Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,667 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,667
Actively exploited
286
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,667 entries Hide N/A Clear all
CVE
CVE-2026-6779
MEDIUM 5.3 1 app

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6778
MEDIUM 5.3 1 app

Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6777
MEDIUM 5.3 1 app

Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6776
HIGH 7.8 1 app

Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunde…

CVE-2026-6775
MEDIUM 5.3 1 app

Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6774
MEDIUM 5.4 1 app

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6773
HIGH 7.5 1 app

Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6772
HIGH 7.5 1 app

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbi…

CVE-2026-6771
CRITICAL 9.8 1 app

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6770
MEDIUM 6.5 1 app

Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6769
HIGH 8.8 1 app

Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6768
CRITICAL 9.8 1 app

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6767
MEDIUM 5.3 1 app

Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunde…

CVE-2026-6766
HIGH 7.5 1 app

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderb…

CVE-2026-6765
MEDIUM 5.3 1 app

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6764
MEDIUM 6.5 1 app

Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Th…

CVE-2026-6763
MEDIUM 6.5 1 app

Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6762
MEDIUM 6.3 1 app

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thu…

CVE-2026-6761
HIGH 8.8 1 app

Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6760
CRITICAL 9.8 1 app

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6759
HIGH 7.5 1 app

Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6758
HIGH 7.5 1 app

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6757
MEDIUM 6.3 1 app

Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140…

CVE-2026-6755
MEDIUM 6.5 1 app

Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

CVE-2026-6754
HIGH 7.5 1 app

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Th…

CVE-2026-6753
HIGH 7.3 1 app

Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6752
HIGH 7.3 1 app

Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, an…

CVE-2026-6751
HIGH 7.3 1 app

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbir…

CVE-2026-6750
HIGH 8.8 1 app

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150…

CVE-2026-6749
HIGH 7.5 1 app

Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefo…

CVE-2026-6748
CRITICAL 9.8 1 app

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbir…

CVE-2026-6747
HIGH 7.5 1 app

Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVE-2026-6746
HIGH 7.5 1 app

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thu…

CVE-2026-6358
HIGH 8.8 1 app

Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML p…

CVE-2026-6319
HIGH 7.5 1 app

Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures…

CVE-2026-6315
HIGH 8.8 1 app

Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestu…

CVE-2026-33829
MEDIUM 4.3

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-33827
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o…

CVE-2026-33826
HIGH 8.0

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

CVE-2026-33824
CRITICAL 9.8 KEV

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

CVE-2026-33104
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p…

CVE-2026-33101
HIGH 7.8

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-33100
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-33099
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-33098
HIGH 7.8

Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-33096
HIGH 7.5

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

CVE-2026-32225
HIGH 8.8

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-32224
HIGH 7.0

Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

CVE-2026-32223
MEDIUM 6.8

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-32222
HIGH 7.8

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.