Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

6,117 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-20928
HIGH 4.6

Windows Recovery Environment Security Feature Bypass Vulnerability

CVE-2026-20806
HIGH 5.5

Windows COM Server Information Disclosure Vulnerability

CVE-2026-0390
HIGH 6.7

UEFI Secure Boot Security Feature Bypass Vulnerability

CVE-2023-20585
HIGH 5.3

AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability

CVE-2026-4371
HIGH 7.4 Network 1 apps

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connectio…

CVE-2026-4727
HIGH 7.5 Network 1 apps

Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

CVE-2026-4726
HIGH 7.5 Network 1 apps

Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

CVE-2026-4718
HIGH 8.1 Network 1 apps

Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

CVE-2026-4694
HIGH 7.5 Network 1 apps

Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, …

CVE-2026-4224
HIGH 7.5 Network 1 apps

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow…

CVE-2026-3644
HIGH 7.5 Network 1 apps

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths wer…

CVE-2026-25180
HIGH 5.5 Local 1 apps

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

CVE-2026-24294
HIGH 7.8 Local

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

CVE-2026-24293
HIGH 7.8 Local

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-24289
HIGH 7.8 Local

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-24285
HIGH 7.0 Local 1 apps

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-26132
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-26128
HIGH 7.8

Windows SMB Server Elevation of Privilege Vulnerability

CVE-2026-26111
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2026-25190
HIGH 7.8

Windows GDI Remote Code Execution Vulnerability

CVE-2026-25189
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2026-25188
HIGH 8.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-25187
HIGH 7.8

Winlogon Elevation of Privilege Vulnerability

CVE-2026-25186
HIGH 5.5

Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability

CVE-2026-25185
HIGH 5.3

Windows Shell Link Processing Spoofing Vulnerability

CVE-2026-25181
HIGH 7.5

GDI+ Information Disclosure Vulnerability

CVE-2026-25179
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-25178
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-25177
HIGH 8.8

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2026-25176
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-25175
HIGH 7.8

Windows NTFS Elevation of Privilege Vulnerability

CVE-2026-25174
HIGH 7.8

Windows Extensible File Allocation Table Elevation of Privilege Vulnerability

CVE-2026-25173
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2026-25172
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2026-25171
HIGH 7.0

Windows Authentication Elevation of Privilege Vulnerability

CVE-2026-25170
HIGH 7.0

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2026-25169
HIGH 6.2

Windows Graphics Component Denial of Service Vulnerability

CVE-2026-25168
HIGH 6.2

Windows Graphics Component Denial of Service Vulnerability

CVE-2026-25167
HIGH 7.4

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2026-25165
HIGH 7.8

Performance Counters for Windows Elevation of Privilege Vulnerability

CVE-2026-24297
HIGH 6.5

Windows Kerberos Security Feature Bypass Vulnerability

CVE-2026-24296
HIGH 7.0

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-24295
HIGH 7.0

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-24292
HIGH 7.8

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2026-24291
HIGH 7.8

Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability

CVE-2026-24290
HIGH 7.8

Windows Projected File System Elevation of Privilege Vulnerability

CVE-2026-24288
HIGH 6.8

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CVE-2026-24287
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-24283
HIGH 8.8

Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability

CVE-2026-24282
HIGH 5.5

Push message Routing Service Elevation of Privilege Vulnerability