Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

11 326 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2026-21221
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz…

CVE-2026-20941
HIGH 7.8 Local

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2026-20940
HIGH 7.8 Local

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-20938
HIGH 7.8 Local

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVE-2026-20934
HIGH 7.5 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20931
HIGH 8.0 Réseau adjacent

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

CVE-2026-20929
HIGH 7.5 Réseau

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

CVE-2026-20926
HIGH 7.5 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20924
HIGH 7.8 Local

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20923
HIGH 7.8 Local

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20922
HIGH 7.8 Local

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-20921
HIGH 7.5 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20920
HIGH 7.8 Local

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20919
HIGH 7.5 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20918
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20877
HIGH 7.8 Local

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20875
HIGH 7.5 Réseau

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVE-2026-20874
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20873
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20871
HIGH 7.8 Local

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-20870
HIGH 7.8 Local

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20869
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacke…

CVE-2026-20868
HIGH 8.8 Réseau

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

CVE-2026-20867
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20866
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20865
HIGH 7.8 Local

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20864
HIGH 7.8 Local

Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

CVE-2026-20863
HIGH 7.0 Local

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20861
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20860
HIGH 7.8 Local

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-20859
HIGH 7.8 Local

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-20858
HIGH 7.8 Local

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20857
HIGH 7.8 Local

Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-20856
HIGH 8.1 Réseau

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

CVE-2026-20854
HIGH 7.5 Réseau

Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

CVE-2026-20853
HIGH 7.4 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate…

CVE-2026-20852
HIGH 7.7 Local

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

CVE-2026-20849
HIGH 7.5 Réseau

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

CVE-2026-20848
HIGH 7.5 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20844
HIGH 7.4 Local

Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.

CVE-2026-20843
HIGH 7.8 Local

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-20842
HIGH 7.0 Local

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2026-20840
HIGH 7.8 Local

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-20837
HIGH 7.8 Local

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-20836
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile…

CVE-2026-20832
HIGH 7.8 Local

Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability

CVE-2026-20831
HIGH 7.8 Local

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-20826
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an autho…

CVE-2026-20822
HIGH 7.8 Local

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2026-20820
HIGH 7.8 Local

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.