Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,750 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,750
Actively exploited
213
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,750 entries Windows Hide N/A Clear all
CVE
CVE-2024-43646
HIGH 6.7

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

CVE-2024-43645
HIGH 6.7

Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability

CVE-2024-43644
HIGH 7.8

Windows Client-Side Caching Elevation of Privilege Vulnerability

CVE-2024-43643
HIGH 6.8

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2024-43642
HIGH 7.5

Windows SMB Denial of Service Vulnerability

CVE-2024-43641
HIGH 7.8

Windows Registry Elevation of Privilege Vulnerability

CVE-2024-43640
HIGH 7.8

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

CVE-2024-43639
CRITICAL 9.8

Windows KDC Proxy Remote Code Execution Vulnerability

CVE-2024-43638
HIGH 6.8

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2024-43637
HIGH 6.8

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2024-43636
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2024-43635
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43634
HIGH 6.8

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2024-43633
HIGH 6.5

Windows Hyper-V Denial of Service Vulnerability

CVE-2024-43631
HIGH 6.7

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

CVE-2024-43630
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-43629
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-43628
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43627
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43626
HIGH 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2024-43625
CRITICAL 8.1

Microsoft Windows VMSwitch Elevation of Privilege Vulnerability

CVE-2024-43624
HIGH 8.8

Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability

CVE-2024-43623
HIGH 7.8

Windows NT OS Kernel Elevation of Privilege Vulnerability

CVE-2024-43622
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43621
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43620
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2024-43530
HIGH 7.8

Windows Update Stack Elevation of Privilege Vulnerability

CVE-2024-43452
HIGH 7.5

Windows Registry Elevation of Privilege Vulnerability

CVE-2024-43451
HIGH 6.5 KEV

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-43450
HIGH 7.5

Windows DNS Spoofing Vulnerability

CVE-2024-43449
HIGH 6.8

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVE-2024-43447
HIGH 8.1

Windows SMBv3 Server Remote Code Execution Vulnerability

CVE-2024-38264
HIGH 5.9

Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability

CVE-2024-38203
HIGH 6.2

Windows Package Library Manager Information Disclosure Vulnerability

CVE-2024-10468
MEDIUM 5.3 1 app

Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 13…

CVE-2024-10467
HIGH 8.8 1 app

Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2024-10466
HIGH 7.5 1 app

By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability…

CVE-2024-10465
MEDIUM 6.5 1 app

A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbir…

CVE-2024-10464
MEDIUM 6.5 1 app

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing r…

CVE-2024-10463
MEDIUM 6.5 1 app

Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Th…

CVE-2024-10462
MEDIUM 6.5 1 app

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird …

CVE-2024-10461
MEDIUM 6.1 1 app

In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could al…

CVE-2024-10460
MEDIUM 5.3 1 app

The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Fire…

CVE-2024-10459
HIGH 7.5 1 app

An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox <…

CVE-2024-10458
HIGH 7.5 1 app

A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Fire…

CVE-2024-9287
MEDIUM 7.8 1 app

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, all…

CVE-2024-44157
MEDIUM 5.5 1 app

A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Par…

CVE-2024-9680
CRITICAL 9.8 KEV 1 app

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner…

CVE-2024-6197
HIGH 8.8

Hackerone: CVE-2024-6197 Freeing stack buffer in utf8asn1str

CVE-2024-43615
HIGH 7.1

Microsoft OpenSSH for Windows Remote Code Execution Vulnerability