Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
25,946
Actively exploited
373
Publication window
1997-01-01 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

25,946 entries
CVE
CVE-2026-77905
HIGH 7.0

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

CVE-2026-77904
HIGH 7.8

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-77901
HIGH 8.8

Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-77899
HIGH 7.0

Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.

CVE-2026-77896
MEDIUM 6.5

Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.

CVE-2026-77895
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77894
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privi…

CVE-2026-77893
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77892
MEDIUM 6.8

No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-77891
MEDIUM 6.4

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

CVE-2026-77890
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77889
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77888
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77887
MEDIUM 6.4

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

CVE-2026-77886
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77505
HIGH 8.1

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

CVE-2026-77504
HIGH 8.8

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-77503
HIGH 8.4

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

CVE-2026-77502
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77501
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77500
HIGH 7.8

Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-77499
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77498
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77495
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-77494
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77493
CRITICAL 9.8

Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2026-77492
MEDIUM 5.5

Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.

CVE-2026-77491
MEDIUM 5.5

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

CVE-2026-77489
HIGH 7.8

Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73026
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73025
CRITICAL 9.8

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-73024
HIGH 7.8

Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-73023
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73022
HIGH 7.0

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVE-2026-73021
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73020
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73019
MEDIUM 4.3

Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-73018
HIGH 8.8

Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.

CVE-2026-73017
HIGH 7.5

Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.

CVE-2026-73016
HIGH 8.8

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73015
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73014
HIGH 7.8

Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.

CVE-2026-73013
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73012
HIGH 8.8

Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.

CVE-2026-73011
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73010
CRITICAL 9.8

Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

CVE-2026-73009
CRITICAL 9.8

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVE-2026-73008
MEDIUM 5.5

Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.

CVE-2026-73007
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73006
HIGH 8.8

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM