Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,667 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,667
Actively exploited
286
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,667 entries Hide N/A Clear all
CVE
CVE-2026-8948
CRITICAL 9.1 1 app

Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

CVE-2026-8947
HIGH 7.3 1 app

Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, a…

CVE-2026-8946
HIGH 7.5 1 app

Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Th…

CVE-2025-54518
HIGH 7.0

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a dif…

CVE-2026-41615
CRITICAL 9.6 2 apps

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

CVE-2026-42893
HIGH 7.4 1 app

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a…

CVE-2026-42832
HIGH 7.7 2 apps

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

CVE-2026-42831
CRITICAL 7.8 1 app

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-41102
HIGH 7.1 1 app

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

CVE-2026-41101
HIGH 7.1 1 app

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

CVE-2026-41088
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-40414
HIGH 7.4

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40413
HIGH 7.4

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40401
HIGH 7.1

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40399
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg…

CVE-2026-40397
HIGH 7.8

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-40369
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-40363
CRITICAL 8.4 1 app

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-35429
MEDIUM 4.3 1 app

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a net…

CVE-2026-35417
HIGH 7.8

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVE-2026-35416
HIGH 7.0

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-34345
HIGH 7.0

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-34336
HIGH 7.8

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-34330
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p…

CVE-2026-33841
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-33840
HIGH 7.8

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-32170
MEDIUM 6.7

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

CVE-2025-46311
HIGH 7.5

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.…

CVE-2025-43524
HIGH 8.8

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app …

CVE-2026-42896
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2026-42825
HIGH 7.0

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-41097
HIGH 6.7

Secure Boot Security Feature Bypass Vulnerability

CVE-2026-41096
CRITICAL 9.8

Windows DNS Client Remote Code Execution Vulnerability

CVE-2026-41095
HIGH 7.8

Data Deduplication Elevation of Privilege Vulnerability

CVE-2026-41089
CRITICAL 9.8

Windows Netlogon Remote Code Execution Vulnerability

CVE-2026-40415
HIGH 8.1

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2026-40410
HIGH 7.0

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2026-40408
HIGH 7.8

Windows WAN ARP Driver Elevation of Privilege Vulnerability

CVE-2026-40407
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2026-40406
HIGH 7.5

Windows TCP/IP Information Disclosure Vulnerability

CVE-2026-40405
HIGH 7.5

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40403
CRITICAL 8.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2026-40402
CRITICAL 9.3

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2026-40398
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-40382
HIGH 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-40380
HIGH 6.2

Windows Volume Manager Extension Driver Remote Code Execution Vulnerability

CVE-2026-40377
HIGH 7.8

Microsoft Cryptographic Services Elevation of Privilege Vulnerability

CVE-2026-35424
HIGH 7.5

Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

CVE-2026-35423
HIGH 5.4

Windows 11 Telnet Client Information Disclosure Vulnerability

CVE-2026-35422
HIGH 6.5

Windows TCP/IP Driver Security Feature Bypass Vulnerability