Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,430 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,430
Actively exploited
21
Publication window
2009-07-30 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,430 entries Medium Windows Clear all
CVE
CVE-2026-17739
MEDIUM 4.2

Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension…

CVE-2026-17737
MEDIUM 5.0

Use after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentiall…

CVE-2026-17736
MEDIUM 5.8

Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the rend…

CVE-2026-17734
MEDIUM 5.4

Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a cra…

CVE-2026-17733
MEDIUM 4.3

Inappropriate implementation in QUIC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML …

CVE-2026-17731
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted H…

CVE-2026-17730
MEDIUM 4.3

Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI ge…

CVE-2026-17728
MEDIUM 5.4

Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a c…

CVE-2026-17714
MEDIUM 6.5

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory vi…

CVE-2026-17707
MEDIUM 6.5

Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain pote…

CVE-2026-17706
MEDIUM 4.3

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the render…

CVE-2026-17700
MEDIUM 4.3

Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process …

CVE-2026-17696
MEDIUM 4.3

Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

CVE-2026-17693
MEDIUM 4.3

Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…

CVE-2026-17690
MEDIUM 6.5

Insufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a c…

CVE-2026-17689
MEDIUM 4.3

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium secur…

CVE-2026-17683
MEDIUM 6.5

Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from proces…

CVE-2026-17679
MEDIUM 6.5

Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer …

CVE-2026-17674
MEDIUM 6.5

Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML pag…

CVE-2026-17668
MEDIUM 6.5

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium secur…

CVE-2026-17667
MEDIUM 6.5

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium secur…

CVE-2026-17664
MEDIUM 6.5

Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process…

CVE-2026-17662
MEDIUM 4.3

Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page…

CVE-2026-17659
MEDIUM 4.2

Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to byp…

CVE-2026-16415
MEDIUM 5.4

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibo…

CVE-2026-16403
MEDIUM 6.5

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-15778
MEDIUM 6.5

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer pr…

CVE-2026-15775
MEDIUM 6.5

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Ch…

CVE-2026-15771
MEDIUM 5.3

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the rende…

CVE-2026-15770
MEDIUM 6.5

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via …

CVE-2026-15768
MEDIUM 6.5

Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted…

CVE-2026-15766
MEDIUM 6.5

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory vi…

CVE-2026-58638
MEDIUM 6.0

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

CVE-2026-58547
MEDIUM 5.5

Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-58546
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58545
MEDIUM 5.5

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

CVE-2026-58543
MEDIUM 6.3

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevat…

CVE-2026-58539
MEDIUM 6.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58535
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58533
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58528
MEDIUM 6.8

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-57982
MEDIUM 6.5

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

CVE-2026-57095
MEDIUM 6.2

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.

CVE-2026-57085
MEDIUM 5.5

Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.

CVE-2026-57084
MEDIUM 5.5

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

CVE-2026-57083
MEDIUM 5.5

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

CVE-2026-56649
MEDIUM 5.9

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to e…

CVE-2026-56184
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-56168
MEDIUM 6.5

Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.

CVE-2026-55898
MEDIUM 6.1

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM