Vulnerabilities
Tracked app vulnerabilities
3,430 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 3,430
- Actively exploited
- 21
- Publication window
- 2009-07-30 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-62720
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. |
|
CVE-2026-62718
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. |
|
CVE-2026-62716
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. |
|
CVE-2026-62715
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. |
|
CVE-2026-62714
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. |
|
CVE-2026-62709
MEDIUM 5.5
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. |
|
CVE-2026-62708
MEDIUM 6.4
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-62703
MEDIUM 5.5
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-62702
MEDIUM 6.8
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-62699
MEDIUM 6.8
Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally. |
|
CVE-2026-61936
MEDIUM 5.5
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-61933
MEDIUM 5.5
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-61928
MEDIUM 5.5
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. |
|
CVE-2026-61924
MEDIUM 6.5
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-61921
MEDIUM 6.5
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-61920
MEDIUM 6.6
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a… |
|
CVE-2026-61918
MEDIUM 6.5
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-61368
MEDIUM 5.0
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. |
|
CVE-2026-61360
MEDIUM 5.5
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. |
|
CVE-2026-61350
MEDIUM 4.6
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-61347
MEDIUM 5.5
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-61345
MEDIUM 6.5
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. |
|
CVE-2026-59138
MEDIUM 6.5
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. |
|
CVE-2026-59137
MEDIUM 5.5
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-59136
MEDIUM 5.5
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. |
|
CVE-2026-59135
MEDIUM 5.5
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-59131
MEDIUM 5.6
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. |
|
CVE-2026-59130
MEDIUM 5.6
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. |
|
CVE-2026-59128
MEDIUM 5.5
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. |
|
CVE-2026-6727
MEDIUM 5.9
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may … |
|
CVE-2026-19146
Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain poten… |
|
CVE-2026-18019
Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. … |
|
CVE-2026-18018
Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file… |
|
CVE-2026-18014
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via … |
|
CVE-2026-18010
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffi… |
|
CVE-2026-18009
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious … |
|
CVE-2026-18008
Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic… |
|
CVE-2026-18007
Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML pa… |
|
CVE-2026-18006
Inappropriate implementation in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perfo… |
|
CVE-2026-18005
Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from proces… |
|
CVE-2026-18004
Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cr… |
|
CVE-2026-18001
Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from proces… |
|
CVE-2026-17999
Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chro… |
|
CVE-2026-17998
Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perfor… |
|
CVE-2026-17996
Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via a malicio… |
|
CVE-2026-17994
Inappropriate implementation in Media in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a craf… |
|
CVE-2026-17992
Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process… |
|
CVE-2026-17988
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer pro… |
|
CVE-2026-17986
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypa… |
|
CVE-2026-17985
Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (… |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.