Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

1,816 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-12316
CRITICAL 9.1 Network 1 apps

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12315
CRITICAL 9.1 Network 1 apps

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12304
CRITICAL 9.1 Network 1 apps

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbi…

CVE-2026-12297
CRITICAL 9.6 Network 1 apps

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 1…

CVE-2026-12296
CRITICAL 9.6 Network 1 apps

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird…

CVE-2026-12295
CRITICAL 9.6 Network 1 apps

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thun…

CVE-2026-12294
CRITICAL 9.6 Network 1 apps

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunder…

CVE-2026-12293
CRITICAL 9.8 Network 1 apps

Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-47291
CRITICAL 9.8 Network

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

CVE-2026-45657
CRITICAL 9.8 Network

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

CVE-2026-45602
CRITICAL 9.1 Network

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

CVE-2026-44815
CRITICAL 9.8 Network

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

CVE-2026-42904
CRITICAL 9.6 Adjacent network

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2025-10263
CRITICAL 9.1 Network

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C…

CVE-2026-21353
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-21352
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-47392
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-8948
CRITICAL 9.1 Network 1 apps

Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

CVE-2026-41615
CRITICAL 9.6 Network 2 apps

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

CVE-2026-42831
CRITICAL 7.8 Local 1 apps

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-40363
CRITICAL 8.4 Local 1 apps

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-41096
CRITICAL 9.8

Windows DNS Client Remote Code Execution Vulnerability

CVE-2026-41089
CRITICAL 9.8

Windows Netlogon Remote Code Execution Vulnerability

CVE-2026-40403
CRITICAL 8.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2026-40402
CRITICAL 9.3

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2026-35421
CRITICAL 7.8

Windows GDI Remote Code Execution Vulnerability

CVE-2026-32161
CRITICAL 7.5

Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability

CVE-2026-8094
CRITICAL 9.8 Network 1 apps

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

CVE-2026-8091
CRITICAL 9.8 Network 1 apps

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thund…

CVE-2026-0073
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-6771
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6768
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6760
CRITICAL 9.8 Network 1 apps

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6748
CRITICAL 9.8 Network 1 apps

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbir…

CVE-2026-33824
CRITICAL 9.8 Network

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

CVE-2026-32157
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-5735
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough …

CVE-2026-5734
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memo…

CVE-2026-5731
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs s…

CVE-2026-28858
CRITICAL 9.8 Network

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause unexpected s…

CVE-2026-28827
CRITICAL 9.3 Local

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.…

CVE-2026-20688
CRITICAL 9.3 Local

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS…

CVE-2026-4729
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2026-4724
CRITICAL 9.1 Network 1 apps

Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

CVE-2026-4721
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence…

CVE-2026-4720
CRITICAL 9.8 Network 1 apps

Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruptio…

CVE-2026-4710
CRITICAL 9.8 Network 1 apps

Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 14…

CVE-2026-4692
CRITICAL 10.0 Network 1 apps

Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, an…

CVE-2026-4689
CRITICAL 10.0 Network 1 apps

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, …

CVE-2026-26110
CRITICAL 8.4 Local 1 apps

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.