Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,756 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,756
Actively exploited
213
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,756 entries Windows Hide N/A Clear all
CVE
CVE-2025-8039
HIGH 8.1 1 app

In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Firefox ESR 1…

CVE-2025-8038
CRITICAL 9.8 1 app

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141…

CVE-2025-8037
CRITICAL 9.1 1 app

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie includ…

CVE-2025-8036
HIGH 8.1 1 app

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Fire…

CVE-2025-8035
HIGH 8.8 1 app

Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of th…

CVE-2025-8034
HIGH 8.8 1 app

Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunder…

CVE-2025-8033
MEDIUM 6.5 1 app

The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in…

CVE-2025-8032
HIGH 8.1 1 app

XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, …

CVE-2025-8031
CRITICAL 9.8 1 app

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability …

CVE-2025-8030
HIGH 8.1 1 app

Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in F…

CVE-2025-8029
HIGH 8.1 1 app

Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 14…

CVE-2025-8028
CRITICAL 9.8 1 app

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect compu…

CVE-2025-8027
MEDIUM 6.5 1 app

On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulner…

CVE-2025-53817
HIGH 7.5 1 app

7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to version 25.0.0, a null pointer dereference …

CVE-2025-53816
HIGH 7.5 1 app

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service …

CVE-2025-6965
HIGH 7.7

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead…

CVE-2025-46789
MEDIUM 6.5 1 app

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

CVE-2025-49731
LOW 3.1 2 apps

Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

CVE-2025-49760
MEDIUM 3.5

Windows Storage Spoofing Vulnerability

CVE-2025-49753
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49744
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-49742
HIGH 7.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-49740
HIGH 8.8

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2025-49735
CRITICAL 8.1

Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability

CVE-2025-49733
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2025-49732
HIGH 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-49730
HIGH 7.8

Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability

CVE-2025-49729
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49727
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2025-49726
HIGH 7.8

Windows Notification Elevation of Privilege Vulnerability

CVE-2025-49725
HIGH 7.8

Windows Notification Elevation of Privilege Vulnerability

CVE-2025-49724
HIGH 8.8

Windows Connected Devices Platform Service Remote Code Execution Vulnerability

CVE-2025-49723
HIGH 8.8

Windows StateRepository API Server file Tampering Vulnerability

CVE-2025-49722
HIGH 5.7

Windows Print Spooler Denial of Service Vulnerability

CVE-2025-49721
HIGH 7.8

Windows Fast FAT File System Driver Elevation of Privilege Vulnerability

CVE-2025-49716
HIGH 7.5

Windows Netlogon Denial of Service Vulnerability

CVE-2025-49694
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-49693
HIGH 7.8

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-49691
HIGH 8.0

Windows Miracast Wireless Display Remote Code Execution Vulnerability

CVE-2025-49690
HIGH 7.4

Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability

CVE-2025-49689
HIGH 7.8

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-49688
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-49687
HIGH 8.8

Windows Input Method Editor (IME) Elevation of Privilege Vulnerability

CVE-2025-49686
HIGH 7.8

Windows TCP/IP Driver Elevation of Privilege Vulnerability

CVE-2025-49685
HIGH 7.0

Windows Search Service Elevation of Privilege Vulnerability

CVE-2025-49684
HIGH 5.5

Windows Storage Port Driver Information Disclosure Vulnerability

CVE-2025-49683
HIGH 7.8

Microsoft Virtual Hard Disk Remote Code Execution Vulnerability

CVE-2025-49682
HIGH 7.3

Windows Media Elevation of Privilege Vulnerability

CVE-2025-49681
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-49680
HIGH 7.3

Windows Performance Recorder (WPR) Denial of Service Vulnerability