Vulnerabilities
Tracked app vulnerabilities
15,601 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,601
- Actively exploited
- 294
- Publication window
- 2004-07-27 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-70583
HIGH · vendor
Windows Core Messaging Elevation of Privilege Vulnerability |
|
CVE-2026-69611
HIGH · vendor
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
|
CVE-2026-69549
HIGH · vendor
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
|
CVE-2026-69516
HIGH · vendor
Connected Devices Platform Service (Cdpsvc) Elevation of Privilege Vulnerability |
|
CVE-2026-69498
HIGH · vendor
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2026-69485
HIGH · vendor
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-69480
HIGH · vendor
Windows Partition Management Driver Elevation of Privilege Vulnerability |
|
CVE-2026-69478
HIGH · vendor
Windows Device Association Service Elevation of Privilege Vulnerability |
|
CVE-2026-69459
HIGH · vendor
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability |
|
CVE-2026-69401
HIGH · vendor
Audio Video Control Transport Protocol Elevation of Privilege Vulnerability |
|
CVE-2026-69384
HIGH · vendor
Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability |
|
CVE-2026-69365
HIGH · vendor
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability |
|
CVE-2026-69359
HIGH · vendor
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2026-69358
HIGH · vendor
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2026-69303
HIGH · vendor
Push Message Routing Service Information Disclosure Vulnerability |
|
CVE-2026-68850
HIGH · vendor
Microsoft Account Elevation of Privilege Vulnerability |
|
CVE-2026-62744
HIGH · vendor
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
|
CVE-2026-56198
HIGH · vendor
Microsoft Trace Data Helper Elevation of Privilege Vulnerability |
|
CVE-2026-85053
Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a… |
|
CVE-2026-85051
Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML… |
|
CVE-2026-85049
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. … |
|
CVE-2026-85048
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary c… |
|
CVE-2026-85046
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C… |
|
CVE-2026-85045
Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C… |
|
CVE-2026-84351
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbi… |
|
CVE-2026-84350
Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside th… |
|
CVE-2026-84349
Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code … |
|
CVE-2026-84347
Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page… |
|
CVE-2026-84335
Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged so… |
|
CVE-2026-84334
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sand… |
|
CVE-2026-84326
Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … |
|
CVE-2026-84642
HIGH 7.5
The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnam… |
|
CVE-2026-84641
HIGH 7.5
A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to pr… |
|
CVE-2026-84640
HIGH 7.5
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.… |
|
CVE-2026-84145
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or … |
|
CVE-2026-84144
Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevan… |
|
CVE-2026-84132
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.… |
|
CVE-2026-84131
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Fir… |
|
CVE-2026-84130
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.… |
|
CVE-2026-84128
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
|
CVE-2026-84123
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, … |
|
CVE-2026-49913
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-49744
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-49743
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-4967
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-45529
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-45518
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-45517
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-45203
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-45202
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.