Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

11,280 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
11,280
Actively exploited
229
Publication window
2010-07-30 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

11,280 entries High Hide N/A Clear all
CVE
CVE-2026-49162
HIGH 7.0

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-48572
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate p…

CVE-2026-48571
HIGH 7.0

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-48564
HIGH 8.8

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

CVE-2026-44800
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-42982
HIGH 7.8

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-42975
HIGH 8.0

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-42900
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate pri…

CVE-2026-40400
HIGH 8.0

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

CVE-2026-40378
HIGH 7.5

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over …

CVE-2026-15308
HIGH 7.5 1 app

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontr…

CVE-2026-43735
HIGH 8.1

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 2…

CVE-2026-43731
HIGH 8.8

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPad…

CVE-2026-43725
HIGH 7.1

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, mac…

CVE-2026-43724
HIGH 7.8

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15…

CVE-2026-43715
HIGH 8.8

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t…

CVE-2026-43705
HIGH 8.8

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, …

CVE-2026-43701
HIGH 7.1

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 2…

CVE-2026-12328
HIGH 8.1 1 app

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed eviden…

CVE-2026-12327
HIGH 8.1 1 app

Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corrupt…

CVE-2026-12326
HIGH 8.1 1 app

Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2026-12324
HIGH 7.3 1 app

Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thu…

CVE-2026-12318
HIGH 7.3 1 app

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12317
HIGH 7.5 1 app

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12314
HIGH 7.5 1 app

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12312
HIGH 7.5 1 app

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12310
HIGH 7.5 1 app

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12305
HIGH 7.5 1 app

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12292
HIGH 8.1 1 app

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140…

CVE-2026-12291
HIGH 8.8 1 app

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thu…

CVE-2026-12290
HIGH 8.1 1 app

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 1…

CVE-2026-12289
HIGH 8.8 1 app

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152…

CVE-2026-8863
HIGH 7.8

Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the bo…

CVE-2026-49160
HIGH 7.5

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

CVE-2026-48583
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-48578
HIGH 7.9

Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.

CVE-2026-48576
HIGH 7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48575
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48574
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-48573
HIGH 7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48570
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48568
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48563
HIGH 7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47656
HIGH 7.9

Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

CVE-2026-47654
HIGH 7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47653
HIGH 8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47652
HIGH 8.2

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

CVE-2026-47648
HIGH 7.0

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-47289
HIGH 8.8

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47288
HIGH 7.1

Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.