Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,601 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,601
Actively exploited
294
Publication window
2004-07-27 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,601 entries High Clear all
CVE
CVE-2026-70583
HIGH · vendor

Windows Core Messaging Elevation of Privilege Vulnerability

CVE-2026-69611
HIGH · vendor

Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability

CVE-2026-69549
HIGH · vendor

Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability

CVE-2026-69516
HIGH · vendor

Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability

CVE-2026-69498
HIGH · vendor

Windows Win32k Elevation of Privilege Vulnerability

CVE-2026-69485
HIGH · vendor

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-69480
HIGH · vendor

Windows Partition Management Driver Elevation of Privilege Vulnerability

CVE-2026-69478
HIGH · vendor

Windows Device Association Service Elevation of Privilege Vulnerability

CVE-2026-69459
HIGH · vendor

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

CVE-2026-69401
HIGH · vendor

Audio Video Control Transport Protocol Elevation of Privilege Vulnerability

CVE-2026-69384
HIGH · vendor

Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability

CVE-2026-69365
HIGH · vendor

Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability

CVE-2026-69359
HIGH · vendor

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2026-69358
HIGH · vendor

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2026-69303
HIGH · vendor

Push Message Routing Service Information Disclosure Vulnerability

CVE-2026-68850
HIGH · vendor

Microsoft Account Elevation of Privilege Vulnerability

CVE-2026-62744
HIGH · vendor

Microsoft Windows Media Foundation Remote Code Execution Vulnerability

CVE-2026-56198
HIGH · vendor

Microsoft Trace Data Helper Elevation of Privilege Vulnerability

CVE-2026-85053
HIGH 8.8

Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a…

CVE-2026-85051
HIGH 8.8

Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML…

CVE-2026-85049
HIGH 8.8

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. …

CVE-2026-85048
HIGH 8.3

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary c…

CVE-2026-85046
HIGH 8.8 KEV

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C…

CVE-2026-85045
HIGH 7.5

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C…

CVE-2026-84351
HIGH 8.3

Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbi…

CVE-2026-84350
HIGH 8.8

Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside th…

CVE-2026-84349
HIGH 8.3

Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code …

CVE-2026-84347
HIGH 8.8

Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page…

CVE-2026-84335
HIGH 8.3

Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged so…

CVE-2026-84334
HIGH 8.1

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sand…

CVE-2026-84326
HIGH 8.8

Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

CVE-2026-84642
HIGH 7.5

The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnam…

CVE-2026-84641
HIGH 7.5

A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to pr…

CVE-2026-84640
HIGH 7.5

A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.…

CVE-2026-84145
HIGH 7.5

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or …

CVE-2026-84144
HIGH 7.5

Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevan…

CVE-2026-84132
HIGH 7.5

Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.…

CVE-2026-84131
HIGH 8.8

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Fir…

CVE-2026-84130
HIGH 7.5

Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.…

CVE-2026-84128
HIGH 8.8

Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

CVE-2026-84123
HIGH 8.8

Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, …

CVE-2026-49913
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-49744
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-49743
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-4967
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45529
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45518
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45517
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45203
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-45202
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM