Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,601 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,601
Actively exploited
294
Publication window
2004-07-27 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,601 entries High Clear all
CVE
CVE-2026-68896
HIGH 7.8

Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-68894
HIGH 8.0

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.

CVE-2026-68893
HIGH 7.1

Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-68892
HIGH 7.8

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

CVE-2026-68890
HIGH 7.8

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

CVE-2026-68889
HIGH 7.1

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

CVE-2026-68888
HIGH 7.8

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

CVE-2026-68887
HIGH 7.5

Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.

CVE-2026-68885
HIGH 7.8

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

CVE-2026-68884
HIGH 7.0

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-68880
HIGH 8.0

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

CVE-2026-68878
HIGH 8.0

Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.

CVE-2026-68877
HIGH 7.8

Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.

CVE-2026-68876
HIGH 8.0

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-68875
HIGH 7.8

Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-68848
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-68847
HIGH 7.0

Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

CVE-2026-68846
HIGH 7.1

Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.

CVE-2026-68845
HIGH 7.8

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

CVE-2026-68844
HIGH 7.8

Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.

CVE-2026-68841
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-68840
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate priv…

CVE-2026-68838
HIGH 8.0

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-68837
HIGH 7.0

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-68835
HIGH 7.1

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.

CVE-2026-68834
HIGH 8.0

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-68832
HIGH 7.8

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-68828
HIGH 8.8

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-68827
HIGH 8.0

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.

CVE-2026-68825
HIGH 7.0

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-68824
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an autho…

CVE-2026-62813
HIGH 7.5

Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.

CVE-2026-62810
HIGH 7.8

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

CVE-2026-62759
HIGH 7.5

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

CVE-2026-62706
HIGH 8.8

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-62697
HIGH 7.8

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-62694
HIGH 7.0

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-56177
HIGH 7.8

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

CVE-2026-56172
HIGH 7.8

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50349
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz…

CVE-2026-7477
HIGH 7.8

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows…

CVE-2026-7476
HIGH 7.8

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows…

CVE-2026-5729
HIGH 7.8

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user proces…

CVE-2026-85877
HIGH · vendor

Windows Print Spooler Remote Code Execution Vulnerability

CVE-2026-83991
HIGH · vendor

Windows Cloud Files Mini Filter Driver Tampering Vulnerability

CVE-2026-83986
HIGH · vendor

Windows Biometric Service Elevation of Privilege Vulnerability

CVE-2026-83975
HIGH · vendor

Windows Biometric Service Elevation of Privilege Vulnerability

CVE-2026-81963
HIGH · vendor KEV

Windows Update Stack Elevation of Privilege Vulnerability

CVE-2026-78447
HIGH · vendor

Windows Biometric Service Elevation of Privilege Vulnerability

CVE-2026-77896
HIGH · vendor

Windows Remote Desktop Client Denial of Service Vulnerability

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM