Vulnerabilities
Tracked app vulnerabilities
25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 25,946
- Actively exploited
- 373
- Publication window
- 1997-01-01 → 2026-09-29
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-81390
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-81389
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-81388
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-81387
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information lo… |
|
CVE-2026-81386
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-81355
HIGH 7.5
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally. |
|
CVE-2026-81354
HIGH 8.2
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-80097
HIGH 8.6
Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-80096
HIGH 8.8
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-80093
HIGH 7.0
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-80090
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-80085
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-80083
HIGH 8.8
Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally. |
|
CVE-2026-80080
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-80079
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-80075
HIGH 7.8
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-80073
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-78525
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78523
MEDIUM 5.9
Use after free in Windows DNS allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-78522
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-78521
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78520
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78519
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78518
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78517
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78516
MEDIUM 4.3
Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locall… |
|
CVE-2026-78514
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78513
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-78512
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78511
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78509
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78508
MEDIUM 4.6
Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-78506
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-78504
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78503
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-78502
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-78464
HIGH 7.0
Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-78457
HIGH 7.0
Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-78455
MEDIUM 4.3
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-78454
MEDIUM 5.5
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-78453
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-78452
MEDIUM 4.6
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-78451
MEDIUM 6.8
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-78450
HIGH 8.1
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78449
HIGH 8.1
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78448
HIGH 7.8
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-78446
MEDIUM 5.3
Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. |
|
CVE-2026-78445
CRITICAL 9.8
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78444
HIGH 8.1
Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-77911
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.