Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,601 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,601
Actively exploited
294
Publication window
2004-07-27 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,601 entries High Clear all
CVE
CVE-2026-69338
HIGH 7.1

Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69337
HIGH 7.1

Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.

CVE-2026-69336
HIGH 7.1

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69335
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69334
HIGH 8.8

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-69333
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69332
HIGH 8.0

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69331
HIGH 7.0

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-69329
HIGH 7.5

Out-of-bounds read in BranchCache allows an unauthorized attacker to deny service over a network.

CVE-2026-69328
HIGH 7.8

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-69325
HIGH 8.1

Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.

CVE-2026-69324
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.

CVE-2026-69323
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69322
HIGH 8.0

Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

CVE-2026-69319
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevat…

CVE-2026-69314
HIGH 7.1

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69313
HIGH 7.1

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69312
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-69311
HIGH 7.0

Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69310
HIGH 7.0

Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-69309
HIGH 7.0

Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-69307
HIGH 7.8

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69305
HIGH 7.1

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

CVE-2026-69301
HIGH 8.0

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

CVE-2026-69300
HIGH 7.0

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-69299
HIGH 7.0

Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.

CVE-2026-69298
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69296
HIGH 7.1

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69295
HIGH 7.8

Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69293
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69292
HIGH 7.0

Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69291
HIGH 8.8

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-69290
HIGH 7.8

Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

CVE-2026-69289
HIGH 7.8

Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.

CVE-2026-69287
HIGH 7.0

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-69284
HIGH 7.8

Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.

CVE-2026-69283
HIGH 7.8

Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69281
HIGH 7.0

Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-69280
HIGH 7.0

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-69279
HIGH 7.0

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69277
HIGH 7.8

Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.

CVE-2026-69275
HIGH 7.0

Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69274
HIGH 7.1

Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.

CVE-2026-69272
HIGH 7.1

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69271
HIGH 8.0

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69270
HIGH 7.8

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69269
HIGH 7.8

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

CVE-2026-69266
HIGH 8.8

Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-69265
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-68897
HIGH 7.0

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM