Vulnerabilities
Tracked app vulnerabilities
3,430 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 3,430
- Actively exploited
- 21
- Publication window
- 2009-07-30 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-50312
MEDIUM 4.7
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50310
MEDIUM 4.7
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. |
|
CVE-2026-50302
MEDIUM 4.2
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-49177
MEDIUM 5.5
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. |
|
CVE-2026-48580
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-58614
MEDIUM 5.5
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-57979
MEDIUM 6.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-57976
MEDIUM 6.5
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. |
|
CVE-2026-57097
MEDIUM 6.4
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-55003
MEDIUM 6.5
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-55000
MEDIUM 6.4
Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-54997
MEDIUM 5.5
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
|
CVE-2026-54988
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-54132
MEDIUM 6.8
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-50678
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-50381
MEDIUM 5.5
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information local… |
|
CVE-2026-50350
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information lo… |
|
CVE-2026-50316
MEDIUM 5.5
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50303
MEDIUM 5.5
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-50300
MEDIUM 5.5
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-50299
MEDIUM 6.8
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-50298
MEDIUM 6.8
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-50295
MEDIUM 5.5
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-50294
MEDIUM 6.2
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-49807
MEDIUM 6.2
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-49804
MEDIUM 6.6
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-49801
MEDIUM 5.5
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. |
|
CVE-2026-49799
MEDIUM 6.5
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. |
|
CVE-2026-49794
MEDIUM 4.6
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-49180
MEDIUM 5.5
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information loca… |
|
CVE-2026-49174
MEDIUM 6.1
Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. |
|
CVE-2026-49168
MEDIUM 6.8
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-49167
MEDIUM 4.7
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-44806
MEDIUM 5.3
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-41087
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-40422
MEDIUM 5.5
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-34349
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. |
|
CVE-2026-34348
MEDIUM 6.5
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. |
|
CVE-2026-34346
MEDIUM 5.5
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. |
|
CVE-2026-34328
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-33842
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-15719
MEDIUM 5.4
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefo… |
|
CVE-2026-15718
MEDIUM 4.3
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefo… |
|
CVE-2026-15131
Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page.… |
|
CVE-2026-15130
Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML pa… |
|
CVE-2026-15128
Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a craft… |
|
CVE-2026-15127
Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a craft… |
|
CVE-2026-15124
Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML… |
|
CVE-2026-15109
Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory v… |
|
CVE-2026-15108
Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perfor… |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.