Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

749 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-49167
MEDIUM 4.7 Local

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-44806
MEDIUM 5.3 Network

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

CVE-2026-41087
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-40422
MEDIUM 5.5 Local

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-34349
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

CVE-2026-34348
MEDIUM 6.5 Network

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

CVE-2026-34346
MEDIUM 5.5 Local

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

CVE-2026-34328
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

CVE-2026-33842
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-57963
MEDIUM 6.5 Network 1 apps

An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. Thi…

CVE-2026-57962
MEDIUM 5.3 Network 1 apps

A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplie…

CVE-2026-4360
MEDIUM 5.3 Network 1 apps

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrust…

CVE-2026-12330
MEDIUM 5.4 Network 1 apps

Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 14…

CVE-2026-12329
MEDIUM 5.3 Network 1 apps

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.

CVE-2026-12325
MEDIUM 6.5 Network 1 apps

Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, an…

CVE-2026-12323
MEDIUM 5.4 Network 1 apps

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12322
MEDIUM 5.4 Network 1 apps

Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12321
MEDIUM 5.4 Network 1 apps

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12320
MEDIUM 4.3 Network 1 apps

Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12319
MEDIUM 6.5 Network 1 apps

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12313
MEDIUM 4.7 Network 1 apps

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderb…

CVE-2026-12311
MEDIUM 4.7 Network 1 apps

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderb…

CVE-2026-12309
MEDIUM 6.5 Network 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12308
MEDIUM 5.3 Network 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12307
MEDIUM 5.3 Network 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12306
MEDIUM 5.3 Network 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12303
MEDIUM 4.3 Network 1 apps

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12302
MEDIUM 6.5 Network 1 apps

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thu…

CVE-2026-12301
MEDIUM 5.3 Network 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12300
MEDIUM 5.3 Network 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12299
MEDIUM 5.4 Network 1 apps

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and…

CVE-2026-12298
MEDIUM 5.4 Network 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-50508
MEDIUM 6.5 Network

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-50507
MEDIUM 6.8 Physical

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-48566
MEDIUM 5.5 Local

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVE-2026-45655
MEDIUM 5.3 Physical

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-45634
MEDIUM 5.5 Local

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

CVE-2026-45608
MEDIUM 6.8 Local

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

CVE-2026-45606
MEDIUM 5.5 Local

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

CVE-2026-45604
MEDIUM 5.5 Local

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

CVE-2026-45595
MEDIUM 5.4 Network

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-45594
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informat…

CVE-2026-44814
MEDIUM 5.5 Local

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVE-2026-44805
MEDIUM 5.5 Local

Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.

CVE-2026-42973
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42972
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2026-42971
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42970
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42969
MEDIUM 5.5 Local

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42968
MEDIUM 5.5 Local

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.