Vulnerabilities
Tracked app vulnerabilities
2,375 CVEs affect a tracked app or OS (Critical, all platforms). 47 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 2,375
- Actively exploited
- 47
- Publication window
- 2007-08-28 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-87464
Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page… |
|
CVE-2026-87455
Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafte… |
|
CVE-2026-87448
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML p… |
|
CVE-2026-87438
Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via … |
|
CVE-2026-58822
CRITICAL 9.8
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no addition… |
|
CVE-2026-49921
CRITICAL 9.8
In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execu… |
|
CVE-2026-28606
CRITICAL 9.8
In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalatio… |
|
CVE-2026-78509
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78445
CRITICAL 9.8
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-77493
CRITICAL 9.8
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73025
CRITICAL 9.8
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-73010
CRITICAL 9.8
Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-73009
CRITICAL 9.8
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72983
CRITICAL 9.8
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72982
CRITICAL 9.8
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-72979
CRITICAL 9.8
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-70296
CRITICAL 9.8
Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69910
CRITICAL 9.8
Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69845
CRITICAL 9.8
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69829
CRITICAL 9.8
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69824
CRITICAL 9.8
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69819
CRITICAL 9.8
Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69769
CRITICAL 9.8
Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69768
CRITICAL 9.8
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69730
CRITICAL 9.8
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69715
CRITICAL 9.8
Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69595
CRITICAL 9.8
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69590
CRITICAL 9.8
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
|
CVE-2026-69586
CRITICAL 9.8
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69579
CRITICAL 9.8
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69525
CRITICAL 9.8
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69496
CRITICAL 9.8
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69493
CRITICAL 9.8
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69491
CRITICAL 9.8
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69463
CRITICAL 9.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69431
CRITICAL 9.8
Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69408
CRITICAL 9.8
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69276
CRITICAL 9.8
Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-68839
CRITICAL 9.8
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69530
CRITICAL · vendor
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
|
CVE-2026-85050
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via … |
|
CVE-2026-85047
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary… |
|
CVE-2026-85043
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffi… |
|
CVE-2026-85042
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML p… |
|
CVE-2026-84354
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code… |
|
CVE-2026-84353
Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute ar… |
|
CVE-2026-84352
Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a cra… |
|
CVE-2026-84333
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a craf… |
|
CVE-2026-84325
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system acce… |
|
CVE-2026-84324
Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network tra… |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.