Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,750 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,750
Actively exploited
213
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,750 entries Windows Hide N/A Clear all
CVE
CVE-2025-29841
HIGH 7.0

Universal Print Management Service Elevation of Privilege Vulnerability

CVE-2025-29840
HIGH 8.8

Windows Media Remote Code Execution Vulnerability

CVE-2025-29839
HIGH 4.0

Windows Multiple UNC Provider Driver Information Disclosure Vulnerability

CVE-2025-29838
HIGH 7.4

Windows ExecutionContext Driver Elevation of Privilege Vulnerability

CVE-2025-29837
HIGH 5.5

Windows Installer Information Disclosure Vulnerability

CVE-2025-29836
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29835
HIGH 6.5

Windows Remote Access Connection Manager Information Disclosure Vulnerability

CVE-2025-29833
CRITICAL 7.7

Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

CVE-2025-29832
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29831
HIGH 7.5

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-29830
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-29829
HIGH 5.5

Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability

CVE-2025-27468
HIGH 7.0

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

CVE-2025-26677
HIGH 7.5

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

CVE-2025-24063
HIGH 7.8

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

CVE-2025-4093
HIGH 8.1 1 app

Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort thi…

CVE-2025-4092
MEDIUM 6.5 1 app

Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-4091
HIGH 8.1 1 app

Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption a…

CVE-2025-4089
MEDIUM 5.1 1 app

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading t…

CVE-2025-4088
MEDIUM 6.5 1 app

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invo…

CVE-2025-4087
MEDIUM 4.8 1 app

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This cou…

CVE-2025-4085
HIGH 7.1 1 app

An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. Th…

CVE-2025-4084
MEDIUM 5.7 1 app

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leadi…

CVE-2025-4083
CRITICAL 9.1 1 app

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level docu…

CVE-2025-4082
MEDIUM 5.9 1 app

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate…

CVE-2025-2817
HIGH 8.8 1 app

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By…

CVE-2022-47112
LOW 2.5 1 app

7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.

CVE-2022-47111
LOW 2.5 1 app

7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected.

CVE-2025-3523
MEDIUM 6.4 1 app

When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering ove…

CVE-2025-3522
MEDIUM 6.3 1 app

Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird a…

CVE-2025-2830
MEDIUM 6.3 1 app

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when t…

CVE-2025-26687
HIGH 7.5 1 app

Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-29824
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-29812
HIGH 7.8

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-29811
HIGH 7.8

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

CVE-2025-29810
HIGH 7.5

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2025-29809
HIGH 7.1

Windows Kerberos Security Feature Bypass Vulnerability

CVE-2025-29808
HIGH 5.5

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2025-27742
HIGH 5.5

NTFS Information Disclosure Vulnerability

CVE-2025-27741
HIGH 7.8

NTFS Elevation of Privilege Vulnerability

CVE-2025-27740
HIGH 8.8

Active Directory Certificate Services Elevation of Privilege Vulnerability

CVE-2025-27739
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-27738
HIGH 6.5

Windows Resilient File System (ReFS) Information Disclosure Vulnerability

CVE-2025-27737
HIGH 8.6

Windows Security Zone Mapping Security Feature Bypass Vulnerability

CVE-2025-27736
HIGH 5.5

Windows Power Dependency Coordinator Information Disclosure Vulnerability

CVE-2025-27735
HIGH 6.0

Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability

CVE-2025-27733
HIGH 7.8

NTFS Elevation of Privilege Vulnerability

CVE-2025-27732
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-27731
HIGH 7.8

Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability

CVE-2025-27730
HIGH 7.8

Windows Digital Media Elevation of Privilege Vulnerability