Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,871 CVEs affect a tracked app or OS (all severities, macOS). 102 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,871
Actively exploited
102
Publication window
2004-07-27 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,871 entries macOS Hide N/A Clear all
CVE
CVE-2026-66810
MEDIUM 5.5

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-66809
MEDIUM 5.5

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-66806
MEDIUM 5.5

Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-65807
HIGH 8.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

CVE-2026-64917
MEDIUM 5.5

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-64915
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-64907
HIGH 7.8

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-64905
HIGH 7.8

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-63531
MEDIUM 5.5

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-63530
MEDIUM 5.5

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-63528
MEDIUM 5.5

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-63527
HIGH 7.8

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-63525
HIGH 7.8

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-63521
MEDIUM 5.5

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-63518
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-62882
MEDIUM 4.3

Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-65400
CRITICAL 9.8 KEV

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, m…

CVE-2026-19177
HIGH 8.3

Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to…

CVE-2026-19176
HIGH 7.5

Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code in…

CVE-2026-19175
CRITICAL 9.6

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

CVE-2026-19174
HIGH 8.8

Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (…

CVE-2026-19173
HIGH 8.3

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform …

CVE-2026-19172
HIGH 8.3

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sa…

CVE-2026-19171
CRITICAL 9.6

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM…

CVE-2026-19170
CRITICAL 9.6

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM…

CVE-2026-19169
HIGH 8.8

Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalati…

CVE-2026-19168
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

CVE-2026-19167
LOW 3.1

Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data v…

CVE-2026-19166
CRITICAL 9.6

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted H…

CVE-2026-19165
HIGH 7.5

Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbi…

CVE-2026-19164
CRITICAL 9.6

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape…

CVE-2026-19163
HIGH 8.3

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially p…

CVE-2026-19162
HIGH 8.8

Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page…

CVE-2026-19161
LOW 3.1

Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data…

CVE-2026-19160
LOW 3.1

Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data…

CVE-2026-19159
HIGH 7.5

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentiall…

CVE-2026-19158
HIGH 7.5

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to…

CVE-2026-19157
CRITICAL 9.6

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafte…

CVE-2026-19156
HIGH 7.5

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially …

CVE-2026-19155
HIGH 8.3

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a…

CVE-2026-19154
HIGH 8.3

Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially pe…

CVE-2026-19153
HIGH 8.1

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer proce…

CVE-2026-19152
HIGH 8.3

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to po…

CVE-2026-19151
HIGH 8.8

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…

CVE-2026-19150
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

CVE-2026-19149
CRITICAL 9.6

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…

CVE-2026-19148
HIGH 8.3

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially …

CVE-2026-19147
HIGH 8.3

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perf…

CVE-2026-19146
MEDIUM 5.3

Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain poten…

CVE-2026-19145
HIGH 8.8

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pa…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM