Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

318 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
318
Actively exploited
213
Publication window
2004-08-06 → 2026-04-14

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

318 entries Windows Public exploit Clear all
CVE
CVE-2026-33829
MEDIUM 4.3

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-32202
MEDIUM 4.3 KEV

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-21250
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-21248
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-21244
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2025-11001
HIGH 7.8 1 app

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte…

CVE-2025-59287
CRITICAL 9.8 KEV

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-59254
HIGH 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-50154
HIGH 6.5

Microsoft Windows File Explorer Spoofing Vulnerability

CVE-2025-6965
HIGH 7.7

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead…

CVE-2025-49744
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-49730
HIGH 7.8

Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability

CVE-2025-49683
HIGH 7.8

Microsoft Virtual Hard Disk Remote Code Execution Vulnerability

CVE-2025-49677
HIGH 7.0

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-47987
HIGH 7.8

Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability

CVE-2025-33073
HIGH 8.8 KEV

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2025-30397
HIGH 7.5 KEV

Scripting Engine Memory Corruption Vulnerability

CVE-2025-26633
HIGH 7.0 KEV

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-24076
HIGH 7.3

Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability

CVE-2025-24071
HIGH 6.5

Microsoft Windows File Explorer Spoofing Vulnerability

CVE-2025-24054
HIGH 6.5 KEV

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-21333
HIGH 7.8 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2024-49138
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-38193
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2024-4367
HIGH 8.8 1 app

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Fire…

CVE-2024-21338
HIGH 7.8 KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-21320
HIGH 6.5

Windows Themes Spoofing Vulnerability

CVE-2023-44487
HIGH 7.5 KEV

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w…

CVE-2023-29336
HIGH 7.8 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2023-28293
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-21752
HIGH 7.1

Windows Backup Service Elevation of Privilege Vulnerability

CVE-2022-21907
CRITICAL 9.8

HTTP Protocol Stack Remote Code Execution Vulnerability

CVE-2020-1472
CRITICAL 10.0 KEV

Netlogon Elevation of Privilege Vulnerability

CVE-2020-0796
CRITICAL 10.0 KEV

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S…

CVE-2019-17026
HIGH 8.8 KEV 1 app

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a…

CVE-2014-4650
CRITICAL 9.8 1 app

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attacke…

CVE-2020-0683
HIGH 7.0 KEV

Windows Installer Elevation of Privilege Vulnerability

CVE-2020-0610
CRITICAL 9.8

Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability

CVE-2020-0609
CRITICAL 9.8

Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability

CVE-2020-0601
HIGH 8.1 KEV

Windows CryptoAPI Spoofing Vulnerability

CVE-2019-1458
HIGH 7.8 KEV

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privil…

CVE-2019-1476
HIGH 7.8

Windows Elevation of Privilege Vulnerability

CVE-2019-1405
HIGH 7.8 KEV

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP…

CVE-2019-1347
HIGH 5.7

Windows Denial of Service Vulnerability

CVE-2019-1346
HIGH 5.7

Windows Denial of Service Vulnerability

CVE-2019-1345
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2019-1344
HIGH 5.5

Windows Code Integrity Module Information Disclosure Vulnerability

CVE-2019-1343
HIGH 6.5

Windows Denial of Service Vulnerability

CVE-2019-1322
HIGH 7.0 KEV

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2019-1253
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability