Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

11,279 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
11,279
Actively exploited
229
Publication window
2010-07-30 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

11,279 entries High Hide N/A Clear all
CVE
CVE-2024-38151
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2024-38150
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-38148
HIGH 7.5

Windows Secure Channel Denial of Service Vulnerability

CVE-2024-38147
HIGH 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-38146
HIGH 7.5

Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability

CVE-2024-38145
HIGH 7.5

Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability

CVE-2024-38144
HIGH 8.8

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2024-38143
HIGH 4.2

Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

CVE-2024-38142
HIGH 7.8

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

CVE-2024-38141
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2024-38138
HIGH 7.5

Windows Deployment Services Remote Code Execution Vulnerability

CVE-2024-38137
HIGH 7.0

Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability

CVE-2024-38136
HIGH 7.0

Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability

CVE-2024-38135
HIGH 7.8

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

CVE-2024-38134
HIGH 7.8

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2024-38133
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-38132
HIGH 7.5

Windows Network Address Translation (NAT) Denial of Service Vulnerability

CVE-2024-38131
HIGH 8.8

Clipboard Virtual Channel Extension Remote Code Execution Vulnerability

CVE-2024-38130
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-38128
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-38127
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2024-38126
HIGH 7.5

Windows Network Address Translation (NAT) Denial of Service Vulnerability

CVE-2024-38125
HIGH 7.8

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2024-38123
HIGH 4.4

Windows Bluetooth Driver Information Disclosure Vulnerability

CVE-2024-38122
HIGH 5.5

Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability

CVE-2024-38121
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-38120
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2024-38118
HIGH 5.5

Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability

CVE-2024-38117
HIGH 7.8

NTFS Elevation of Privilege Vulnerability

CVE-2024-38116
HIGH 8.8

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

CVE-2024-38115
HIGH 8.8

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

CVE-2024-38114
HIGH 8.8

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

CVE-2024-38107
HIGH 7.8 KEV

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

CVE-2024-38106
HIGH 7.0 KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-37968
HIGH 7.5

Windows DNS Spoofing Vulnerability

CVE-2024-29995
HIGH 8.1

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2024-21302
HIGH 6.7

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

CVE-2024-42219
HIGH 7.8 1 app

1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.

CVE-2024-7528
HIGH 8.8 1 app

Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Th…

CVE-2024-7527
HIGH 8.8 1 app

Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ES…

CVE-2024-7525
HIGH 9.1 1 app

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on…

CVE-2024-7522
HIGH 9.1 1 app

Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, F…

CVE-2024-7521
HIGH 9.8 1 app

Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.…

CVE-2024-7520
HIGH 8.8 1 app

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox …

CVE-2024-4607
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-36971
HIGH 7.8 KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-34743
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-34742
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-34741
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-34740
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.