Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,770 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,770
Actively exploited
214
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,770 entries Windows Hide N/A Clear all
CVE
CVE-2023-36395
HIGH 7.5

Windows Deployment Services Denial of Service Vulnerability

CVE-2023-36394
HIGH 7.0

Windows Search Service Elevation of Privilege Vulnerability

CVE-2023-36393
HIGH 7.8

Windows User Interface Application Core Remote Code Execution Vulnerability

CVE-2023-36392
HIGH 7.5

DHCP Server Service Denial of Service Vulnerability

CVE-2023-36047
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2023-36046
HIGH 7.1

Windows Authentication Denial of Service Vulnerability

CVE-2023-36036
HIGH 7.8 KEV

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-36033
HIGH 7.8 KEV

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2023-36028
HIGH 9.8

Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

CVE-2023-36025
HIGH 8.8 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-36017
HIGH 8.8

Windows Scripting Engine Memory Corruption Vulnerability

CVE-2023-31102
HIGH 7.8 1 app

Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

CVE-2023-5732
MEDIUM 6.5 1 app

An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affect…

CVE-2023-5730
CRITICAL 9.8 1 app

Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2023-5728
HIGH 7.5 1 app

During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerab…

CVE-2023-5727
MEDIUM 6.5 1 app

The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. …

CVE-2023-5726
MEDIUM 4.3 1 app

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. …

CVE-2023-5725
MEDIUM 4.3 1 app

A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulner…

CVE-2023-5724
HIGH 7.5 1 app

Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119…

CVE-2023-5721
MEDIUM 4.3 1 app

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This …

CVE-2023-44487
HIGH 7.5 KEV

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w…

CVE-2023-41774
CRITICAL 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41773
CRITICAL 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41772
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2023-41771
CRITICAL 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41770
CRITICAL 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41769
CRITICAL 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41768
CRITICAL 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41767
CRITICAL 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41766
HIGH 7.8

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

CVE-2023-41765
CRITICAL 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-38545
HIGH

Hackerone: CVE-2023-38545 SOCKS5 heap buffer overflow

CVE-2023-38171
HIGH 7.5

Microsoft QUIC Denial of Service Vulnerability

CVE-2023-38166
CRITICAL 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-38159
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2023-38039
LOW

Hackerone: CVE-2023-38039 HTTP headers eat all memory

CVE-2023-36902
HIGH 7.0

Windows Runtime Remote Code Execution Vulnerability

CVE-2023-36776
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2023-36743
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2023-36732
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2023-36731
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2023-36729
HIGH 7.8

Named Pipe File System Elevation of Privilege Vulnerability

CVE-2023-36726
HIGH 7.8

Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability

CVE-2023-36725
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-36724
HIGH 5.5

Windows Power Management Service Information Disclosure Vulnerability

CVE-2023-36723
HIGH 7.8

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2023-36722
HIGH 4.4

Active Directory Domain Services Information Disclosure Vulnerability

CVE-2023-36721
HIGH 7.0

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2023-36720
HIGH 7.5

Windows Mixed Reality Developer Tools Denial of Service Vulnerability

CVE-2023-36718
CRITICAL 7.8

Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability