Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

7,772 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-62699
HIGH 6.8

Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability

CVE-2026-62698
HIGH 7.8

Microsoft Digest Authentication Elevation of Privilege Vulnerability

CVE-2026-61936
HIGH 5.5

Windows Defender Firewall Service Security Feature Bypass Vulnerability

CVE-2026-61933
HIGH 5.5

Windows DWM Core Library Information Disclosure Vulnerability

CVE-2026-61928
HIGH 5.5

Windows Hello Tampering Vulnerability

CVE-2026-61924
HIGH 6.5

Windows Remote Desktop Client Information Disclosure Vulnerability

CVE-2026-61923
HIGH 7.8

Windows Display Enhancement Service Elevation of Privilege Vulnerability

CVE-2026-61921
HIGH 6.5

Windows Remote Desktop Client Information Disclosure Vulnerability

CVE-2026-61918
HIGH 6.5

Windows Remote Desktop Client Information Disclosure Vulnerability

CVE-2026-61368
HIGH 5.0

Windows Hyper-V Information Disclosure Vulnerability

CVE-2026-61366
HIGH 7.0

Windows Network Connection Broker Elevation of Privilege Vulnerability

CVE-2026-61360
HIGH 5.5

Windows GDI Information Disclosure Vulnerability

CVE-2026-61358
HIGH 7.8

Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability

CVE-2026-61357
HIGH 7.8

Application Information Services Elevation of Privilege Vulnerability

CVE-2026-61352
HIGH 7.5

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-61350
HIGH 4.6

Windows NTFS Information Disclosure Vulnerability

CVE-2026-61347
HIGH 5.5

Windows Event Logging Service Information Disclosure Vulnerability

CVE-2026-61346
HIGH 7.0

Windows Graphics Kernel Elevation of Privilege Vulnerability

CVE-2026-61345
HIGH 6.5

Microsoft Remote Registry Service Denial of Service Vulnerability

CVE-2026-59138
HIGH 6.5

Microsoft Remote Registry Service Denial of Service Vulnerability

CVE-2026-59137
HIGH 5.5

Windows Event Logging Service Information Disclosure Vulnerability

CVE-2026-59136
HIGH 5.5

Microsoft COM for Windows Information Disclosure Vulnerability

CVE-2026-59135
HIGH 5.5

Microsoft Windows Search Component Information Disclosure Vulnerability

CVE-2026-59132
HIGH 7.5

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-59131
HIGH 5.6

AMD Zen Information Disclosure Vulnerability

CVE-2026-59130
HIGH 5.6

AMD Zen Information Disclosure Vulnerability

CVE-2026-59128
HIGH 5.5

Windows Encrypting File System (EFS) Information Disclosure Vulnerability

CVE-2026-59125
HIGH 7.0

Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability

CVE-2026-56179
MEDIUM 8.3

Windows Network Address Translation (NAT) Spoofing Vulnerability

CVE-2026-54984
HIGH 7.8

Windows Imaging Component Remote Code Execution Vulnerability

CVE-2026-54113
HIGH 7.5

Remote Procedure Call Denial of Service Vulnerability

CVE-2026-14266
HIGH 7.8 Local 1 apps

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on …

CVE-2026-14899
HIGH 7.5 Network 1 apps

The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a singl…

CVE-2026-16410
CRITICAL 9.8 Network 1 apps

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16409
HIGH 7.5 Network 1 apps

Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16407
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16403
MEDIUM 6.5 Network 1 apps

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16402
CRITICAL 9.8 Network 1 apps

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16401
HIGH 8.8 Network 1 apps

Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16400
HIGH 7.5 Network 1 apps

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16399
HIGH 7.5 Network 1 apps

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16398
HIGH 7.5 Network 1 apps

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16396
HIGH 8.8 Network 1 apps

Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVE-2026-16393
CRITICAL 9.1 Network 1 apps

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16392
CRITICAL 9.1 Network 1 apps

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16391
HIGH 7.5 Network 1 apps

Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1…

CVE-2026-16390
CRITICAL 9.1 Network 1 apps

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.1…

CVE-2026-16389
CRITICAL 9.8 Network 1 apps

Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16388
CRITICAL 9.8 Network 1 apps

Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16387
CRITICAL 9.8 Network 1 apps

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.