIGH 8.8
1 app
Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, … |
|
CVE-2026-72971
MEDIUM 5.5
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to p… |
|
CVE-2026-71331
HIGH 8.1
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-70348
MEDIUM 5.5
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. |
|
CVE-2026-70347
HIGH 7.8
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70346
HIGH 7.8
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70345
HIGH 7.8
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70344
HIGH 7.8
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70330
MEDIUM 6.7
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-70307
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |