Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

2,375 CVEs affect a tracked app or OS (Critical, all platforms). 47 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
2,375
Actively exploited
47
Publication window
2007-08-28 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

2,375 entries Critical Hide N/A Clear all
CVE
CVE-2026-87464
CRITICAL 9.6

Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page…

CVE-2026-87455
CRITICAL 9.6

Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafte…

CVE-2026-87448
CRITICAL 9.6

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML p…

CVE-2026-87438
CRITICAL 9.6

Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via …

CVE-2026-58822
CRITICAL 9.8

In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no addition…

CVE-2026-49921
CRITICAL 9.8

In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execu…

CVE-2026-28606
CRITICAL 9.8

In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalatio…

CVE-2026-78509
CRITICAL 9.8

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

CVE-2026-78445
CRITICAL 9.8

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-77493
CRITICAL 9.8

Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73025
CRITICAL 9.8

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-73010
CRITICAL 9.8

Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

CVE-2026-73009
CRITICAL 9.8

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVE-2026-72983
CRITICAL 9.8

Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.

CVE-2026-72982
CRITICAL 9.8

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

CVE-2026-72979
CRITICAL 9.8

Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-70296
CRITICAL 9.8

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-69910
CRITICAL 9.8

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

CVE-2026-69845
CRITICAL 9.8

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-69829
CRITICAL 9.8

Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.

CVE-2026-69824
CRITICAL 9.8

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.

CVE-2026-69819
CRITICAL 9.8

Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.

CVE-2026-69769
CRITICAL 9.8

Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.

CVE-2026-69768
CRITICAL 9.8

Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.

CVE-2026-69730
CRITICAL 9.8

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-69715
CRITICAL 9.8

Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.

CVE-2026-69595
CRITICAL 9.8

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-69590
CRITICAL 9.8

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-69586
CRITICAL 9.8

Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.

CVE-2026-69579
CRITICAL 9.8

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

CVE-2026-69525
CRITICAL 9.8

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

CVE-2026-69496
CRITICAL 9.8

Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.

CVE-2026-69493
CRITICAL 9.8

Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

CVE-2026-69491
CRITICAL 9.8

Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.

CVE-2026-69463
CRITICAL 9.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.

CVE-2026-69431
CRITICAL 9.8

Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.

CVE-2026-69408
CRITICAL 9.8

Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-69276
CRITICAL 9.8

Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.

CVE-2026-68839
CRITICAL 9.8

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-69530
CRITICAL · vendor

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

CVE-2026-85050
CRITICAL 9.6

Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via …

CVE-2026-85047
CRITICAL 9.6

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary…

CVE-2026-85043
CRITICAL 9.1

Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffi…

CVE-2026-85042
CRITICAL 9.6

Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML p…

CVE-2026-84354
CRITICAL 9.6

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code…

CVE-2026-84353
CRITICAL 9.6

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute ar…

CVE-2026-84352
CRITICAL 9.6

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a cra…

CVE-2026-84333
CRITICAL 9.6

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a craf…

CVE-2026-84325
CRITICAL 9.8

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system acce…

CVE-2026-84324
CRITICAL 9.0

Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network tra…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM