Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

11,275 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
11,275
Actively exploited
229
Publication window
2010-07-30 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

11,275 entries High Hide N/A Clear all
CVE
CVE-2026-20816
HIGH 7.8

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-20815
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz…

CVE-2026-20814
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile…

CVE-2026-20811
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20809
HIGH 7.8

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

CVE-2026-20808
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elev…

CVE-2026-20804
HIGH 7.7

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

CVE-2026-0891
HIGH 8.1 1 app

Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruptio…

CVE-2026-0889
HIGH 7.5 1 app

Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

CVE-2026-0882
HIGH 8.8 1 app

Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVE-2026-0880
HIGH 8.8 1 app

Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbi…

CVE-2026-0878
HIGH 8.0 1 app

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thu…

CVE-2026-0877
HIGH 8.1 1 app

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thun…

CVE-2026-20833
HIGH 5.5

Windows Kerberos Information Disclosure Vulnerability

CVE-2026-20830
HIGH 7.0

Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

CVE-2026-20818
HIGH 6.2

Windows Kernel Information Disclosure Vulnerability

CVE-2026-20810
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-0386
HIGH 7.5

Windows Deployment Services Remote Code Execution Vulnerability

CVE-2024-55414
HIGH 7.8

Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability

CVE-2023-31096
HIGH 7.8

MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability

CVE-2025-54957
HIGH 7.0

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-46291
HIGH 7.8

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An app may bypass Gatekeeper checks.

CVE-2025-46281
HIGH 8.8

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to bre…

CVE-2025-43529
HIGH 8.8 KEV

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.…

CVE-2025-46285
HIGH 7.8

An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 1…

CVE-2025-43542
HIGH 7.5

This issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, m…

CVE-2025-43539
HIGH 8.8

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS…

CVE-2025-43527
HIGH 7.8

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26.2. An app may be able to gain root …

CVE-2025-43512
HIGH 7.8

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 2…

CVE-2025-43510
HIGH 7.8 KEV

A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS…

CVE-2025-43506
HIGH 7.5

A logic error was addressed with improved error handling. This issue is fixed in macOS Tahoe 26.1. iCloud Private Relay may not activate when more than one use…

CVE-2025-43494
HIGH 7.5

A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15…

CVE-2025-43467
HIGH 7.8

This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to gain root privileges.

CVE-2025-43402
HIGH 7.8

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.1. An app may be able t…

CVE-2025-43320
HIGH 7.8

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app may be able to bypass launch constraint…

CVE-2025-14174
HIGH 8.8 KEV

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a cra…

CVE-2025-14333
HIGH 8.1 1 app

Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruptio…

CVE-2025-14332
HIGH 7.3 1 app

Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-14329
HIGH 8.8 1 app

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVE-2025-14328
HIGH 8.8 1 app

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVE-2025-14327
HIGH 7.5 1 app

Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7.

CVE-2025-14325
HIGH 7.3 1 app

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14…

CVE-2025-14323
HIGH 8.8 1 app

Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, …

CVE-2025-14322
HIGH 8.0 1 app

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Fi…

CVE-2025-64680
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-64679
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-64678
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-64673
HIGH 7.8

Windows Storage VSP Driver Elevation of Privilege Vulnerability

CVE-2025-64670
HIGH 6.5

Windows DirectX Information Disclosure Vulnerability

CVE-2025-64661
HIGH 7.8

Windows Shell Elevation of Privilege Vulnerability