Vulnerabilities
Tracked app vulnerabilities
3,429 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 3,429
- Actively exploited
- 21
- Publication window
- 2009-07-30 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-70328
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-70327
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-70318
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-70310
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-70304
MEDIUM 6.7
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68819
MEDIUM 5.9
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-68809
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-68808
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-68802
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-68799
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-68797
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-66810
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-66809
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-66806
Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-65799
MEDIUM 6.7
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65798
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65797
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65795
MEDIUM 6.7
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65794
MEDIUM 6.5
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-65785
MEDIUM 6.5
Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. |
|
CVE-2026-65784
MEDIUM 5.5
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-65777
MEDIUM 5.3
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network. |
|
CVE-2026-65662
MEDIUM 5.5
Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. |
|
CVE-2026-64917
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-63531
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-63530
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-63528
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-63521
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-62887
MEDIUM 5.5
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-62883
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62882
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-62881
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62814
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. |
|
CVE-2026-62798
MEDIUM 5.5
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-62796
MEDIUM 5.5
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-62793
MEDIUM 5.5
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-62786
MEDIUM 5.5
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-62782
MEDIUM 6.5
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-62775
MEDIUM 5.5
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. |
|
CVE-2026-62769
MEDIUM 6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62757
MEDIUM 5.3
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-62750
MEDIUM 6.5
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. |
|
CVE-2026-62746
MEDIUM 5.5
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-62745
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. |
|
CVE-2026-62743
MEDIUM 5.5
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-62742
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. |
|
CVE-2026-62740
MEDIUM 5.5
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-62738
MEDIUM 5.5
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. |
|
CVE-2026-62730
MEDIUM 5.5
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-62720
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.