Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

840 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-12294
CRITICAL 9.6 Network 1 apps

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunder…

CVE-2026-12293
CRITICAL 9.8 Network 1 apps

Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-47291
CRITICAL 9.8 Network

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

CVE-2026-45657
CRITICAL 9.8 Network

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

CVE-2026-45602
CRITICAL 9.1 Network

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

CVE-2026-44815
CRITICAL 9.8 Network

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

CVE-2026-42904
CRITICAL 9.6 Adjacent network

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2025-10263
CRITICAL 9.1 Network

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C…

CVE-2026-8948
CRITICAL 9.1 Network 1 apps

Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

CVE-2026-41096
CRITICAL 9.8

Windows DNS Client Remote Code Execution Vulnerability

CVE-2026-41089
CRITICAL 9.8

Windows Netlogon Remote Code Execution Vulnerability

CVE-2026-40403
CRITICAL 8.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2026-40402
CRITICAL 9.3

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2026-35421
CRITICAL 7.8

Windows GDI Remote Code Execution Vulnerability

CVE-2026-32161
CRITICAL 7.5

Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability

CVE-2026-8094
CRITICAL 9.8 Network 1 apps

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

CVE-2026-8091
CRITICAL 9.8 Network 1 apps

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thund…

CVE-2026-6771
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6768
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6760
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6748
CRITICAL 9.8 Network 1 apps

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbir…

CVE-2026-33824
CRITICAL 9.8 Network

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

CVE-2026-32157
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-5735
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough …

CVE-2026-5734
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memo…

CVE-2026-5731
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs s…

CVE-2026-4729
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2026-4724
CRITICAL 9.1 Network 1 apps

Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

CVE-2026-4721
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence…

CVE-2026-4720
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruptio…

CVE-2026-4710
CRITICAL 9.8 Network 1 apps

Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 14…

CVE-2026-4692
CRITICAL 10.0 Network 1 apps

Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, an…

CVE-2026-4689
CRITICAL 10.0 Network 1 apps

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, …

CVE-2026-2807
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2026-2806
CRITICAL 9.1 Network 1 apps

Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

CVE-2026-2805
CRITICAL 9.8 Network 1 apps

Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

CVE-2026-2799
CRITICAL 9.8 Network 1 apps

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

CVE-2026-2797
CRITICAL 9.8 Network 1 apps

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

CVE-2026-2796
CRITICAL 9.8 Network 1 apps

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

CVE-2026-2795
CRITICAL 9.8 Network 1 apps

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

CVE-2026-2793
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence…

CVE-2026-2792
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruptio…

CVE-2026-2791
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVE-2026-2790
CRITICAL 9.8 Network 1 apps

Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14…

CVE-2026-2789
CRITICAL 9.8 Network 1 apps

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Th…

CVE-2026-2788
CRITICAL 9.8 Network 1 apps

Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbir…

CVE-2026-2787
CRITICAL 9.8 Network 1 apps

Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, …

CVE-2026-2786
CRITICAL 9.8 Network 1 apps

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVE-2026-2785
CRITICAL 9.8 Network 1 apps

Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVE-2026-2784
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.