Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

8,497 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-2772
CRITICAL 9.8 Network 1 apps

Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and…

CVE-2026-2771
CRITICAL 9.8 Network 1 apps

Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and …

CVE-2026-2770
CRITICAL 9.8 Network 1 apps

Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, an…

CVE-2026-2769
HIGH 8.8 Network 1 apps

Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Th…

CVE-2026-2768
CRITICAL 10.0 Network 1 apps

Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVE-2026-2767
CRITICAL 9.8 Network 1 apps

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVE-2026-2766
CRITICAL 9.8 Network 1 apps

Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVE-2026-2765
CRITICAL 9.8 Network 1 apps

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVE-2026-2764
CRITICAL 9.8 Network 1 apps

JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8,…

CVE-2026-2763
CRITICAL 9.8 Network 1 apps

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thu…

CVE-2026-2762
CRITICAL 9.8 Network 1 apps

Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbir…

CVE-2026-2761
CRITICAL 10.0 Network 1 apps

Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and T…

CVE-2026-2760
CRITICAL 10.0 Network 1 apps

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fire…

CVE-2026-2759
CRITICAL 9.8 Network 1 apps

Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderb…

CVE-2026-2758
CRITICAL 9.8 Network 1 apps

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunde…

CVE-2026-2757
CRITICAL 9.8 Network 1 apps

Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunder…

CVE-2026-2447
HIGH 8.8 Network 1 apps

Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbir…

CVE-2026-21533
HIGH 7.8 KEV

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-21525
MEDIUM 6.2 KEV

Windows Remote Access Connection Manager Denial of Service Vulnerability

CVE-2026-21519
HIGH 7.8 KEV

Desktop Window Manager Elevation of Privilege Vulnerability

CVE-2026-21513
HIGH 8.8 KEV

MSHTML Framework Security Feature Bypass Vulnerability

CVE-2026-21510
HIGH 8.8 KEV

Windows Shell Security Feature Bypass Vulnerability

CVE-2026-21508
HIGH 7.0

Windows Storage Elevation of Privilege Vulnerability

CVE-2026-21255
HIGH 8.8

Windows Hyper-V Security Feature Bypass Vulnerability

CVE-2026-21253
HIGH 7.0

Mailslot File System Elevation of Privilege Vulnerability

CVE-2026-21251
HIGH 7.8

Cluster Client Failover (CCF) Elevation of Privilege Vulnerability

CVE-2026-21250
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-21249
HIGH 3.3

Windows NTLM Spoofing Vulnerability

CVE-2026-21248
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-21247
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-21246
HIGH 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2026-21245
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21244
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-21243
HIGH 7.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2026-21242
HIGH 7.0

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVE-2026-21241
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-21240
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-21239
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21238
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-21237
HIGH 7.0

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVE-2026-21236
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-21235
HIGH 7.3

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2026-21234
HIGH 7.0

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2026-21232
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-21231
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21222
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2026-20846
HIGH 7.5

GDI+ Denial of Service Vulnerability

CVE-2023-2804
HIGH 6.5

Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo

CVE-2026-0818
MEDIUM 4.3 Network 1 apps

When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled…

CVE-2025-11002
HIGH 7.8 Local 1 apps

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte…