Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,770 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,770
Actively exploited
214
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,770 entries Windows Hide N/A Clear all
CVE
CVE-2024-26217
HIGH 5.5

Windows Remote Access Connection Manager Information Disclosure Vulnerability

CVE-2024-26216
HIGH 7.3

Windows File Server Resource Management Service Elevation of Privilege Vulnerability

CVE-2024-26215
HIGH 7.5

DHCP Server Service Denial of Service Vulnerability

CVE-2024-26214
HIGH 8.8

Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability

CVE-2024-26213
HIGH 7.0

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2024-26212
HIGH 7.5

DHCP Server Service Denial of Service Vulnerability

CVE-2024-26211
HIGH 7.8

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2024-26210
HIGH 8.8

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVE-2024-26209
HIGH 5.5

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

CVE-2024-26208
HIGH 7.2

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2024-26207
HIGH 5.5

Windows Remote Access Connection Manager Information Disclosure Vulnerability

CVE-2024-26205
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-26202
HIGH 7.2

DHCP Server Service Remote Code Execution Vulnerability

CVE-2024-26200
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-26195
HIGH 7.2

DHCP Server Service Remote Code Execution Vulnerability

CVE-2024-26194
HIGH 7.4

Secure Boot Security Feature Bypass Vulnerability

CVE-2024-26189
HIGH 8.0

Secure Boot Security Feature Bypass Vulnerability

CVE-2024-26183
HIGH 6.5

Windows Kerberos Denial of Service Vulnerability

CVE-2024-26180
HIGH 8.0

Secure Boot Security Feature Bypass Vulnerability

CVE-2024-26179
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-26175
HIGH 7.8

Secure Boot Security Feature Bypass Vulnerability

CVE-2024-26172
HIGH 5.5

Windows DWM Core Library Information Disclosure Vulnerability

CVE-2024-26171
HIGH 6.7

Secure Boot Security Feature Bypass Vulnerability

CVE-2024-26168
HIGH 6.8

Secure Boot Security Feature Bypass Vulnerability

CVE-2024-26158
HIGH 7.8

Microsoft Install Service Elevation of Privilege Vulnerability

CVE-2024-23594
HIGH 6.4

Lenovo: CVE-2024-23594 Stack buffer overflow in Lenovo system recovery boot manager

CVE-2024-23593
HIGH 6.7

Lenovo: CVE-2024-23593 Modify Boot Manager and Escalate Privileges

CVE-2024-21447
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2024-20693
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-20678
HIGH 8.8

Remote Procedure Call Runtime Remote Code Execution Vulnerability

CVE-2024-20669
HIGH 6.7

Secure Boot Security Feature Bypass Vulnerability

CVE-2024-20665
HIGH 6.1

BitLocker Security Feature Bypass Vulnerability

CVE-2022-0001
HIGH 4.7

Intel: CVE-2022-0001 Branch History Injection

CVE-2024-30370
MEDIUM 4.3 1 app

RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected i…

CVE-2024-2616
LOW 2.7 1 app

To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects F…

CVE-2024-2614
HIGH 8.8 1 app

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2024-2612
HIGH 8.1 1 app

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code …

CVE-2024-2611
MEDIUM 5.5 1 app

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox…

CVE-2024-2610
MEDIUM 6.1 1 app

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability a…

CVE-2024-2609
MEDIUM 6.1 1 app

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerabi…

CVE-2024-2608
HIGH 8.4 1 app

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underalloc…

CVE-2024-2607
HIGH 8.1 1 app

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other opera…

CVE-2024-2605
MEDIUM 5.9 1 app

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows …

CVE-2023-5388
MEDIUM 6.5 1 app

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data…

CVE-2023-42938
HIGH 7.8 1 app

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.

CVE-2024-26197
HIGH 6.5

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2024-26190
HIGH 7.5

Microsoft QUIC Denial of Service Vulnerability

CVE-2024-26185
HIGH 6.5

Windows Compressed Folder Tampering Vulnerability

CVE-2024-26182
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-26181
HIGH 5.5

Windows Kernel Denial of Service Vulnerability