Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,765 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,765
Actively exploited
213
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,765 entries Windows Hide N/A Clear all
CVE
CVE-2025-60705
HIGH 7.8

Windows Client-Side Caching Elevation of Privilege Vulnerability

CVE-2025-60704
HIGH 7.5

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2025-60703
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2025-59515
HIGH 7.0

Windows Broadcast DVR User Service Elevation of Privilege Vulnerability

CVE-2025-59514
HIGH 7.8

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVE-2025-59513
HIGH 5.5

Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability

CVE-2025-59512
HIGH 7.8

Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability

CVE-2025-59511
HIGH 7.8

Windows WLAN Service Elevation of Privilege Vulnerability

CVE-2025-59510
HIGH 5.5

Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability

CVE-2025-59509
HIGH 5.5

Windows Speech Recognition Information Disclosure Vulnerability

CVE-2025-59508
HIGH 7.0

Windows Speech Recognition Elevation of Privilege Vulnerability

CVE-2025-59507
HIGH 7.0

Windows Speech Runtime Elevation of Privilege Vulnerability

CVE-2025-59506
HIGH 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-59505
HIGH 7.8

Windows Smart Card Reader Elevation of Privilege Vulnerability

CVE-2025-6075
MEDIUM 5.5 1 app

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVE-2025-11721
CRITICAL 9.8 1 app

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could h…

CVE-2025-11719
CRITICAL 9.8 1 app

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption.…

CVE-2025-11716
MEDIUM 6.5 1 app

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thu…

CVE-2025-11715
HIGH 8.8 1 app

Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruptio…

CVE-2025-11714
HIGH 8.8 1 app

Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence…

CVE-2025-11713
HIGH 8.1 1 app

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the app…

CVE-2025-11712
MEDIUM 6.1 1 app

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a…

CVE-2025-11711
MEDIUM 6.5 1 app

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefo…

CVE-2025-11710
CRITICAL 9.8 1 app

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised proce…

CVE-2025-11709
CRITICAL 9.8 1 app

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability …

CVE-2025-11708
CRITICAL 9.8 1 app

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

CVE-2025-59502
MEDIUM 7.5

Remote Procedure Call Denial of Service Vulnerability

CVE-2025-59295
HIGH 8.8

Windows URL Parsing Remote Code Execution Vulnerability

CVE-2025-59294
HIGH 2.1

Windows Taskbar Live Preview Information Disclosure Vulnerability

CVE-2025-59290
HIGH 7.8

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-59289
HIGH 7.0

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-59287
CRITICAL 9.8 KEV

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-59284
HIGH 3.3

Windows NTLM Spoofing Vulnerability

CVE-2025-59282
HIGH 7.0

Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-59280
HIGH 3.1

Windows SMB Client Tampering Vulnerability

CVE-2025-59278
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2025-59277
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2025-59275
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2025-59261
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-59260
HIGH 5.5

Microsoft Failover Cluster Virtual Driver Information Disclosure Vulnerability

CVE-2025-59259
HIGH 6.5

Windows Local Session Manager (LSM) Denial of Service Vulnerability

CVE-2025-59258
HIGH 6.2

Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability

CVE-2025-59257
HIGH 6.5

Windows Local Session Manager (LSM) Denial of Service Vulnerability

CVE-2025-59255
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-59254
HIGH 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-59253
HIGH 5.5

Windows Search Service Denial of Service Vulnerability

CVE-2025-59244
HIGH 6.5

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-59242
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-59241
HIGH 7.8

Windows Health and Optimized Experiences Elevation of Privilege Vulnerability

CVE-2025-59230
HIGH 7.8 KEV

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability