Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,750 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,750
Actively exploited
213
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,750 entries Windows Hide N/A Clear all
CVE
CVE-2025-24059
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-24056
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-24055
HIGH 4.3

Windows USB Video Class System Driver Information Disclosure Vulnerability

CVE-2025-24054
HIGH 6.5 KEV

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-24051
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-24050
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-24048
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-24046
HIGH 7.8

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

CVE-2025-24045
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-24044
HIGH 7.8

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVE-2025-24035
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-21247
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-21180
HIGH 7.8

Windows exFAT File System Remote Code Execution Vulnerability

CVE-2024-9157
HIGH

Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability

CVE-2025-26696
HIGH 7.0 1 app

Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown…

CVE-2025-26695
MEDIUM 5.3 1 app

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested emai…

CVE-2025-1943
HIGH 8.2 1 app

Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-1942
CRITICAL 9.8 1 app

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability …

CVE-2025-1938
MEDIUM 6.5 1 app

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption a…

CVE-2025-1937
HIGH 7.5 1 app

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of…

CVE-2025-1936
HIGH 7.3 1 app

jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but…

CVE-2025-1935
MEDIUM 4.3 1 app

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR…

CVE-2025-1934
MEDIUM 6.5 1 app

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was no…

CVE-2025-1933
HIGH 7.6 1 app

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a di…

CVE-2025-1932
HIGH 8.1 1 app

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This …

CVE-2025-1931
HIGH 7.5 1 app

It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerabil…

CVE-2025-1930
HIGH 8.8 1 app

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led t…

CVE-2025-21420
HIGH 7.8

Windows Disk Cleanup Tool Elevation of Privilege Vulnerability

CVE-2025-21419
HIGH 7.1

Windows Setup Files Cleanup Elevation of Privilege Vulnerability

CVE-2025-21418
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-21414
HIGH 7.0

Windows Core Messaging Elevation of Privileges Vulnerability

CVE-2025-21410
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-21407
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21406
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21391
HIGH 7.1 KEV

Windows Storage Elevation of Privilege Vulnerability

CVE-2025-21379
CRITICAL 7.1

DHCP Client Service Remote Code Execution Vulnerability

CVE-2025-21377
HIGH 6.5

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-21376
CRITICAL 8.1

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVE-2025-21375
HIGH 7.8

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2025-21373
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2025-21371
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-21369
HIGH 8.8

Microsoft Digest Authentication Remote Code Execution Vulnerability

CVE-2025-21368
HIGH 8.8

Microsoft Digest Authentication Remote Code Execution Vulnerability

CVE-2025-21367
HIGH 7.8

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVE-2025-21359
HIGH 7.8

Windows Kernel Security Feature Bypass Vulnerability

CVE-2025-21358
HIGH 7.8

Windows Core Messaging Elevation of Privileges Vulnerability

CVE-2025-21352
HIGH 6.5

Internet Connection Sharing (ICS) Denial of Service Vulnerability

CVE-2025-21351
HIGH 7.5

Windows Active Directory Domain Services API Denial of Service Vulnerability

CVE-2025-21350
HIGH 5.9

Windows Kerberos Denial of Service Vulnerability

CVE-2025-21349
HIGH 6.8

Windows Remote Desktop Configuration Service Tampering Vulnerability