Vulnerabilities
Tracked app vulnerabilities
15,601 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,601
- Actively exploited
- 294
- Publication window
- 2004-07-27 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-69619
HIGH 8.0
Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69617
HIGH 7.0
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69613
HIGH 7.0
Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69612
HIGH 7.8
Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69610
HIGH 7.0
Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69608
HIGH 7.8
Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69607
HIGH 7.5
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69606
HIGH 7.0
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69605
HIGH 7.0
Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69604
HIGH 7.8
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69603
HIGH 8.8
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. |
|
CVE-2026-69602
HIGH 7.1
Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69601
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69600
HIGH 7.0
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69599
HIGH 7.5
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-69598
HIGH 8.8
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69597
HIGH 7.1
Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69594
HIGH 7.8
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69593
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69592
HIGH 7.8
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69589
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69588
HIGH 7.5
Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69587
HIGH 7.5
Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-69585
HIGH 7.8
Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69584
HIGH 7.8
Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69583
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69582
HIGH 7.8
Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69581
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69580
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69578
HIGH 7.0
Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69576
HIGH 7.8
Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69575
HIGH 7.0
Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69574
HIGH 7.0
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69573
HIGH 7.0
Use after free in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69571
HIGH 7.8
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69567
HIGH 7.0
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69564
HIGH 7.0
Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69563
HIGH 7.0
Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69561
HIGH 7.8
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69560
HIGH 7.0
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69556
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69553
HIGH 7.1
Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69551
HIGH 8.8
Use after free in Windows DNS allows an authorized attacker to execute code over a network. |
|
CVE-2026-69547
HIGH 8.8
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. |
|
CVE-2026-69546
HIGH 8.1
Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-69544
HIGH 7.8
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69542
HIGH 7.8
Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69541
HIGH 7.8
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69540
HIGH 7.0
Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69539
HIGH 7.5
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.