Skip to content
English

Products › End-user applications

End-user applications

Browsers and web engines

Browsers, rendering and script engines, and legacy plug-ins (Flash, Silverlight).

For example: Chrome, Edge, Firefox, Safari.

Category RSS feed

Pace of additions

Number of “Browsers” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20251
Oct 4, 2025 to Nov 2, 20253
Nov 3, 2025 to Dec 2, 20251
Dec 3, 2025 to Jan 1, 20262
Jan 2, 2026 to Jan 31, 20260
Feb 1, 2026 to Mar 2, 20261
Mar 3, 2026 to Apr 1, 20266
Apr 2, 2026 to May 1, 20260
May 2, 2026 to May 31, 20262
Jun 1, 2026 to Jun 30, 20261
Jul 1, 2026 to Jul 30, 20260
Jul 31, 2026 to Aug 29, 20260
Aug 30, 2026 to Sep 28, 2026 (in progress)2

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

  • Adobe 36 vulnerabilities
  • Apple 36 vulnerabilities · 5 in the last 12 months
  • ChakraCore 1 vulnerability
  • Google 74 vulnerabilities · 9 in the last 12 months
  • Microsoft 47 vulnerabilities · 3 in the last 12 months
  • Mozilla 13 vulnerabilities · 1 in the last 12 months
  • WebKitGTK 1 vulnerability

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Google Chrome / Chromium

    CVE-2026-87491

    Recently added

    Google Chromium V8 Out of Bounds Write Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  2. Rank 2Google Chrome / Chromium

    CVE-2026-85046

    Recently added

    Google Chromium V8 Type Confusion Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 4, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  3. Rank 3Mozilla Firefox

    CVE-2010-3765

    CVE from 2010, added in 2025

    Mozilla Multiple Products Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Google Chrome / Chromium

    CVE-2026-11645

    Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 9, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  5. Rank 5Microsoft Internet Explorer / Edge (legacy)

    CVE-2010-0249

    CVE from 2010, added in 2026

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  6. Rank 6Microsoft Internet Explorer / Edge (legacy)

    CVE-2010-0806

    CVE from 2010, added in 2026

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  7. Rank 7Google Chrome / Chromium

    CVE-2026-5281

    Google Dawn Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 1, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  8. Rank 8Apple Safari / WebKit

    CVE-2025-31277

    Apple Multiple Products Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  9. Rank 9Google Chrome / Chromium

    CVE-2026-3909

    Google Skia Out-of-Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 13, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  10. Rank 10Google Chrome / Chromium

    CVE-2026-3910

    Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 13, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
Show 158 more vulnerabilities
  1. Rank 11Apple Safari / WebKit

    CVE-2023-43000

    CVE from 2023, added in 2026

    Apple Multiple products Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 5, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  2. Rank 12Google Chrome / Chromium

    CVE-2026-2441

    Google Chromium CSS Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 17, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  3. Rank 13Apple Safari / WebKit

    CVE-2025-43529

    Apple Multiple Products Use-After-Free WebKit Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 15, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  4. Rank 14Google Chrome / Chromium

    CVE-2025-14174

    Google Chromium Out of Bounds Memory Access Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 12, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  5. Rank 15Google Chrome / Chromium

    CVE-2025-13223

    Google Chromium V8 Type Confusion Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 19, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  6. Rank 16Apple Safari / WebKit

    CVE-2022-48503

    CVE from 2022, added in 2025

    Apple Multiple Products Unspecified Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  7. Rank 17Microsoft Internet Explorer / Edge (legacy)

    CVE-2010-3962

    CVE from 2010, added in 2025

    Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  8. Rank 18Apple Safari / WebKit

    CVE-2021-30952

    CVE from 2021, added in 2026

    Apple Multiple Products Integer Overflow or Wraparound Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 5, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  9. Rank 19Apple Safari / WebKit

    CVE-2025-24201

    Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 13, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  10. Rank 20Mozilla Firefox

    CVE-2019-11708

    CVE from 2019, added in 2022

    Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  11. Rank 21Google Chrome / Chromium

    CVE-2025-10585

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 23, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  12. Rank 22Mozilla Firefox

    CVE-2024-9680

    Ransomware

    Mozilla Firefox Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Rank 23Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-1776

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Apple Safari / WebKit

    CVE-2021-1870

    Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Apple Safari / WebKit

    CVE-2021-1871

    Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Google Chrome / Chromium

    CVE-2024-7971

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 26, 2024
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  17. Rank 27Google Chrome / Chromium

    CVE-2024-5274

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 28, 2024
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  18. Rank 28Google Chrome / Chromium

    CVE-2024-4947

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 20, 2024
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  19. Rank 29Google Chrome / Chromium

    CVE-2024-4671

    Google Chromium Visuals Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2024
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  20. Rank 30Google Chrome / Chromium

    CVE-2023-6345

    Google Skia Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 30, 2023
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  21. Rank 31Google Chrome / Chromium

    CVE-2023-2136

    Google Chrome Skia Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 21, 2023
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  22. Rank 32Google Chrome / Chromium

    CVE-2022-4135

    Google Chromium GPU Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 28, 2022
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  23. Rank 33Google Chrome / Chromium

    CVE-2022-3075

    Google Chromium Mojo Insufficient Data Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.6 (critical)
  24. Rank 34Mozilla Firefox

    CVE-2022-26486

    Mozilla Firefox Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    14 days
    CVSS severity
    9.6 (critical)
  25. Rank 35Google Chrome / Chromium

    CVE-2020-15999

    Google Chrome FreeType Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.6 (critical)
  26. Rank 36Google Chrome / Chromium

    CVE-2020-16010

    Google Chrome for Android UI Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.6 (critical)
  27. Rank 37Google Chrome / Chromium

    CVE-2020-16017

    Google Chrome Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.6 (critical)
  28. Rank 38Google Chrome / Chromium

    CVE-2021-30633

    Google Chromium Indexed DB API Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.6 (critical)
  29. Rank 39Google Chrome / Chromium

    CVE-2021-37973

    Google Chromium Portals Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.6 (critical)
  30. Rank 40Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-3893

    CVE from 2013, added in 2025

    Microsoft Internet Explorer Resource Management Errors Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 12, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  31. Rank 41Google Chrome / Chromium

    CVE-2025-6558

    Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  32. Rank 42Google Chrome / Chromium

    CVE-2025-5419

    Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 5, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  33. Rank 43Apple Safari / WebKit

    CVE-2024-44308

    Apple Multiple Products Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 21, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  34. Rank 44Google Chrome / Chromium

    CVE-2024-7965

    Google Chromium V8 Inappropriate Implementation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 28, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  35. Rank 45Google Chrome / Chromium

    CVE-2024-4761

    Google Chromium V8 Out-of-Bounds Memory Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 16, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  36. Rank 46Google Chrome / Chromium

    CVE-2023-4762

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 6, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  37. Rank 47Apple Safari / WebKit

    CVE-2024-23222

    Apple Multiple Products WebKit Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 23, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  38. Rank 48Google Chrome / Chromium

    CVE-2024-0519

    Google Chromium V8 Out-of-Bounds Memory Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  39. Rank 49Google Chrome / Chromium

    CVE-2023-7024

    Google Chromium WebRTC Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 2, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  40. Rank 50Apple Safari / WebKit

    CVE-2023-42917

    Apple Multiple Products WebKit Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 4, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  41. Rank 51Google Chrome / Chromium

    CVE-2023-5217

    Google Chromium libvpx Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 2, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  42. Rank 52Apple Safari / WebKit

    CVE-2023-41993

    Apple Multiple Products WebKit Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 25, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  43. Rank 53Google Chrome / Chromium

    CVE-2023-4863

    Google Chromium WebP Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 13, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  44. Rank 54Apple Safari / WebKit

    CVE-2023-37450

    Apple Multiple Products WebKit Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 13, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  45. Rank 55Apple Safari / WebKit

    CVE-2023-32435

    Apple Multiple Products WebKit Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 23, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  46. Rank 56Apple Safari / WebKit

    CVE-2023-32439

    Apple Multiple Products WebKit Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 23, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  47. Rank 57Google Chrome / Chromium

    CVE-2023-3079

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 7, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  48. Rank 58Apple Safari / WebKit

    CVE-2023-32373

    Apple Multiple Products WebKit Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 22, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  49. Rank 59Google Chrome / Chromium

    CVE-2023-2033

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 17, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  50. Rank 60Apple Safari / WebKit

    CVE-2023-28205

    Apple Multiple Products WebKit Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 10, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  51. Rank 61Google Chrome / Chromium

    CVE-2022-3038

    Google Chromium Network Service Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  52. Rank 62Apple Safari / WebKit

    CVE-2023-23529

    Apple Multiple Products WebKit Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 14, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  53. Rank 63Apple Safari / WebKit

    CVE-2022-42856

    Apple iOS Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 14, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  54. Rank 64Google Chrome / Chromium

    CVE-2022-4262

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 5, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  55. Rank 65Google Chrome / Chromium

    CVE-2022-3723

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  56. Rank 66Google Chrome / Chromium

    CVE-2022-2294

    Ransomware

    WebRTC Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  57. Rank 67Apple Safari / WebKit

    CVE-2022-32893

    Apple iOS and macOS Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  58. Rank 68Google Chrome / Chromium

    CVE-2016-1646

    CVE from 2016, added in 2022

    Google Chromium V8 Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  59. Rank 69Google Chrome / Chromium

    CVE-2016-5198

    CVE from 2016, added in 2022

    Google Chromium V8 Out-of-Bounds Memory Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  60. Rank 70Google Chrome / Chromium

    CVE-2017-5030

    CVE from 2017, added in 2022

    Google Chromium V8 Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  61. Rank 71Google Chrome / Chromium

    CVE-2017-5070

    CVE from 2017, added in 2022

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  62. Rank 72Google Chrome / Chromium

    CVE-2018-17463

    CVE from 2018, added in 2022

    Google Chromium V8 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  63. Rank 73Google Chrome / Chromium

    CVE-2018-17480

    CVE from 2018, added in 2022

    Google Chromium V8 Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  64. Rank 74Google Chrome / Chromium

    CVE-2018-6065

    CVE from 2018, added in 2022

    Google Chromium V8 Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  65. Rank 75Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-2817

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  66. Rank 76Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-4123

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  67. Rank 77Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-2425

    CVE from 2015, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  68. Rank 78Mozilla Firefox

    CVE-2015-4495

    CVE from 2015, added in 2022

    Mozilla Firefox Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  69. Rank 79Apple Safari / WebKit

    CVE-2016-4657

    CVE from 2016, added in 2022

    Apple iOS Webkit Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  70. Rank 80Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0149

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  71. Rank 81Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0210

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  72. Rank 82Mozilla Firefox

    CVE-2019-11707

    CVE from 2019, added in 2022

    Mozilla Firefox and Thunderbird Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  73. Rank 83Google Chrome / Chromium

    CVE-2019-13720

    CVE from 2019, added in 2022

    Google Chrome WebAudio Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  74. Rank 84WebKitGTK

    CVE-2019-8720

    CVE from 2019, added in 2022

    WebKitGTK Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  75. Rank 85Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-0322

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 4, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  76. Rank 86Apple Safari / WebKit

    CVE-2019-8506

    CVE from 2019, added in 2022

    Apple Multiple Products Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 4, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  77. Rank 87Apple Safari / WebKit

    CVE-2021-1789

    Apple Multiple Products Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 4, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  78. Rank 88Google Chrome / Chromium

    CVE-2022-1364

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  79. Rank 89Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-2502

    CVE from 2015, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  80. Rank 90Mozilla Firefox

    CVE-2013-1690

    CVE from 2013, added in 2022

    Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  81. Rank 91Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-2551

    RansomwareCVE from 2013, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  82. Rank 92Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-2419

    CVE from 2015, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  83. Rank 93Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-7200

    CVE from 2016, added in 2022

    Microsoft Edge Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  84. Rank 94Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-7201

    CVE from 2016, added in 2022

    Microsoft Edge Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  85. Rank 95Google Chrome / Chromium

    CVE-2022-1096

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  86. Rank 96Mozilla Firefox

    CVE-2022-26485

    Mozilla Firefox Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  87. Rank 97Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-1347

    CVE from 2013, added in 2022

    Microsoft Internet Explorer Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  88. Rank 98Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-3897

    CVE from 2013, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  89. Rank 99Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0222

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  90. Rank 100Google Chrome / Chromium

    CVE-2022-0609

    Google Chromium Animation Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  91. Rank 101Apple Safari / WebKit

    CVE-2022-22620

    Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 11, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  92. Rank 102Google Chrome / Chromium

    CVE-2020-6572

    CVE from 2020, added in 2022

    Google Chrome Media Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  93. Rank 103Google Chrome / Chromium

    CVE-2021-4102

    Google Chromium V8 Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 15, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  94. Rank 104Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-0541

    CVE from 2019, added in 2021

    Microsoft MSHTML Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  95. Rank 105Mozilla Firefox

    CVE-2019-17026

    CVE from 2019, added in 2021

    Mozilla Firefox And Thunderbird Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  96. Rank 106Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-1380

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  97. Rank 107Google Chrome / Chromium

    CVE-2020-16009

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  98. Rank 108Google Chrome / Chromium

    CVE-2020-16013

    Google Chromium V8 Incorrect Implementation Vulnerabililty

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  99. Rank 109Google Chrome / Chromium

    CVE-2020-6418

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  100. Rank 110Google Chrome / Chromium

    CVE-2021-21148

    Google Chromium V8 Heap Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  101. Rank 111Google Chrome / Chromium

    CVE-2021-21166

    Google Chromium Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  102. Rank 112Google Chrome / Chromium

    CVE-2021-21193

    Google Chromium Blink Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  103. Rank 113Google Chrome / Chromium

    CVE-2021-21206

    Google Chromium Blink Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  104. Rank 114Google Chrome / Chromium

    CVE-2021-21220

    Google Chromium V8 Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  105. Rank 115Google Chrome / Chromium

    CVE-2021-21224

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  106. Rank 116Microsoft Internet Explorer / Edge (legacy)

    CVE-2021-26411

    Ransomware

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  107. Rank 117Microsoft Internet Explorer / Edge (legacy)

    CVE-2021-27085

    Microsoft Internet Explorer Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  108. Rank 118Google Chrome / Chromium

    CVE-2021-30551

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  109. Rank 119Google Chrome / Chromium

    CVE-2021-30554

    Google Chromium WebGL Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  110. Rank 120Google Chrome / Chromium

    CVE-2021-30563

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  111. Rank 121Google Chrome / Chromium

    CVE-2021-30632

    Google Chromium V8 Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  112. Rank 122Apple Safari / WebKit

    CVE-2021-30661

    Apple Multiple Products WebKit Storage Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  113. Rank 123Apple Safari / WebKit

    CVE-2021-30663

    Apple Multiple Products WebKit Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  114. Rank 124Apple Safari / WebKit

    CVE-2021-30665

    Apple Multiple Products WebKit Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  115. Rank 125Apple Safari / WebKit

    CVE-2021-30666

    Apple iOS WebKit Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  116. Rank 126Apple Safari / WebKit

    CVE-2021-30761

    Apple iOS WebKit Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  117. Rank 127Apple Safari / WebKit

    CVE-2021-30762

    Apple iOS WebKit Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  118. Rank 128Apple Safari / WebKit

    CVE-2021-30858

    Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  119. Rank 129Google Chrome / Chromium

    CVE-2021-37975

    Google Chromium V8 Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  120. Rank 130Google Chrome / Chromium

    CVE-2021-38003

    Google Chromium V8 Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  121. Rank 131Apple Safari / WebKit

    CVE-2023-32409

    Apple Multiple Products WebKit Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 22, 2023
    CISA deadline
    21 days
    CVSS severity
    8.6 (high)
  122. Rank 132Google Chrome / Chromium

    CVE-2025-2783

    Google Chromium Mojo Sandbox Escape Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 27, 2025
    CISA deadline
    21 days
    CVSS severity
    8.3 (high)
  123. Rank 133Google Chrome / Chromium

    CVE-2025-6554

    Google Chromium V8 Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 2, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  124. Rank 134Microsoft Internet Explorer / Edge (legacy)

    CVE-2012-4969

    CVE from 2012, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.1 (high)
  125. Rank 135Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0037

    CVE from 2017, added in 2022

    Microsoft Edge and Internet Explorer Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  126. Rank 136Mozilla Firefox

    CVE-2020-6819

    Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  127. Rank 137Mozilla Firefox

    CVE-2020-6820

    Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  128. Rank 138Adobe Flash Player

    CVE-2009-1862

    CVE from 2009, added in 2022

    Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  129. Rank 139Microsoft Internet Explorer / Edge (legacy)

    CVE-2021-40444

    Ransomware

    Microsoft MSHTML Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  130. Rank 140Mozilla Firefox

    CVE-2016-9079

    CVE from 2016, added in 2023

    Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  131. Rank 141Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-0189

    RansomwareCVE from 2016, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  132. Rank 142Microsoft Internet Explorer / Edge (legacy)

    CVE-2018-8373

    CVE from 2018, added in 2022

    Microsoft Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  133. Rank 143ChakraCore scripting engine

    CVE-2018-8298

    CVE from 2018, added in 2022

    ChakraCore Scripting Engine Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  134. Rank 144Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-0752

    RansomwareCVE from 2019, added in 2022

    Microsoft Internet Explorer Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  135. Rank 145Microsoft Internet Explorer / Edge (legacy)

    CVE-2018-8653

    CVE from 2018, added in 2021

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  136. Rank 146Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-1367

    RansomwareCVE from 2019, added in 2021

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  137. Rank 147Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-1429

    CVE from 2019, added in 2021

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  138. Rank 148Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-0674

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  139. Rank 149Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-0878

    Ransomware

    Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  140. Rank 150Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-0968

    Ransomware

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  141. Rank 151Apple Safari / WebKit

    CVE-2023-42916

    Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 4, 2023
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  142. Rank 152Apple Safari / WebKit

    CVE-2023-28204

    Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 22, 2023
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  143. Rank 153Google Chrome / Chromium

    CVE-2022-2856

    Google Chromium Intents Insufficient Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  144. Rank 154Google Chrome / Chromium

    CVE-2021-30533

    Google Chromium PopupBlocker Security Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 27, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  145. Rank 155Google Chrome / Chromium

    CVE-2019-5825

    CVE from 2019, added in 2022

    Google Chromium V8 Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  146. Rank 156Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-7331

    CVE from 2013, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  147. Rank 157Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-0071

    CVE from 2015, added in 2022

    Microsoft Internet Explorer ASLR Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  148. Rank 158Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-3298

    CVE from 2016, added in 2022

    Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  149. Rank 159Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-3351

    RansomwareCVE from 2016, added in 2022

    Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  150. Rank 160Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-0676

    CVE from 2019, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  151. Rank 161Google Chrome / Chromium

    CVE-2019-5786

    CVE from 2019, added in 2022

    Google Chrome Blink Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  152. Rank 162Mozilla Firefox

    CVE-2013-1675

    CVE from 2013, added in 2022

    Mozilla Firefox Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  153. Rank 163Google Chrome / Chromium

    CVE-2021-37976

    Google Chromium Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  154. Rank 164Apple Safari / WebKit

    CVE-2024-44309

    Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 21, 2024
    CISA deadline
    21 days
    CVSS severity
    6.3 (medium)
  155. Rank 165Apple Safari / WebKit

    CVE-2021-1879

    Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  156. Rank 166Google Chrome / Chromium

    CVE-2021-38000

    Google Chromium Intents Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  157. Rank 167Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-0162

    CVE from 2016, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    4.3 (medium)
  158. Rank 168Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0059

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    4.3 (medium)

Filed under another category

These 12 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.

  1. Microsoft Windows

    CVE-2026-21513

    Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  2. Microsoft Windows

    CVE-2024-43461

    Microsoft Windows MSHTML Platform Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 16, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  3. Microsoft Windows

    CVE-2024-30040

    Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 14, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  4. Microsoft Windows

    CVE-2022-41128

    Microsoft Windows Scripting Languages Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    31 days
    CVSS severity
    8.8 (high)
  5. Microsoft Windows

    CVE-2021-33742

    Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
Show 7 more vulnerabilities
  1. Microsoft Windows

    CVE-2021-34448

    Microsoft Windows Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  2. Microsoft Windows

    CVE-2024-43573

    Microsoft Windows MSHTML Platform Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 8, 2024
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  3. Microsoft Windows

    CVE-2023-32046

    Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  4. Microsoft Windows

    CVE-2025-30397

    Microsoft Windows Scripting Engine Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  5. Microsoft Windows

    CVE-2024-38178

    Microsoft Windows Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  6. Microsoft Windows

    CVE-2024-38112

    Microsoft Windows MSHTML Platform Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  7. Microsoft Windows

    CVE-2018-8174

    RansomwareCVE from 2018, added in 2022

    Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Adobe Flash Player

    CVE-2013-0643

    End of lifeCVE from 2013, added in 2024

    Adobe Flash Player Incorrect Default Permissions Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  2. Adobe Flash Player

    CVE-2013-0648

    End of lifeCVE from 2013, added in 2024

    Adobe Flash Player Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  3. Adobe Flash Player

    CVE-2014-0497

    End of lifeCVE from 2014, added in 2024

    Adobe Flash Player Integer Underflow Vulnerablity

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Adobe Flash Player

    CVE-2014-0502

    End of lifeCVE from 2014, added in 2024

    Adobe Flash Player Double Free Vulnerablity

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 17, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  5. Microsoft Internet Explorer / Edge (legacy)

    CVE-2012-4792

    End of lifeCVE from 2012, added in 2024

    Microsoft Internet Explorer Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jul 23, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  6. Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-3163

    End of lifeCVE from 2013, added in 2023

    Microsoft Internet Explorer Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  7. Adobe Flash Player

    CVE-2010-1297

    End of lifeCVE from 2010, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  8. Adobe Flash Player

    CVE-2011-0609

    End of lifeCVE from 2011, added in 2022

    Adobe Flash Player Unspecified Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  9. Adobe Flash Player

    CVE-2012-0754

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.1 (high)
  10. Adobe Flash Player

    CVE-2012-0767

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
Show 30 more vulnerabilities
  1. Adobe Flash Player

    CVE-2012-5054

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Integer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  2. Microsoft Silverlight

    CVE-2013-0074

    RansomwareEnd of lifeCVE from 2013, added in 2022

    Microsoft Silverlight Double Dereference Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  3. Microsoft Silverlight

    CVE-2013-3896

    End of lifeCVE from 2013, added in 2022

    Microsoft Silverlight Information Disclosure Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  4. Adobe Flash Player

    CVE-2014-8439

    End of lifeCVE from 2014, added in 2022

    Adobe Flash Player Dereferenced Pointer Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  5. Adobe Flash Player

    CVE-2015-0310

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player ASLR Bypass Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  6. Adobe Flash Player

    CVE-2015-8651

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Integer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  7. Microsoft Silverlight

    CVE-2016-0034

    RansomwareEnd of lifeCVE from 2016, added in 2022

    Microsoft Silverlight Runtime Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  8. Adobe Flash Player

    CVE-2016-0984

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player and AIR Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  9. Adobe Flash Player

    CVE-2016-1010

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player and AIR Integer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  10. Adobe Flash Player

    CVE-2018-5002

    End of lifeCVE from 2018, added in 2022

    Adobe Flash Player Stack-based Buffer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  11. Adobe Flash Player

    CVE-2014-9163

    End of lifeCVE from 2014, added in 2022

    Adobe Flash Player Stack-Based Buffer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  12. Adobe Flash Player

    CVE-2015-0311

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Adobe Flash Player

    CVE-2015-0313

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Adobe Flash Player

    CVE-2015-3113

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Heap-Based Buffer Overflow Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Adobe Flash Player

    CVE-2015-5122

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  16. Adobe Flash Player

    CVE-2015-5123

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  17. Adobe Flash Player

    CVE-2012-2034

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  18. Adobe Flash Player

    CVE-2016-4171

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  19. Adobe Flash Player

    CVE-2016-7892

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  20. Adobe Flash Player

    CVE-2011-0611

    End of lifeCVE from 2011, added in 2022

    Adobe Flash Player Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  21. Adobe Flash Player

    CVE-2012-1535

    End of lifeCVE from 2012, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  22. Adobe Flash Player

    CVE-2015-3043

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  23. Adobe Flash Player

    CVE-2015-5119

    End of lifeCVE from 2015, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  24. Adobe Flash Player

    CVE-2015-7645

    RansomwareEnd of lifeCVE from 2015, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  25. Adobe Flash Player

    CVE-2016-1019

    RansomwareEnd of lifeCVE from 2016, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  26. Adobe Flash Player

    CVE-2016-4117

    RansomwareEnd of lifeCVE from 2016, added in 2022

    Adobe Flash Player Arbitrary Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  27. Adobe Flash Player

    CVE-2016-7855

    End of lifeCVE from 2016, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  28. Adobe Flash Player

    CVE-2017-11292

    End of lifeCVE from 2017, added in 2022

    Adobe Flash Player Type Confusion Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  29. Adobe Flash Player

    CVE-2018-15982

    RansomwareEnd of lifeCVE from 2018, added in 2022

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  30. Adobe Flash Player

    CVE-2018-4878

    RansomwareEnd of lifeCVE from 2018, added in 2021

    Adobe Flash Player Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.